LEGAL & COMPLIANCE

Privacy Policy

Last updated:

1. Introduction

Welcome to NodeXCloud ("we", "our", or "us"), provided by Elzora at nodexa.elzora.tech. NodeXCloud is an Internet of Things (IoT) edge device and container workload deployment platform designed to connect, monitor, and manage connected device fleets.

We respect your privacy and are committed to protecting the personal data you share with us. This Privacy Policy outlines what information we collect, why we collect it, how it is handled and secured, and your rights regarding your data.

2. Google OAuth API User Data & Limited Use Disclosure

NodeXCloud allows users to authenticate using Google Sign-In ("Continue with Google"). When you log in or create an account using Google OAuth, our application requests access strictly to your basic Google profile information:

  • Email address: To identify your account, send critical fleet notifications, and link your organization memberships.
  • Full Name (First and Last Name): To personalize your dashboard experience and display your identity on fleet audit logs and releases.
  • Profile Picture URL: To display your avatar within the user interface.

Google API Services User Data Policy Compliance:

NodeXCloud's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically:

  • We never sell your Google user data or personal information to any third parties.
  • We do not use or transfer your Google user data for serving personalized, retargeted, or interest-based advertising.
  • We do not use your Google user data to train generalized artificial intelligence or machine learning models.
  • Access to Google user data is strictly limited to providing and improving core user-facing functionality (user authentication and fleet authorization).

3. Additional Information We Collect

In addition to Google OAuth credentials, we may collect:

  • Account Information: Email address, hashed passwords (for standard email/password accounts), and account creation timestamps.
  • Fleet & Device Telemetry: Device identifiers, hostnames, IP addresses, OS versions, agent heartbeat statuses, and configuration variables needed to manage your edge hardware.
  • API Tokens: One-way hashed cryptographic tokens generated by users for CLI deployment access (nodex push).
  • Operational Logs: System activity logs, release build tags, and deployment histories necessary for fleet audits and troubleshooting.

4. How We Use Your Information

We process your personal and fleet data strictly for legitimate operational purposes:

  • To verify identity and grant authorized access to fleets and device management consoles.
  • To enforce role-based access control (Admin, Maintainer) when releasing software or generating SSH session tickets for devices.
  • To send critical security alerts, password resets, and maintenance notifications.
  • To maintain platform security, prevent unauthorized access, and protect against fraudulent activity.

5. Data Storage, Security & Encryption

We implement industry-standard administrative, physical, and technical safeguards to protect your information:

  • Encryption in Transit: All data transmitted between your browser, devices, CLI, and our servers is encrypted using modern TLS 1.2 / TLS 1.3 protocols.
  • Encryption at Rest: Sensitive data, including password hashes (Argon2/bcrypt) and API token hashes (SHA-256), are stored using one-way cryptographic hashes.
  • Zero Plaintext Storage for Tokens: API tokens and device authentication tokens are shown once upon creation and never stored in plaintext on our servers.

6. Data Retention & Deletion

We retain your personal data only for as long as your account remains active or as needed to provide you with NodeXCloud services:

  • Account Deletion: You can request complete deletion of your account, fleets, and associated data at any time by contacting our support team at support@elzora.tech. Upon request, your account data will be permanently purged within 30 days.
  • Revoking Google Access: You may revoke NodeXCloud's access to your Google account at any time via your Google Account Permissions page.
  • Token Revocation: You can instantly revoke any generated CLI deployment token directly from your Fleet dashboard.

7. Third-Party Services & Subprocessors

We work with trusted third-party providers to deliver our infrastructure:

  • Google Identity Services: For secure OAuth 2.0 authentication.
  • Tailscale / WireGuard: For encrypted, zero-trust peer-to-peer device networking and SSH tunneling.
  • Cloud Infrastructure Providers: For cloud hosting, container registry storage, and database management.

We do not share your personal information with third parties for their independent marketing or commercial purposes.

8. Your Rights (GDPR, CCPA & Global Rights)

Depending on your jurisdiction, you have the right to:

  • Access the personal information we hold about you.
  • Request correction of inaccurate or incomplete information.
  • Request erasure of your personal data ("right to be forgotten").
  • Object to or restrict the processing of your data.
  • Export a copy of your personal data in a portable format.

9. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:

NodeXCloud Support & Data Protection

Email: support@elzora.tech

Website: https://nodexa.elzora.tech