In case of a stolen key, if one can copy files with the rights of the group www-data, one can copy the certificate of the website and then usurpate the actual NextCloud server site ! Accesses of the user who performs the backup must be restrained to the minimum and avoid that kind of sensitive files.
SSH Chroot could be the solution.