Skip to content
Nexus365

Legal

Data Processing Terms

How we handle the business data — including personal information — that organisations store in Nexus365.

Draft template — to be reviewed by legal counsel before launch. A signed data processing agreement will be offered to customers once finalised.

1. Roles

The organisation using Nexus365 decides what data to store and why (the controller). Nexus365 processes that data only to provide the service, on the organisation's documented instructions (the processor).

2. Categories of data

  • Business records: products, stock, sales, purchases, suppliers, accounts and journals.
  • Customer information: names, phone numbers, purchase history, Baki balances, loyalty and consent settings.
  • Employee and user information: names, roles, branch access and activity in the audit log.

3. Processing principles

  • Purpose limitation: data is used only to operate, secure and support the organisation's workspace.
  • Isolation: each organisation's data is logically separated and access is enforced on the server, not only in the interface.
  • Least privilege: access within an organisation follows its roles and branch permissions; Nexus365 staff access is restricted and logged.
  • AI processing: AI features use the organisation's own data within its workspace. Customer data is not used to train models for other organisations.
  • Consent: marketing features respect the consent recorded against each customer.

4. Sub-processors

A list of sub-processors (for example hosting and email delivery) and the process for notifying customers of changes will be published before launch.

5. Data location and transfers

Where data is hosted, and the safeguards for any cross-border transfer, will be documented here in line with applicable Bangladesh law and customer requirements.

6. Security incidents

We will notify affected organisations without undue delay after becoming aware of a personal data breach affecting their workspace, with the information they need to meet their own obligations.

7. Export and deletion

Organisations will be able to export their data and request deletion at the end of their subscription, subject to legal retention requirements such as financial records.

8. More information

See also our Privacy Policy and Security page.