NimbusNexus
Legal · Privacy Policy

Privacy Policy

How Fortlab Corporation collects, uses, shares, and protects personal information when you use NimbusNexus. We don't sell your data and we don't train AI on Customer Data.

VERSION
2.0
EFFECTIVE
Pending
LAST CHANGE
Major rewrite
REVIEW CYCLE
Quarterly
NEW · v2.0Major rewrite, published with Terms v2.0. Adds detailed processing-purposes breakdown, GDPR Art. 22 commitments around automated fraud detection, full transfer-mechanism list, and per-jurisdiction rights coverage (EEA/UK, California, other US states, APAC regimes).
View summary →
Plain-English version

This Privacy Policy describes how Fortlab Corporation, operator of the NimbusNexus™ cloud service (collectively, "Fortlab", "we", "us"), collects, uses, shares, and protects personal information in connection with the products, services, websites, and APIs offered under the NimbusNexus brand (the "Service"). This Policy works alongside the Terms of Service at /terms-of-service and, for customers whose use of the Service is subject to the EU or UK General Data Protection Regulation, the Data Processing Addendum at /dpa. If there is any conflict between this Policy and the DPA on matters within the DPA's scope, the DPA controls.

01

Quick summary

IN PLAIN ENGLISH

We collect what we need to run NimbusNexus and bill you accurately. We don't sell your personal information. We don't train AI models on Customer Data. You can ask us to access, correct, export, or delete your data, and we'll respond within the timelines required by your local law. Questions go to [email protected].

Scope. This Policy covers personal information we process when you visit our websites, create an account, use the Service, or contact us. It does not cover the contents of workloads you run on the Service ("Customer Data") in the role of a processor — that processing is governed by the Terms of Service and, where applicable, the DPA.

02

Information we collect

We collect personal information in three ways: information you provide to us, information we collect automatically, and information we receive from third parties.

Information you provide. Account information including your name, email address, billing address, and (where you are an enterprise contact) company name and role. Payment information processed by our payment provider — we receive a token and the last four digits, but we do not store full payment card numbers. Communications you send us, including support tickets, abuse reports, and feedback. Identity verification information where required for sanctioned-jurisdiction screening or higher-tier accounts.

Information collected automatically. Technical data including IP address, browser type, operating system, device identifiers, and pages or API endpoints accessed. Usage data including the resources you deploy, metering data used for billing, and aggregated performance data. Cookies and similar technologies as described in §9.

Information from third parties. Information from your single sign-on provider if you use SSO. Fraud prevention and identity verification signals from our compliance vendors. Publicly available information about your company where you sign up with a business email.

What we do not collect. We do not collect biometric data, special category data under GDPR Art. 9 (e.g. health, racial or ethnic origin, political opinions, religious beliefs), or data of any kind that you have not provided to us or that has not been generated by your interaction with the Service.

03

How we use your information

IN PLAIN ENGLISH

To run the Service, bill you, support you, keep things secure, and (with your consent) tell you about new features.

Service provision. To create and manage your account, provision compute and storage resources, meter usage, and provide support.

Billing and payments. To process payments and manage disputes.

Fraud and abuse detection. To detect, prevent, and respond to fraudulent activity, payment fraud, account takeover, and abuse of the Service. This involves automated analysis of signals such as IP address, device characteristics, billing information, and usage patterns. Lower-risk signals may trigger automated actions (e.g. rate-limiting a specific API endpoint, requiring re-authentication, requesting additional verification). Higher-impact decisions — including account suspension or termination — are reviewed by a human before being taken. See §4 for your rights in relation to this processing.

Communications. To respond to your inquiries, send service-related notices (e.g. security incidents, billing changes, scheduled maintenance), and — only with your consent or where lawful under your local law — to send product updates and marketing.

Pricing-page region default. When you visit the /pricing page, our CDN derives a country code from your IP address and exposes it to our edge proxy as a request header. We use that country code, transiently, to pre-select a default data-centre region in the pricing dropdown (for example, a visitor from Germany lands on Frankfurt pricing). We do not see the raw IP address at this layer, we do not log or store the country code, and no cookie is set. You can override the default with one click; the override persists as a `?region=` URL parameter. Legal basis: legitimate interest in providing a useful default (GDPR Art. 6(1)(f)). The processing is limited to the marketing site and is not applied to logged-in customers.

Security. To detect, investigate, and respond to security incidents.

Service improvement. To understand how the Service is used in aggregate so we can improve it. We do not use Customer Data for this purpose.

Legal compliance. To comply with applicable law, respond to lawful requests from public authorities, and enforce our agreements.

Corporate transactions. In connection with a merger, acquisition, financing, or sale of assets, subject to confidentiality protections and continued application of this Policy.

What we do not do. We do not sell your personal information. We do not "share" your personal information for cross-context behavioral advertising as defined under California law. We do not use Customer Data to train or improve any machine learning models.

04

Legal bases for processing (EEA, UK, Switzerland)

If you are located in the European Economic Area, the United Kingdom, or Switzerland, we process your personal data under the following lawful bases:

Contract (GDPR Art. 6(1)(b)). Most processing related to providing the Service to you, billing, and account management is necessary to perform our contract with you.

Legal obligation (GDPR Art. 6(1)(c)). Processing for tax, accounting, anti-money-laundering, sanctions screening, and law-enforcement response.

Legitimate interests (GDPR Art. 6(1)(f)). Security monitoring, fraud and abuse prevention, network operations, aggregate analytics for service improvement, and limited business-to-business marketing to existing customers. Where we rely on legitimate interests, we have balanced our interests against your rights and you have the right to object (see §8).

Consent (GDPR Art. 6(1)(a)). Marketing communications where consent is required by law (e.g. ePrivacy/PECR), non-essential cookies, and any other processing where we ask you to opt in. You may withdraw consent at any time without affecting the lawfulness of prior processing.

Automated decision-making. Our fraud and abuse detection system uses automated processing to flag potentially suspicious activity (see §3). Lower-risk automated actions — such as rate-limiting, requiring re-authentication, or requesting additional verification — may be applied without human review. Higher-impact decisions, including account suspension or termination, involve human review before action is taken.

To the extent any automated decision produces legal effects on you or similarly significantly affects you within the meaning of GDPR Art. 22, you have the right to: obtain human intervention, express your point of view, and contest the decision. To exercise these rights, contact [email protected].

05

How we share your information

We share personal information only in the following circumstances:

Service providers (processors). We use third-party vendors to run the Service — including payment processors, infrastructure providers, email and communications platforms, support tooling, analytics, and security vendors. These vendors process personal information only on our instructions and under written contracts that include confidentiality and security obligations. Our current sub-processors list is published at /sub-processors and updated when we add or change a sub-processor.

Legal compliance and protection. We may disclose personal information when required by law, legal process, or government request, or when we reasonably believe disclosure is necessary to protect our rights, our customers' rights, or public safety. Where we are not legally prohibited from doing so, we will notify the affected customer of any government request for their data.

Corporate transactions. In connection with a merger, acquisition, financing, or sale of assets — in which case the recipient will be required to honor this Policy with respect to your personal information.

With your consent. Where you direct us to share information with another party.

We do not sell personal information. We do not sell or rent personal information to third parties for their own marketing purposes, and we have not done so in the prior 12 months.

06

International data transfers

Fortlab is established in the United States. When you use the Service, your personal information may be transferred to, stored in, and processed in the United States and in any country where we or our sub-processors operate.

For transfers from the EEA, UK, or Switzerland. We rely on the following transfer mechanisms, depending on the recipient and the destination country:

Adequacy decisions where the destination country has been recognized as providing adequate protection by the European Commission, the UK Information Commissioner's Office, or Swiss authorities.

Standard Contractual Clauses (the European Commission's 2021 SCCs) for transfers to countries without an adequacy decision.

The UK International Data Transfer Addendum to the EU SCCs for UK transfers.

The Swiss Addendum for transfers under Swiss FADP.

The EU-US Data Privacy Framework, UK Extension, and Swiss-US Data Privacy Framework where the recipient is self-certified.

Where required, we conduct transfer impact assessments and apply supplementary measures. A copy of the SCCs in effect for a given transfer is available on request to [email protected].

07

Data security

IN PLAIN ENGLISH

Encrypted at rest and in transit, role-based access, network segmentation, monitoring, SOC 2 attestation in progress. Confirmed breach affecting your data → email within 72 hours.

We maintain administrative, physical, and technical safeguards designed to protect personal information, including AES-256 encryption at rest, TLS 1.3 in transit, role-based access controls, network segmentation, and logging and monitoring. We are implementing the controls necessary for SOC 2 Type I attestation, with Type II attestation to follow over the subsequent observation period.

Incident notification. In the event of a Security Incident affecting your personal information, we will notify affected customers without undue delay and in any event within seventy-two (72) hours of confirmation, with relevant details and remediation steps. Where required, we will also notify the relevant supervisory authority within the timelines required by law (under GDPR Art. 33, within 72 hours of becoming aware of a personal data breach).

No system is perfectly secure. While we work hard to protect your information, we cannot guarantee absolute security.

08

Your privacy rights

Depending on where you live, you have rights over your personal information. We honor these rights for all users where we can do so consistently with our legal obligations, regardless of whether they are formally required in your jurisdiction.

Universal rights — available to all users:

Access. Request a copy of the personal information we hold about you.

Correction. Ask us to correct inaccurate or incomplete information.

Deletion. Ask us to delete your personal information, subject to legal exceptions (e.g. tax records we are required to keep).

Portability. Receive your personal information in a structured, commonly used, machine-readable format.

Withdraw consent. Where processing is based on consent, withdraw it at any time.

Additional GDPR/UK rights — for users in the EEA, UK, and Switzerland:

Restriction. Ask us to restrict processing in certain circumstances.

Object. Object to processing based on legitimate interests, including profiling and direct marketing.

Lodge a complaint. With your local supervisory authority. We would appreciate the chance to address your concerns first, but you do not have to contact us before lodging a complaint.

Additional CCPA/CPRA rights — for California residents:

Right to know the categories and specific pieces of personal information we have collected, the sources, the purposes, and the categories of recipients.

Right to delete personal information we have collected from you.

Right to correct inaccurate personal information.

Right to opt out of sale or sharing — we do not sell or share personal information for cross-context behavioral advertising, but you have the right.

Right to limit use of sensitive personal information — we do not use sensitive personal information for purposes that would trigger this right.

Right to non-discrimination for exercising any of the above.

Additional rights under other US state laws. Residents of states with comprehensive privacy laws (including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and others as enacted) have rights similar to those above. We honor them on the same terms.

Additional rights under Asian regimes. Residents of jurisdictions including Japan (APPI), South Korea (PIPA), Singapore (PDPA), and India (DPDPA) have rights under their local laws, including access, correction, and deletion. We honor them on the same terms.

How to exercise your rights. Email [email protected] or use the privacy controls in your account dashboard. We will respond within 30 days for GDPR-based requests, 45 days for CCPA-based requests (extendable to 90 days where permitted), and within the timelines required by other applicable laws. We may need to verify your identity before fulfilling a request. There is no charge for reasonable requests.

Authorized agents. California residents may use an authorized agent to make a request, subject to verification.

09

Cookies and tracking technologies

We use cookies and similar technologies to operate the Service and to understand how it is used.

Strictly necessary cookies. Required for authentication, session management, security, and load balancing. These cannot be turned off.

Functional cookies. Remember your preferences (e.g. theme, language). Set only with your consent where required by law.

Analytics cookies. Help us understand aggregate usage. Set only with your consent where required by law.

No advertising cookies. We do not use cookies for cross-site advertising or behavioral profiling.

EU/UK/Swiss visitors are presented with a consent banner allowing granular control. You can change your preferences at any time via the cookie settings link in our website footer. You may also manage cookies through your browser, though this may affect how the Service works.

10

Data retention

We retain personal information only as long as necessary for the purposes described in this Policy or as required by law.

Account information. For the duration of your account plus the post-termination retention windows in the Terms of Service (60 days for export, then deletion within 30 days from active systems and 90 days from backups).

Billing and tax records. For at least seven (7) years after the relevant transaction, as required by US tax law and applicable local equivalents.

Security and audit logs. For up to 24 months, then deleted or anonymized.

Marketing communications data. Until you unsubscribe or withdraw consent, plus a short suppression-list retention so we can honor your unsubscribe.

Support communications. For up to three (3) years after the ticket is resolved.

After these periods, we delete or anonymize the relevant information.

11

Children's privacy

The Service is not directed at children. We do not knowingly collect personal information from anyone under the age of 18. The Terms of Service require account holders to be at least 18. If you believe a child has provided us with personal information, please contact [email protected] and we will take steps to delete it. For users in jurisdictions with a lower digital-consent age (e.g. some EU member states under GDPR Art. 8), we still apply the 18+ requirement for account holders consistent with the Terms.

12

EU and UK representatives

Because Fortlab does not have an establishment in the European Economic Area or the United Kingdom, we have appointed representatives under GDPR Art. 27 and UK GDPR Art. 27 respectively.

EU Representative: [TO BE FILLED — supplied by your appointed Art. 27 representative; format: name, EU address, contact email or web form]

UK Representative: [TO BE FILLED — supplied by your appointed UK Art. 27 representative; format: name, UK address, contact email or web form]

EEA, Swiss, and UK residents may contact our representatives directly with questions about this Policy or to exercise their rights.

13

Privacy contact

For questions about this Policy or to exercise your rights, email [email protected]. We respond to privacy inquiries within ten (10) business days, and to formal data subject requests within the statutory timelines described in §8.

For security incidents, contact [email protected].

Notices may also be sent to Fortlab Corporation at its registered office in Sheridan, WY, United States.

14

Changes to this Policy

IN PLAIN ENGLISH

We may update this Policy. We'll post the new version, link to the prior version, and email registered users at least 30 days before material changes take effect.

We may update this Policy from time to time. The current version will always be posted at /privacy-policy with a revision date and a link to the prior version. We will notify registered users of material changes by email at least thirty (30) days before they take effect. Continued use of the Service after the effective date constitutes acceptance.

SIGN-OFF
Fortlab Corporation · Sheridan, WY, United States
Issued by Fortlab Corporation, Office of the General Counsel · effective date pending publication
Download signed PDF →
Version history

Every change, on the record.

v2.0PendingMajor rewrite. New scope, detailed processing-purposes breakdown, GDPR Art. 22 commitments, full transfer-mechanism list, per-jurisdiction rights coverage.view →