Privacy Policy
How Nexus collects, uses, and protects your institution's data.
Last updated: January 20251. Information We Collect
2. How We Use Your Information
3. Data Isolation
4. Data Security
5. Data Retention
6. Your Rights
7. Cookies
8. Third-Party Services
9. Changes to This Policy
10. Contact
1. Information We Collect
We collect information you provide directly — such as institution name, administrator contact details, and user account information (name, email, role). We also collect usage data such as login timestamps, session metadata, and feature usage to improve the platform. We do not collect any payment card information directly — payments are handled by third-party processors.
2. How We Use Your Information
We use your information to provide and operate the Nexus platform, authenticate users, communicate with you about your account and subscription, send service updates and security notices, and comply with applicable legal obligations. We do not sell, rent, or share your data with third parties for marketing purposes.
3. Data Isolation
Each institution's data is fully isolated at the database level using institution-scoped queries. Users of one institution cannot access, view, or modify the data of any other institution. Superadmin access is limited to Wisemen Soft platform operators only.
4. Data Security
All data transmitted between your browser and Nexus is encrypted using TLS 1.2 or higher. Passwords are hashed using bcrypt and never stored in plain text. Access tokens are short-lived (15 minutes) with secure, HttpOnly refresh token rotation via cookies. Session records are stored and validated server-side.
5. Data Retention
We retain your institution's data for as long as your subscription is active. Upon cancellation or account termination, data is retained for 30 days to allow for export, after which it is permanently deleted. Audit logs may be retained for a longer period as required by law.
6. Your Rights
You have the right to access, correct, or request deletion of your data at any time. Institution administrators can export data directly from the platform. To exercise rights on behalf of your institution, contact us at privacy@wisemensoft.com. We will respond to requests within 30 days.
7. Cookies
Nexus uses only essential cookies for authentication and session management. We do not use advertising, tracking, or analytics cookies. See our Cookie Policy for full details.
8. Third-Party Services
Nexus may use third-party services for infrastructure (hosting, database) and communication (email notifications). These providers are contractually bound to protect your data and may not use it for any other purpose.
9. Changes to This Policy
We may update this Privacy Policy periodically. We will notify institution administrators of material changes via email or an in-platform notice. Continued use of Nexus after changes constitutes acceptance of the updated policy.
10. Contact
For privacy-related enquiries, data requests, or to report a concern, contact us at privacy@wisemensoft.com.