Nexus SaaS Privacy Policy

Version 2026-08-15 · Last updated: August 15, 2026

This Privacy Policy explains what information Stingray Technology Solutions, LLC ("Stingray," "we," "our," or "us") collects in connection with Nexus, how we use it, who we share it with, and how long we keep it. It applies to the Nexus platform, the Nexus desktop and web clients, the Nexus Excel add-in, and the Stingray marketing website (together, the "Service"). It is part of, and should be read with, our SaaS Terms of Service.

Nexus is enterprise software sold to organizations. Most of the information we handle relates to a business customer and its personnel rather than to consumers.

This policy covers the Nexus software-as-a-service subscription, which Stingray operates for you. If Nexus is instead deployed into your own Microsoft Azure subscription as a Managed Application, the Nexus Self-Hosted Privacy Policy applies to you instead, and the difference is significant: in that model we never hold your business data at all.

1. Our Role

Our role depends on the type of information:

If you are an employee of one of our customers and have a question about the business data your employer processes in Nexus, please contact your own organization first. We will refer such requests to the customer that controls the data.

2. Where Your Data Lives

This is the single most important thing to understand about our handling of Customer Data, so it is stated plainly: under this policy, we hold it.

Stingray runs the customer's Nexus instance in a Stingray-operated Microsoft Azure subscription, in the United States. In this model Customer Data is stored on infrastructure we operate. Each customer gets a dedicated application instance, a dedicated database, and a dedicated Azure Key Vault for credentials. The database server is shared at the server level with other customers' separate databases; the data itself is not commingled.

2.1 Government deployments

Deployments into Microsoft Azure Government, including GCC High, run in the customer's own government-cloud tenant and are governed by a separate written agreement. Stingray does not hold Customer Data from those deployments.

3. Information We Collect

3.1 Identity and authorization information

Users sign in through Microsoft Entra ID. Microsoft performs the authentication and returns a token to Nexus. From that token and from the Microsoft directory we may receive:

We never receive or store user passwords.

3.2 Subscription and billing information

For subscriptions purchased through the Microsoft Azure Marketplace, Microsoft is the merchant of record. Microsoft sends us the information needed to provision and maintain the subscription, which includes the subscription identifier, the plan, the purchaser's name and email address, the Azure tenant identifier, and lifecycle notifications such as renewal, suspension, and cancellation.

We do not receive, process, or store payment card numbers, bank details, or any other payment instrument. Those are handled entirely by Microsoft.

3.3 Operational telemetry

A Nexus instance can report limited operational information to a Stingray-operated control plane so we can monitor product health, diagnose faults, and understand which capabilities are used. Telemetry is deliberately narrow, and what it contains is fixed by an allowlist in the software:

CategoryWhat is sent
Instance identityTenant and deployment identifiers, Nexus version, adapter names and versions
Usage countersCounts only — for example the number of active reports, pipelines, and configured connections. Names and values of connections are never sent.
Errors and diagnosticsError type, error message, the connector or pipeline step involved, and HTTP status. Error messages are automatically stripped of file paths, IP addresses, and credential-shaped strings before transmission.
Security alertsAggregate signals such as an unusual number of failed sign-ins or pipeline failures within a time window

Telemetry does not include customer business records, query results, report contents, file contents, or connection credentials. An administrator can turn telemetry off at any time from the product's administration settings, and it can also be disabled in the instance's configuration at deployment time.

3.4 Support communications

When you contact support, we retain your name and email address, the content of your request, and any logs, screenshots, or diagnostic information you choose to send us. Please do not send us production business records or credentials in a support request; if you do, they will be handled as Customer Data and deleted when the request is closed.

3.5 Marketplace leads and enquiries

If you ask to be contacted about Nexus through the Microsoft Azure Marketplace — for example by requesting a private offer or asking us to get in touch — Microsoft passes us the contact details you provided, which typically include your name, business email address, company name, country, and any message you wrote. We store those details in our own Microsoft Azure storage in the United States and use them solely to respond to your enquiry and to keep a record of it. We do not use them for unrelated marketing, and we do not sell or share them. Ask us to delete a lead record at any time using the contact address in Section 13.

3.6 Website information

Our marketing website is a static site delivered through a content delivery network. Standard server-side request logs, including IP address, user agent, and requested URL, are generated by that infrastructure. We do not use advertising cookies or third-party tracking or analytics scripts on the marketing website.

4. Information We Do Not Collect

We necessarily store what the customer puts into their instance, because we operate that instance. Beyond that, and beyond material a customer voluntarily sends us in a support request, we do not collect:

We do not sell personal information, we do not share it for cross-context behavioral advertising, and we do not use Customer Data to train machine-learning or artificial-intelligence models. Nexus itself ships no artificial-intelligence features.

5. How We Use Information

We use the information described above to:

Where the law requires a legal basis for processing, ours is the performance of our contract with the customer, our legitimate interests in operating and securing the Service, and compliance with legal obligations.

6. Sharing and Sub-processors

We do not sell information, and we share it only as described here. Our sub-processors are:

ProviderWhat it does for usWhat it may handle
Microsoft Corporation — AzureCloud infrastructure for your Nexus instance and for our control plane: compute, database, key vault, storage, and container registryCustomer Data, account and operational information
Microsoft Corporation — Entra IDUser authentication and directory lookupIdentity information
Microsoft Corporation — Azure MarketplaceSale, billing, and subscription lifecycle for Marketplace subscriptions, and delivery of any lead or private-offer enquiry you submitSubscription, purchaser, and lead information
Microsoft Corporation — Azure Monitor and Application InsightsOperational logging and application diagnosticsOperational logs and telemetry
Amazon Web Services — S3 and CloudFrontHosting the marketing website and distributing the desktop client installersWebsite request logs only. No Customer Data.

We require each sub-processor to be bound by obligations no less protective than those we owe our customers, and we remain responsible for their performance. We may update this list as our infrastructure changes; material additions affecting Customer Data will be reflected here.

We may also disclose information where we are legally required to do so, where necessary to establish or defend legal claims, or to a successor in connection with a merger, acquisition, or sale of assets. If we are legally compelled to disclose a customer's data, we will give that customer notice before doing so unless the law forbids it.

Separately, Nexus connects to third-party systems that the customer chooses, such as NetSuite, SQL Server, PostgreSQL, MySQL, QuickBooks Online, Monday.com, or a REST API. Those systems are not our sub-processors. Data sent to or read from them is governed by the customer's own relationship with those providers.

7. Security

We maintain administrative, technical, and organizational safeguards designed to protect the information under our control. These include encryption of data in transit using TLS and encryption at rest, per-customer isolation of application instances, databases, and credential vaults, credential storage in Azure Key Vault with values never returned in plaintext through the API, role-based access control, audit logging, and restricted internal access on a need-to-know basis.

We do not hold, and do not claim, SOC 2, ISO 27001, HIPAA, FedRAMP, or CMMC certification, and we do not claim a third-party penetration test. Microsoft's certifications for the underlying Azure platform are Microsoft's and are not ours. We do operate a documented internal security program and can provide evidence of it under a non-disclosure agreement.

No system can be guaranteed absolutely secure. If we become aware of a security incident affecting Customer Data under our control, we will notify the affected customer without undue delay and cooperate in their investigation and notification obligations.

8. Retention and Deletion

InformationHow long we keep it
Customer DataFor the life of the subscription. On cancellation, or on expiry of the term without renewal, access is suspended immediately and the data is retained in recoverable form for thirty (30) days, after which the instance, its database, its stored files, and its key vault contents are permanently deleted.
Operational telemetry and logsUp to thirty (30) days, unless a longer period is required for security investigation, audit, or legal reasons.
Account and subscription recordsFor the life of the relationship and for as long as needed afterwards for tax, accounting, and legal purposes.
Marketplace leads and enquiriesFor as long as reasonably necessary to respond and to keep a record of the enquiry, and then deleted on request.
Support communicationsFor as long as reasonably necessary to resolve the request and to maintain a support history, and then deleted on request.

Deletion after the thirty-day window is irreversible. We recommend exporting anything you wish to keep before cancelling, and in any event during that window.

9. Your Choices and Rights

Customers and their users may:

Send requests to support@stingraytechnologysolutions.com. We will verify that the request comes from the customer or an authorized administrator before acting on it, and we will respond within a reasonable period. Where a request concerns Customer Data that we hold as a processor, we will refer it to the customer who controls that data, or act on that customer's documented instructions.

10. International Transfers

Stingray is based in the United States, and Hosted Deployments run in Microsoft Azure regions within the United States. If you access the Service from outside the United States, information about you will be transferred to and processed in the United States, where data-protection laws may differ from those in your country. Customers with data-residency requirements that a United States region does not satisfy should deploy Nexus into their own Azure subscription under the Self-Hosted Privacy Policy, which runs in the Azure region the customer chooses, or contact us to discuss options.

11. Children's Privacy

Nexus is business software intended solely for organizational use. It is not directed to children, and we do not knowingly collect personal information from anyone under 18. If we learn that we have, we will delete it.

12. Changes to This Policy

We may update this Privacy Policy. We will publish the updated version at this address with a new version identifier and "Last updated" date. For changes that materially affect how we handle personal information, we will give at least thirty (30) days' advance notice through the Service or by email to customer administrators before the change takes effect. Continued use of the Service after an updated version takes effect constitutes acceptance of it, and we may ask users to re-accept it in the product.

13. Contact

Stingray Technology Solutions, LLC
12 Bristol Ln
Palm Coast, FL 32137
United States

PurposeAddress
Privacy and data requests, legal and contractual notices, and technical supportsupport@stingraytechnologysolutions.com
Security reportssecurity@stingraytechnologysolutions.com