1. Introduction

At CloudNexus, we recognize that trust is the foundation of modern cloud infrastructure. We process data solely to deliver, secure, and optimize our hosting and cloud services. This policy outlines our data handling practices in alignment with GDPR, CCPA, and SOC 2 Type II standards.

Note: This document applies to all customers, administrators, and end-users interacting with CloudNexus infrastructure, APIs, and support channels.

2. What Data We Collect

We only collect data necessary to provide, maintain, and improve our services. Categories include:

  • Account & Billing Information: Email, company name, payment details (processed securely via PCI-DSS compliant providers), and subscription preferences.
  • Infrastructure Metadata: Resource usage metrics, deployment logs, API call patterns, and configuration settings required for service operation.
  • Security & Compliance Data: IP addresses, authentication events, access logs, and threat detection signals used exclusively for infrastructure protection.
  • Communication Records: Support tickets, email correspondence, and optional feedback submitted through our help center.

3. How We Use Your Data

Service Delivery & Optimization

We use infrastructure metrics to automatically scale resources, balance traffic across global nodes, and ensure 99.999% uptime SLA compliance. Performance data is anonymized and aggregated before analysis.

Security & Threat Mitigation

Authentication logs and network traffic patterns are monitored in real-time to detect DDoS attacks, unauthorized access attempts, and anomalous behavior. This data never leaves our secure monitoring environment.

Billing & Account Management

Usage metrics are correlated with billing cycles to generate accurate invoices. Payment data is tokenized and never stored on our primary servers.

Communication & Support

Account emails and support submissions are used to respond to inquiries, send critical security alerts, and notify you of service maintenance windows.

4. Data Sharing & Third Parties

We do not sell, rent, or trade your personal data. Limited sharing occurs only under the following conditions:

  • Infrastructure Partners: Network providers and hardware vendors who require anonymized routing data to maintain global connectivity.
  • Legal Compliance: When required by valid legal process, government subpoena, or to protect the rights, property, or safety of CloudNexus and our users.
  • Business Transfers: In the event of a merger or acquisition, data will be transferred in accordance with this privacy policy.

All third-party vendors are bound by strict data processing agreements (DPAs) and undergo annual security audits.

5. Security & Storage

Your data is protected using enterprise-grade safeguards:

  • Encryption: AES-256 at rest, TLS 1.3 in transit, and optional customer-managed keys (CMK) for storage volumes.
  • Access Controls: Role-based access control (RBAC), multi-factor authentication (MFA), and principle of least privilege for all internal systems.
  • Physical Security: All data centers are ISO 27001 certified with 24/7 surveillance, biometric access, and environmental controls.
  • Audits: Continuous SOC 2 Type II monitoring, quarterly penetration testing, and transparent public status reporting.

6. Retention & Deletion

We retain data only as long as necessary to fulfill its purpose:

  • Active Accounts: Data is retained while your account is active.
  • Inactive Accounts: After 12 months of inactivity, personal data is anonymized or securely deleted.
  • Logs & Security Events: Retained for 90 days for compliance and forensic analysis, then automatically purged.
  • Billing Records: Kept for 7 years to meet tax and financial regulations.

You may request immediate deletion of non-essential data through your account dashboard or by contacting our privacy team.

7. Your Rights & Choices

Depending on your jurisdiction, you may have the right to:

  • Access, correct, or export your personal data
  • Request deletion of account and associated metadata
  • Opt out of non-essential communications
  • Withdraw consent for data processing where applicable
  • Lodge a complaint with a supervisory authority

To exercise these rights, use the Privacy Controls section in your CloudNexus dashboard or email our Data Protection Officer.

8. Contact Us

For questions, concerns, or formal requests regarding this data usage policy, please reach out to our compliance team:

Email: privacy@cloudnexus.io
Mailing Address: CloudNexus Inc., Privacy & Compliance Dept., 100 Cloud Drive, Suite 400, San Francisco, CA 94107
Response Time: Within 5 business days

We are committed to maintaining transparent, secure, and compliant data practices across all our cloud infrastructure services.