1. Data Controller
The Data Controller is Nexus (hereinafter "Controller" or "NEXUS.dev"), reachable through the contact form on the site or at the email address indicated in the Contact section.
2. Types of Data Collected
The personal data collected through this website are exclusively those voluntarily provided by the user through the Contact Form:
- Name – to identify the sender
- Email Address – to respond to the request
- Project Type – to understand the nature of the request
- Message – content of the communication
3. Purpose of Processing
Personal data collected are used exclusively for:
- Responding to information requests sent through the contact form
- Providing requested quotes or consultations
- Managing any professional relationships arising from initial contact
No newsletters, marketing or promotional communications are sent unless separate explicit consent is given.
4. Legal Basis for Processing
The processing of personal data is based on the consent of the data subject (Art. 6, par. 1, letter a) of GDPR), expressed at the time of submitting the contact form, and on the need to follow up on the received request (Art. 6, par. 1, letter b) of GDPR – execution of pre-contractual measures).
5. Third-Party Services
For sending emails from the contact form, we use the Resend service (resend.com), a GDPR-compliant transactional email service. Data is transmitted to Resend exclusively for message processing and delivery.
For more information about Resend's privacy: Privacy Policy Resend
6. Cookies and Tracking Technologies
This website does not use profiling or marketing cookies. Only strictly necessary technical cookies may be used for site functionality (e.g., for managing language preference), which do not require consent.
No third-party analytics services that track user behavior are active.
7. Data Retention
Personal data collected through the contact form are retained for the time strictly necessary to fulfill the request and, subsequently, for the period required by current regulations or to protect the Controller's rights (maximum 24 months from collection, unless required by law).
8. Data Subject Rights
Pursuant to Articles 15-22 of GDPR, the data subject has the right to:
- Access – obtain confirmation of the existence of their data and receive a copy
- Rectification – correct inaccurate or incomplete data
- Erasure – request deletion of data ("right to be forgotten")
- Restriction – limit processing in certain circumstances
- Portability – receive data in a structured format
- Objection – object to processing for legitimate reasons
- Withdrawal of consent – withdraw consent at any time
To exercise your rights, you can contact the Controller through the contact form on the site.
9. Complaint to Supervisory Authority
The data subject has the right to lodge a complaint with the Data Protection Authority (www.garanteprivacy.it) if they believe that the processing of their data violates current regulations.
10. Changes to Privacy Policy
The Controller reserves the right to modify this Privacy Policy at any time. Changes will be published on this page with an indication of the last update date. We recommend consulting this page periodically.