Sprint Nexus Solutions Pvt. Ltd. (“Sprint Nexus,” “we,” “us,” or “our”) provides cloud architecture, cloud migration, managed cloud, DevOps and platform engineering, cloud security and compliance, SaaS and AI infrastructure, and cloud cost optimization services (collectively, the “Services”) to enterprise and business customers (“Customers”), in addition to operating this website and related digital properties (the “Site”).
This Privacy Policy explains how we collect, use, disclose, retain, transfer, and protect personal data in two distinct capacities, which we distinguish throughout this Policy:
- As a Data Controller — when we collect personal data through the Site (e.g., from visitors, prospects, job applicants, and our own personnel) or in the course of our own business operations, sales, marketing, vendor management, and billing.
- As a Data Processor / Service Provider — when we access, host, manage, migrate, secure, or otherwise process personal data contained within Customer environments, workloads, or infrastructure in the course of delivering the Services under a signed Master Services Agreement (“MSA”), Statement of Work (“SOW”), and/or Data Processing Agreement (“DPA”).
Where we act as a processor on behalf of a Customer, that Customer remains the data controller responsible for determining the purposes and means of processing, and the terms of the applicable DPA govern in the event of any conflict with this Policy. This Policy does not itself constitute, replace, or override any DPA, MSA, SOW, or Sub-Processor Agreement in place between Sprint Nexus and a Customer.
This Policy applies to personal data processed in connection with our Site and all Service lines, including Cloud Architecture, Cloud Migration, Managed Cloud, DevOps & Platform Engineering, Cloud Security & Compliance, SaaS & AI Infrastructure, and Cloud Cost Optimization. By using the Site or engaging our Services, you acknowledge the practices described in this Policy, subject to the terms of any governing contractual agreement.
1. Scope and Roles: Controller vs. Processor
Understanding whether Sprint Nexus is acting as a controller or a processor determines which part of this Policy applies to a given category of personal data.
1.1 When We Act as a Controller
We act as a controller for personal data relating to:
- Visitors to and users of the Site, including form submissions, resource downloads, and newsletter sign-ups;
- Prospective Customers and business contacts engaged through sales, marketing, RFPs, or partnership discussions;
- Job applicants and candidates;
- Our own employees, contractors, and personnel (governed separately by internal HR policies, referenced here for completeness only);
- Customer business contacts (e.g., named signatories, technical points of contact, billing contacts) for the purpose of contract administration, account management, and invoicing.
1.2 When We Act as a Processor / Service Provider
In the course of delivering Managed Cloud, Cloud Migration, DevOps & Platform Engineering, Cloud Security & Compliance, and SaaS & AI Infrastructure Services, our personnel and systems may obtain access to Customer environments that contain personal data relating to the Customer’s own employees, customers, or end users (“Customer Data”). In these circumstances:
- We process Customer Data solely on documented instructions from the Customer, as set out in the applicable DPA, MSA, or SOW;
- We do not use Customer Data for our own marketing, analytics, AI model training, or any purpose outside the scope of the engagement, except as expressly agreed in writing;
- Access is restricted to authorized personnel under the principle of least privilege, subject to the confidentiality and security obligations described in Section 8;
- Customers are responsible for ensuring they have a lawful basis to share such data with us and for meeting their own notice and consent obligations to their end users.
2. Information We Collect
2.1 Information Collected via the Site (Controller Capacity)
- Contact and identity data: name, business email, phone number, job title, company name, submitted via contact forms, demo requests, or resource downloads related to any Service page (Cloud Architecture, Cloud Migration, Managed Cloud, DevOps & Platform Engineering, Cloud Security & Compliance, SaaS & AI Infrastructure, Cloud Cost Optimization);
- Engagement and inquiry details: information you voluntarily provide describing your infrastructure, cloud provider(s), workloads, compliance requirements, or project scope when requesting a consultation or proposal;
- Technical and usage data: IP address, browser type, device identifiers, referring URLs, pages viewed, session duration, and interaction data, collected via cookies and similar technologies (see Section 6);
- Recruitment data: CVs, cover letters, and related information submitted through careers pages or job applications;
- Communications: records of correspondence, support tickets, and meeting notes arising from pre-sales or general inquiries.
2.2 Information Processed in Delivering Services (Processor Capacity)
Depending on the scope of the engagement and Service line, this may include:
- Infrastructure and configuration metadata: cloud account structures, IAM policies, network topologies, resource inventories, and cost and usage data (relevant to Cloud Architecture, Managed Cloud, Cloud Cost Optimization);
- Application and workload data: source code, container images, CI/CD pipeline artifacts, logs, and telemetry (relevant to DevOps & Platform Engineering, SaaS & AI Infrastructure), which may incidentally contain personal data embedded by the Customer’s own systems (e.g., end-user identifiers in logs);
- Security and compliance data: vulnerability scan results, audit logs, access logs, incident records, and compliance evidence (relevant to Cloud Security & Compliance);
- Migration data: data sets, databases, and file stores transferred in the course of Cloud Migration engagements, which may include Customer end-user personal data depending on the nature of the workload being migrated.
The precise categories, volumes, and sensitivity of Customer Data processed under this Section 2.2 are determined by the Customer and documented in the applicable DPA and SOW, not by this Policy.
3. How We Use Information
3.1 Site and Business Contact Data
- Responding to inquiries and providing requested information about our Service lines;
Preparing proposals, quotes, and statements of work; - Administering contracts, invoicing, and account management for existing Customers;
- Sending marketing communications, technical content, and event invitations, where permitted, with an opt-out available at any time;
- Operating, securing, and improving the Site, including analytics and fraud/abuse prevention;
- Complying with applicable legal, tax, and regulatory obligations;
- Processing job applications and evaluating candidates.
3.2 Customer Data Processed Under Engagement
Customer Data is used exclusively to perform the contracted Services — for example, designing and provisioning cloud architecture, executing a migration runbook, operating managed infrastructure, deploying CI/CD pipelines, conducting security assessments, or generating cost-optimization recommendations — strictly in accordance with the Customer’s documented instructions. We do not sell Customer Data, and we do not use Customer Data to train general-purpose or third-party AI/ML models unless separately and explicitly authorized in writing by the Customer for a specific SaaS & AI Infrastructure engagement.
4. Legal Bases for Processing
Where applicable data protection law requires a documented legal basis, we rely on one or more of the following:
- Contractual necessity — to negotiate, enter into, and perform an MSA, SOW, or DPA with a Customer;
- Legitimate interests — to respond to inquiries, operate and secure the Site, conduct direct B2B marketing, and improve our Services, balanced against your rights and expectations;
- Consent — where required, for example for certain cookies or opted-in marketing communications, withdrawable at any time;
- Legal obligation — to comply with tax, corporate, employment, and regulatory requirements;
- Documented Customer instructions — for Customer Data processed in our capacity as a processor, as set out in the relevant DPA.
5. Data Sharing and Sub-Processors
We do not sell personal data. We share personal data only in the categories described below, and, where we act as a processor, only with sub-processors that are subject to written confidentiality and data protection obligations no less protective than those in the applicable DPA.
5.1 Categories of Third Parties
• Hyperscale cloud infrastructure providers (used to host the Site, our internal tooling, and, where contracted, Customer workloads under Managed Cloud and related Services);
• Site analytics and web performance providers;
• Customer relationship management (CRM) and marketing automation providers, used to manage sales and marketing communications;
• Communication and collaboration tooling providers (email, video conferencing, ticketing systems) used for Customer support and delivery;
• Identity, security, and monitoring tooling providers, used to secure our own systems and, where contracted, Customer environments under Cloud Security & Compliance engagements;
• Payment processing and invoicing providers;
• Professional advisors, including auditors, legal counsel, and insurers, on a need-to-know basis;
• Regulators, law enforcement, or courts, where required by applicable law or legal process;
• A successor entity, in the event of a merger, acquisition, financing, or sale of assets, subject to continued protection of personal data.
5.2 Sub-Processor Governance
For Services performed as a processor, we maintain an internal register of sub-processors engaged in the delivery of each Service line. Where an applicable DPA provides for it, we will provide advance notice of the addition or replacement of a sub-processor and allow the Customer to object in accordance with the terms of that DPA. A current sub-processor list is available to Customers on request through their account contact.
6. Cookies and Tracking Technologies
The Site uses cookies and similar technologies to operate core functionality, remember preferences, understand aggregate usage patterns across our Service pages, and, where consented to, support marketing measurement. This may include:
• Strictly necessary cookies, required for the Site to function and which cannot be disabled;
• Analytics cookies, used to understand how visitors engage with content such as our Cloud Migration, Managed Cloud, and DevOps & Platform Engineering pages, so we can improve navigation and content relevance;
• Marketing and attribution cookies, used to measure campaign performance, where permitted by your consent.
Where required by applicable law, non-essential cookies are only set with your consent, obtained via the Site’s cookie consent mechanism. You can manage or withdraw cookie consent at any time via that mechanism or your browser settings; disabling certain cookies may affect Site functionality.
7. International Data Transfers
As a provider of cloud, infrastructure, and SaaS services, we and our sub-processors may process and store personal data in India and in other countries where our infrastructure providers, sub-processors, or delivery teams operate, which may differ from the jurisdiction in which you or the relevant data subjects are located.
Where we transfer personal data across borders — whether Site visitor data as a controller, or Customer Data as a processor — we implement appropriate safeguards designed to ensure an adequate level of protection, which may include standard contractual clauses, equivalent transfer mechanisms recognized under applicable law, and contractual, technical, and organizational security measures. Where a Customer’s DPA specifies particular data residency or transfer restrictions for its workloads, those terms govern our processing of that Customer’s data.
8. Data Security
We maintain administrative, technical, and physical safeguards designed to protect personal data against unauthorized access, disclosure, alteration, and destruction, appropriate to the nature and sensitivity of the data processed. These include, as applicable to the relevant Service line and system:
• Access controls based on the principle of least privilege and role-based access, including for engineers engaged in Managed Cloud, DevOps, and Cloud Security & Compliance delivery;
• Encryption of data in transit and, where applicable, at rest;
• Network segmentation, monitoring, and logging of access to Customer environments;
• Change management and audit trails for infrastructure and configuration changes made on Customer environments;
• Personnel confidentiality obligations, background screening, and security awareness training;
• Vendor and sub-processor risk assessment;
• Incident detection, response, and breach notification procedures.
Specific security commitments, audit rights, and control frameworks applicable to a given engagement — including any specific certifications, audit reports, or control attestations to be provided — are set out in the applicable MSA, SOW, or DPA, and are not expanded beyond those contractual commitments by this Policy.
In the event of a personal data breach affecting Customer Data, we will notify the affected Customer without undue delay and in accordance with the timelines and procedures set out in the applicable DPA, to support the Customer’s own regulatory notification obligations.
9. Data Retention
We retain personal data for as long as necessary to fulfil the purposes described in this Policy, unless a longer retention period is required or permitted by law.
• Site inquiry and lead data is retained for the duration of the sales relationship and for a limited period thereafter for record-keeping and re-engagement purposes, unless you request earlier deletion;
• Customer contract and billing records are retained for the period required by applicable tax, corporate, and contractual record-keeping obligations;
• Job applicant data is retained for the duration of the recruitment process and a limited period thereafter, unless you consent to longer retention for future opportunities;
• Customer Data processed under a Service engagement is retained and, upon termination of the engagement, returned or deleted in accordance with the offboarding, data return, and deletion terms set out in the applicable MSA or DPA.
10. Your Rights
Subject to applicable data protection law and depending on your jurisdiction, you may have the right to:
• Request access to, and a copy of, personal data we hold about you;
• Request correction of inaccurate or incomplete personal data;
• Request deletion of your personal data, subject to legal and contractual retention requirements;
• Object to, or request restriction of, certain processing, including direct marketing;
• Withdraw consent, where processing is based on consent, without affecting the lawfulness of processing prior to withdrawal;
• Request data portability, where applicable;
• Lodge a complaint with your local data protection authority.
To exercise these rights in relation to data we hold as a controller (Site visitor, lead, or applicant data), contact us using the details in the Contact Us section below. If your personal data was provided to us by a Customer in the context of a Service engagement — for example, because you are an employee or end user of one of our Customers — we act as a processor for that data, and you should direct your request to the relevant Customer, who remains responsible for responding as the data controller. We will support our Customers in fulfilling such requests in accordance with the applicable DPA.
11. Children’s Data
The Site and Services are intended for business and enterprise use and are not directed to individuals under the age of 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us so we can take appropriate action.
12. Changes to This Policy
We may update this Policy from time to time to reflect changes in our practices, Service offerings, or legal requirements. Material changes will be indicated by updating the “last updated” date at the top of this Policy, and, where required by law or contractually agreed with Customers, we will provide additional notice. We encourage you to review this Policy periodically.
13. Relationship to Contractual Agreements
This Policy is a general statement of our data protection practices and does not create or expand any contractual obligation. Where Sprint Nexus and a Customer have entered into an MSA, SOW, and/or DPA governing the processing of Customer Data, the terms of those agreements shall prevail over this Policy to the extent of any conflict, specifically with respect to the scope of processing, security commitments, sub-processor arrangements, audit rights, liability, and data return or deletion upon termination.
Contact Us
For questions, requests, or complaints regarding this Privacy Policy or our data processing practices — including data subject access requests, data protection queries related to a specific engagement, or reports of a suspected personal data breach — please contact our Privacy Office using the details below. Customers with an active Master Services Agreement or Data Processing Agreement should route data-processing-specific requests through their designated account contact or the escalation path defined in their DPA, in addition to notifying the Legal Team.
legal@sprintnexus.com