Legal & Compliance

Security & Privacy Policy

How Nexo Development Group collects, processes, and protects your data — and the security standards we hold ourselves to.
GDPR Compliant
EU Data Residency
Last updated: April 2026

Overview

Nexo Development Group BV ("Nexo", "we", "us") is a software engineering company headquartered in Barcelona, Spain (Tech Barcelona — Pier01), with offices in Luxembourg and London. We build full-stack platforms for retail, manufacturing, and logistics — including warehouse intelligence, product lifecycle management, track & trace, and battery digital product passport systems.

This policy applies to all Nexo products, services, and websites including nexodev.group and all subpaths. By using our services, you agree to the practices described here.

Plain English summary: We collect only what we need, store it in the EU, never sell it, and give you full control over it.

Data We Collect

Information you provide directly

  • Name and business email address when contacting us or requesting access
  • Company name, role, and country for onboarding and account setup
  • Messages and enquiries submitted via our contact form
  • Login credentials (email and bcrypt-hashed passwords) for the client portal

Information collected automatically

  • IP address, browser type, and device information for security logging
  • Session activity within the client portal (pages visited, documents accessed)
  • QR code scan events within our Track & Trace and DPP platforms
  • Server-side access logs retained for 90 days

Information we do not collect

  • We do not collect payment card data — all billing is handled via invoicing
  • We do not collect biometric data or sensitive personal categories under GDPR Art. 9
  • We do not purchase or import third-party marketing lists

How We Use Data

  • To provide, operate, and maintain our software platforms
  • To authenticate users and secure access to the client portal
  • To send transactional communications (access credentials, system alerts)
  • To respond to support requests and sales enquiries
  • To detect and prevent fraudulent or unauthorised access
  • To comply with legal obligations under EU and Netherlands law

We do not use personal data for advertising, profiling, or automated decision-making that produces legal effects.

Storage & Data Residency

All personal data processed by Nexo is stored and processed exclusively within the European Union. We do not transfer personal data outside the EEA without appropriate safeguards in place (Standard Contractual Clauses where applicable).

🗄️
Database
DB hosted on EU-region servers via TransIP (Netherlands)
☁️
Object Storage
S3-compatible storage, EU-West region
🌐
CDN & DDoS
Cloudflare — EU data localisation enabled
📧
Email
Transactional mail via server-side PHP mail(), no third-party ESP

Security Measures

Security is a core engineering requirement at Nexo, not an afterthought. Our platforms are built with the following controls in place:

🔒
Encryption in transit
TLS 1.2+ enforced on all endpoints. HSTS enabled.
🔑
Password hashing
bcrypt with cost factor 12. Passwords are never stored in plaintext.
🛡️
CSRF protection
Token-based CSRF validation on all state-changing requests.
🚫
SQL injection
Parameterised PDO queries throughout. No raw string interpolation.
🔐
Session security
HttpOnly, Secure, SameSite cookies. Session IDs regenerated on login.
📋
Audit logging
All authentication and data access events are logged with timestamps and IP.
🏢
Multi-tenancy
Strict tenant isolation enforced at query level on all shared platforms.
📁
File access control
Uploaded documents served exclusively through authenticated download handlers.

Third Parties

Nexo does not sell, rent, or trade personal data with third parties. We share data only with the following categories of sub-processors, solely to deliver our services:

  • TransIP BV — hosting and infrastructure provider (Netherlands)
  • Cloudflare Inc. — DDoS protection and CDN (EU data localisation enabled)
  • Amazon Web Services — object storage, EU-West region only
  • Google Fonts — font delivery via fonts.googleapis.com (no personal data transmitted)

All sub-processors are bound by GDPR-compliant Data Processing Agreements.

Your Rights Under GDPR

As a data subject under the General Data Protection Regulation, you have the following rights:

  • Right of access — request a copy of all personal data we hold about you
  • Right to rectification — request correction of inaccurate data
  • Right to erasure — request deletion of your data ("right to be forgotten")
  • Right to restriction — request that we limit processing of your data
  • Right to portability — receive your data in a structured, machine-readable format
  • Right to object — object to processing based on legitimate interests
  • Right to lodge a complaint — with the Autoriteit Persoonsgegevens (Netherlands DPA) at autoriteitpersoonsgegevens.nl

To exercise any of these rights, contact us at sales@nexodev.group. We respond within 30 days.

Cookies

Our public website (nexodev.group) does not use tracking cookies or analytics cookies. No third-party advertising cookies are set.

The client portal (nexodev.group/clients) uses the following functional cookies only:

  • cp_session — session authentication cookie, expires on browser close or after 8 hours
  • cp_remember — optional persistent login cookie, 30-day expiry, set only if "Keep me signed in" is selected

These cookies are strictly necessary for the portal to function. No consent banner is required under ePrivacy Directive exemptions for strictly necessary cookies.

Data Retention

  • Client portal account data is retained for the duration of the commercial relationship plus 2 years
  • Activity and audit logs are retained for 12 months then purged automatically
  • Server access logs are retained for 90 days
  • Contact form submissions are retained for 6 months unless a commercial relationship follows
  • Uploaded quote documents are retained until manually deleted by an administrator

Upon termination of a contract, personal data is deleted within 60 days unless retention is required by law.

Questions about this policy?

Our data controller is Nexo Development Group BV, Barcelona, Spain.
For all privacy and security enquiries:

Contact us →