Nexos Privacy Policy

Version 2026-07-16 · Effective 16 July 2026

This Privacy Policy explains how LUKA BJELICA PR FIDERAIT ZRENJANIN, Pariske komune 28, 23000 Zrenjanin, Republic of Serbia, PIB 115208742 ("Nexos", "we", "us") processes personal data when you use the Nexos platform, websites, dashboard, APIs, CLI tools, and node agent (the "Service"). We are the data controller for the processing described here, and we process personal data in accordance with the EU General Data Protection Regulation ("GDPR") and Serbia's Law on Personal Data Protection ("ZZPL").

Contact for all privacy matters: legal@nexos.rs.

1. Data we collect

Account data

Content you deploy

Usage, billing, and technical data

2. Why we process it (purposes and legal bases)

PurposeLegal basis (GDPR Art. 6 / ZZPL)
Creating and operating your account; building, deploying, and running your environments; providing supportPerformance of a contract (Art. 6(1)(b))
Billing and subscription managementPerformance of a contract; legal obligation (Art. 6(1)(b), (c))
Securing the Service: abuse prevention, quota enforcement, incident investigation, loggingLegitimate interests (Art. 6(1)(f)) — keeping the platform and its users safe
Service emails (verification, security notices, material changes to terms)Performance of a contract; legitimate interests
Complying with accounting, tax, and other legal dutiesLegal obligation (Art. 6(1)(c))
Optional communications, if anyConsent (Art. 6(1)(a)), withdrawable at any time

3. Distributed infrastructure — where your workloads run

Nexos schedules workloads onto a network of nodes. Shared nodes are operated by Nexos as a global pool. If your project uses the shared pool, your built images, source checkouts, running containers, and environment data are processed on that Nexos-operated infrastructure. Traffic between the control plane and nodes, and between nodes, is encrypted (TLS and WireGuard tunnels); secrets are encrypted at rest and only decrypted for injection into your workloads. If you need workloads to stay on hardware you control, configure your projects to use private nodes that you connect yourself.

Private nodes — reduced processing scope

When a project runs exclusively on private nodes (hardware you own and operate), your source-code checkouts, build caches, built images, running containers, and application databases — including any personal data inside them — are processed and stored on your hardware, not on Nexos infrastructure. In that configuration, the Nexos control plane still processes:

For business customers, our Data Processing Addendum documents this shared-responsibility split, our processor obligations (including notification of personal-data breaches without undue delay and within 72 hours of becoming aware), and the current subprocessor list. Where we process personal data contained in Customer Content on your behalf, we act as your processor and on your instructions.

4. Who we share data with

We do not sell personal data and we do not use it for third-party advertising.

5. International transfers

We are based in Serbia, and nodes, subprocessors, and users are located in multiple countries, so personal data may be transferred internationally — including between Serbia, the EU/EEA, and other jurisdictions. Where a transfer requires safeguards under the GDPR or ZZPL, we rely on adequacy decisions where available or on appropriate safeguards such as the European Commission's Standard Contractual Clauses (Serbia's government has likewise adopted standard contractual clauses under the ZZPL).

6. How long we keep data

7. Security

We apply technical and organizational measures appropriate to the risk, including: TLS for data in transit and WireGuard tunnels between nodes; AES-256-GCM encryption at rest for secrets, OAuth tokens, and uploaded database seeds; bcrypt password hashing; hashed API keys with granular scopes; container isolation with resource limits; role-based access control; and audit logging of administrative actions. No system is perfectly secure; if we learn of a personal-data breach that requires notification, we will notify the competent authority and affected users as required by the GDPR and ZZPL.

8. Your rights

Under the GDPR and the ZZPL you have the right to:

To exercise any right, email legal@nexos.rs. We respond within the statutory deadline (one month under the GDPR, extendable as permitted). You also have the right to lodge a complaint with a supervisory authority — in Serbia, the Commissioner for Information of Public Importance and Personal Data Protection (poverenik.rs); in the EU/EEA, the data protection authority of your country of residence.

9. Children

The Service is not directed to children under 16, and our Terms require users to be at least 16 years old. We do not knowingly collect personal data from children under 16; if you believe a child has created an account, contact us and we will delete it.

10. Changes to this policy

We may update this Privacy Policy from time to time. The version date at the top identifies the current version, which shares a version identifier with our Terms; material changes will be presented for your review in the dashboard and, where appropriate, announced by email.

11. Contact

LUKA BJELICA PR FIDERAIT ZRENJANIN
Pariske komune 28, 23000 Zrenjanin, Republic of Serbia
PIB: 115208742
legal@nexos.rs