Nexus · Legal
Privacy Policy Terms of Service Community Guidelines Cookie Policy Moderation & Complaints Data Retention & Deletion Data Processing

Nexus — Personal Data Processing Policy

Last updated: 22 July 2026
Version: 1.0

This document describes how Nexus processes personal data. It also serves as a
summary record of processing activities in the spirit of Article 30 GDPR.
It reflects the actual processing implemented in the Service.


1. Controller

[CONTROLLER FULL NAME] (individual operator)
E-mail: [CONTROLLER CONTACT EMAIL]
Address: [CONTROLLER POSTAL ADDRESS]

Nexus does not currently meet the mandatory thresholds for appointing a Data
Protection Officer (Article 37 GDPR). If large-scale or high-risk processing
begins, a DPO appointment will be reassessed.


2. Processing activities

# Activity Data categories Purpose Legal basis Recipients
1 Account registration & sign-in E-mail/phone/Google ID, username Provide the Service Contract 6(1)(b) Google (if used), e-mail/SMTP provider
2 Messaging, files, calls Message text (encrypted at rest), files, voice, presence Deliver the Service Contract 6(1)(b) Other users you contact
3 One-time login codes E-mail/phone, code Authenticate the user Contract 6(1)(b) Resend/SMTP provider
4 Security & login alerts Session token, IP, approximate location, device label Protect accounts, detect new logins Legitimate interests 6(1)(f) ip-api.com (IP lookup)
5 Moderation Reports, content snapshots, punishments, appeals Safety, rule enforcement Legitimate interests 6(1)(f); legal obligation 6(1)(c) Authorised moderators
6 Push notifications Push subscription data Notify the user Consent 6(1)(a) Browser push service
7 Analytics Usage/interaction data Improve the Service Consent 6(1)(a) Google Analytics
8 In-app currency (Nexors) Ledger, gift/transfer records Provide optional features Contract 6(1)(b)
9 Legal compliance Relevant data Comply with law Legal obligation 6(1)(c) Competent authorities

3. Data minimisation and purpose limitation


4. Security measures (Article 32 GDPR)


5. Sub-processors

See the Privacy Policy, Section 6, for the current list (Google, Resend/SMTP,
ip-api.com, hosting provider). Each processes data under its own terms.


6. International transfers

Some sub-processors may process data outside the EEA. Transfers rely on the
mechanisms offered by those providers (e.g. Standard Contractual Clauses or an
adequacy decision). See the Privacy Policy, Section 5.


7. Data subject rights

We support the full set of GDPR rights (access, rectification, erasure,
restriction, portability, objection, withdrawal of consent, and the right to
complain to a supervisory authority). See the Privacy Policy, Section 10. Access
and portability are available in-app via data export; erasure via account
deletion.


8. Breach handling

In the event of a personal data breach that poses a risk to individuals, we will
notify the competent supervisory authority within 72 hours where required
(Article 33 GDPR) and affected users where required (Article 34 GDPR).


9. Review

This Policy is reviewed when the Service or the applicable law changes.

Contact: [CONTROLLER CONTACT EMAIL]