info@nexoprivacy.com +254 768200243 Mon - Sat | 24 Hours
HomePrivacy Policy

Privacy Policy

Last updated: August 7, 2026

We are a privacy company. So we expect you to actually be able to read this - no legalese, no surprises.

Who we are

NexoPrivacy (“we”, “us”, “our”) is the data controller for personal data you give us through this website and through our sales and consulting engagements. You can reach us any time at hello@nexoprivacy.com.

What we collect

  • Site-scan requests: company, name, email, phone, website URL, country, optional notes.
  • Contact form messages: name, email, company, subject and your message.
  • Newsletter subscriptions: your email address.
  • Usage data: standard request data (IP address, browser, page visited) for security and aggregate analytics.
  • Cookies: only with your consent. See our Cookie Policy.

How we use your data

  • To respond to your enquiry, deliver the report you requested, or provide the services you contracted for.
  • To send you the newsletter you subscribed to (you can unsubscribe at any time, every email has a link).
  • To keep the website secure, prevent abuse and improve content.

Our lawful bases (GDPR Article 6)

  • Consent - for newsletter subscriptions and optional cookies.
  • Contract - for site-scan delivery and consulting engagements.
  • Legitimate interests - to respond to enquiries and protect the integrity of our website.
  • Legal obligation - for tax, accounting and regulatory record-keeping.

How long we keep your data

We keep enquiry data for 24 months, scan-request records for 36 months, and contractual records for 7 years (driven by accounting rules). You can ask us to delete sooner - see your rights below.

Your rights

If you are in the EU/UK, California, Kenya, South Africa, Brazil, Singapore or anywhere with a modern privacy regime, you have the right to access, correct, delete, restrict, port or object to our processing of your personal data. To exercise any of these rights, email hello@nexoprivacy.com. You also have the right to lodge a complaint with your local supervisory authority.

International transfers

We operate globally. Where we transfer your data across borders, we use Standard Contractual Clauses and, where applicable, the UK IDTA / Addendum, together with appropriate technical and organisational safeguards.

Security

We hold ourselves to the same standards we set for our clients: encryption in transit and at rest, least-privilege access, MFA, logging, monitoring and a documented incident-response plan.

Updates

We will note material updates at the top of this page. The current effective date is shown above.