1. Privacy at a Glance
This privacy policy informs you about the nature, scope, and purpose of the collection and use of personal data on our website nxs.digital and within our SaaS platform Nexus Digital. The responsible entity is Nexus Digital GmbH.
2. Responsible Party
3. Data Collection on Our Website
Server Log Files
Each time our website is accessed, information is automatically collected that your browser transmits. This includes: IP address, date and time of the request, time zone difference to GMT, content of the request, access status/HTTP status code, data volume transferred, referrer URL, browser and operating system. This data is required to ensure a smooth connection and system security.
Contact Form
When you contact us via the contact form, your information (name, email address, company, message) will be stored for processing your inquiry. This data will not be shared with third parties without your consent. Processing is based on Art. 6 Para. 1 lit. b GDPR (pre-contractual measures) or Art. 6 Para. 1 lit. f GDPR (legitimate interest).
4. Use of Firebase
Our platform uses Google Firebase for authentication (Firebase Authentication), database (Cloud Firestore), and file storage (Cloud Storage). Firebase services are hosted in the EU (region europe-west3, Frankfurt).
Google is certified under the EU-US Data Privacy Framework. For more information, see Google's privacy policy: https://policies.google.com/privacy
5. Cookies
Our website uses technically necessary cookies that are required for the operation of the site (e.g., session cookies for authentication). These cookies are automatically deleted at the end of your browser session. Consent is not required for technically necessary cookies pursuant to § 25 Para. 2 TDDDG. Analytics or tracking cookies are not used.
6. Data Processing in the Platform
In the context of using our SaaS platform, we process personal data on behalf of our clients (data processing agreement pursuant to Art. 28 GDPR). The categories of processed data include: employee master data, project data, time tracking data, financial data, and documents. Data is stored separately per tenant and is only accessible to authorized users of the respective tenant.
7. Your Rights
Under the GDPR, you have the following rights:
- Right to access (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure (Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object (Art. 21 GDPR)
- Right to lodge a complaint with a supervisory authority (Art. 77 GDPR)
8. Data Security
We implement technical and organizational security measures to protect your data against manipulation, loss, destruction, or access by unauthorized persons. Our security measures are continuously improved in line with technological developments. Data transmission is encrypted via TLS/SSL.
9. Changes to This Privacy Policy
We reserve the right to update this privacy policy from time to time to ensure it always complies with current legal requirements or to implement changes to our services. The new privacy policy will then apply to your subsequent visits.