Last updated: 19 July 2026
This policy explains what personal data NexusCloud Group LTD collects, why we collect it, how long we keep it and what rights you have over it. It covers this website and the services we provide to our customers.
NexusCloud Group LTD ("NexusCloud", "we", "us") is a company registered in England and Wales, company number 14738381, with its registered office at 100 Gresty Road, Crewe, CW2 6EF.
For the personal data described in section 3 we are the data controller.
Questions about this policy, or any request to exercise your rights, should go to [email protected], or by post to the address above marked for the attention of [DATA PROTECTION CONTACT].
We handle personal data in two distinct capacities, and it matters which one applies:
Our contact forms collect your name, email address and message, and optionally your telephone number, company name and subject. We also record the IP address the submission came from, to help us identify spam and abuse.
Why: to reply to you and, where relevant, to prepare a quote. Lawful basis: our legitimate interest in responding to enquiries about our services, and taking steps at your request before entering a contract.
If you request a backup trial we collect your name, organisation name, email address and a chosen username, and use them to create your trial account.
Why: to provision and support the trial. Lawful basis: steps taken at your request before entering a contract.
For customers we hold contact details for the individuals named on the account, billing and payment records, service configuration details, and correspondence including support tickets.
Why: to deliver and bill for the services. Lawful basis: performance of our contract with you, and legal obligation for records we are required to retain.
Our web servers and network equipment record IP addresses, timestamps, requested URLs, user agent strings and, for authenticated services, account identifiers.
Why: security monitoring, abuse investigation, fault diagnosis and capacity planning. Lawful basis: our legitimate interest in keeping our network secure and available.
This website uses Google Analytics to understand how visitors use our pages. It sets cookies that record a randomly generated identifier, the pages you view and a truncated version of your IP address. Analytics cookies are only set if you consent to them, and you can change your mind at any time using Cookie Settings.
If you reject analytics, we store a single cookie recording that choice so we do not ask again. That cookie is strictly necessary and holds nothing else.
We also use Google reCAPTCHA on our forms to distinguish real visitors from automated abuse. reCAPTCHA collects hardware and software information and behavioural signals, and sends them to Google for analysis. Its use is subject to Google's privacy policy and terms of service. Without it we cannot accept form submissions.
Cookies strictly necessary to make the site work do not require consent and cannot be switched off.
We do not sell personal data. We share it only with the suppliers that make our services work, each of whom is bound by contract to protect it:
We will also disclose data where we are legally required to — for example in response to a valid court order or a lawful request from law enforcement. Where a request concerns a customer's data and we are permitted to tell them, we will.
A current list of the sub-processors used to deliver each service is available on request, and customers are notified before a new sub-processor is added.
Customer data and backups are held in the United Kingdom. Some of the suppliers listed above are based outside the UK or may process data outside it. Where that happens we rely on UK adequacy regulations or on the International Data Transfer Agreement (or the UK Addendum to the EU Standard Contractual Clauses), together with any additional safeguards the transfer requires.
| Data | Retention period |
|---|---|
| Enquiries that do not become customers | [24 months] from last contact |
| Customer account and correspondence records | Duration of the contract, then [24 months] |
| Billing and accounting records | 7 years, as required by HMRC |
| Web and server access logs | [90 days] |
| Security and audit logs | [12 months] |
| Customer backup data | As set by the customer's retention policy; deleted [30 days] after the service ends |
| Trial accounts and their data | Deleted [30 days] after the trial ends |
Where a retention period has passed we delete the data or irreversibly anonymise it.
We apply technical and organisational measures appropriate to the risk, including encryption of data in transit, access control on a least-privilege basis, multi-factor authentication for administrative access, monitoring and logging, and physical security at our data centre facilities. No system is perfectly secure, but we test and review these measures regularly.
Under UK GDPR you have the right to: be told how your data is used; get a copy of it; have inaccurate data corrected; have data erased in certain circumstances; restrict or object to processing; receive your data in a portable format; and withdraw consent where consent is the basis we rely on.
To exercise any of these, email [email protected]. We respond within one month. There is no charge unless a request is manifestly unfounded or excessive.
If the data you are asking about is held by us as a processor on a customer's behalf, we will direct you to that customer, who is the controller and the right party to answer.
If you are unhappy with how we have handled your data, please tell us first so we can put it right. You also have the right to complain to the Information Commissioner's Office at ico.org.uk/make-a-complaint, by calling 0303 123 1113, or by writing to Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF.
Where we host, back up or otherwise process data for a customer, that customer remains the controller and decides what is stored and for how long. We process it only on their documented instructions.
Our obligations in that role — including confidentiality, security measures, use of sub-processors, assistance with data subject requests, breach notification and deletion or return of data at the end of the contract — are set out in our Data Processing Agreement, which forms part of our terms of service and is available on request.
We will notify an affected customer without undue delay, and in any event within 24 hours, of becoming aware of a personal data breach affecting their data.
We may update this policy from time to time. The date at the top shows when it last changed. Where a change materially affects how we use your data we will tell you directly.