Privacy Policy
What we collect, why we collect it, and what you can ask us to do with it.
Version 3.1 · Effective 15 September 2026 · Previous versions
Template, not legal advice. This document is illustrative content written for a design build. It describes practices a CDN plausibly has, not practices any real company has been audited against. A published privacy policy must describe what your systems actually do — have counsel and your security team verify every claim here before use.
01Scope
This policy covers personal data handled by NimbusCDN, Inc. ("NimbusCDN", "we") through our website, our dashboard and API, and our sales and support activity.
It does not describe how our customers handle the personal data of their own end users. If you reached this page after visiting a site that uses NimbusCDN to deliver content, the operator of that site — not us — decides what happens to your data. Their privacy policy is the one that applies to you.
02Controller or processor
Which role we play depends on the data, and it changes what you can ask us for.
| Data | Our role | Who to ask |
|---|---|---|
| Account, billing, support, marketing | Controller | Us — see section 10 |
| Traffic passing through the edge for a customer | Processor | That customer |
| Aggregate network telemetry, threat intelligence | Controller | Us |
Where we act as processor, we act on our customer's documented instructions under the Data Processing Addendum, and we pass any request we receive directly to them rather than acting on it ourselves.
03What we collect
You give us
- Account data — name, work email, password (stored only as an Argon2id hash), organisation, role, and multi-factor settings.
- Billing data — company name, billing address, tax identifiers and the last four digits and brand of a payment card. Full card numbers go directly to our payment processor; we never receive or store them.
- Support and sales data — the content of tickets, emails and calls with us, including any diagnostic files you attach.
We collect automatically
- Dashboard usage — pages viewed, features used, approximate location from IP, browser and device type.
- Security telemetry — sign-in attempts, source IP, session and API token identifiers, and administrative actions in an immutable audit log.
We do not buy personal data from data brokers, and we do not sell personal data or share it for cross-context behavioural advertising as those terms are defined under US state privacy laws.
04Edge and traffic data
Delivering content requires processing request metadata at the edge. For each request this can include the source IP address, the requested URL, timestamp, HTTP method and status, user agent, referrer, bytes transferred, TLS parameters, and the PoP that served it. Source IP addresses are personal data in most jurisdictions.
We process this data to route and serve the request, to maintain caches, to detect and mitigate attacks, to bill accurately, and to deliver the logs our customer has configured. We act as processor for this data. The customer whose property served the request decides its retention and destination.
Separately, we derive aggregate network telemetry — attack signatures, traffic patterns, PoP health, abusive ASN reputation — which we use as controller to keep the network running and to improve mitigation for everyone. This aggregation does not identify individuals and is not reversible into per-person records.
05Why, and on what basis
Where the GDPR or UK GDPR applies, we rely on these legal bases:
| Purpose | Legal basis |
|---|---|
| Providing the Service and support | Performance of a contract |
| Billing, collections, tax records | Contract; legal obligation |
| Securing the platform, preventing abuse and fraud | Legitimate interests |
| Improving the product and network | Legitimate interests |
| Marketing emails to business contacts | Consent, or legitimate interests with opt-out |
| Non-essential cookies and analytics | Consent |
| Responding to lawful requests | Legal obligation |
Where we rely on legitimate interests, we have assessed that our interest in operating a secure and reliable network is not overridden by your rights, and we can share that assessment on request.
07International transfers
The network spans six continents, so data necessarily crosses borders. Where we move personal data out of the EEA, UK or Switzerland, we rely on an adequacy decision where one exists, and otherwise on the European Commission's Standard Contractual Clauses together with a transfer impact assessment and supplementary technical measures.
Customers with residency requirements can pin caching, logging and edge-function state to the EU, UK, US or a specific region. See the network page for what that covers.
08How long we keep it
| Data | Retention |
|---|---|
| Account data | Life of the account, then 90 days |
| Billing and tax records | 7 years (statutory) |
| Edge request logs | 30 days by default, or as the customer configures |
| Security and audit logs | 12 months |
| Support tickets | 3 years from closure |
| Aggregate telemetry | Indefinite (no longer identifies individuals) |
| Backups | 35-day rolling window |
Deletion requests are honoured within the backup window: data is removed from live systems immediately and expires from backups as those rotate.
09Security
We encrypt data in transit with TLS 1.2 or better and at rest with AES-256. Access to production is least-privilege, requires hardware-backed multi-factor authentication, and is logged. We run background checks on staff with production access, require annual security training, and engage independent penetration testers at least yearly.
We hold SOC 2 Type II, ISO 27001 and ISO 27018 certifications, and PCI DSS Level 1 for the delivery path. Reports are available under NDA.
If a breach affects your personal data, we will notify the relevant supervisory authority within 72 hours of becoming aware where required, and notify you without undue delay where the risk to you is high.
10Your rights
Depending on where you live, you may have the right to access your data, correct it, delete it, restrict or object to its processing, receive it in a portable format, withdraw consent, and not be subject to solely automated decisions with legal effects. We make no such automated decisions.
Under US state laws including the CCPA as amended, you may also request disclosure of the categories we collect, request deletion or correction, and opt out of sale or sharing — though as noted in section 3 we do neither. We will not discriminate against you for exercising any right.
Email privacy@nimbuscdn.example or use the dashboard's privacy controls. We respond within 30 days and may extend by a further 60 where a request is complex, telling you why. We will ask you to verify your identity first. An authorised agent may act for you with written proof.
If we get it wrong you can complain to your supervisory authority. Our EU representative and lead authority are listed in section 14.
12Children
The Service is a business product, is not directed at children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has given us data, contact us and we will delete it.
13Changes
We update this policy as our practices change. The effective date is at the top, and previous versions stay available. For material changes we give at least 30 days' notice by email and in the dashboard before they take effect.
14Contact us
- Privacy team — privacy@nimbuscdn.example
- Data Protection Officer — dpo@nimbuscdn.example
- Security reports — security@nimbuscdn.example
- Postal — NimbusCDN, Inc., Attn: Privacy, Wilmington, Delaware, USA
- EU representative (Art. 27) — NimbusCDN Europe B.V., Amsterdam, Netherlands
- UK representative — NimbusCDN UK Ltd., London, United Kingdom
See also the Terms of Service and the Data Processing Addendum.