How We Use Your Data

Last updated: November 15, 2025

What We Collect

CloudNexus only collects data that is strictly necessary to provide, secure, and improve our cloud infrastructure services. We do not collect unnecessary personal information.

  • Account Information: Name, email address, company name, and contact details required for registration and authentication.
  • Billing & Payment Data: Payment method details, invoices, and transaction history (processed securely via PCI-compliant partners).
  • Usage & Infrastructure Metrics: CPU, memory, storage, and network utilization data from your deployed instances to ensure performance and billing accuracy.
  • Technical Logs: IP addresses, browser/OS information, API request logs, and error reports for debugging and security monitoring.
  • Support Communications: Messages, tickets, and calls exchanged with our engineering and support teams.

How We Use Your Data

We use your data exclusively for the following operational, security, and service-related purposes:

  • Service Delivery: Provisioning, managing, and maintaining your cloud infrastructure, VMs, storage, and networking resources.
  • Billing & Accounting: Generating invoices, processing payments, and enforcing fair-use policies.
  • Security & Fraud Prevention: Detecting unauthorized access, mitigating DDoS attacks, verifying identities, and complying with threat intelligence standards.
  • Performance Optimization: Analyzing aggregated, anonymized usage patterns to improve latency, scaling algorithms, and regional load balancing.
  • Communication: Sending critical service notices, maintenance windows, security alerts, and responding to support requests. Marketing communications are opt-in only.
  • Legal & Compliance: Meeting regulatory obligations, retaining audit trails, and responding to lawful government requests.

Data Sharing & Third Parties

We do not sell, rent, or trade your personal data. We only share information when strictly necessary:

  • Service Providers: Payment gateways, email delivery services, and backup storage partners bound by strict data processing agreements (DPAs).
  • Infrastructure Partners: Colocation facilities and network providers required to maintain physical security and connectivity (access is strictly limited and logged).
  • Legal Requirements: When compelled by valid subpoenas, court orders, or to prevent imminent harm/fraud. We always notify users where legally permitted.
  • Business Transfers: In the event of a merger or acquisition, data will be transferred subject to the same privacy obligations outlined in this policy.
Note: All third-party processors are vetted for ISO 27001 and SOC 2 Type II compliance. Full vendor lists are available upon request.

Storage & Security

Your data is protected by enterprise-grade security controls across the entire lifecycle:

  • Encryption: AES-256 at rest and TLS 1.3 in transit. Customer data keys can be managed via our KMS integration.
  • Access Controls: Role-based access control (RBAC), multi-factor authentication (MFA), and zero-trust network architecture.
  • Infrastructure Hardening: Regular penetration testing, vulnerability scanning, automated patch management, and immutable audit logs.
  • Data Residency: You can select the geographic region for your workloads. We do not transfer data across borders without explicit consent or legal necessity.

Retention & Deletion

We retain data only as long as necessary to fulfill the purposes outlined in this policy:

  • Active Accounts: Retained for the duration of your subscription.
  • Terminated Accounts: Infrastructure data is securely wiped within 30 days. Billing and legal records are retained for 7 years per tax/compliance requirements.
  • Logs & Analytics: Aggregated, anonymized usage data may be retained indefinitely for service improvement. Raw logs are purged after 90 days.

Upon request, we will permanently delete your personal data from active systems, subject to legal retention obligations.

Your Rights & Choices

Depending on your jurisdiction, you may have the following rights regarding your data:

  • Access & Portability: Request a copy of your personal data in a machine-readable format.
  • Correction: Update or correct inaccurate information via your dashboard or support ticket.
  • Deletion: Request erasure of your data, except where legally required to retain.
  • Opt-Out: Unsubscribe from marketing communications at any time using the link in emails or dashboard preferences.
  • Restrict Processing: Limit how we use your data pending verification of a request.
GDPR/CCPA Compliance: We maintain a comprehensive Data Processing Agreement (DPA) for EU and California residents. Contact our DPO team to access it.

Contact Our Data Protection Team

If you have questions about this policy, wish to exercise your rights, or need to report a data concern, please reach out to our dedicated privacy team:

CloudNexus Data Protection Office

📧 privacy@cloudnexus.com

🌐 Full Privacy Policy & DPA

📍 100 Infrastructure Way, Suite 400, San Francisco, CA 94107, USA

We respond to all valid requests within 30 business days.