This page reflects the supplied v1.0 review draft. It is not yet intended for contractual reliance and remains excluded from search indexing until legal approval.
- Legal entity
- NexusReef Ltd · 17390669
- Contact
- info@nexusreef.com
- Registered office
- 82A James Carter Road, Bury St. Edmunds, England, IP28 7DE
1. Who we are and scope
1.1 NexusReef Ltd ("NexusReef", "we", "us" or "our") is a private limited company registered in England and Wales under company number 17390669. Our registered office is 82A James Carter Road, Bury St. Edmunds, England, IP28 7DE.
1.2 For questions, rights requests or data protection complaints, contact us at info@nexusreef.com and use the subject line "Data Protection".
1.3 This notice explains how we collect and use personal data in connection with: our corporate website; contact forms, email, calls and meetings; proposals and sales activity; client projects and support; supplier and partner relationships; events and marketing; recruitment; and the security and administration of our business.
1.4 Separate notices apply where a NexusReef product or service collects personal data for its own end users. In particular, Silent Run, Findex and future platforms must publish product-specific notices appropriate to their features, users, age groups, content, marketplaces and payment flows.
1.5 Where we build or operate a system for a Client and process personal data only on that Client's instructions, the Client is normally responsible for explaining that processing to its users. This corporate notice does not replace the Client's privacy notice.
2. Our data protection roles
2.1 We act as controller when we decide why and how to use personal data for our own website, business development, contracts, billing, security, recruitment, legal compliance and relationship management.
2.2 We may act as processor when we host, develop, maintain, migrate, test or support a Client system using personal data on the Client's documented instructions. In that case, our Data Processing Schedule and the Client's instructions govern the processing.
2.3 In some projects the parties may each be independent controllers or, less commonly, joint controllers. We will document the actual role allocation where needed rather than relying only on labels.
3. Personal data we collect
| Category | Examples |
|---|---|
| Identity and contact data | Name, job title, organisation, business email, telephone number, postal address, country and preferred language. |
| Professional and business data | Role, department, company size, sector, website, public professional profile and purchasing authority. |
| Enquiry and proposal data | Project brief, requirements, budget range, timescale, requested features, technical environment, meeting notes and proposal decisions. |
| Contract and project data | SOWs, approvals, change requests, task history, project communications, deliverable feedback, support tickets and service records. |
| Account and access data | User name, account identifiers, role, access permissions, authentication events and security settings. We do not ask you to send passwords in ordinary messages. |
| Financial and transaction data | Billing contact, invoices, payment status, bank transaction references and tax information. Payment-card details are normally handled by the relevant payment provider, not stored by us. |
| Website and technical data | IP address, device and browser details, referring page, pages viewed, timestamps, diagnostic logs, security events and cookie or consent choices. |
| Communications | Emails, contact-form submissions, meeting records, call notes, feedback, complaints, rights requests and preferences. |
| Marketing data | Topics of interest, campaign interaction, source of the contact, opt-in, opt-out and suppression status. |
| Recruitment data | CV, work history, skills, interview notes, right-to-work information and references where relevant. |
| Public and third-party data | Professional contact information obtained from company websites, public registers, professional networks or reputable business directories. |
| AI interaction data | Prompts, answers, configuration choices and conversation history submitted to an AI-assisted enquiry or requirements tool, together with human follow-up notes. |
3.1 Please do not send special category data, criminal-offence data, children's data, passwords, private keys or highly confidential information through a general contact form or AI-assisted enquiry tool unless we have agreed a secure process and there is a clear need.
4. Where the data comes from
4.1 We collect data directly from you when you visit our website, contact us, request a proposal, attend a meeting, enter into a contract, use a support channel, apply for a role, subscribe to updates or otherwise interact with us.
4.2 We may receive data from your employer or organisation, another project stakeholder, a referrer, professional adviser, payment provider, subcontractor or Client system administrator.
4.3 For relevant B2B outreach, we may obtain professional contact data from public company websites, public corporate registers, professional networking platforms and reputable business directories. Where Article 14 EU or UK GDPR applies, we provide privacy information within the required period and normally no later than our first communication.
4.4 Technical data may be generated automatically by our website, hosting, security, communications and consent-management systems.
5. How and why we use personal data
The table below states our usual purposes and lawful bases. The basis can vary with context. "Legitimate interests" means a genuine business or security need that we have assessed against your rights and reasonable expectations.
| Purpose | Data used | Usual lawful basis |
|---|---|---|
| Respond to enquiries, scope requirements and prepare a proposal | Identity, contact, professional, enquiry and communications data | Steps at your request before a contract where you are the contracting person; otherwise our legitimate interests in responding and developing business relationships. |
| Enter into and manage Client contracts and projects | Identity, contact, contract, project, account and communications data | Contract where you are personally a party; otherwise legitimate interests in delivering and administering services to your organisation. |
| Provide support, maintenance, hosting and security | Account, project, technical, log, support and communications data | Contract or legitimate interests in service delivery, security, troubleshooting and continuity; legal obligation where applicable. |
| Invoice, receive payments and keep financial records | Identity, contact, financial, transaction and contract data | Contract, legitimate interests in getting paid and legal obligations relating to tax, accounting and fraud prevention. |
| Manage suppliers, subcontractors and partners | Identity, contact, professional, contract and payment data | Contract and legitimate interests in procurement, delivery and relationship management. |
| Protect systems, investigate incidents and prevent misuse | Account, technical, security, communications and project data | Legitimate interests in protecting our business, Clients, users and systems; legal obligation where applicable. |
| Improve our website, services and user experience | Website, technical, feedback, enquiry and service data | Legitimate interests for low-risk operational improvement; consent where cookies or similar technologies require it. |
| Measure website use and campaigns | Cookie identifiers, technical and interaction data | Consent for non-essential analytics or advertising technologies, unless a specific statutory exception is lawfully implemented and documented. |
| Send relevant B2B marketing and follow up professional contacts | Identity, contact, professional, marketing and public-source data | Legitimate interests where permitted and appropriate; consent where PECR or another e-privacy rule requires it. |
| Recruit personnel and contractors | Identity, contact, recruitment, communications and right-to-work data | Steps before a contract, legitimate interests in recruitment, and legal obligations. |
| Handle rights requests, complaints, disputes and legal claims | Identity, communications, project, contract, security and other relevant data | Legal obligation and legitimate interests in resolving issues and establishing, exercising or defending legal rights. |
| Comply with law, court orders, regulators and due diligence | Any relevant categories, limited to what is necessary | Legal obligation and, where appropriate, legitimate interests in lawful governance and risk management. |
5.1 Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect processing that was lawful before withdrawal.
5.2 Where we rely on legitimate interests, you may object. We will consider the circumstances and stop unless we have compelling legitimate grounds or need the data for legal claims. We always stop direct marketing when you object or opt out.
5.3 If we need data to enter into or perform a contract or meet a legal requirement and you do not provide it, we may be unable to respond, contract, provide the Service or process payment.
6. AI-assisted enquiries and automated decisions
6.1 Our website may include an AI-assisted enquiry, chatbot or configuration tool. Where it is AI-driven, we will make that clear in the interface so you know you are interacting with an AI system.
6.2 We may use the information you submit to structure requirements, suggest questions, route an enquiry or prepare a non-binding draft. AI output can be inaccurate. A human reviews material commercial decisions, scope, pricing and contractual commitments.
6.3 We do not use the corporate website to make decisions about you solely by automated means that produce legal or similarly significant effects.
6.4 If an external AI provider processes the interaction, we will identify the relevant category of recipient, apply appropriate contractual and transfer safeguards and configure the service to limit retention and training where reasonably available. Do not submit sensitive or confidential information unless the interface expressly permits it.
7. Cookies and similar technologies
7.1 Cookies and similar technologies include browser storage, pixels, tags, scripts, device identifiers and other methods that store information on, or access information from, your device.
7.2 We use strictly necessary technologies to operate security, forms, sessions and consent choices. These do not require consent where the applicable legal exception is met.
7.3 We do not activate non-essential analytics, preference, advertising or cross-service tracking technologies until you have made the required choice, unless a specific statutory exception applies and we have implemented all conditions for that exception. Rejecting non-essential technologies must be as easy as accepting them.
7.4 The live Cookie Settings panel is the definitive current inventory and should state each active technology, provider, purpose, category and duration. You can revisit Cookie Settings at any time to change or withdraw consent.
| Category | Purpose | Consent position |
|---|---|---|
| Strictly necessary | Security, load balancing, session continuity, form submission, fraud prevention and remembering consent choices. | Used only where necessary for the service or another legal exception applies. |
| Preferences / functionality | Remembering optional language, layout or feature choices. | Consent unless the functionality exception applies and all statutory conditions are met. |
| Analytics | Understanding aggregate website use, errors and performance. | Consent by default. A consent-free statistical exception may be used only after documented legal and technical assessment. |
| Marketing / advertising | Campaign measurement, profiling, retargeting or cross-site advertising. | Prior consent required. Not activated merely because a visitor continues browsing. |
7.5 Your browser may allow you to block or delete technologies. Blocking strictly necessary technologies may prevent parts of the website from working. Browser settings do not replace our obligation to provide compliant choices for technologies we control.
8. Direct marketing and business development
8.1 We may send relevant marketing to business contacts where permitted by data protection and electronic-marketing rules. We consider the type of recipient, the source of the contact, the relationship, reasonable expectations and the relevance of the message.
8.2 Under UK PECR, electronic marketing to corporate subscribers such as limited companies may not require prior consent, but we identify ourselves and provide a simple opt-out. Sole traders and some partnerships are treated like individual subscribers and normally require consent or a valid soft opt-in.
8.3 For EEA recipients, we also consider the applicable national e-privacy rules, which may be stricter. We use consent where required.
8.4 You can opt out at any time using the unsubscribe option or by contacting us. We may retain a minimal suppression record so we do not contact you again contrary to your choice.
8.5 We do not sell personal data or buy consumer marketing lists. Where we use professional data from a public source or business directory, we keep outreach proportionate and relevant and provide this notice at first contact where required.
9. Who we share data with
9.1 We share personal data only where necessary, proportionate and lawful. Recipients may include:
- hosting, cloud, email, communications, security, consent-management and IT service providers;
- analytics, website performance and customer-relationship providers, but only in line with cookie choices and applicable law;
- payment, banking, accounting, invoicing and fraud-prevention providers;
- developers, designers, consultants, support contractors and other approved delivery partners;
- professional advisers, auditors, insurers, financiers and prospective investors or acquirers subject to confidentiality;
- Clients and project stakeholders where needed for the relevant engagement;
- courts, regulators, law enforcement, tax authorities and other public bodies where legally required or necessary to protect rights; and
- a buyer, seller or successor in a genuine corporate transaction, subject to appropriate safeguards.
9.2 Service providers that act as processors may use personal data only under our instructions, written terms and appropriate security. Some providers act as independent controllers for their own regulated or security purposes, such as banks and certain platform providers.
9.3 We do not allow a third party to use business-contact data for unrelated advertising merely because it supplies a service to us.
10. International transfers
10.1 NexusReef is based in the United Kingdom and may use suppliers or work with Clients in the United Kingdom, EEA and other countries. This can involve international transfers of personal data.
10.2 Personal data may flow from the EEA to the United Kingdom in reliance on the European Commission's UK adequacy decision while it remains valid. The current renewed decision is due to expire on 27 December 2031 unless extended or replaced.
10.3 For transfers to a country or recipient without an applicable adequacy decision, we use an appropriate mechanism where required, such as the EU Standard Contractual Clauses, the UK International Data Transfer Agreement or UK Addendum, together with any required transfer assessment and supplementary safeguards.
10.4 You may contact us for further information about the applicable transfer safeguard, subject to confidentiality and security limitations.
11. How long we keep data
We keep identifiable personal data only for as long as reasonably necessary for the purpose, legal obligations and legitimate claims. Typical periods are:
| Record | Typical retention |
|---|---|
| General enquiries and unaccepted proposals | 24 months after the last meaningful contact, unless a longer period is justified by an active opportunity, request or dispute. |
| Client contracts, SOWs and core project records | The relationship plus 6 years, reflecting tax, contract and legal-claim requirements, or longer where a claim, audit or legal hold applies. |
| Invoices, transaction and accounting records | At least 6 years from the end of the relevant company financial year, and longer where tax or compliance rules require. |
| Support tickets and operational communications | Usually the contract term plus 6 years where material to service history or claims; routine low-risk communications may be deleted sooner. |
| Security, access and diagnostic logs | Usually up to 12 months, or longer where needed to investigate an incident, fraud, abuse or legal issue. |
| Marketing contacts | Until opt-out or after 24 months of inactivity and no continuing legitimate reason. A minimal suppression record may be kept for as long as needed to respect the opt-out. |
| Cookie and analytics data | As stated in the live Cookie Settings panel and no longer than justified for the stated purpose. |
| Unsuccessful recruitment applications | Usually 6 months after the decision, or up to 24 months with clear permission for future opportunities. |
| Rights requests and data protection complaints | Usually 3 years after closure, or longer where needed for a regulator, claim or legal obligation. |
| Routine backups | According to the relevant backup cycle, normally overwritten within 90 days unless the SOW or incident-preservation need requires otherwise. |
11.1 We periodically review retention. When data is no longer needed, we delete it, anonymise it or place it beyond ordinary use until secure deletion through a backup cycle.
12. Your rights
12.1 Depending on the law and circumstances, you may have rights to:
- be informed about how we use your personal data;
- access your personal data and receive a copy;
- correct inaccurate data and complete incomplete data;
- ask us to delete data in certain circumstances;
- restrict processing in certain circumstances;
- object to processing based on legitimate interests and object at any time to direct marketing;
- receive certain data in a structured, commonly used and machine-readable format and transmit it to another controller;
- withdraw consent at any time where processing is based on consent; and
- ask for human intervention and challenge certain solely automated decisions, where that right applies.
12.2 To exercise a right, email info@nexusreef.com with the subject "Data Protection Request". State what you are requesting and provide enough information to identify the relevant records. We may request proportionate identity evidence before disclosing or changing data.
12.3 We normally respond without undue delay and within one month, subject to lawful extensions for complex or multiple requests. Rights are not absolute; if an exemption applies, we will explain the decision where permitted.
12.4 We do not normally charge a fee. We may charge a reasonable fee or refuse a manifestly unfounded or excessive request where the law permits.
13. Data protection complaints
13.1 You may raise a data protection complaint by emailing info@nexusreef.com with the subject "Data Protection Complaint". Explain the concern, relevant dates and the outcome you are seeking. You may also ask for an accessible or alternative way to submit the complaint.
13.2 We will acknowledge a data protection complaint within 30 days of receipt. Without undue delay, we will take appropriate steps to investigate, keep you informed where needed and tell you the outcome.
13.3 You may complain to the UK Information Commissioner's Office. If EU GDPR applies, you may also complain to the supervisory authority in the EEA country where you live, work or believe an infringement occurred. We encourage you to contact us first so we can try to resolve the issue.
13.4 A rights request and a complaint can overlap. We will handle each applicable legal obligation, even if the outcome dates differ.
14. Children
14.1 The NexusReef corporate website and B2B services are not directed at children. We do not knowingly use the corporate website to collect personal data from children for marketing or contracting.
14.2 A NexusReef product that is likely to be accessed by children requires a separate privacy-by-design assessment, age-appropriate notice, default protections, moderation and product rules. This is particularly relevant to social, creator, content, marketplace and messaging features.
14.3 If you believe a child has submitted personal data through the corporate website, contact us so we can assess and take appropriate action.
15. Security
15.1 We use technical and organisational measures appropriate to the risk, which may include access controls, multi-factor authentication, encryption in transit, secure development, patching, logging, backups, supplier controls, staff confidentiality and incident procedures.
15.2 No online service is completely secure. You should use secure channels for sensitive data, protect credentials and notify us promptly of suspected misuse or a vulnerability.
15.3 Where a personal data breach creates a legal notification duty, we will notify the relevant regulator and affected individuals in accordance with the applicable law and our role.
16. External links
16.1 Our website may link to third-party websites, platforms or social networks. Their operators control their own processing. Review their privacy information before providing personal data.
16.2 A link does not mean NexusReef controls or endorses the third party's privacy practices.
17. Changes to this notice
17.1 We may update this notice to reflect changes in law, services, suppliers or processing. The effective date and version appear at the top.
17.2 If a change is material, we will take reasonable steps to draw attention to it, for example through the website, account notice or email where appropriate. We will obtain new consent where the law requires it.
18. Contact and regulatory details
| Item | Details |
|---|---|
| Controller | NexusReef Ltd |
| Company number | 17390669 |
| Registered jurisdiction | England and Wales |
| Registered office | 82A James Carter Road, Bury St. Edmunds, England, IP28 7DE |
| Data protection contact | info@nexusreef.com - use subject "Data Protection" |
| Website | nexusreef.com |
| UK regulator | Information Commissioner's Office (ICO), United Kingdom |
| EU representative | [ACTION REQUIRED: determine Article 27 position and, if required, appoint and insert the representative's legal name, address and contact details before actively targeting EEA individuals.] |
| Effective date | 18 August 2026 |
| Version | 1.0 |
