Privacy Policy
Last updated: 9 October 2026
This policy explains how Nexus International Commerce (“we”, “us”) collects and uses personal data when you visit this website or contact us, in line with the EU General Data Protection Regulation (GDPR) and Cyprus Law 125(I)/2018.
1. Controller
Nexus International Commerce, Nicosia, Cyprus. Contact: +972 50-467-7970 (phone and WhatsApp).
2. What data we collect
- Contact and enquiry data: name, company, email, phone, country, company size, and anything you write to us by form, email or WhatsApp.
- Client and project data: contact details of client staff and business information needed to deliver our services.
- Technical data: IP address, browser type, pages visited and time of visit, recorded in server logs for security.
- Cookies: see our Cookie Policy.
We do not intentionally collect special categories of data, and our website is not directed at children.
3. Why we use it and our legal basis
- To answer your enquiry and prepare a proposal: steps before a contract, or our legitimate interest in responding to business enquiries (Art. 6(1)(b) and (f) GDPR).
- To deliver and invoice our services: performance of a contract (Art. 6(1)(b)).
- To keep accounting and tax records: legal obligation (Art. 6(1)(c)).
- To keep the website secure and working: legitimate interest (Art. 6(1)(f)).
- To send newsletters or marketing emails: only with your consent (Art. 6(1)(a)), which you can withdraw at any time.
4. Who we share it with
We do not sell personal data. We share it only with service providers who process it on our behalf under a data processing agreement, such as:
- Our website hosting provider
- WhatsApp (Meta Platforms Ireland Ltd), if you choose to contact us there
- Odoo S.A., when we set up an Odoo subscription on your behalf
- Our accountants, auditors and legal advisers, and authorities when the law requires it
5. Transfers outside the EU
Some providers may process data outside the European Economic Area. Where this happens we rely on an adequacy decision of the European Commission (such as the EU-US Data Privacy Framework) or on Standard Contractual Clauses.
6. How long we keep it
- Enquiries that do not lead to a contract: up to 24 months after our last contact.
- Client and invoicing records: as long as required by Cyprus tax and company law (generally 7 years).
- Server logs: up to 30 days unless needed to investigate a security incident.
7. Your rights
You can ask us for access to your data, correction, deletion, restriction, data portability, and you can object to processing based on legitimate interest or withdraw consent at any time. Contact us at +972 50-467-7970 (phone and WhatsApp). We answer within one month.
You can also complain to the Commissioner for Personal Data Protection of Cyprus (www.dataprotection.gov.cy) or to the data protection authority in your EU country.
8. Visitors and clients outside the EU
We apply this policy and the GDPR rights above to everyone, wherever you are. If local law gives you additional rights, for example the UK GDPR, the Swiss FADP, US state privacy laws such as the CCPA where they apply, or the UAE Personal Data Protection Law, we honour them too. When we deliver a project for a client outside the EU, the data needed for that project is transferred to the client’s country under Standard Contractual Clauses or another safeguard recognised by the GDPR.
9. Security
We use encrypted connections (HTTPS), access controls and regular backups to protect your data.
10. Changes
We may update this policy. The date at the top shows the latest version.