This page explains how PCI-Nexus handles the data you and your clients place in the platform. It complements our Privacy Policy and Terms of Service.
We store the information needed to run your compliance program: your organization and client profiles, users and roles, uploaded evidence documents, policies, findings, requirement statuses, calendar events, and generated documents (such as the SAQ, AOC, and Program Charter). We also keep operational records such as audit logs of activity within the platform.
Data is stored with our infrastructure providers [hosting/provider names, e.g., Supabase / cloud region]. Access is restricted by tenant, so each organization can only reach its own records.
Data is encrypted in transit using industry-standard TLS. Data at rest is encrypted by our infrastructure providers. [Confirm specifics with your provider before publishing.]
Access within an organization is governed by role-based permissions. Row-level security enforces tenant isolation at the database level, so users only see data belonging to their own organization or the clients they are authorized to manage.
We retain your data for as long as your account is active and as needed to provide the Service, and thereafter as required to meet legal, regulatory, or contractual obligations. You may request export or deletion of your data as described in our Privacy Policy.
We use a limited set of third-party service providers to operate the platform (for example, hosting, authentication, and email delivery). [List sub-processors and their purposes.]
For questions about data handling, contact [contact email], [Company legal name].