Home Privacy policy
← Back to site
Legal

Privacy policy

This policy explains what personal information NexusMind collects through this website and in the course of client work, why we collect it, how long we keep it, and the rights you have over it.

Last updated 22 August 2026Applies to nexusmind.dev and client engagements
Note
This page is a drafting template, not legal advice. Have a qualified lawyer in your jurisdiction review and adapt it before you publish — particularly the sections on data handling, liability and governing law.
01

Who is responsible

NexusMind (“we”, “us”) is the controller of personal information collected through this website. For questions about this policy or to exercise any right described below, contact hello@nexusmind.dev.

Where we process personal information on behalf of a client — for example inside software we have built and operate for them — the client is the controller and we act as their processor under a written agreement. This policy covers our own processing.

02

What we collect

Information you give us

  • Contact form. Name, business name, kind of business, email address, optional phone number, and whatever you write in the message field.
  • Correspondence. Emails, call notes and documents you send us during a scoping conversation or engagement.

Information collected automatically

  • Server logs. IP address, user agent, requested page, timestamp and referrer. Generated by our hosting provider for security and diagnostics.
  • Analytics. Aggregate page views and referrers. See the cookie notice for what is set and how to refuse it.

We do not collect special category data through this website, we do not buy contact lists, and we do not enrich your record with data from third-party brokers.

03

Why we use it, and on what basis

PurposeData usedLawful basis
Replying to an enquiry and scoping workContact form, correspondenceLegitimate interests; steps prior to a contract
Delivering an engagement and invoicingContact details, project recordsPerformance of a contract
Keeping accounting and tax recordsInvoices, contract recordsLegal obligation
Site security and abuse preventionServer logsLegitimate interests
Understanding which pages are readAggregate analyticsConsent

We do not use your information for automated decision-making or profiling, and we do not add enquirers to a marketing list. If you ask a question and decide not to proceed, you will not hear from us again unless you get back in touch.

04

Who we share it with

We share personal information only with service providers who need it to operate our business, under contracts that restrict what they may do with it.

RecipientPurposeLocation
Hosting providerServing this website; server logsNorth America / EU
Email providerBusiness correspondenceNorth America
Analytics providerAggregate site statisticsNorth America / EU
Accounting softwareInvoicing and statutory recordsNorth America
Professional advisersLegal or accounting advice, where neededNorth America

We do not sell personal information, and we do not share it for cross-context behavioural advertising. We may disclose information where required by law or to establish or defend a legal claim.

05

How long we keep it

RecordRetention
Enquiry that did not become an engagement24 months from last contact
Client project records and correspondence7 years after the engagement ends
Invoices and accounting recordsAs required by tax law (typically 6–7 years)
Server logs90 days
Aggregate analytics26 months

When a retention period ends we delete the record or irreversibly anonymise it.

06

International transfers

Some providers listed above process data outside your country. Where personal information moves out of the UK, EEA, or Canada, we rely on an adequacy decision where one exists, and otherwise on standard contractual clauses together with an assessment of the destination. You may request a copy of the safeguards applied to a specific transfer.

07

Your rights

Depending on where you live, you may have the right to:

  • Access a copy of the personal information we hold about you.
  • Correct information that is inaccurate or incomplete.
  • Delete information where we no longer have a valid reason to keep it.
  • Restrict or object to processing based on our legitimate interests.
  • Withdraw consent at any time, where consent is the basis — this does not affect processing already carried out.
  • Portability — receive information you gave us in a machine-readable format.
  • Non-discrimination for exercising any of these rights.

To exercise a right, email hello@nexusmind.dev. We will respond within 30 days and will not charge a fee for a reasonable request. We may ask you to confirm your identity first.

If you are unhappy with our response you may complain to your data protection authority — in the UK the Information Commissioner’s Office, in Canada the Office of the Privacy Commissioner, or your state Attorney General in the United States.

08

Security

Access to personal information is limited to those who need it. Data in transit is encrypted, credentials are stored in a password manager with multi-factor authentication, and client credentials are handled as described in our security page. No system is perfectly secure; if a breach affects your information and presents a real risk to you, we will notify you and the relevant regulator within the time limits that apply.

09

Children

This website is aimed at businesses and is not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe a child has given us information, contact us and we will delete it.

10

Changes to this policy

If we change this policy we will update the date at the top of this page. Where a change materially affects how we use information you have already given us, we will contact you directly rather than relying on you noticing this page.

11

Contact

Questions, requests or complaints: hello@nexusmind.dev. A postal address for formal correspondence is available on request.

Building software that handles personal data? We treat privacy as a design constraint, not a policy page written afterwards.

Request a 30-min call