Privacy Policy

Definitions

Personal Data: any information related to an identified or identifiable person. Processor: an entity that processes personal data on behalf of the controller, as defined by the GDPR and the LGPD. Controller: the natural or legal person responsible for collecting personal data and making decisions about its processing.

Scope

Nexu acts exclusively as a data processor, providing and maintaining a SaaS platform. Nexu does not have autonomy to collect, modify, delete, or make decisions about the processing of personal data stored in the system. Those responsibilities belong to the controller. Nexu is committed to keeping data protected, accessible only for operational support purposes, and handled in accordance with applicable data protection regulations.

Nexu Responsibility

Nexu acts exclusively as a data processor, providing and maintaining a SaaS platform. Nexu does not have autonomy to collect, modify, delete, or make decisions about the processing of personal data stored in the system. Those responsibilities belong to the controller.

Data Access Control

To ensure the security and integrity of data stored in the technology environment, Nexu implements strict access-control mechanisms, including least-privilege access, multi-factor authentication, audit logs, monitoring, and regular access reviews.

Data Handling and Processing

Nexu professionals are not authorized to modify, extract, copy, or delete any personal data stored in its systems unless there is a formal and documented request from the controller. When operational support requires data access, Nexu documents the request, records the action, performs only the strictly necessary activities, and reviews the work to ensure no improper changes were made.

Confidentiality and Security

Nexu adopts strict measures to protect information against improper access and leaks. Personnel with access to the environment are subject to confidentiality obligations. Stored and transmitted data is protected by encryption, and monitoring tools are used to detect unauthorized access and suspicious activity.

Privacy Incident Management

If a security incident compromises personal data, Nexu will notify the controller within 24 hours after confirming the incident. The controller is responsible for notifying competent authorities within applicable regulatory deadlines, including ANPD guidance under the LGPD and supervisory authority requirements under the GDPR when applicable.

Awareness and Training

Nexu promotes regular awareness activities so professionals understand the risks and responsibilities associated with data access. Initiatives include periodic security materials, formal training at least annually, and review of operational policies and procedures.

Data Retention and Deletion

Personal data is retained only for the period strictly necessary to provide the services. At the end of the contractual relationship or upon formal controller request, Nexu may return the data in a structured format, securely and irreversibly delete the data including backups, and issue a deletion certificate upon request. Operational records such as audit logs may be retained for the minimum period required by applicable law.

Subprocessors

Nexu does not use subprocessors for the processing of personal data stored in the platform. All processing is performed internally by authorized professionals subject to the obligations described in this policy.

International Data Transfers

If personal data is stored or processed outside Brazil or the European Union, Nexu will adopt appropriate safeguards to ensure a level of protection equivalent to that required by the LGPD and GDPR, including standard contractual clauses or equivalent mechanisms when applicable.

Support for Data Subject Rights

As a processor, Nexu does not maintain a direct relationship with data subjects. However, Nexu commits to supporting the controller in responding to data subject requests, including access, correction, deletion, portability, objection, and restriction, within contractually established deadlines and applicable legal limits.

Data Protection Officer (DPO)

Nexu has appointed a Data Protection Officer responsible for acting as a communication channel between the company, controllers, and data protection authorities, and for providing internal guidance on compliance with applicable privacy rules. For privacy-related questions, requests, or communications, contact: dpo@nexu.ca.