LEGAL FRAMEWORK
PRIVACY POLICY
Last Updated: January 2026
Data Controller: NimbusForgeSystems, Calle Castillo, 22, 38002 Santa Cruz de Tenerife, España.
1. Data Collection
NimbusForgeSystems collects personal data strictly for the purpose of delivering managed IT services. This includes: name, email address, phone number, company affiliation, and technical environment details submitted through our contact forms or communication channels.
2. Legal Basis for Processing
We process personal data under Article 6(1)(b) of the GDPR — processing is necessary for the performance of a contract to which the data subject is party, or in order to take steps at the request of the data subject prior to entering into a contract. Additionally, we rely on Article 6(1)(f) — legitimate interest — for maintaining operational security and service quality.
3. Data Retention
Personal data is retained for the duration of the service relationship plus 24 months following contract termination. Technical logs and infrastructure data are purged within 90 days of contract completion unless otherwise specified.
4. Data Security
All personal data is encrypted at rest (AES-256) and in transit (TLS 1.3). Access is restricted to authorized NimbusForgeSystems personnel on a need-to-know basis. We implement ISO 27001-aligned security controls.
5. Third-Party Sharing
NimbusForgeSystems does not sell, rent, or share personal data with third parties for marketing purposes. Data may be shared with: payment processors (Stripe) for transaction execution, cloud infrastructure providers for service delivery, and legal authorities when required by law.
6. Data Subject Rights
Under GDPR, you have the right to: access your personal data, rectify inaccurate data, erase your data ("right to be forgotten"), restrict processing, data portability, and object to processing. Exercise these rights by contacting [email protected].
7. International Transfers
If data is transferred outside the EEA, we ensure appropriate safeguards are in place via Standard Contractual Clauses (SCCs) as approved by the European Commission.
8. Contact
For privacy-related inquiries: [email protected] | NimbusForgeSystems, Calle Castillo, 22, 38002 Santa Cruz de Tenerife, España.
REFUND POLICY
Last Updated: January 2026
Provider: NimbusForgeSystems, Calle Castillo, 22, 38002 Santa Cruz de Tenerife, España.
1. One-Time Service Fees
Fees for one-time services (Cybersecurity Hardening, VoIP Deployment, Migration, Compliance Audits) are refundable in full if work has not commenced. If work has commenced, a pro-rata refund will be calculated based on completed deliverables against the total scope.
2. Subscription Services
Monthly subscription services (24/7 Monitoring, Cloud Management, Helpdesk Support, Backup & Disaster Recovery) can be cancelled with 30 days written notice. The current billing cycle is non-refundable. No prorated refunds for partial months.
3. Refund Process
Refund requests must be submitted via email to [email protected] within 14 days of payment. Refunds are processed within 10-15 business days to the original payment method via Stripe.
4. Non-Refundable Items
The following are non-refundable: setup and onboarding fees, third-party license costs incurred on behalf of the client, hardware procurement costs, and completed DR drill execution fees.
5. Dispute Resolution
Any disputes regarding refunds shall first be addressed through direct communication. If unresolved, disputes may be escalated under the applicable consumer protection laws of the Canary Islands, Spain.
TERMS OF SERVICE
Last Updated: January 2026
Provider: NimbusForgeSystems, Calle Castillo, 22, 38002 Santa Cruz de Tenerife, España.
1. Acceptance of Terms
By engaging NimbusForgeSystems for managed IT services, you agree to these Terms of Service. These terms govern the relationship between NimbusForgeSystems ("Provider") and the client ("Client").
2. Service Scope
Services are defined in individual Statements of Work (SOWs) provided at engagement commencement. NimbusForgeSystems will deliver services as specified in the applicable SOW. Scope changes require written mutual agreement.
3. Client Obligations
The Client must: provide necessary access credentials and infrastructure details, designate a primary point of contact, respond to provider requests within 24 hours, and maintain adequate internal backups independent of provider-managed backups.
4. Service Level Agreement
NimbusForgeSystems commits to: 99.9% uptime for managed environments, 15-minute initial response for critical incidents, 4-hour resolution target for high-priority issues, and weekly infrastructure health reports.
5. Liability
NimbusForgeSystems liability is limited to the total fees paid by the Client in the 12 months preceding the claim. The Provider is not liable for indirect damages, data loss resulting from Client's failure to maintain independent backups, or downtime caused by third-party services.
6. Intellectual Property
All custom scripts, configurations, and documentation created specifically for the Client during service delivery become the Client's property upon full payment. NimbusForgeSystems retains ownership of proprietary tools and methodologies.
7. Confidentiality
Both parties agree to maintain confidentiality of proprietary information exchanged during the service relationship. This obligation survives contract termination by 36 months.
8. Termination
Either party may terminate with 30 days written notice. Immediate termination is permitted in cases of material breach, non-payment for 30+ days, or violation of applicable law.
9. Governing Law
These terms are governed by the laws of Spain and the Canary Islands. Disputes shall be resolved in the courts of Santa Cruz de Tenerife.
10. Contact
Questions about these terms: [email protected] | NimbusForgeSystems, Calle Castillo, 22, 38002 Santa Cruz de Tenerife, España.