Legal
Privacy Policy
This policy explains how NexaCore Technology Services Ltd collects, uses, shares and protects personal data, and how you can exercise your rights in relation to that data.
1. Scope and controller
This policy applies to personal data that NexaCore Technology Services Ltd and its group companies (together, “NexaCore”, “we”, “us”) process as a data controller. That includes data collected through this website, through our marketing and business development activity, through our recruitment process, and in the course of managing relationships with client and supplier personnel.
It does not describe how we handle personal data that we process on behalf of a client as a data processor — for example, data contained within systems we operate under a managed service agreement. Those activities are governed by the data processing agreement in place with that client. Section 5 explains the distinction in more detail.
Where a NexaCore group company established outside the United Kingdom acts as controller for its local activities, that entity is the controller for those activities and this policy applies to it as adapted by local law. A list of group entities and their registered addresses is available from the Data Protection Officer on request.
2. Data we collect
We collect the following categories of personal data. We do not seek special category data through this website and ask that you do not submit it via our enquiry form.
| Category | Examples | Source |
|---|---|---|
| Contact data | Name, job title, employer, work email address, work telephone number, office location. | Provided by you, or by your employer where you are our client or supplier contact. |
| Enquiry data | The content of your enquiry, the practice area selected, indicated timeline and related correspondence. | Provided by you via our enquiry form, by email or by telephone. |
| Contractual data | Records of engagements, statements of work, service reports, meeting notes and billing contacts. | Generated in the course of our relationship with your organisation. |
| Technical data | IP address, browser type and version, device type, operating system, referring page, pages viewed and timestamps. | Collected automatically by our web server logs when you visit this website. |
| Recruitment data | CV, work history, qualifications, right-to-work evidence, interview notes and references. | Provided by you or by a recruitment agency acting on your instruction. |
| Due diligence data | Sanctions, politically exposed person and adverse media screening results for relevant counterparties. | Obtained from third-party screening providers where legally required. |
3. How and why we use personal data
We use personal data for the following purposes only:
- Responding to enquiries. To assess your enquiry, route it to the appropriate practice, prepare an indicative approach and correspond with you about it.
- Providing services. To deliver, manage, invoice and support the engagements agreed with your organisation, including service reporting and governance meetings.
- Relationship management. To maintain accurate records of the individuals we work with at client, prospect and supplier organisations.
- Marketing. To send occasional sector-relevant material to business contacts, always with a functioning unsubscribe mechanism and never to individuals who have opted out.
- Recruitment. To assess applications, conduct interviews, verify eligibility to work and, where an offer is made, prepare employment documentation.
- Security and integrity. To monitor for, investigate and respond to security incidents affecting our own systems, and to maintain audit logs required by our certifications.
- Legal and regulatory compliance. To meet obligations under company, tax, employment, anti-bribery, sanctions and data protection law, and to establish or defend legal claims.
We do not sell personal data. We do not use personal data collected through this website for automated decision-making that produces legal or similarly significant effects, and we do not engage in profiling for advertising purposes.
4. Lawful bases for processing
Under the UK GDPR and EU GDPR we rely on the following lawful bases:
- Legitimate interests (Article 6(1)(f)). For business development, relationship management, business-to-business marketing to corporate contacts, service improvement and network security. We have assessed in each case that our interest in operating and growing a professional services firm is not overridden by the interests or fundamental rights of the individuals concerned. You may object at any time (see section 10).
- Performance of a contract (Article 6(1)(b)). For delivering services, administering accounts, invoicing and supporting the contractual relationship with your organisation, and for progressing a job application at your request.
- Legal obligation (Article 6(1)(c)). For statutory record keeping, tax reporting, right-to-work verification, sanctions screening and responding to lawful requests from regulators or law enforcement.
- Consent (Article 6(1)(a)). For non-essential cookies and for marketing to individuals where consent is required by local law. Where we rely on consent you may withdraw it at any time without affecting the lawfulness of prior processing.
Where we process special category data — which happens principally in employment contexts, for example health information supporting a workplace adjustment — we additionally rely on Article 9(2)(b) (employment, social security and social protection law) or Article 9(2)(f) (legal claims), as applicable.
5. Client data we process as a processor
In the course of delivering managed services, migrations, application development and analytics work, NexaCore frequently has access to personal data held within a client's systems. In relation to that data our client is the controller and NexaCore is a processor.
In every such engagement we contract on terms that require us to:
- Process personal data only on the documented instructions of the client.
- Impose binding confidentiality obligations on all personnel with access.
- Implement the technical and organisational measures set out in section 9 and in the applicable data processing agreement.
- Obtain prior written authorisation before engaging any sub-processor, and flow down equivalent obligations.
- Assist the client with data subject requests, data protection impact assessments and regulator engagement.
- Notify the client without undue delay, and in any event within 24 hours of confirmation, of any personal data breach affecting their data.
- Delete or return personal data at the end of the engagement in accordance with the agreed exit plan.
If you believe your personal data is held within a client system that NexaCore operates, please direct your request to that organisation. Where you contact us instead, we will forward the request to the relevant client and inform you that we have done so.
7. International transfers
NexaCore operates delivery centres in the United Kingdom, Germany, Poland, the United States, India, Singapore and the United Arab Emirates. Personal data may therefore be transferred outside the country in which it was collected.
Where personal data is transferred out of the UK or the European Economic Area, we rely on one of the following safeguards:
- An adequacy decision adopted by the UK Government or the European Commission in respect of the destination country.
- The European Commission's Standard Contractual Clauses, together with the UK International Data Transfer Addendum where the UK GDPR applies.
- Binding intra-group commitments equivalent in substance to the above, applied between NexaCore group companies.
In each case we carry out and document a transfer impact assessment considering the law and practice of the destination country, and we apply supplementary technical measures — encryption in transit and at rest, key management retained in the originating jurisdiction, and access limited to named personnel — where the assessment indicates they are needed. Clients requiring strict data residency can contract for delivery from a single named jurisdiction, enforced at the platform layer.
8. Retention
We retain personal data only for as long as necessary for the purpose for which it was collected, subject to the following standard periods:
| Data | Retention period | Rationale |
|---|---|---|
| Website enquiries not proceeding | 24 months from last contact | Business development follow-up cycle |
| Client contact records | Duration of relationship plus 6 years | Limitation period for contractual claims |
| Contracts and engagement records | 7 years from contract end | Statutory and tax record keeping |
| Marketing preferences | Retained indefinitely | To honour opt-outs and suppression lists |
| Unsuccessful job applications | 12 months from decision | Discrimination claim limitation period |
| Web server logs | 13 months | Security monitoring and incident investigation |
| Security audit logs | 36 months | ISO 27001 and SOC 2 evidence requirements |
At the end of the applicable period data is securely deleted or irreversibly anonymised. Where deletion is not immediately technically feasible — for example within backup media — the data is isolated from active processing and deleted at the end of the backup cycle.
9. Security measures
NexaCore maintains an information security management system certified to ISO/IEC 27001:2022 and attested annually under SOC 2 Type II. Measures relevant to personal data include:
- Encryption of personal data in transit (TLS 1.2 or above) and at rest (AES-256).
- Role-based access control with least-privilege provisioning and quarterly access recertification.
- Multi-factor authentication mandatory for all corporate and client-facing systems.
- Segregated environments for development, testing and production, with production data never used in lower environments.
- Centralised logging and 24×7 monitoring by our security operations centres.
- Annual independent penetration testing and continuous vulnerability management.
- Documented incident response plan, rehearsed at least twice a year.
- Mandatory annual security and data protection training for all personnel, with role-specific modules for those handling client data.
No system can be guaranteed completely secure. Where a personal data breach is likely to result in a risk to individuals, we notify the relevant supervisory authority within 72 hours and affected individuals without undue delay where the risk is high.
10. Your rights
Subject to the conditions and exemptions in applicable data protection law, you have the right to:
- Access the personal data we hold about you and receive a copy of it.
- Rectification of inaccurate data and completion of incomplete data.
- Erasure of your data where we no longer have a lawful reason to hold it.
- Restriction of processing while a dispute about accuracy or legitimacy is resolved.
- Portability of data you provided to us, in a structured, commonly used, machine-readable format, where processing is based on consent or contract and carried out by automated means.
- Object to processing based on legitimate interests, and to object to direct marketing at any time and without qualification.
- Withdraw consent where processing is based on consent, at any time.
To exercise a right, contact dpo@nexacore.com. We will respond within one month, extendable by two further months for complex requests, and will tell you if an extension applies. We may ask for information to verify your identity. There is no charge unless a request is manifestly unfounded or excessive.
If you are located in California, you may also have rights under the California Consumer Privacy Act, including the right to know, delete and opt out of “sales” or “sharing” of personal information. NexaCore does not sell or share personal information as those terms are defined in that Act.
12. Children's data
Our services are directed exclusively at organisations, and this website is not intended for anyone under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact the Data Protection Officer and we will delete it promptly.
13. Changes to this policy
We review this policy at least annually and whenever our processing activities change materially. The version number and effective date at the top of this page indicate the current issue. Where a change materially affects how we use personal data for which you are identifiable, we will notify affected individuals directly by email before the change takes effect. Previous versions are available from the Data Protection Officer on request.
14. Contact and complaints
Our Data Protection Officer can be reached at dpo@nexacore.com, or by post at: Data Protection Officer, NexaCore Technology Services Ltd, 40 Fenchurch Avenue, London EC3M 5BY, United Kingdom.
If you are dissatisfied with our response, you have the right to lodge a complaint with a supervisory authority. In the United Kingdom this is the Information Commissioner's Office (ico.org.uk). In the European Union you may complain to the supervisory authority in your country of residence, place of work, or the place of the alleged infringement. We would nonetheless appreciate the opportunity to address your concern directly first.
General enquiries about NexaCore's services should be directed through our contact page.
Assurance Pack
Need our full data protection documentation?
Our standard data processing agreement, transfer impact assessment template, sub-processor list and security schedule are available to clients and prospective clients under NDA.