Trust

How we handle your data

Nexus connects people across communities, and that means we handle personal and professional information you trust us with. This page explains how we handle your data, our GDPR position, the vendors we rely on, and where we are on our security roadmap.

Overview

Trust is a system, not a statement. The way we handle your data, the vendors we rely on, and the commitments we make to EU and enterprise customers all live on this page so you can audit them in one place.

If you are evaluating Nexus for your community or organization and you need a document we do not yet publish here — a signed DPA, our security questionnaire response, a specific compliance attestation — email privacy@nexus.app and we will respond within five business days.

How we handle your data

Nexus is a platform for communities to connect their members. That means we handle two kinds of data: data about the people in a community (names, emails, profile information, the interactions they have in Nexus) and data about the communities themselves (member lists, admin configuration, billing details).

What we collect

Identity and contact data you provide when you create an account; profile content you publish inside a community; meeting content (calendar bookings, session transcripts when you explicitly enable transcription); and technical usage data we use to operate and secure the service.

Where it lives

Primary application data is stored in PostgreSQL hosted on AWS. Files and uploads are stored in AWS S3. We do not sell, trade, or rent your data. A full list of sub-processors who may access data on our behalf is below.

How long we keep it

We retain personal data only as long as we need it for the purpose it was collected. When an account is deleted, personal data is removed from production systems within 30 days, with the category-specific exceptions below.

  • Account and profile data: for as long as the account is active; deleted within 30 days of account deletion.
  • Meeting transcripts: retained for 12 months from the session date, or until you delete the meeting, whichever is sooner.
  • Inferred profile and matching signals: deleted with the account; regenerated from source data as it changes.
  • Behavioral and usage telemetry: aggregated and de-identified after 90 days.
  • Application and access logs: 30 days.
  • Backups: rotated out within 35 days.
  • Billing and tax records: retained for 7 years to meet financial and legal obligations.

GDPR

If you are an individual in the EU, UK, or EEA using Nexus, the General Data Protection Regulation (GDPR) and UK GDPR give you a set of rights over your personal data. We comply with those regulations and will honor requests from any user worldwide that fall within them.

Our role

For community members, Nexus typically acts as a data processor on behalf of the community operator (our customer), who is the data controller. For the Nexus account itself — billing, admin users, platform-level activity — we act as the data controller.

Lawful basis

Where we act as data controller, we rely on the following lawful bases under Article 6 of the GDPR:

  • Performance of a contract: creating and operating your account, providing the platform, and billing.
  • Legitimate interests: matching and recommendation, fraud and abuse prevention, securing the service, and improving the product. We balance these against your rights, and you can object at any time.
  • Consent: optional features such as session transcription. You can withdraw consent at any time without affecting prior processing.
  • Legal obligation: retaining financial records and responding to lawful requests from authorities.

Where we act as processor for a community operator, the operator is responsible for determining the lawful basis for processing community member data, and we process that data on their documented instructions.

Your rights

You have the right to access the personal data we hold about you, correct it, delete it, restrict or object to processing, and receive it in a portable format. You can exercise most of these rights from your account settings. For anything that cannot be handled in-app, email privacy@nexus.app and we will respond within 30 days.

International transfers

Some of our sub-processors operate in the United States. Where personal data moves from the EU, UK, or EEA to a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum as the transfer mechanism.

Data Processing Addendum

We offer a Data Processing Addendum (DPA) to customers who need one for their own GDPR compliance. Email privacy@nexus.app and we will send it over for signature.

Sub-processors

These are the third parties we rely on to operate Nexus. They may process personal data on our behalf and are bound by contractual obligations equivalent to those we make to you.

VendorPurposeRegion
Amazon Web Services (AWS)Application hosting, database, file storage (S3)United States
ClerkAuthentication and identity managementUnited States
OpenAIAI model inference for platform featuresUnited States
Daily.co1:1 video sessions and transcriptionUnited States / EU
ResendTransactional email deliveryUnited States
SentryError monitoring and observabilityUnited States

We have executed data processing agreements with each sub-processor listed above. Where personal data is transferred outside the EU, UK, or EEA, those agreements incorporate the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum, where applicable) as the transfer mechanism.

We will notify customers in advance of any material change to this list. To subscribe to sub-processor update notifications, email privacy@nexus.app.

Security practices

Encryption

Data is encrypted in transit using TLS 1.2 or higher. Data at rest in our databases and file storage is encrypted using AES-256.

Access control

Access to production systems is limited to authorized Nexus personnel, gated by single sign-on and multi-factor authentication, and logged. Engineers are granted the minimum privileges necessary to do their work.

Monitoring

We log application and infrastructure events and alert on anomalies. Errors are captured through Sentry for investigation.

Secure development

Code changes are reviewed before deployment. Dependencies are monitored for known vulnerabilities, and we update promptly when issues are disclosed.

Compliance & SOC 2

SOC 2 Type II: We are currently preparing for a SOC 2 Type II audit. We will publish the report here, available under NDA, once the audit is complete. If you need visibility into our controls before then, we will share our in-progress control documentation under NDA — email security@nexus.app.

GDPR: See the GDPR section above.

CCPA / CPRA: California residents have the rights to know, access, delete, correct, and port their personal information, and the right to non-discrimination for exercising them. We do not sell or share personal information for cross-context behavioral advertising. Full disclosures are in the California section of our Privacy Policy.

Other frameworks: If your procurement process requires a specific standard (ISO 27001, HIPAA, etc.) that we have not yet pursued, tell us — it helps us prioritize.

Incident response

If we discover a security incident that affects your data, we will notify you without undue delay, and in any event within the timeframes required by applicable law (for GDPR-covered incidents, within 72 hours of becoming aware). Notifications will describe what happened, what data was affected, what we are doing to contain and remediate it, and what you can do in response.

If you believe you have discovered a vulnerability in Nexus, please report it to security@nexus.app. We will acknowledge your report within two business days.

Contact

Privacy, data subject requests, DPAs: privacy@nexus.app

Security issues, vulnerability reports, SOC 2 documentation: security@nexus.app