Skip to content
NexusReef
WorkCapabilitiesMethodAboutContact
🇬🇧EN🇳🇱NL
Start a project
Navigate the ecosystem
01Work02Capabilities03Method04About05Contact
🇬🇧English🇳🇱Nederlands
Send the signal

NexusReef legal

Privacy and Cookie Notice

How NexusReef handles personal data and uses cookies across its business website, enquiries and commercial relationships.

Review draftVersion 1.0 · Effective 18 August 2026
DocumentPrivacy and Cookie Notice
On this page
1. Who we are and scope2. Our data protection roles3. Personal data we collect4. Where the data comes from5. How and why we use personal data6. AI-assisted enquiries and automated decisions7. Cookies and similar technologies8. Direct marketing and business development9. Who we share data with10. International transfers11. How long we keep data12. Your rights13. Data protection complaints14. Children15. Security16. External links17. Changes to this notice18. Contact and regulatory details
Review draft

This page reflects the supplied v1.0 review draft. It is not yet intended for contractual reliance and remains excluded from search indexing until legal approval.

Legal entity
NexusReef Ltd · 17390669
Contact
info@nexusreef.com
Registered office
82A James Carter Road, Bury St. Edmunds, England, IP28 7DE

1. Who we are and scope

1.1 NexusReef Ltd ("NexusReef", "we", "us" or "our") is a private limited company registered in England and Wales under company number 17390669. Our registered office is 82A James Carter Road, Bury St. Edmunds, England, IP28 7DE.

1.2 For questions, rights requests or data protection complaints, contact us at info@nexusreef.com and use the subject line "Data Protection".

1.3 This notice explains how we collect and use personal data in connection with: our corporate website; contact forms, email, calls and meetings; proposals and sales activity; client projects and support; supplier and partner relationships; events and marketing; recruitment; and the security and administration of our business.

1.4 Separate notices apply where a NexusReef product or service collects personal data for its own end users. In particular, Silent Run, Findex and future platforms must publish product-specific notices appropriate to their features, users, age groups, content, marketplaces and payment flows.

1.5 Where we build or operate a system for a Client and process personal data only on that Client's instructions, the Client is normally responsible for explaining that processing to its users. This corporate notice does not replace the Client's privacy notice.

2. Our data protection roles

2.1 We act as controller when we decide why and how to use personal data for our own website, business development, contracts, billing, security, recruitment, legal compliance and relationship management.

2.2 We may act as processor when we host, develop, maintain, migrate, test or support a Client system using personal data on the Client's documented instructions. In that case, our Data Processing Schedule and the Client's instructions govern the processing.

2.3 In some projects the parties may each be independent controllers or, less commonly, joint controllers. We will document the actual role allocation where needed rather than relying only on labels.

3. Personal data we collect

CategoryExamples
Identity and contact dataName, job title, organisation, business email, telephone number, postal address, country and preferred language.
Professional and business dataRole, department, company size, sector, website, public professional profile and purchasing authority.
Enquiry and proposal dataProject brief, requirements, budget range, timescale, requested features, technical environment, meeting notes and proposal decisions.
Contract and project dataSOWs, approvals, change requests, task history, project communications, deliverable feedback, support tickets and service records.
Account and access dataUser name, account identifiers, role, access permissions, authentication events and security settings. We do not ask you to send passwords in ordinary messages.
Financial and transaction dataBilling contact, invoices, payment status, bank transaction references and tax information. Payment-card details are normally handled by the relevant payment provider, not stored by us.
Website and technical dataIP address, device and browser details, referring page, pages viewed, timestamps, diagnostic logs, security events and cookie or consent choices.
CommunicationsEmails, contact-form submissions, meeting records, call notes, feedback, complaints, rights requests and preferences.
Marketing dataTopics of interest, campaign interaction, source of the contact, opt-in, opt-out and suppression status.
Recruitment dataCV, work history, skills, interview notes, right-to-work information and references where relevant.
Public and third-party dataProfessional contact information obtained from company websites, public registers, professional networks or reputable business directories.
AI interaction dataPrompts, answers, configuration choices and conversation history submitted to an AI-assisted enquiry or requirements tool, together with human follow-up notes.

3.1 Please do not send special category data, criminal-offence data, children's data, passwords, private keys or highly confidential information through a general contact form or AI-assisted enquiry tool unless we have agreed a secure process and there is a clear need.

4. Where the data comes from

4.1 We collect data directly from you when you visit our website, contact us, request a proposal, attend a meeting, enter into a contract, use a support channel, apply for a role, subscribe to updates or otherwise interact with us.

4.2 We may receive data from your employer or organisation, another project stakeholder, a referrer, professional adviser, payment provider, subcontractor or Client system administrator.

4.3 For relevant B2B outreach, we may obtain professional contact data from public company websites, public corporate registers, professional networking platforms and reputable business directories. Where Article 14 EU or UK GDPR applies, we provide privacy information within the required period and normally no later than our first communication.

4.4 Technical data may be generated automatically by our website, hosting, security, communications and consent-management systems.

5. How and why we use personal data

The table below states our usual purposes and lawful bases. The basis can vary with context. "Legitimate interests" means a genuine business or security need that we have assessed against your rights and reasonable expectations.

PurposeData usedUsual lawful basis
Respond to enquiries, scope requirements and prepare a proposalIdentity, contact, professional, enquiry and communications dataSteps at your request before a contract where you are the contracting person; otherwise our legitimate interests in responding and developing business relationships.
Enter into and manage Client contracts and projectsIdentity, contact, contract, project, account and communications dataContract where you are personally a party; otherwise legitimate interests in delivering and administering services to your organisation.
Provide support, maintenance, hosting and securityAccount, project, technical, log, support and communications dataContract or legitimate interests in service delivery, security, troubleshooting and continuity; legal obligation where applicable.
Invoice, receive payments and keep financial recordsIdentity, contact, financial, transaction and contract dataContract, legitimate interests in getting paid and legal obligations relating to tax, accounting and fraud prevention.
Manage suppliers, subcontractors and partnersIdentity, contact, professional, contract and payment dataContract and legitimate interests in procurement, delivery and relationship management.
Protect systems, investigate incidents and prevent misuseAccount, technical, security, communications and project dataLegitimate interests in protecting our business, Clients, users and systems; legal obligation where applicable.
Improve our website, services and user experienceWebsite, technical, feedback, enquiry and service dataLegitimate interests for low-risk operational improvement; consent where cookies or similar technologies require it.
Measure website use and campaignsCookie identifiers, technical and interaction dataConsent for non-essential analytics or advertising technologies, unless a specific statutory exception is lawfully implemented and documented.
Send relevant B2B marketing and follow up professional contactsIdentity, contact, professional, marketing and public-source dataLegitimate interests where permitted and appropriate; consent where PECR or another e-privacy rule requires it.
Recruit personnel and contractorsIdentity, contact, recruitment, communications and right-to-work dataSteps before a contract, legitimate interests in recruitment, and legal obligations.
Handle rights requests, complaints, disputes and legal claimsIdentity, communications, project, contract, security and other relevant dataLegal obligation and legitimate interests in resolving issues and establishing, exercising or defending legal rights.
Comply with law, court orders, regulators and due diligenceAny relevant categories, limited to what is necessaryLegal obligation and, where appropriate, legitimate interests in lawful governance and risk management.

5.1 Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect processing that was lawful before withdrawal.

5.2 Where we rely on legitimate interests, you may object. We will consider the circumstances and stop unless we have compelling legitimate grounds or need the data for legal claims. We always stop direct marketing when you object or opt out.

5.3 If we need data to enter into or perform a contract or meet a legal requirement and you do not provide it, we may be unable to respond, contract, provide the Service or process payment.

6. AI-assisted enquiries and automated decisions

6.1 Our website may include an AI-assisted enquiry, chatbot or configuration tool. Where it is AI-driven, we will make that clear in the interface so you know you are interacting with an AI system.

6.2 We may use the information you submit to structure requirements, suggest questions, route an enquiry or prepare a non-binding draft. AI output can be inaccurate. A human reviews material commercial decisions, scope, pricing and contractual commitments.

6.3 We do not use the corporate website to make decisions about you solely by automated means that produce legal or similarly significant effects.

6.4 If an external AI provider processes the interaction, we will identify the relevant category of recipient, apply appropriate contractual and transfer safeguards and configure the service to limit retention and training where reasonably available. Do not submit sensitive or confidential information unless the interface expressly permits it.

7. Cookies and similar technologies

7.1 Cookies and similar technologies include browser storage, pixels, tags, scripts, device identifiers and other methods that store information on, or access information from, your device.

7.2 We use strictly necessary technologies to operate security, forms, sessions and consent choices. These do not require consent where the applicable legal exception is met.

7.3 We do not activate non-essential analytics, preference, advertising or cross-service tracking technologies until you have made the required choice, unless a specific statutory exception applies and we have implemented all conditions for that exception. Rejecting non-essential technologies must be as easy as accepting them.

7.4 The live Cookie Settings panel is the definitive current inventory and should state each active technology, provider, purpose, category and duration. You can revisit Cookie Settings at any time to change or withdraw consent.

CategoryPurposeConsent position
Strictly necessarySecurity, load balancing, session continuity, form submission, fraud prevention and remembering consent choices.Used only where necessary for the service or another legal exception applies.
Preferences / functionalityRemembering optional language, layout or feature choices.Consent unless the functionality exception applies and all statutory conditions are met.
AnalyticsUnderstanding aggregate website use, errors and performance.Consent by default. A consent-free statistical exception may be used only after documented legal and technical assessment.
Marketing / advertisingCampaign measurement, profiling, retargeting or cross-site advertising.Prior consent required. Not activated merely because a visitor continues browsing.

7.5 Your browser may allow you to block or delete technologies. Blocking strictly necessary technologies may prevent parts of the website from working. Browser settings do not replace our obligation to provide compliant choices for technologies we control.

COOKIE AUDIT REQUIRED

Before publication, scan the live production website and populate the Cookie Settings panel with actual names, providers, purposes and durations. Verify forms, embedded media, analytics, reCAPTCHA alternatives, fonts, chat widgets and any tag manager. The policy must never claim tools or locations that are not true.

8. Direct marketing and business development

8.1 We may send relevant marketing to business contacts where permitted by data protection and electronic-marketing rules. We consider the type of recipient, the source of the contact, the relationship, reasonable expectations and the relevance of the message.

8.2 Under UK PECR, electronic marketing to corporate subscribers such as limited companies may not require prior consent, but we identify ourselves and provide a simple opt-out. Sole traders and some partnerships are treated like individual subscribers and normally require consent or a valid soft opt-in.

8.3 For EEA recipients, we also consider the applicable national e-privacy rules, which may be stricter. We use consent where required.

8.4 You can opt out at any time using the unsubscribe option or by contacting us. We may retain a minimal suppression record so we do not contact you again contrary to your choice.

8.5 We do not sell personal data or buy consumer marketing lists. Where we use professional data from a public source or business directory, we keep outreach proportionate and relevant and provide this notice at first contact where required.

9. Who we share data with

9.1 We share personal data only where necessary, proportionate and lawful. Recipients may include:

  • hosting, cloud, email, communications, security, consent-management and IT service providers;
  • analytics, website performance and customer-relationship providers, but only in line with cookie choices and applicable law;
  • payment, banking, accounting, invoicing and fraud-prevention providers;
  • developers, designers, consultants, support contractors and other approved delivery partners;
  • professional advisers, auditors, insurers, financiers and prospective investors or acquirers subject to confidentiality;
  • Clients and project stakeholders where needed for the relevant engagement;
  • courts, regulators, law enforcement, tax authorities and other public bodies where legally required or necessary to protect rights; and
  • a buyer, seller or successor in a genuine corporate transaction, subject to appropriate safeguards.

9.2 Service providers that act as processors may use personal data only under our instructions, written terms and appropriate security. Some providers act as independent controllers for their own regulated or security purposes, such as banks and certain platform providers.

9.3 We do not allow a third party to use business-contact data for unrelated advertising merely because it supplies a service to us.

10. International transfers

10.1 NexusReef is based in the United Kingdom and may use suppliers or work with Clients in the United Kingdom, EEA and other countries. This can involve international transfers of personal data.

10.2 Personal data may flow from the EEA to the United Kingdom in reliance on the European Commission's UK adequacy decision while it remains valid. The current renewed decision is due to expire on 27 December 2031 unless extended or replaced.

10.3 For transfers to a country or recipient without an applicable adequacy decision, we use an appropriate mechanism where required, such as the EU Standard Contractual Clauses, the UK International Data Transfer Agreement or UK Addendum, together with any required transfer assessment and supplementary safeguards.

10.4 You may contact us for further information about the applicable transfer safeguard, subject to confidentiality and security limitations.

11. How long we keep data

We keep identifiable personal data only for as long as reasonably necessary for the purpose, legal obligations and legitimate claims. Typical periods are:

RecordTypical retention
General enquiries and unaccepted proposals24 months after the last meaningful contact, unless a longer period is justified by an active opportunity, request or dispute.
Client contracts, SOWs and core project recordsThe relationship plus 6 years, reflecting tax, contract and legal-claim requirements, or longer where a claim, audit or legal hold applies.
Invoices, transaction and accounting recordsAt least 6 years from the end of the relevant company financial year, and longer where tax or compliance rules require.
Support tickets and operational communicationsUsually the contract term plus 6 years where material to service history or claims; routine low-risk communications may be deleted sooner.
Security, access and diagnostic logsUsually up to 12 months, or longer where needed to investigate an incident, fraud, abuse or legal issue.
Marketing contactsUntil opt-out or after 24 months of inactivity and no continuing legitimate reason. A minimal suppression record may be kept for as long as needed to respect the opt-out.
Cookie and analytics dataAs stated in the live Cookie Settings panel and no longer than justified for the stated purpose.
Unsuccessful recruitment applicationsUsually 6 months after the decision, or up to 24 months with clear permission for future opportunities.
Rights requests and data protection complaintsUsually 3 years after closure, or longer where needed for a regulator, claim or legal obligation.
Routine backupsAccording to the relevant backup cycle, normally overwritten within 90 days unless the SOW or incident-preservation need requires otherwise.

11.1 We periodically review retention. When data is no longer needed, we delete it, anonymise it or place it beyond ordinary use until secure deletion through a backup cycle.

12. Your rights

12.1 Depending on the law and circumstances, you may have rights to:

  • be informed about how we use your personal data;
  • access your personal data and receive a copy;
  • correct inaccurate data and complete incomplete data;
  • ask us to delete data in certain circumstances;
  • restrict processing in certain circumstances;
  • object to processing based on legitimate interests and object at any time to direct marketing;
  • receive certain data in a structured, commonly used and machine-readable format and transmit it to another controller;
  • withdraw consent at any time where processing is based on consent; and
  • ask for human intervention and challenge certain solely automated decisions, where that right applies.

12.2 To exercise a right, email info@nexusreef.com with the subject "Data Protection Request". State what you are requesting and provide enough information to identify the relevant records. We may request proportionate identity evidence before disclosing or changing data.

12.3 We normally respond without undue delay and within one month, subject to lawful extensions for complex or multiple requests. Rights are not absolute; if an exemption applies, we will explain the decision where permitted.

12.4 We do not normally charge a fee. We may charge a reasonable fee or refuse a manifestly unfounded or excessive request where the law permits.

13. Data protection complaints

13.1 You may raise a data protection complaint by emailing info@nexusreef.com with the subject "Data Protection Complaint". Explain the concern, relevant dates and the outcome you are seeking. You may also ask for an accessible or alternative way to submit the complaint.

13.2 We will acknowledge a data protection complaint within 30 days of receipt. Without undue delay, we will take appropriate steps to investigate, keep you informed where needed and tell you the outcome.

13.3 You may complain to the UK Information Commissioner's Office. If EU GDPR applies, you may also complain to the supervisory authority in the EEA country where you live, work or believe an infringement occurred. We encourage you to contact us first so we can try to resolve the issue.

13.4 A rights request and a complaint can overlap. We will handle each applicable legal obligation, even if the outcome dates differ.

14. Children

14.1 The NexusReef corporate website and B2B services are not directed at children. We do not knowingly use the corporate website to collect personal data from children for marketing or contracting.

14.2 A NexusReef product that is likely to be accessed by children requires a separate privacy-by-design assessment, age-appropriate notice, default protections, moderation and product rules. This is particularly relevant to social, creator, content, marketplace and messaging features.

14.3 If you believe a child has submitted personal data through the corporate website, contact us so we can assess and take appropriate action.

15. Security

15.1 We use technical and organisational measures appropriate to the risk, which may include access controls, multi-factor authentication, encryption in transit, secure development, patching, logging, backups, supplier controls, staff confidentiality and incident procedures.

15.2 No online service is completely secure. You should use secure channels for sensitive data, protect credentials and notify us promptly of suspected misuse or a vulnerability.

15.3 Where a personal data breach creates a legal notification duty, we will notify the relevant regulator and affected individuals in accordance with the applicable law and our role.

16. External links

16.1 Our website may link to third-party websites, platforms or social networks. Their operators control their own processing. Review their privacy information before providing personal data.

16.2 A link does not mean NexusReef controls or endorses the third party's privacy practices.

17. Changes to this notice

17.1 We may update this notice to reflect changes in law, services, suppliers or processing. The effective date and version appear at the top.

17.2 If a change is material, we will take reasonable steps to draw attention to it, for example through the website, account notice or email where appropriate. We will obtain new consent where the law requires it.

18. Contact and regulatory details

ItemDetails
ControllerNexusReef Ltd
Company number17390669
Registered jurisdictionEngland and Wales
Registered office82A James Carter Road, Bury St. Edmunds, England, IP28 7DE
Data protection contactinfo@nexusreef.com - use subject "Data Protection"
Websitenexusreef.com
UK regulatorInformation Commissioner's Office (ICO), United Kingdom
EU representative[ACTION REQUIRED: determine Article 27 position and, if required, appoint and insert the representative's legal name, address and contact details before actively targeting EEA individuals.]
Effective date18 August 2026
Version1.0
Related documentBusiness Terms and Conditions
NexusReef

We build and operate digital ecosystems.

© 2026 NexusReef
LegalPrivacy & cookiesTerms
Designed to evolve.