← Back to PCI-Nexus

Data Handling

Last updated: [EFFECTIVE DATE]
Draft — pending legal review. Replace all bracketed placeholders before production.

This page explains how PCI-Nexus handles the data you and your clients place in the platform. It complements our Privacy Policy and Terms of Service.

PCI-Nexus does not store cardholder data.
The platform is designed so that cardholder data (the full card number, and sensitive authentication data such as CVV, PIN, or magnetic-stripe data) is never collected, stored, processed, or transmitted by PCI-Nexus. Compliance evidence, policies, and questionnaire responses do not require and must not include cardholder data.

What we store

We store the information needed to run your compliance program: your organization and client profiles, users and roles, uploaded evidence documents, policies, findings, requirement statuses, calendar events, and generated documents (such as the SAQ, AOC, and Program Charter). We also keep operational records such as audit logs of activity within the platform.

Where data is stored

Data is stored with our infrastructure providers [hosting/provider names, e.g., Supabase / cloud region]. Access is restricted by tenant, so each organization can only reach its own records.

Encryption

Data is encrypted in transit using industry-standard TLS. Data at rest is encrypted by our infrastructure providers. [Confirm specifics with your provider before publishing.]

Access controls

Access within an organization is governed by role-based permissions. Row-level security enforces tenant isolation at the database level, so users only see data belonging to their own organization or the clients they are authorized to manage.

Retention

We retain your data for as long as your account is active and as needed to provide the Service, and thereafter as required to meet legal, regulatory, or contractual obligations. You may request export or deletion of your data as described in our Privacy Policy.

Sub-processors

We use a limited set of third-party service providers to operate the platform (for example, hosting, authentication, and email delivery). [List sub-processors and their purposes.]

Contact

For questions about data handling, contact [contact email], [Company legal name].