Last updated: 15 August 2026
TODO(LEGAL): This policy describes the implemented site behavior but requires review by qualified counsel for the jurisdictions in which NexisDigital operates.
1. Who We Are (Data Controller)
This website is operated by NexisDigital ("NexisDigital", "we", "us", "our"), a web development agency registered under Business Identification Number (BIN) 031105651391 in the Republic of Kazakhstan, with registered office at Dostyk 5/2, Astana 010017, Republic of Kazakhstan, serving clients internationally. NexisDigital is the data controller responsible for your personal data. For any privacy question or to exercise your rights, contact us at privacy@nexisdigital.tech. This policy applies to nexisdigital.tech and all its subdomains and language versions (EN/DE/RU/KZ).
2. Personal Data We Collect
We collect only what we need. (a) Data you give us: when you submit the contact form we collect your name, email address, project type if you choose to provide it, and the content of your message. If you contact us by email, WhatsApp, or Instagram, we receive whatever you choose to share. (b) Data collected automatically: standard technical data your browser sends (including IP address, browser type, device, and timestamps), which our hosting provider may process in server and security logs. (c) Cookies: see section 4. We do not use advertising or profiling cookies. If you explicitly accept analytics, we load Google Analytics 4 to measure site use. We do not knowingly collect special-category data.
3. Why We Use It and Our Legal Bases
We process your data to: respond to your enquiries and take steps to enter into a contract at your request (legal basis: consent and/or pre-contractual steps under GDPR Art. 6(1)(a)/(b)); operate, secure, and improve the website and prevent spam or abuse (legal basis: our legitimate interests, GDPR Art. 6(1)(f)); and comply with legal obligations that apply to us (GDPR Art. 6(1)(c)). We do not use your data for automated decision-making or for selling to third parties.
4. Cookies and Consent
We use one necessary, host-only cookie named 'nexis-klaro-consent' to store your consent choice for up to 183 days. Optional Google Analytics 4 (Measurement ID G-HBB2VWE15L) loads only after you select 'Accept analytics'. Before consent, the site does not render the Google Analytics script or contact Google's analytics endpoints. After consent, GA4 may set first-party cookies named _ga and _ga_*. You can change your choice through 'Cookie Settings' in the footer; withdrawing consent disables analytics and asks Klaro to remove matching GA cookies. Deleting the consent cookie makes the banner appear again.
5. Service Providers and Third Parties
We share data only with trusted providers who help us run the site, and only as needed: Web3Forms (api.web3forms.com) processes and relays contact-form submissions to us; Proton Mail receives and stores the enquiry emails; Cloudflare hosts the website on its global edge network and processes technical data (including IP addresses) in server and security logs; Google Ireland (Google LLC) provides Google Analytics 4 and processes aggregate usage data under the Google Data Processing Terms. Each acts as our processor or an independent controller for their own infrastructure. We also link to third-party platforms (Instagram, WhatsApp); once you leave our site, their own privacy policies apply. We never sell or rent your personal data.
6. International Data Transfers
NexisDigital serves an international audience and some of our providers store or process data outside your country of residence, including in the United States, the European Union, and Switzerland. Where data is transferred out of the EEA/UK, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses or an adequacy decision, so your data receives an equivalent level of protection.
7. How Long We Keep Your Data
We keep contact-form and email enquiries only as long as necessary to handle your request and for a reasonable period afterwards for our legitimate business records, after which they are deleted. Cookies expire according to the lifespan described in section 4. Server logs held by our hosting provider are retained for a limited period for security and diagnostics.
8. Your Rights
Depending on where you live, you have rights over your personal data. Under the EU/UK GDPR you may request access to, correction, or erasure of your data; restrict or object to processing; request portability; and withdraw consent at any time. Under the California CCPA/CPRA you may request to know, delete, or correct your data and opt out of its 'sale' or 'sharing' — note that we do not sell or share personal data. You also have the right to lodge a complaint with your local data protection authority. To exercise any right, email privacy@nexisdigital.tech; we will respond within the timeframe required by applicable law.
9. Data Security and Breach Response
We protect your data with industry-standard measures: all traffic is encrypted in transit via HTTPS/TLS, the contact form uses anti-spam protection (a honeypot field), and access to enquiry data is limited to authorised personnel. No method of transmission or storage is ever completely secure, but we work to protect your information and to address any incident promptly. We maintain an internal breach response process: in the event of a personal-data breach that is likely to result in a risk to your rights and freedoms, we will document the incident, notify the competent supervisory authority without undue delay and, where feasible, no later than 72 hours after becoming aware of it (GDPR Art. 33), and communicate to affected data subjects without undue delay where the breach is likely to result in a high risk to your rights and freedoms (GDPR Art. 34). To report a suspected breach or ask about our process, email privacy@nexisdigital.tech.
10. Children's Privacy
Our website and services are intended for businesses and adults. We do not knowingly collect personal data from children under the age of 16. If you believe a child has provided us personal data, contact us and we will delete it.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes to our practices or the law. The 'Last updated' date at the top shows the current version. For material changes we will take reasonable steps to notify you. Your continued use of the website after an update constitutes acceptance of the revised policy.
12. Contact Us
For any question about this policy or your personal data, or to exercise your privacy rights, contact NexisDigital at privacy@nexisdigital.tech. You can also reach us on LinkedIn at https://www.linkedin.com/company/nexisdigital/. We will be glad to help.
13. EU Representative — Legal Review Required
NexisDigital is established outside the European Economic Area in the Republic of Kazakhstan. TODO(LEGAL): qualified counsel must determine whether Article 27 GDPR requires an EU representative for the company's actual processing activities. Until that review is complete, privacy enquiries may be sent directly to privacy@nexisdigital.tech.
14. Free Website Scan
When you use the free website scan, NexisDigital's Cloudflare-hosted scan endpoint fetches the public URL you enter and inspects a limited set of HTML and response signals. Cloudflare may process technical request data, including IP addresses, in its infrastructure and security logs. No email is required to view the first findings. If you request the complete report, we also collect your name, company, business email, consent, the submitted URL, and the visible scan summary through Web3Forms so we can review the evidence and contact you about that request. Automated results are not used for automated decision-making and may be incomplete or unavailable.