Nexxiot claims no ownership over customer data and the customer retains all intellectual property and other rights to their data. The privacy of customer data is protected and Nexxiot will never make those data publicly available without permission. Nexxiot is committed to the Federal Act on Data Protection (FADP) of Switzerland and the General Data Protection Regulation of the EU 2016/679 (GDPR). Nexxiot stores and processes the personal data of cloud customers. In doing so, there are several additional obligations that are fulfilled.
Nexxiot’s policies are aligned with ISO/IEC 27018 – Code of Practice for Protection of Personally Identifiable Information (PII) in Public Clouds acting as PII Processors, which recommends specific enhancements to ISO/IEC 27001 controls. Nexxiot ensures the security and privacy of customer data by using up to 256-bit encrypted connection via TLS 1.2 and a world-class certificate provider for all data transfers between user devices and the Nexxiot Cloud Platform. At Nexxiot, we also use encryption at rest (AES-256 or stronger) to protect the secrecy of all data.