CloudNexus maintains a transparent list of all third-party service providers that process customer data on our behalf. All subprocessors are bound by strict Data Processing Agreements (DPAs) and undergo regular security assessments.
| Vendor | Service Category | Location(s) | Data Processed | Effective Date | Transfer Mechanism | Status |
|---|---|---|---|---|---|---|
|
Amazon Web Services (AWS)
aws.amazon.com
|
Cloud Compute & Object Storage | US-East, EU-West | Account data, telemetry, backup snapshots | 2019-04-12 | SCCs / Adequacy Decision | ● Active |
|
Cloudflare Inc.
cloudflare.com
|
CDN, WAF, DDoS Mitigation | Global Edge | IP addresses, HTTP headers, access logs | 2020-01-15 | SCCs | ● Active |
|
Datadog, Inc.
datadoghq.com
|
Monitoring & Observability | US, EU | Metrics, logs, trace data, metadata | 2021-06-22 | SCCs / Data Residency Controls | ● Active |
|
Stripe, Inc.
stripe.com
|
Payment Processing | Global | Billing info, tokenized payment data | 2019-08-10 | SCCs / PCI DSS L1 | ● Active |
|
Twilio Inc.
twilio.com
|
Communication Services (SMS/Email) | US, EU, APAC | Contact info, message logs, OTPs | 2020-11-03 | SCCs | ● Active |
|
GitHub (Microsoft)
github.com
|
Collaboration & CI/CD | Global | Repository data, build logs, metadata | 2021-02-18 | SCCs | ● Active |
|
Snyk Ltd.
snyk.io
|
Application Security & SBOM | EU, US | Dependency manifests, vulnerability scans | 2022-05-14 | SCCs | ● Active |
|
Redis Ltd.
redis.io
|
Managed In-Memory Data Store | Multi-Region | Session data, cache payloads, keys | 2022-09-01 | SCCs / Data Residency | ● Active |
CloudNexus processes customer data in strict accordance with GDPR, CCPA, SOC 2 Type II, and ISO 27001 standards. All subprocessors are required to:
Per our Terms of Service and DPA, CloudNexus will provide at least 30 days advance notice before adding, removing, or materially changing any subprocessor. Customers may opt-out of new subprocessors by contacting our Data Protection Officer within the notice period, subject to service availability constraints.
All cross-border data transfers are governed by the EU Standard Contractual Clauses (SCCs). Where applicable, we supplement SCCs with technical and organizational measures (TOMs), including end-to-end encryption, tokenization, and regional data residency controls.
For compliance inquiries, DPA requests, or subprocessor concerns, please contact our Data Protection team directly.
✉️ Contact Data Protection Officer