Last updated: 22 July 2026
Version: 1.0
This document describes how Nexus processes personal data. It also serves as a
summary record of processing activities in the spirit of Article 30 GDPR.
It reflects the actual processing implemented in the Service.
[CONTROLLER FULL NAME] (individual operator)
E-mail: [CONTROLLER CONTACT EMAIL]
Address: [CONTROLLER POSTAL ADDRESS]
Nexus does not currently meet the mandatory thresholds for appointing a Data
Protection Officer (Article 37 GDPR). If large-scale or high-risk processing
begins, a DPO appointment will be reassessed.
| # | Activity | Data categories | Purpose | Legal basis | Recipients |
|---|---|---|---|---|---|
| 1 | Account registration & sign-in | E-mail/phone/Google ID, username | Provide the Service | Contract 6(1)(b) | Google (if used), e-mail/SMTP provider |
| 2 | Messaging, files, calls | Message text (encrypted at rest), files, voice, presence | Deliver the Service | Contract 6(1)(b) | Other users you contact |
| 3 | One-time login codes | E-mail/phone, code | Authenticate the user | Contract 6(1)(b) | Resend/SMTP provider |
| 4 | Security & login alerts | Session token, IP, approximate location, device label | Protect accounts, detect new logins | Legitimate interests 6(1)(f) | ip-api.com (IP lookup) |
| 5 | Moderation | Reports, content snapshots, punishments, appeals | Safety, rule enforcement | Legitimate interests 6(1)(f); legal obligation 6(1)(c) | Authorised moderators |
| 6 | Push notifications | Push subscription data | Notify the user | Consent 6(1)(a) | Browser push service |
| 7 | Analytics | Usage/interaction data | Improve the Service | Consent 6(1)(a) | Google Analytics |
| 8 | In-app currency (Nexors) | Ledger, gift/transfer records | Provide optional features | Contract 6(1)(b) | — |
| 9 | Legal compliance | Relevant data | Comply with law | Legal obligation 6(1)(c) | Competent authorities |
See the Privacy Policy, Section 6, for the current list (Google, Resend/SMTP,
ip-api.com, hosting provider). Each processes data under its own terms.
Some sub-processors may process data outside the EEA. Transfers rely on the
mechanisms offered by those providers (e.g. Standard Contractual Clauses or an
adequacy decision). See the Privacy Policy, Section 5.
We support the full set of GDPR rights (access, rectification, erasure,
restriction, portability, objection, withdrawal of consent, and the right to
complain to a supervisory authority). See the Privacy Policy, Section 10. Access
and portability are available in-app via data export; erasure via account
deletion.
In the event of a personal data breach that poses a risk to individuals, we will
notify the competent supervisory authority within 72 hours where required
(Article 33 GDPR) and affected users where required (Article 34 GDPR).
This Policy is reviewed when the Service or the applicable law changes.
Contact: [CONTROLLER CONTACT EMAIL]