Controller and scope
Nexus Soft Ltd is the controller for personal data collected through this public website. Business address: Jordan Nenov 32, Pazardjik, Bulgaria. For privacy enquiries, use our contact form or select Show email in the Legal contact panel and include “Privacy request” in the subject line.
This notice covers www.nexus-soft.org, its member workspace, the separate administration portal at admin.nexus-soft.org, people who contact us and business representatives whose details an authorised administrator provides. It does not replace a deployment-specific privacy notice or data processing agreement where Nexus processes advertising or customer data on documented instructions for a client.
Selling AdTech software is different from using visitor data for advertising. This corporate website does not run customer advertising campaigns or sell advertising profiles. An operator using Nexus modules under its own brand must explain its own traffic collection, partners, consent requirements and data protection roles to its users.
The Nexus platform is intended for business users. Customer deployments can use different infrastructure, subprocessors and retention settings; those details must be recorded in the applicable contract.
Personal data we process
We collect information that you provide, limited technical information required to operate and secure the service, and authentication information created when you use an account.
| Context | Data categories | Source |
|---|---|---|
| Contact enquiry | Name, business email, optional company and project context, area of interest, message, submission time, internal follow-up notes, workflow status and notification status | Submitted by you; follow-up notes and status are recorded by the Nexus team and notification system |
| Website account | Name, verified email, Google profile image URL and Google subject where used, role, account status, assigned platform identifiers, authentication provider, salted password hash for email accounts, encrypted authenticator seed, keyed recovery-code hashes, account dates, terms acceptance time and last sign-in time | Provided during registration, received from Google where selected, or provisioned by an administrator |
| Platform onboarding records, where held | Account identifier, requester name and email, company and website or requested domain, chosen modules, channels, volume, markets, project objective, request dates and review or cancellation status | Provided during platform onboarding, including retained earlier requests, and reviewed by an authorised Nexus administrator; this does not imply a currently available self-service request form |
| Administrator-linked MCP connections | Connected server and platform references, remote account identifier, username, name, role or type, domain and encrypted connector credentials | Created by an authorised administrator when connecting a platform service, separately from the public product-discovery MCP interface |
| Secure access | Opaque signed session and temporary 2FA challenge identifiers, OAuth state and PKCE verifier, accepted TOTP counter, failed-login and 2FA controls, recovery-code use and security audit records | Generated by Nexus when you use protected services |
| AI product assistant | The current question and bounded recent messages used locally to identify the product context; the current question, inferred product context and selected public facts if an external AI provider is used | Provided directly by you |
| Service operation | Request metadata that may include IP address, user agent, time, requested endpoint and error or rate-limit information | Generated when your browser communicates with our infrastructure |
| Privacy choice | Consent version, allowed categories, decision type and decision/expiry times | Stored locally in your browser |
| Optional public website analytics | Canonical public page paths and fixed titles, limited predefined interaction events, origin-only referral information and approved fixed campaign labels, pseudonymous analytics cookie identifiers and browser/device information. Raw query strings, arbitrary campaign text and individual recipient identifiers are not sent. Google also receives technical connection metadata when the browser contacts its service. | Google Analytics 4, only when configured and after current analytics consent |
Purposes and legal bases
We use personal data only where a lawful basis applies. The applicable basis can vary with the context of your request.
| Purpose | Typical legal basis |
|---|---|
| Respond to an enquiry and prepare a requested proposal | GDPR Article 6(1)(b) for a requested contract with you; Article 6(1)(f) for communication with a business representative and assessment of a company enquiry |
| Provision authorised access, authenticate you and provide role-scoped portal functions | Article 6(1)(b) where necessary to provide your requested account service; Article 6(1)(f) to administer authorised representatives of customer organisations |
| Bind an approved account to the verified Google identity and enforce assigned platform access | Article 6(1)(f): preventing impersonation and protecting customer data and infrastructure |
| Prevent abuse, enforce access controls and investigate incidents | Article 6(1)(f): protecting users, services and infrastructure; Article 6(1)(c) where a specific legal obligation applies |
| Provide the AI product assistant after you submit a question | Article 6(1)(f): answering a voluntarily submitted product question using the public product guide |
| Keep records needed for legal claims and compliance | Article 6(1)(c) for applicable statutory records; Article 6(1)(f) for establishing, exercising or defending legal claims |
| Measure use of the public website with configured Google Analytics 4 | Article 6(1)(a): your optional analytics consent; marketing tracking is not installed |
What is optional and what happens if you do not provide it
You can read public pages without an account, submitting an enquiry, using AI or accepting analytics. The contact form requires a name, reply email, area of interest and message so we can handle the request. Company and other project context are optional. You can instead use Show email on the contact page.
Account access needs an email address that you control and successful verification. If you choose Google, we receive identity information, not your Google password or permission to read your Gmail mailbox. Platform onboarding details, where collected, help an administrator evaluate provisioning; an enquiry or retained onboarding request does not automatically create a deployment.
Acknowledging this notice or accepting website Terms is not consent to analytics, direct marketing or customer advertising tracking. Submitting an enquiry does not subscribe you to a newsletter. You may object to business follow-up; essential responses to your request and security or account messages are separate from marketing.
AI assistant and MCP interfaces
The public MCP server exposes product documentation, structured advertising-format information and deployment guidance. It is not designed to receive personal data and its public tools do not provide arbitrary access to customer databases or credentials.
The website AI assistant selects answers from the Nexus public product knowledge base. Nexus processes the current question and bounded recent messages to identify context. When an OpenAI API connection is configured, we send the current question, inferred product context and candidate public facts to OpenAI to select supporting evidence; we do not send the complete conversation history in that provider request. The request disables response storage, which is not a promise of zero provider-side retention. Without that connection, the guide uses local knowledge selection.
The website application does not save a chat transcript in its database. Conversation state remains in the open page; provider-side security or service retention may apply to external requests. Do not submit personal, confidential, regulated or customer traffic data to the public assistant.
The public guide cannot approve accounts, award a contract, buy media, change a customer platform or make decisions with legal or similarly significant effects about you. Account permissions and platform requests are reviewed by administrators. Authentication and abuse controls may automatically deny a request; contact us if you believe access was blocked in error.
A commercial AI or MCP integration that processes customer data requires its own documented scope, access controls, retention settings and data processing terms.
Recipients and service providers
Google Workspace is used for business email and the configured transactional SMTP relay. It processes recipient addresses and message content for registration confirmation, password reset and business correspondence. Account passwords are never included in those messages. Software support for an alternative mail provider does not mean your messages are sent to every supported provider.
Website enquiries are saved in a protected administrator inbox. When email delivery is configured, the selected mail provider also processes the submitted business brief and your email address to notify the Nexus team inbox. Your email is used as Reply-To so the team can respond. Submitting the form does not automatically send an email to the visitor or book a meeting.
Access inside Nexus Soft is limited to people who need the information for sales, support, account administration, security or legal responsibilities. Hosting and database operators process information needed to run the website and private workspaces. Configured monitoring services may receive sanitised technical error and security metadata; the application supports Better Stack for this purpose. Professional advisers or competent authorities may receive information needed for a specific legal matter. Provider access and processing locations must be covered by the relevant service arrangements.
Google receives and returns authentication data when an authorised portal user chooses Google sign-in. OpenAI may process AI chat content only when the external AI connection is configured and you submit a question. We may disclose information where required by law or necessary to protect legal rights and service security.
Google processes the limited public website analytics data described above only when Google Analytics 4 is configured and you consent to analytics. That analytics purpose is separate from Google sign-in and account email delivery. We do not send account User-IDs, form content or AI conversations to Google Analytics.
We do not sell personal data collected through this corporate website.
International transfers
Google services, an enabled external AI connection and infrastructure or support providers may involve processing outside the European Economic Area, including in the United States. A European company address or server location does not by itself mean that all service-provider access remains in the EEA.
An international transfer requires an applicable safeguard, such as an adequacy decision covering the recipient or Standard Contractual Clauses with any necessary supplementary measures. The relevant mechanism depends on the receiving entity and service agreement, not merely the provider brand. You can request information about the safeguards applicable to your data, including a copy where available, through the privacy contact route. This notice is not itself a transfer agreement or a claim that every provider has the same certification.
The precise hosting region and subprocessors for a customer platform are confirmed in deployment documentation rather than assumed from this public website notice.
How long we retain data
The table distinguishes application expiry rules from records that require a purpose-based review. Database expiry cleanup is asynchronous, not instantaneous. A separate restricted record may be kept where a specific legal obligation or active claim requires it. Deleting browser storage does not delete server-side records or correspondence already delivered to a mailbox.
| Record | Typical retention |
|---|---|
| Contact enquiry | Website database records expire 730 days after submission, including their internal notes and notification metadata. Related email correspondence is managed separately and may form part of a customer record. |
| Website account and member platform requests | Kept while needed to administer requested access, an open platform request or the related business relationship. Account deactivation and request cancellation do not automatically erase these records. Ask us to close the account or review deletion; retained records are assessed against outstanding requests, security needs, legal obligations and claims rather than a fixed automatic post-closure deletion deadline. |
| Administrator-linked MCP connections | Kept while the connection is required for authorised platform operations, until it is removed through the protected administration workflow. Removing a connection does not itself erase separate audit records or data held by the remote platform. |
| Authentication session cookie | Up to 7 days for members or 12 hours for administrators, or until logout/revocation/expiry |
| OAuth state and PKCE verifier cookies | 10 minutes or completion of the authentication attempt |
| Temporary 2FA challenge cookie | 10 minutes, cancellation or successful verification |
| Email verification and password-reset token hashes | 30 minutes or earlier single-use redemption; expired records are removed by database TTL cleanup |
| Privacy preference record | Valid for 180 days, then the site asks again. An expired local-storage entry is removed when next read by the site; browser storage does not expire itself. |
| Google Analytics cookies, where enabled with consent | Up to 180 days, without renewal on each visit. Withdrawal denies further optional measurement and attempts cookie cleanup when the analytics configuration is loaded; browser site-data controls can remove any remaining cookies. |
| Optional acquisition context in the browser tab | A fixed 30-minute validity window, not extended by ordinary internal navigation or reload. An expired record is removed when next checked; withdrawal and navigation to a private or unknown page clear it. Browser tab-session storage also ends with the tab session. |
| Google Analytics event data, where enabled with consent | The GA4 property configuration last checked on 9 September 2026 uses 2 months for user-level and event-level retention, with reset on new activity off. Standard aggregated reports are not governed by that setting. This is separate from the 180-day cookie and consent lifetime. |
| AI chat in the browser | Held in memory while the page is open; a full reload clears this conversation state. External request retention, where applicable, is governed separately by the provider service configuration; disabling response storage is not a zero-retention guarantee. |
| Authentication audit and platform change history | Database expiry is configured at 365 days after each record is created. A separately preserved incident or legal record may be retained where necessary for that specific matter. |
| Operational logs, backups and business correspondence | Managed separately from the application expiry rules. Retention depends on recovery cycles, incident investigation, outstanding correspondence and applicable record-keeping duties. A database deletion does not immediately remove delivered email or backup copies; these require their own controlled lifecycle. Contact us for information relevant to your request. |
Your data protection rights
Subject to the conditions in applicable law, you may request access, correction, erasure, restriction, portability, or object to processing based on legitimate interests. Where processing relies on consent, you may withdraw it at any time without affecting earlier lawful processing.
Send a privacy request through our contact form or select Show email in the Legal contact panel and use “Privacy request” in the subject. No account is required. We may request proportionate identity verification, not your password. We respond within one month; if the number or complexity of requests requires up to two additional months, we explain the extension within the first month. Requests are normally free, subject to the statutory rules for manifestly unfounded or excessive requests.
You may complain to the Bulgarian Commission for Personal Data Protection or the supervisory authority in the EU/EEA country of your habitual residence, workplace or the alleged infringement.
Security and data minimisation
Nexus supports member registration with a verified email and password or Google. Passwords are stored as salted scrypt hashes, never plaintext. Email verification and password reset use expiring, single-use links. Revocable opaque sessions use signed HTTP-only cookies; Google sign-in uses state and PKCE protection. Server-side role and platform assignment checks, credential-version checks, administrator allowlists, bounded inputs, trusted-origin checks, rate limits and security audit records protect access. Registration never grants platform access. No internet service is risk-free.
Please do not send passwords, authentication tokens, raw user-level advertising data, payment details, special-category data or other unnecessary confidential information through the contact form or public AI assistant.
Children
This business website and its authenticated services are not directed to children. We do not knowingly request personal data from anyone under 18 through the public website. Contact us if you believe a child has submitted information so that we can review and take appropriate action.
Changes and contact
We may update this notice when the website, providers or legal requirements change. Material changes will be identified by a new effective date and, where appropriate, an additional notice.
Controller: Nexus Soft Ltd. Contact us through the contact form or select Show email in the Legal contact panel. Use the subject “Privacy request” so the request reaches the appropriate team.