Nexus
dpdp processing notice

What Nexus does with your data

Written to be read by a Chartered Accountant doing diligence on a tool, not by a lawyer. Every category, region and retention period below is the real one.

version 2026-07 · last reviewed 12 August 2026

what we hold

What we collect

Three things, and nothing else. Your account — name, email, phone, and the firm details you give at onboarding. Your work — the questions you ask, the answers Nexus returns, and text extracted from documents you attach. Security records — sign-in times with IP, approximate location and device, plus an audit log of exports, invitations and joins.

We do not sell personal data, we do not run advertising, and we do not use behavioural tracking cookies. There is no third-party analytics script on the signed-in product.

client confidentiality

Your clients' data

A question about a client is client data, and it is handled as your work product: it belongs to your firm, it is not used to train any model, and it is not shared with other firms. Personal identifiers in the text — PAN, GSTIN, Aadhaar — are masked before the question is sent to the AI model and restored only in what is shown back to you.

Text we extract from a document you attach is deleted within 24 hours. The document is a working input, not something we keep.

Can we see your questions?A small number of named people at Nexus can, and only to run the service — to investigate a failed answer, a wrong citation, or a bill you query. We would rather say that plainly than imply nobody ever looks. Two things bound it: the operations dashboard shows the first few words of a question, not the whole of it, and every time someone at Nexus opens the full text or a firm's saved answer, that is written to an audit log with who did it and whose work it was. We do not read your matters for any other purpose, and we never use them to train a model.

where it goes

Who else processes it

Running Nexus means sending some of your data to specialist providers. Here is every category, what goes to it, and where it sits. Cross-border transfer is lawful under DPDP Rule 15, which uses a blocklist model, and no restricted country has been notified as of mid-2026 — but that is a legal position, not an excuse to be vague.

What forWhat we sendWhere
AI model providerYour question, the statute and case law retrieved for it, text and images from anything you attach, and your firm profileUnited States
Database and hostingAll account, firm and research data at rest; request metadata and server logsUnited States (migration to a Mumbai region planned)
AuthenticationName, email, phone, firm metadata, session dataUnited States
Search and retrieval infrastructureYour question text and knowledge-graph textUnited States
Tracing and cost observabilityQuery text, user id, truncated verdicts, token and cost countsUnited States
Transactional emailRecipient email address. Internal alerts carry query IDs only — never query textUnited States
Business messaging (optional — only if you connect WhatsApp)Your WhatsApp number and the progress updates you choose to text in; outbound messages carry assignment titles and daily counts only — never research content or colleagues' updatesUnited States / global

We keep a register naming each provider individually, kept current and reviewed. If your firm needs the named list for its own DPDP records, ask us at info@nexusca.ai and we will send it. Most of this sits in the United States today; a migration of the primary database to a Mumbai region is planned, and when it happens you will be asked to accept the updated notice.

how long

How long we keep it

WhatKept forWhy
Your research questions and the answersUntil you delete themThey are your firm's work product. Deleting them by default would destroy your records.
Text extracted from documents you attach24 hoursClient documents should not linger past the session that needed them.
Cached answers30 daysMatches the lookup window; deleted, not merely hidden.
Sign-in records (IP, approximate location, device)180 daysThe CERT-In log floor. Personal data kept beyond it is a liability, not an asset.
Audit log of exports, invitations and joins400 daysAbove the CERT-In minimum, with bounded growth.
An account you ask us to eraseHard-deleted 30 days after the requestThe DPDP right of erasure, with a short grace period in case the request was an accident.
your rights

What you can do about it

Under the Digital Personal Data Protection Act you can see your data, correct it, and have it erased. Those are not email requests here — they are buttons. Your account page exports everything we hold about you as a file, and deletes your account with a 30-day grace period before the hard purge.

To raise a grievance, or to ask anything this page does not answer, write to info@nexusca.ai. If a breach affects your data we will tell you and the Data Protection Board within 72 hours.

changes

When this notice changes

This notice carries a version (2026-07). A material change — a new sub-processor, a new category of data, a new region — bumps it, and you are asked to accept the new version before continuing. We do not change what we do with your data and leave you on an old notice.