Legal
Privacy Policy
What we collect, why we collect it, and how to have it removed. Written to be read, not survived.
Last updated September 5, 2026
01Scope of this policy
This policy explains what personal data NEXUS collects when you visit this site or write to us, why we collect it, and what you can do about it. It covers this website and the enquiries you send through it.
NEXUS is the controller of the data described here. If you engage us for a project, the contract we sign governs how we handle data inside your systems; this policy covers only our own site and correspondence.
02Data we collect
We keep collection deliberately small. We do not sell personal data and we run no advertising trackers on this site.
- Contact details you give us — your name, email address, company and the contents of the message you send through the contact panel or by email.
- Technical data our hosting provider records in order to serve the site — IP address, browser and device type, referring page and timestamps.
- Preferences stored in your browser, such as the language you selected.
03How we use it
We use that data for a short, closed list of purposes.
- Answering your enquiry and discussing a possible engagement.
- Preparing the proposals, estimates and contracts you asked for.
- Keeping the site secure, available and free of abuse.
- Understanding in aggregate which pages are useful — never to profile individuals.
04Legal basis
Where data protection law requires a legal basis, we rely on your consent when you choose to contact us, on the steps necessary to enter into a contract when we prepare a proposal, and on our legitimate interest in operating and securing this site.
You can withdraw consent at any time by asking us to delete your enquiry.
06How long we keep it
We keep enquiry correspondence while the conversation is live, and for up to twenty-four months afterwards so we can pick up where we left off. Contract and billing records are kept for the period tax and commercial law require.
Server logs are retained briefly for security and diagnostics, then discarded.
07How we protect it
We hold our own systems to the standards we apply to client work.
No system is perfectly secure. If a breach ever affects your data, we will notify you and the competent authority within the deadlines the law sets.
- Encryption in transit for every request to this site.
- Access to correspondence limited to the people who need it, behind multi-factor authentication.
- Least-privilege access, reviewed periodically.
- No production client data is stored on this website.
08Your rights
Depending on where you live you have some or all of the following rights over your personal data. Write to us and we will act within thirty days.
- Access a copy of the data we hold about you.
- Correct data that is inaccurate or incomplete.
- Delete your data where no overriding obligation requires us to keep it.
- Object to, or restrict, a particular use.
- Receive your data in a portable, machine-readable format.
- Complain to your local data protection authority.
10International transfers
Our providers may process data on servers outside your country. Where that happens we rely on the safeguards those providers offer, such as standard contractual clauses, so the protection travels with the data.
11Changes to this policy
We update this policy when our practices change. The revision date at the top always reflects the current version, and material changes are highlighted on this page.
12Contact
To exercise a right, ask a question or raise a concern about this policy, write to us and tell us what you need. We answer every message.
Questions about this document? Write to nexussas6@gmail.com