GDPR Compliance

Your Data Rights Under GDPR

We are committed to protecting your personal data and ensuring full compliance with the General Data Protection Regulation (GDPR). This page explains your rights and how we safeguard your information.

Effective: July 22, 2026

What is GDPR?

The General Data Protection Regulation (GDPR) (EU) 2016/679 is a regulation in EU law on data protection and privacy in the European Union and the European Economic Area. It addresses the transfer of personal data outside the EU and EEA areas, and gives individuals control over their personal data.

NexusAI is committed to full compliance with GDPR. This means we respect your privacy, protect your data, and give you control over how your information is used.

Our Commitment to Data Protection

We are committed to the following principles:

  • Transparency: We are open about how we collect and use your data.
  • Security: We implement robust security measures to protect your information.
  • Control: We give you control over your personal data.
  • Accountability: We take responsibility for protecting your data.

Data Protection Principles

We follow the core data protection principles outlined in GDPR:

Lawfulness, Fairness & Transparency
Purpose Limitation
Data Minimisation
Accuracy
Storage Limitation
Integrity & Confidentiality

Your Data Subject Rights

Under GDPR, you have the following rights regarding your personal data:

Right to Access

Request a copy of your personal data.

Right to Rectification

Correct inaccurate or incomplete data.

Right to Erasure

Request deletion of your data ('Right to be Forgotten').

Right to Restriction

Restrict processing of your data.

Right to Data Portability

Receive your data in a machine-readable format.

Right to Object

Object to processing for marketing or profiling.

Right to Withdraw Consent

Withdraw consent at any time.

Right to Lodge a Complaint

Complain to a supervisory authority.

To exercise any of these rights, please contact us at umaarahmed03@gmail.com.

Lawful Basis for Processing

We process your personal data only when we have a lawful basis to do so. Our lawful bases include:

  • Consent: You have given us explicit consent to process your data.
  • Contract: Processing is necessary for the performance of a contract with you.
  • Legal Obligation: Processing is necessary to comply with a legal obligation.
  • Legitimate Interests: Processing is necessary for our legitimate business interests, provided they do not override your rights.

International Data Transfers

As a global company, we may transfer your personal data to countries outside the European Economic Area (EEA). When we do so, we ensure that appropriate safeguards are in place, such as:

  • Standard Contractual Clauses approved by the European Commission
  • Data transfers to countries with adequate protection levels
  • Binding Corporate Rules (BCRs) for intra-group transfers

Data Retention Policy

We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, or reporting requirements.

When we no longer need your data, we securely delete or anonymise it.

Security Measures

We implement industry-standard security measures to protect your personal data from unauthorised access, alteration, disclosure, or destruction:

  • Encryption: SSL/TLS encryption for all data in transit
  • Access Control: Role-based access controls and strong authentication
  • Monitoring: Continuous security monitoring and threat detection
  • Audits: Regular security audits and vulnerability assessments

Data Breach Notification

In the event of a data breach that poses a risk to your rights and freedoms, we will notify you and the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by GDPR.

Data Protection Officer (DPO)

We have appointed a Data Protection Officer (DPO) to oversee our data protection strategy and ensure compliance with GDPR.

DPO Name: NexusAI Data Protection Team

Email: umaarahmed03@gmail.com

Policy Updates

We may update this GDPR page from time to time to reflect changes in our practices or for operational, legal, or regulatory reasons. We encourage you to review this page periodically. Any changes will be posted on this page with a revised effective date.

Questions about your data rights?

We're here to help. Reach out to our Data Protection Team anytime.

Contact Our DPO