This Privacy Policy describes how Nexagen Networks LLC (“Nexagen”, “we”, “us”) collects, uses, and shares information when you use the OrionHub platform (the “Service”). It is written to satisfy the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA) as amended by the CPRA, and analogous U.S. state privacy laws.
1. Data we collect
We collect the minimum information needed to operate the Service. We do not sell personal information, and we do not collect biometric or location data. Categories:
- Account data: name, work email, employer / tenant name, role within the tenant. Collected at sign-up or via the AWS Marketplace fulfillment flow.
- Authentication data: Keycloak / OIDC subject identifier, session timestamps, IP addresses on sign-in events.
- Configuration data you provide: cloud connection credentials (always encrypted at rest with HashiCorp Vault Transit), GitLab tokens, secret values, repository URLs.
- Application telemetry: deployment events, scan results, SBOMs, audit-log entries that record state changes you initiate inside the platform.
- Billing data (for AWS Marketplace subscribers only): your AWS Customer Identifier, AWS Account ID, product code, and dimension entitlements. We do not collect credit-card or bank-account information — billing flows entirely through AWS Marketplace.
- Diagnostic data: error logs and request traces retained for 30 days for operational troubleshooting.
2. How we use it
- To operate, secure, and improve the Service.
- To authenticate users and enforce role-based access controls.
- To detect and prevent fraud, abuse, and security incidents (including audit logging of all state changes).
- To comply with legal obligations (subpoenas, lawful access requests, financial reporting tied to AWS Marketplace).
- To send transactional and security notifications (account creation, incident notifications, contract renewals).
We do not use customer code, SBOMs, deployment artifacts, or scan results to train any machine learning model. The AI features in OrionHub run on a per-request basis under the customer’s own configured AI model (the Marketplace bundle offers an opt-in Bedrock default).
3. How we share it
- Sub-processors: Amazon Web Services (hosting), HashiCorp Vault (managed by Nexagen on AWS), Keycloak (managed by Nexagen on AWS), and SES for transactional email. We do not use third-party analytics or advertising networks.
- Authorized customer personnel: tenant Owners and Maintainers see configuration data within their tenant scope. Platform administrators may see cross-tenant metadata (counts, statuses, billing dimensions) but cannot decrypt customer secret values from the cross-tenant view.
- Legal compliance: we may disclose information if required by valid legal process or to protect rights, safety, or property.
- Corporate transactions: if Nexagen is acquired or merges, information may transfer subject to this Policy.
4. Retention
We retain data for as long as your subscription is active and for a bounded period afterward. Specific retention windows are listed in the Data Handling Disclosure. Highlights:
- Audit log entries: 395 days (one year + buffer).
- Application telemetry: 90 days.
- Diagnostic logs: 30 days.
- Customer data deleted within 30 days of contract termination or verified deletion request, except where retention is required by law.
5. Your rights
Subject to applicable law, you have the right to:
- Request access to the personal data we hold about you.
- Request correction of inaccurate data.
- Request deletion of your data (the “right to be forgotten”).
- Request a machine-readable export of your data (data portability).
- Object to or restrict certain processing.
- Withdraw consent at any time where processing is based on consent.
- Lodge a complaint with your supervisory authority (for EU/UK residents) or your state attorney general (for U.S. residents).
To exercise any of these rights, email privacy@nexagen.com. We respond to verifiable requests within 30 days.
6. International transfers
OrionHub runs in U.S. AWS regions by default (us-east-1 and us-west-2, with AWS GovCloud available for U.S. Government customers). For EU and UK personal data, we rely on AWS’s Standard Contractual Clauses and Data Processing Addendum as our transfer mechanism.
7. Security
See the Security page for technical and organizational measures. In summary: TLS 1.2+ in transit, AES-256 at rest (RDS storage encryption + Vault Transit for secrets), row-level security in Postgres for tenant isolation, audit logging on every state change, principle-of-least-privilege IAM.
8. Children
The Service is not directed to individuals under 18 and we do not knowingly collect their data.
9. Changes
We may update this Policy. Material changes are announced via the in-product notification system and via email to tenant Owners at least 30 days before they take effect.
10. Contact
Data Protection Officer: privacy@nexagen.com
Postal address: Nexagen Networks LLC, Attn: DPO, [street address — legal review required], United States.