Last updated: August 7, 2026
We are a privacy company. So we expect you to actually be able to read this - no legalese, no surprises.
NexoPrivacy (“we”, “us”, “our”) is the data controller for personal data you give us through this website and through our sales and consulting engagements. You can reach us any time at hello@nexoprivacy.com.
We keep enquiry data for 24 months, scan-request records for 36 months, and contractual records for 7 years (driven by accounting rules). You can ask us to delete sooner - see your rights below.
If you are in the EU/UK, California, Kenya, South Africa, Brazil, Singapore or anywhere with a modern privacy regime, you have the right to access, correct, delete, restrict, port or object to our processing of your personal data. To exercise any of these rights, email hello@nexoprivacy.com. You also have the right to lodge a complaint with your local supervisory authority.
We operate globally. Where we transfer your data across borders, we use Standard Contractual Clauses and, where applicable, the UK IDTA / Addendum, together with appropriate technical and organisational safeguards.
We hold ourselves to the same standards we set for our clients: encryption in transit and at rest, least-privilege access, MFA, logging, monitoring and a documented incident-response plan.
We will note material updates at the top of this page. The current effective date is shown above.