Privacy Policy
How Nexa Core Digital Ltd collects, uses, discloses, and safeguards your personal data across our website, applications, and services.
Last Updated: August 21, 2026
1. Introduction
Welcome to Nexa Core Digital Ltd (“Company”, “we”, “us”, or “our”). We operate the website https://www.nexacoredigital.agency, along with our proprietary web applications, software products, mobile applications (including Nexa Legal and related ecosystem apps), and agency services.
We are committed to respecting your privacy and protecting the personal data you share with us or that we handle on your behalf. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you:
- Visit or interact with our website or web portals.
- Engage us for software engineering, web design/development, MVP launches, applied AI, or branding and marketing services.
- Access or use our web applications, mobile apps, or proprietary SaaS platforms.
Nexa Core Digital Ltd is the Data Controller for personal information collected through our website, direct client relationships, and internal administrative operations. When we process data on behalf of our corporate clients or SaaS end-users (e.g., handling client user records during software development or maintaining legal/case management platforms), we act as a Data Processor under UK data protection laws.
2. Company Information & Contact Details
If you have any questions, concerns, or requests regarding this Privacy Policy or how your data is handled, please contact us at:
Company Name: Nexa Core Digital Ltd
Registered Location: London, United Kingdom
Email: hello@nexacoredigital.agency
Phone: +44 07508 389267
3. Information We Collect
We collect information that identifies, relates to, or describes you (“Personal Data”). The types of data we collect depend on how you interact with us:
A. Information You Provide Directly
- Identity and Contact Data: Name, business name, job title, email address, phone number, and postal address when you submit contact forms, book a consultation call, or sign a service agreement.
- Project & Billing Information: Invoicing details, bank details, tax identification numbers, project specifications, NDAs, and trade requirements.
- Account & Profile Data: Account login credentials, user profile details, and system preferences created within our proprietary mobile apps or SaaS platforms.
- Marketing & Communications: Your preferences regarding receiving updates, quotes, newsletters, and marketing materials from us.
B. Information Automatically Collected
- Technical Data: IP address, browser type and version, device type, operating system, time zone setting, and location data when you browse our site.
- Usage Data: Pages viewed, links clicked, time spent on pages, referral sources, and platform interaction metrics gathered via cookies and analytics tools.
C. Information Collected via Services, Mobile Apps, & SaaS Platforms
When using applications developed or hosted by Nexa Core Digital Ltd (including legal operating systems and client software solutions):
- Platform usage logs, user activity, role-based access configurations, and system error logs necessary for technical support and software maintenance.
4. Legal Basis for Processing Personal Data
Under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, we rely on the following lawful bases to process your personal data:
- Performance of a Contract: Where processing is necessary to execute a contract or pre-contractual steps (e.g., delivering software/design services, building an MVP, or operating customer app accounts).
- Legitimate Interests: Where processing is necessary for our legitimate business interests, such as improving our software solutions, ensuring network and application security, preventing fraud, and marketing our services to business prospects (provided your rights do not override these interests).
- Legal Obligation: Where processing is required to comply with statutory obligations, accounting requirements, or legal compliance in the UK.
- Consent: Where you have given explicit consent for specific processing, such as non-essential marketing communications or non-essential web cookies (you may withdraw consent at any time).
5. How We Use Your Information
We use your personal data for the following core business purposes:
- Service Delivery: To design, build, test, deploy, and maintain software platforms, websites, branding, and MVP launches for our clients.
- App & Product Administration: To manage user accounts, authenticate logins, deliver platform updates, and run our mobile and web applications (including Nexa Legal).
- Client Management & Operations: To handle project communication, billing, payments, customer support, and contractual notices.
- Applied AI & System Optimization: To optimize platform code, train or calibrate customized software features (using anonymized or non-identifiable data sets), and resolve technical issues.
- Marketing & Business Growth: To send tailored quotes, business updates, and marketing communications regarding Nexa Core Digital Ltd services (you can opt out at any time).
- Legal Compliance & Security: To protect against unauthorized access, maintain data integrity, enforce our Terms of Service, and fulfill statutory tax and legal obligations.
6. How We Share and Disclose Your Data
We do not sell, rent, or trade your personal data to third parties. We may share your information only under the following strictly controlled circumstances:
- Third-Party Service Providers (Sub-Processors): We work with trusted vendor partners to support our infrastructure, including cloud hosting providers (e.g., AWS, Hostinger, Vercel), analytics platforms, payment gateways, CRM tools, and communication channels. These service providers act strictly under data processing agreements.
- Corporate Client Platforms: If you access a custom app or software environment built by us on behalf of a third-party client or enterprise partner, your data may be processed in accordance with that client’s privacy instructions.
- Legal & Regulatory Authorities: We may disclose data if required to do so by UK law, court order, regulatory bodies, or law enforcement agencies.
- Business Transfers: In the event of a merger, acquisition, restructuring, or sale of company assets, client and app data may be transferred as part of the business assets under appropriate confidentiality agreements.
7. International Data Transfers
Nexa Core Digital Ltd is based in the United Kingdom. Primary data storage and processing occur within the UK and the European Economic Area (EEA).
If we transfer personal data outside the UK/EEA (for example, to cloud servers or global technology vendors located in third countries), we ensure appropriate safeguards are implemented, such as:
- UK International Data Transfer Agreements (IDTAs) or Addendums to EU Standard Contractual Clauses (SCCs).
- Transferring data only to countries recognized by the UK Government as providing an adequate level of data protection.
8. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including:
- For the duration of active service agreements, project builds, or platform subscription lifecycles.
- Up to 6 years following contract completion for statutory UK accounting, tax, and legal liability compliance.
- For account holders on our mobile apps/SaaS tools, until you request account deletion or after a specified period of account inactivity.
Once data is no longer required, it is securely destroyed, permanently deleted, or anonymized for statistical analysis.
9. Data Security
We implement robust technical and organizational measures to safeguard your personal data against accidental loss, unauthorized access, alteration, disclosure, or misuse. These measures include:
- Transport Layer Security (TLS/SSL) encryption for web traffic and platform data in transit.
- Role-based access controls (RBAC) and strict authentication protocols for software environments.
- Non-Disclosure Agreements (NDAs) and strict data protection contracts signed with all team members and software engineers.
While we take rigorous precautions, no digital platform or internet transmission is 100% secure, and we cannot guarantee absolute security.
10. Your Data Protection Rights (UK GDPR)
If you are located in the UK or EEA, you possess the following statutory rights regarding your personal data:
- Right of Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Request correction of inaccurate or incomplete data.
- Right to Erasure (“Right to be Forgotten”): Request deletion of your personal data under certain conditions.
- Right to Restrict Processing: Request that we limit how we process your personal data.
- Right to Data Portability: Request a copy of your personal data in a structured, commonly used, and machine-readable format.
- Right to Object: Object to our processing of your personal data based on legitimate interests or direct marketing.
- Right to Withdraw Consent: Withdraw consent at any time where processing is based on consent.
To exercise any of these rights, please email us at hello@nexacoredigital.agency. We will respond to valid requests within one calendar month.
If you believe we have not resolved a data protection concern satisfactorily, you have the right to lodge a complaint with the UK data protection supervisory authority:
Information Commissioner’s Office (ICO): https://ico.org.uk | Helpline: 0303 123 1113
11. Third-Party Links & External Platforms
Our website, applications, and marketing materials may contain links to third-party websites, external software tools, or client case studies. We do not control these third-party platforms and are not responsible for their privacy practices. We encourage you to review the privacy policies of any third-party websites you visit.
12. Updates to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our legal obligations, software features, or business practices. Any updates will be posted on this page with an updated “Last Updated” date. We encourage you to review this policy periodically.