1. Scope & Applicability
This Children's Online Privacy Protection Act (COPPA) Compliance Policy outlines how CloudNexus, Inc. ("CloudNexus," "we," "us," or "our") handles personal information in compliance with the COPPA and related child privacy regulations. This policy applies to our cloud infrastructure, hosting services, API platforms, and associated management tools.
CloudNexus operates primarily as a Business-to-Business (B2B) cloud infrastructure provider. Our services are designed for developers, IT administrators, and enterprise clients, and are not directed at children under the age of 13. However, we recognize that our customers may deploy applications, websites, or services that interact with younger audiences. This policy clarifies our role, your responsibilities, and the safeguards we maintain to support a compliant ecosystem.
2. Age Requirements
CloudNexus services require users to be at least 18 years of age, or the age of legal majority in their jurisdiction, to register for an account, enter into service agreements, or access administrative features.
Important: We do not knowingly collect, maintain, or use personal information from children under 13. If you are under 18, you may use our services only under the direct supervision and approval of a parent or legal guardian.
Our registration process includes age verification mechanisms. If we discover that an account has been created by a minor without proper authorization, we will promptly suspend access and delete associated data unless required to retain it for legal or security reasons.
3. Parental Rights & Consent
While CloudNexus does not directly market to children, we support parental rights as defined under COPPA and global child privacy frameworks:
- Review & Access: Parents or guardians may request access to personal data collected through customer applications hosted on our platform. We will cooperate with valid legal requests or customer-forwarded parental consent forms.
- Data Deletion: Upon verified parental request, we will assist in the removal of personal information from inactive or terminated customer deployments, subject to data retention laws.
- Consent Verification: We provide secure APIs and compliance documentation to help customers implement verifiable parental consent (VPC) mechanisms within their own applications.
- Refusal of Collection: Parents may opt their children out of data collection. CloudNexus respects downstream opt-out signals and does not override customer-configured privacy settings.
4. Customer Responsibilities
As a service provider, CloudNexus acts as a data processor for information hosted on our infrastructure. Customers deploying services that collect data from users under 13 retain the primary responsibility as data controllers under COPPA. You agree to:
- Implement appropriate age gates, parental consent workflows, and privacy notices compliant with applicable laws.
- Configure CloudNexus security groups, encryption, and access controls to protect sensitive data.
- Respond to parental requests for access, modification, or deletion of personal information.
- Audit third-party SDKs, analytics tools, or integrations for COPPA compliance.
- Notify CloudNexus immediately if a data breach or compliance incident involving minor's data occurs.
Failure to comply with COPPA obligations may result in service suspension in accordance with our Acceptable Use Policy and Terms of Service.
5. Data Security & Retention
CloudNexus maintains industry-leading security standards to protect all data hosted on our infrastructure, including any personal information related to minors:
- Encryption: AES-256 at rest, TLS 1.3+ in transit, with optional customer-managed keys (CMK).
- Access Controls: Role-based access control (RBAC), multi-factor authentication (MFA), and audit logging for all administrative actions.
- Network Security: DDoS mitigation, Web Application Firewalls (WAF), and isolated tenant environments.
- Retention & Deletion: Data is retained only as long as necessary to provide services or comply with legal obligations. Upon service termination or valid deletion request, data is cryptographically erased within 30 days.
6. Compliance Support & Tools
We are committed to empowering our customers to build child-safe digital experiences. CloudNexus offers:
- Compliance Dashboards: Real-time visibility into data flows, access logs, and retention policies.
- API-Driven Consent Management: Webhooks and endpoints to integrate with third-party consent management platforms (CMPs).
- Regional Data Residency: Deploy workloads in specific geographic regions to comply with localized privacy regulations.
- Documentation & Guidance: Technical guides on implementing age verification, data minimization, and secure storage practices.
For enterprise clients requiring dedicated compliance architecture reviews, our Trust & Safety team offers paid consultation services.
7. Policy Updates
We may update this COPPA Compliance Policy to reflect changes in legislation, technology, or our service offerings. Significant updates will be communicated via email to account administrators and posted on this page with a revised effective date. Continued use of CloudNexus services constitutes acceptance of the updated policy.
8. Contact Information
If you have questions about this policy, suspect unauthorized data collection involving minors, or wish to exercise parental rights regarding data hosted on CloudNexus infrastructure, please contact our Privacy & Compliance Team:
CloudNexus Privacy & Compliance Office
Email: coppa@cloudnexus.io
Mail: CloudNexus Inc., Attn: COPPA Compliance, 100 Cloud Drive, Suite 400, San Francisco, CA 94107, USA
For urgent compliance or safety concerns, please include "COPPA INQUIRY" in your subject line. We respond to all verified requests within 15 business days.