1. Scope & Applicability
This policy applies to all CloudNexus cloud infrastructure services, including virtual private servers (VPS), managed Kubernetes, object storage, global CDN, and managed databases. All customers, partners, and third-party integrators interacting with CloudNexus infrastructure must comply with the requirements outlined herein.
Last Updated: November 15, 2024
Governing Law: Delaware, United States (with region-specific data residency options available)
2. Data Protection & Privacy Frameworks
CloudNexus processes personal data in strict compliance with applicable data protection legislation. We maintain a comprehensive Data Processing Agreement (DPA) framework aligned with the following regulations:
- GDPR (EU/EEA): Lawful basis for processing, Data Subject Access Request (DSAR) workflows, Right to Erasure, Data Protection Impact Assessments (DPIA) available upon request.
- CCPA/CPRA (California): Notice at Collection, Opt-Out mechanisms for sale/sharing, Verifiable Consumer Requests, and Service Provider contracts.
- PIPEDA (Canada) & LGPD (Brazil): Cross-border data transfer safeguards, consent management, and breach notification protocols.
All customer data is encrypted at rest (AES-256) and in transit (TLS 1.3). CloudNexus acts as a Data Processor where customer data is involved, and customers retain full Data Controller responsibilities.
3. Security & Certification Standards
Our infrastructure undergoes continuous third-party auditing and maintains the following certifications:
| Standard | Scope | Frequency | Status |
|---|---|---|---|
| ISO 27001:2022 | Information Security Management System | Annual | ✅ Certified |
| SOC 2 Type II | Security, Availability, Confidentiality | Annual | ✅ Certified |
| PCI DSS v4.0 | Payment Card Data Processing Environments | Annual + QSA Scan | ✅ Compliant |
| HIPAA BAA | Protected Health Information Workloads | Per Contract | ✅ Available |
Penetration testing is conducted quarterly by accredited third-party firms. Vulnerability disclosures follow our coordinated disclosure policy and bug bounty program.
4. Data Residency & Sovereignty
CloudNexus supports strict data residency requirements. Customers may designate specific geographic regions for data storage and processing. Cross-border data transfers are only permitted where:
- Explicit customer authorization is provided in writing
- Standard Contractual Clauses (SCCs) or equivalent legal safeguards are executed
- Applicable export controls and trade regulations are satisfied
Infrastructure is isolated per region. Shared tenancy models maintain logical separation with encryption keys managed under customer control (BYOK/HYOK supported).
5. Service Level & Operational Requirements
CloudNexus guarantees infrastructure availability and performance under the following operational standards:
- Uptime SLA: 99.999% monthly availability for core infrastructure components
- Incident Response: Tier-1 response within 15 minutes, Tier-2 within 45 minutes, full post-mortem within 5 business days
- Change Management: Zero-impact deployment windows, 30-day advance notice for major maintenance, rollback capabilities guaranteed
- Disaster Recovery: RTO ≤ 4 hours, RPO ≤ 15 minutes for managed storage and database services
6. Accessibility & Regulatory Standards
CloudNexus management console, documentation, and customer support interfaces comply with:
- WCAG 2.1 Level AA
- Section 508 (U.S. Federal)
- EN 301 549 / European Accessibility Act (EAA)
Accessibility testing is integrated into our CI/CD pipeline. Audit reports and VPAT documentation are available upon request.
7. Shared Responsibility Model & Customer Obligations
Cloud infrastructure security follows a shared responsibility framework:
Customer Responsibilities (Security IN the Cloud): Instance configuration, IAM policies, application-layer security, data encryption keys (if not using CloudNexus KMS), compliance of workloads, and access management.
Customers must maintain up-to-date security configurations, rotate credentials regularly, and promptly address vulnerability notifications. Non-compliance with security best practices may void SLA credits.
8. Audit Rights & Compliance Reviews
Enterprise customers may request compliance audit access under the following conditions:
- Advance notice of 10 business days
- Execution of a mutual NDA and audit scope agreement
- Auditors must be accredited and independent
- Findings are shared within 15 business days
Annual compliance reviews are conducted internally and validated by our independent certifying bodies. Updated audit reports are published quarterly on the Trust Center.
⚖️ Legal Disclaimer
This document outlines CloudNexus' compliance framework and operational requirements for informational purposes only. It does not constitute legal advice. Regulatory requirements vary by jurisdiction, industry, and use case. Customers are responsible for ensuring their deployment of CloudNexus services complies with applicable local, state, and federal laws. For contractual compliance documentation, audit reports, or DPA execution, please contact legal@cloudnexus.io.