Controller and scope
Nexus Soft Ltd is the controller for personal data collected through this public website. Our business contact location is Pazardzhik 4400, Bulgaria. Privacy enquiries may be sent to contacts@nexus-soft.org with “Privacy request” in the subject line.
This notice covers visitors, people who contact us, and authorised private-portal users. It does not replace a deployment-specific privacy notice or data processing agreement where Nexus processes advertising or customer data on documented instructions for a client.
The Nexus platform is intended for business users. Customer deployments can use different infrastructure, subprocessors and retention settings; those details must be recorded in the applicable contract.
Personal data we process
We collect information that you provide, limited technical information required to operate and secure the service, and authentication information created when you use an account.
| Context | Data categories | Source |
|---|---|---|
| Contact enquiry | Name, business email, company, area of interest, message and submission time | Provided directly by you |
| Website account | Name, approved business email, role, account status, assigned platform identifiers, authentication provider, stable Google subject, encrypted authenticator seed, keyed recovery-code hashes, account dates and last sign-in time | Provisioned by a Nexus administrator and received from Google when the approved user signs in |
| Secure access | Opaque signed session and temporary 2FA challenge identifiers, OAuth state and PKCE verifier, accepted TOTP counter, failed-login and 2FA controls, recovery-code use and security audit records | Generated by Nexus when you use protected services |
| AI product assistant | The question you submit and the recent conversation needed to answer it | Provided directly by you |
| Service operation | Request metadata that may include IP address, user agent, time, requested endpoint and error or rate-limit information | Generated when your browser communicates with our infrastructure |
| Privacy choice | Consent version, allowed categories, decision type and decision/expiry times | Stored locally in your browser |
Purposes and legal bases
We use personal data only where a lawful basis applies. The applicable basis can vary with the context of your request.
| Purpose | Typical legal basis |
|---|---|
| Respond to an enquiry and prepare a requested proposal | Steps at your request before a contract; legitimate interests in business communication |
| Provision authorised access, authenticate you and provide role-scoped portal functions | Performance of a contract or requested service |
| Bind an approved account to the verified Google identity and enforce assigned platform access | Legitimate interests in preventing impersonation and protecting customer data and infrastructure |
| Prevent abuse, enforce access controls and investigate incidents | Legitimate interests in protecting users, services and infrastructure; legal obligations where applicable |
| Provide the AI product assistant after you submit a question | Your request for the service; legitimate interests in product support |
| Keep records needed for legal claims and compliance | Legal obligations and legitimate interests in establishing, exercising or defending legal claims |
| Use optional analytics or marketing technologies | Consent, where such technologies are introduced and you choose to allow them |
AI assistant and MCP interfaces
The public MCP server exposes product documentation, structured advertising-format information and deployment guidance. It is not designed to receive personal data and its public tools do not provide arbitrary access to customer databases or credentials.
The website AI assistant uses the Nexus product knowledge base. When an OpenAI API connection is configured, the recent conversation required to answer your question is sent to OpenAI as a service provider. When it is not configured, the answer is generated locally from the public knowledge base. Do not submit personal, confidential, regulated or customer traffic data to the public assistant.
A commercial AI or MCP integration that processes customer data requires its own documented scope, access controls, retention settings and data processing terms.
Recipients and service providers
Access inside Nexus Soft is limited to people who need the information for sales, support, account administration, security or legal responsibilities. We may use contracted infrastructure, hosting, database, security, communications and professional service providers under appropriate confidentiality and data protection terms.
Google receives and returns authentication data when an authorised portal user chooses Google sign-in. OpenAI may process AI chat content only when the external AI connection is configured and you submit a question. We may disclose information where required by law or necessary to protect legal rights and service security.
We do not sell personal data collected through this corporate website.
International transfers
Some technology providers may process information outside the European Economic Area. Where this occurs, Nexus Soft uses an applicable transfer mechanism, such as an adequacy decision or the European Commission Standard Contractual Clauses, together with supplementary safeguards where required.
The precise hosting region and subprocessors for a customer platform are confirmed in deployment documentation rather than assumed from this public website notice.
How long we retain data
We retain personal data only for as long as needed for the stated purpose, security, legal and contractual requirements. The periods below are operating targets and may be extended where a record is needed for an active dispute, legal hold or statutory obligation.
| Record | Typical retention |
|---|---|
| Contact enquiry | Up to 24 months after the last substantive interaction, unless it becomes part of a customer record |
| Website account | For the life of the account and up to 90 days after closure, subject to security and legal records |
| Authentication session cookie | Up to 7 days for members or 12 hours for administrators, or until logout/revocation/expiry |
| OAuth state and PKCE verifier cookies | 10 minutes or completion of the authentication attempt |
| Temporary 2FA challenge cookie | 10 minutes, cancellation or successful verification |
| Privacy preference record | 180 days, then the site asks again |
| AI chat in the browser | Current page session; provider-side retention, if applicable, follows the contracted service configuration |
| Security and audit records | Normally up to 12 months, longer only where necessary for investigation or legal claims |
Your data protection rights
Subject to the conditions in applicable law, you may request access, correction, erasure, restriction, portability, or object to processing based on legitimate interests. Where processing relies on consent, you may withdraw it at any time without affecting earlier lawful processing.
Send a request to contacts@nexus-soft.org with “Privacy request” in the subject. We may ask for proportionate information to verify identity. We normally respond within one month, subject to lawful extensions for complex requests.
You may complain to the Bulgarian Commission for Personal Data Protection or the supervisory authority in the EU/EEA country of your habitual residence, workplace or the alleged infringement.
Security and data minimisation
Nexus uses a closed account-provisioning model with no public registration or local password database, revocable opaque sessions in signed HTTP-only cookies, Google state and PKCE protection, stable verified identity binding, server-enforced role and platform assignment checks, session invalidation when identity, role, scope or status changes, administrator allowlist checks, bounded inputs, trusted-origin checks, rate limits and audit events for sensitive operations. No internet service is risk-free, and these measures are reviewed against the deployment and the data involved.
Please do not send passwords, authentication tokens, raw user-level advertising data, payment details, special-category data or other unnecessary confidential information through the contact form or public AI assistant.
Children
This business website and its authenticated services are not directed to children. We do not knowingly request personal data from anyone under 18 through the public website. Contact us if you believe a child has submitted information so that we can review and take appropriate action.
Changes and contact
We may update this notice when the website, providers or legal requirements change. Material changes will be identified by a new effective date and, where appropriate, an additional notice.
Controller: Nexus Soft Ltd · Pazardzhik 4400, Bulgaria · contacts@nexus-soft.org. Use the subject “Privacy request” so the request reaches the appropriate team.