How the Nexus consent model works
Strictly necessary technologies operate without optional consent because they are required to provide a service you explicitly request, such as secure sign-in, or to remember your expressed privacy choice. Optional categories are off by default.
“Reject optional” and “Accept all” are available at the same level. “Customize choices” provides category controls. Refusing optional technologies does not block access to the public website. You can reopen the controls through “Cookie settings” in the footer.
“Accept all” allows the installed optional analytics purpose only; marketing remains off. A previous consent version does not authorize Google Analytics 4. If preferences are invalid, expired or cannot be read or saved, optional analytics remains off.
Your decision is valid for 180 days. Nexus asks again on a subsequent visit after expiry, or sooner if the consent model materially changes. Local storage does not self-expire; the site removes an expired entry when it next reads it.
Technology inventory and activation conditions
Necessary cookies appear when you use the related account function. The optional Google Analytics cookies below appear only on the public website when analytics is configured and you have given current consent; an inventory entry does not mean tracking is always active.
| Name | Type / provider | Purpose | Duration / category |
|---|---|---|---|
| nexus_member_session / __Host-nexus_member_session | First-party, HTTP-only cookie / Nexus | Carries an opaque signed identifier for a revocable server-side member session. It contains no profile or role data and is not readable by client-side JavaScript. | Up to 7 days · Strictly necessary |
| nexus_admin_session / __Host-nexus_admin_session | First-party, HTTP-only cookie / Nexus | Carries an independently signed administrator session identifier. Member sessions are never accepted by the administration API. | Up to 12 hours · Strictly necessary |
| nexus_member_oauth_state, nexus_admin_oauth_state and __Host- production variants | First-party, HTTP-only cookie / Nexus | Protects the selected member or administrator Google sign-in redirect against request forgery and validates the returning authentication attempt. | Up to 10 minutes · Strictly necessary |
| nexus_member_oauth_verifier, nexus_admin_oauth_verifier and __Host- production variants | First-party, HTTP-only cookie / Nexus | Stores the one-time PKCE verifier bound to the Google authorization attempt. | Up to 10 minutes · Strictly necessary |
| nexus_member_oauth_registration / __Host-nexus_member_oauth_registration | First-party, HTTP-only cookie / Nexus | Remembers an explicit member registration request, cryptographically bound to the same Google sign-in attempt. It cannot authorize administrator registration. | Up to 10 minutes · Strictly necessary |
| nexus_member_two_factor, nexus_admin_two_factor and __Host- production variants | First-party, HTTP-only cookie / Nexus | Carries a portal-bound opaque identifier for the temporary 2FA recommendation or verification step. It cannot access either workspace. An unenrolled account may explicitly skip setup; an enrolled account must verify before a session is issued. | Up to 10 minutes · Strictly necessary |
| nexus_cookie_preferences_v1 | First-party local storage / Nexus | Records consent version, allowed categories, type of decision and decision/expiry times so the banner respects your choice. | 180-day validity; expired data removed on the next read, or by clearing browser site data · Strictly necessary |
| nexus_analytics_denied_v2 | First-party session storage / Nexus | Keeps analytics denied across reloads if a privacy-choice update cannot be saved. Contains only a denial marker, not an identifier. | Until the browser tab session ends or an explicit choice is successfully saved · Strictly necessary |
| _ga and _ga_<measurement identifier> | Public-host-only cookies / Google Analytics 4 | Recognises pseudonymous browsers and analytics sessions for consented public-page measurement. Cookies use path / and are not shared with the administration subdomain. | Up to 180 days, without renewal on each visit · Optional analytics |
| nexus_analytics_acquisition_v1 | Public-origin tab session storage / Nexus | After current analytics consent and valid public-site configuration only: preserves the public origin, an approved fixed campaign code if present, an external origin-only referrer and an expiry time. It contains no recipient identifier, raw URL, query string or browsing history. | 30-minute validity without rolling extension on ordinary internal navigation or reload; removed on the next check after expiry, withdrawal or private/unknown-page navigation, or when the tab session ends · Optional analytics |
Optional categories
Google Analytics 4, when configured, measures canonical public page visits and limited predefined website interactions only after analytics consent. No Google analytics script, collection request or consent-mode ping is loaded before consent. No analytics runs on member, administrator, authentication or API pages or the administration hostname.
Analytics events exclude raw URL query strings and fragments, form contents, AI chat text and account User-IDs. Only approved fixed campaign labels and origin-only referral information may describe where a consented public visit came from; arbitrary query values and individual recipient identifiers are not forwarded. Advertising features, Google Signals and marketing tracking are disabled. We do not request consent for an uninstalled marketing provider.
Consent version 3 adds the disclosed limited acquisition measurement and short-lived tab storage and requires a fresh choice; version 1 and version 2 choices do not authorize it. Adding another provider or materially changing a purpose requires an updated notice and inventory, a new consent version and fresh consent; a previous general category choice is not reused.
The 180-day cookie expiry and consent lifetime do not determine how long Google retains analytics event data. The GA4 property configuration last checked on 9 September 2026 uses 2 months for user-level and event-level data, with reset on new activity off. Standard aggregated reports are not governed by that retention setting.
Google can create technical analytics events such as first_visit and session_start alongside the public events we send after consent. Turning off Enhanced Measurement is not a promise that these baseline events disappear. We do not install advertising tags, a session-replay recorder or customer ad-serving cookies on this corporate website.
| Category | Default | Current status |
|---|---|---|
| Analytics | Off | Google Analytics 4 only when configured on the public website and after current consent |
| Marketing | Off | Not installed; remains denied |
Change or withdraw your choice
Use the “Cookie settings” control in the website footer, then choose “Reject optional” or turn analytics off and save. Turning off a category withdraws consent for future use. It does not affect processing that was lawful before withdrawal or delete analytics events already received by Google.
Withdrawing analytics denies subsequent optional measurement. When the analytics configuration has been loaded, the site also attempts to remove its accessible analytics cookies and reloads to stop the loaded tag. Cookies can remain if withdrawal occurs on an unmeasured page or the browser blocks deletion; use browser site-data controls to remove them. Open tabs on the same website origin receive preference changes where browser storage is available. A later grant starts from the current public page; it does not send previously refused activity.
If a privacy update cannot be saved, Nexus attempts to retain a separate temporary denial and remove any older preference. If neither storage mechanism works, the current page stops analytics and moves to an unmeasured sign-in screen instead of reloading analytics under an old grant. Clear this website’s saved data before manually reopening public pages if your browser cannot save or remove preferences; a fully blocked browser cannot guarantee that a failed choice persists.
You can also remove website data through your browser settings. Removing the applicable nexus_member_session or nexus_admin_session cookie signs you out of that portal. Removing the privacy preference causes the site to ask for your choice again.
Browser and device controls
Most browsers let you view, block or delete cookies and site data. Blocking all storage may prevent secure sign-in and may cause the privacy notice to reappear because the browser cannot remember your choice.
Browser-level “Do Not Track” signals do not have one universally agreed technical meaning. Nexus instead uses the explicit category choices shown in the consent interface.
A choice belongs to this browser and website origin, not to a universal account preference across devices or subdomains. Google sign-in takes you to Google, which controls storage on its own service. This notice does not describe the trackers or consent tools that a customer may install in a separately operated white-label platform.
Selecting Show email reveals the team address locally. The reveal control does not set a cookie or send a request to an email-masking service. Selecting the revealed link opens your configured mail application, which has its own settings and provider.
Updates and contact
We review this notice when technologies or providers change. For questions about this inventory or privacy choices, use our contact form or select Show email in the Legal contact panel and include “Cookie question” in the subject line.