Nexusscopes — Privacy Policy
Version 1.0 — Effective [DD Month YYYY]
Last updated: [DD Month YYYY]
1. Summary
Nexusscopes is a data-compliance discovery and assessment tool. This notice explains what personal data we collect about you — as a visitor, account holder, or billing contact — why, on what legal basis, how long we keep it, who we share it with, and what rights you have.
Separate roles matter here. When you upload or connect your own data to be analysed, that content may contain personal data about other people. For that data we act on your instructions as a processor, not as controller, and our Data Processing Agreement governs it — not this notice. See Section 3.
We do not sell personal data, and we do not use customer content to train general-purpose AI models.
2. Who is responsible
Controller:
Noah Baumann, sole proprietor, trading as Nexusscopes
[street, postal code, city], Switzerland
[CHE-###.###.###]
Privacy contact: [privacy@nexusscopes.com]
EU/EEA representative (Art. 27 GDPR): [Name, address, e-mail]
Data protection officer: We are not required to appoint a DPO under Art. 37 GDPR / Art. 10 revFADP. [If appointed: name and contact.]
We process personal data under the EU General Data Protection Regulation (GDPR) and the revised Swiss Federal Act on Data Protection (revFADP), in force since 1 September 2023.
3. Two different roles — please read
| We are controller | We are processor | |
|---|---|---|
| What data | Your account, billing, support, and usage data | Personal data inside the content you upload, connect, or scan |
| Who decides purposes | We do | You do |
| Governed by | This Privacy Policy | The DPA |
| Who answers data subject requests | We do | You do; we assist you |
If you are an employee of a business customer and want to know how your employer uses Nexusscopes on your data, contact your employer — they are the controller for that processing.
4. What we collect, why, and on what basis
4.1 Account and identity data
Data: name, e-mail address, password hash, organisation name, role, language, profile settings, and any details you add.
Purpose: creating and administering your account, authentication, providing the Service.
Legal basis: performance of a contract (Art. 6(1)(b) GDPR); Art. 31(2)(a) revFADP.
Retention: for the life of the account, then [90] days, then deleted or anonymised.
4.2 Billing and transaction data
Data: billing name and address, VAT ID, plan, invoices, payment status, partial card details and payment token (full card data is handled by our payment provider, never by us).
Purpose: processing subscriptions, invoicing, accounting, fraud prevention.
Legal basis: contract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c)) for accounting and tax retention.
Retention: 10 years from the end of the financial year, as required by Art. 958f of the Swiss Code of Obligations and comparable EU tax rules.
4.3 Usage, telemetry, and log data
Data: IP address, device and browser type, operating system, timestamps, pages and features used, scan volumes, API calls, error traces, referrer.
Purpose: operating and securing the Service, diagnosing faults, capacity planning, abuse prevention, aggregate product analytics.
Legal basis: legitimate interests (Art. 6(1)(f)) in running a secure and functional service; where a cookie or similar technology is not strictly necessary, consent (Art. 6(1)(a)).
Retention: security and access logs [12] months; application logs [90] days; aggregated statistics indefinitely in non-identifiable form.
4.4 Support and communications
Data: the content of your e-mails, tickets, chat messages, and any attachments or screenshots you send.
Purpose: answering your requests, improving support quality, evidencing what was agreed.
Legal basis: contract; legitimate interests; consent where you volunteer extra information.
Retention: [3] years after the case is closed.
4.5 Scan configuration and targets
Data: domains, endpoints, repositories, connected accounts, credentials or tokens you supply, scan schedules, findings and reports.
Purpose: performing the assessments you request and retaining your report history.
Legal basis: contract. Where the scanned content contains personal data about third parties, we act as processor under the DPA.
Note: you are responsible for holding authorisation over every target you add. Credentials and tokens are stored encrypted and are only decrypted at the moment of use.
Retention: for the life of the account; see Section 9.
4.6 Marketing
Data: e-mail address, engagement metrics (opens, clicks), preferences.
Purpose: product updates, newsletters, feature announcements.
Legal basis: consent (Art. 6(1)(a)) for prospects; legitimate interests for existing customers receiving information about similar services, subject to Art. 3 of the Swiss Unfair Competition Act and applicable e-privacy rules. Every message contains a one-click unsubscribe and withdrawing consent is as easy as giving it.
Retention: until you unsubscribe, then a minimal suppression record so we do not contact you again.
4.7 Website visitors
Data: as in 4.3, plus cookie identifiers.
Purpose: delivering the site, measuring reach, security.
Legal basis: legitimate interests for strictly necessary cookies; consent for everything else.
See Section 8.
5. Where the data comes from
Almost all of it comes directly from you. We also generate data about your use of the Service, and we receive limited data from our payment provider (payment status), from authentication providers if you sign in via [Google / Microsoft / GitHub SSO], and from security services (e.g. abuse and bot signals).
6. Who we share it with
We share personal data only with the categories below, and only as far as necessary. Every processor is bound by a written contract meeting Art. 28 GDPR / Art. 9 revFADP.
| Recipient category | Examples | Purpose | Location |
|---|---|---|---|
| Hosting and infrastructure | [provider] | Running the Service | [Switzerland / EU] |
| Payment processing | [Stripe] | Subscriptions, invoicing | [EU / US, DPF-certified] |
| Transactional e-mail | [provider] | Account and system e-mails | [EU] |
| Support desk | [provider] | Handling tickets | [EU] |
| Product analytics | [provider] | Aggregated usage insight | [EU] |
| Error monitoring | [provider] | Diagnosing faults | [EU] |
| AI/model providers (if used) | [provider] | AI-assisted analysis features | [EU / US] |
| Professional advisers | Accountants, lawyers, auditors | Legal and financial obligations | [Switzerland] |
The authoritative, current list is published at /legal/subprocessors.
We may also disclose data where legally required — to courts, supervisory authorities, or law enforcement acting under a valid legal basis. We assess each request, disclose the minimum necessary, and notify you unless legally prohibited.
We may transfer data in connection with a merger, acquisition, or asset sale, subject to notice and equivalent protection.
We never sell personal data or share it for third-party advertising.
7. International transfers
Production data is hosted in [Switzerland / the EU]. Where a recipient sits outside Switzerland or the EEA, we rely on one of the following:
Adequacy. The European Commission confirmed in January 2024 that Switzerland provides an adequate level of data protection, so EU→CH transfers need no additional instrument. For US recipients, the Swiss-US Data Privacy Framework, in effect since 15 September 2024, provides adequacy for certified companies, alongside the EU-US DPF.
Standard Contractual Clauses. The European Commission's SCCs (Implementing Decision 2021/914), with the Swiss adaptations recognised by the FDPIC for transfers under Swiss law, plus a transfer impact assessment and supplementary technical measures such as encryption.
Derogations under Art. 49 GDPR / Art. 17 revFADP, only in exceptional and narrowly defined cases.
You may request a copy of the relevant safeguards at [privacy@nexusscopes.com].
8. Cookies and similar technologies
| Category | Purpose | Consent needed |
|---|---|---|
| Strictly necessary | Session, login, load balancing, CSRF protection | No |
| Preference | Language, UI settings | Yes |
| Analytics | Aggregate usage measurement | Yes |
| Marketing | Campaign attribution [if used] | Yes |
Our banner lets you accept all, reject all, or choose per category, with reject as prominent as accept. You can change or withdraw your choice at any time via /cookie-settings. Full details, names, and lifetimes are in our Cookie Policy.
9. How long we keep data
Retention periods are stated per category in Section 4. In summary:
Active account: for as long as the account exists.
After termination: Customer Content stays exportable for [30] days, is then deleted from production, and is purged from backups within a further [90] days.
Legal minimums override deletion: invoices and accounting records are kept 10 years; records needed to establish, exercise, or defend legal claims are kept until the limitation period expires.
When a retention period ends, we delete the data or irreversibly anonymise it.
10. Security
We apply appropriate technical and organisational measures under Art. 32 GDPR and Art. 8 revFADP, including:
TLS 1.2+ in transit and AES-256 encryption at rest
role-based access control, least privilege, and multi-factor authentication for administrative access
secrets and scan credentials stored in a dedicated encrypted vault
audit logging of administrative actions
environment separation (development / staging / production)
backup with tested restore procedures
dependency and vulnerability scanning, patch management
background checks and confidentiality undertakings for anyone with production access
an incident response plan with 72-hour breach notification to the competent supervisory authority under Art. 33 GDPR, notification to the FDPIC under Art. 24 revFADP, and notification to affected individuals where the risk is high
No system is perfectly secure, but we work to keep the risk proportionate to the sensitivity of the data.
11. Automated decision-making and AI
Some features use automated analysis, heuristics, and machine-learning or large language models to produce findings, scores, and recommendations.
These outputs are advisory and are reviewed by you before you act on them.
We do not carry out automated decision-making producing legal or similarly significant effects on natural persons within the meaning of Art. 22 GDPR / Art. 21 revFADP.
We do not use Customer Content to train or fine-tune general-purpose models. Any feature that would do so is strictly opt-in and separately described.
Where a third-party model provider is involved, it is listed in our sub-processor list and bound by contract, including a no-training-on-input commitment.
12. Your rights
Under the GDPR and the revFADP you may:
Access the personal data we hold about you and receive a copy
Rectify inaccurate or incomplete data
Erase data ("right to be forgotten"), subject to legal retention duties
Restrict processing in defined circumstances
Port data you provided to us, in a structured, commonly used, machine-readable format
Object to processing based on legitimate interests, including profiling, and at any time and without reason to direct marketing
Withdraw consent at any time, without affecting the lawfulness of processing before withdrawal
Not be subject to a decision based solely on automated processing with legal or similarly significant effects
How to exercise them: e-mail [privacy@nexusscopes.com] or use the in-app privacy controls. We respond within one month (extendable by two further months for complex requests, with notice) and free of charge, unless a request is manifestly unfounded or excessive. We may ask for information to verify your identity.
Complaints. You may lodge a complaint with:
your local supervisory authority in the EU/EEA (a list is maintained by the European Data Protection Board), or
the Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern, Switzerland — edoeb.admin.ch
We would appreciate the chance to resolve the matter first.
13. Children
The Service is not directed at children. We do not knowingly collect data from anyone under 16 (or the higher age of digital consent where applicable). If you believe a child has provided us data, contact [privacy@nexusscopes.com] and we will delete it.
14. Changes to this policy
We may update this notice. Material changes will be announced by e-mail and in-app at least [30] days before they take effect, and the version history is kept at /legal/privacy-history. Where a change requires consent, we will ask for it.