Nexus AI Consulting Limited — Privacy Policy
Notice: This Privacy Policy describes how Nexus AI Consulting Limited (the “Company” or “Nexus”) collects, uses, discloses, retains, transfers across borders, and protects personal data. By accessing the Company’s website, registering for the Services, or otherwise interacting with the Company, you acknowledge that you have read and understood this Policy. For data subjects who are registered Customers, this Policy operates in conjunction with the Company’s customer-verification standards and is incorporated by reference into the Terms of Service per ToS Section 8.
1. Purpose and Scope
1.1 Purpose
This Privacy Policy (the “Policy”) sets forth the standards by which the Company processes personal data in compliance with: (a) the Hong Kong Personal Data (Privacy) Ordinance (Cap. 486) (“PDPO”); (b) the Personal Information Protection Law of the People’s Republic of China (“PIPL”); and (c) any other applicable data protection law in the jurisdictions in which the Company operates.
1.2 Scope of Application
This Policy applies to three categories of data subjects: - (a) Website Visitors — natural persons who access the Company’s website (nexusaistart.com) prior to registration; - (b) Registered Customers — business entities and their authorized natural-person representatives who have completed the Company’s customer verification; and - (c) Refused Applicants — natural persons or entities whose applications were refused or withdrawn, whose data is processed per the Company’s verification-refusal standards.
1.3 Relationship to Other Documents
This Policy is a public-facing document complementing the Company’s internal customer-verification standards. Where this Policy overlaps with those standards (such as data retention, cross-border transfer architecture, and customer rights), the substantive standards are identical. This Policy is the authoritative public statement; the internal verification standards provide additional operational detail to registered Customers. The Cookie Policy is incorporated by reference for matters relating to cookies and similar tracking technologies.
1.4 Legal Framework
The Company processes personal data in compliance with: - The Hong Kong PDPO and the six Data Protection Principles (DPP1-DPP6); - The PRC PIPL (including Articles 13, 17, 38-40, 44-50); - Applicable laws of the Hong Kong Special Administrative Region; and - Other applicable laws where data subjects or operations are located.
2. Information We Collect
The Company collects three categories of personal data, with the categories and specific data elements varying by data subject type.
2.1 Category A — Website Visitor Data
Collected from all visitors to the Company’s website prior to KYC registration: - IP address (and approximate geo-location derived from IP); - Browser User-Agent string and screen resolution; - Pages visited, time spent, referring URL, and exit URL; - Date and time of access; - Cookies and similar local-storage data (described in the Cookie Policy); - Contact-form submission contents (name, business email, country, business description); and - Other technical metadata necessary for the secure operation of the website.
2.2 Category B — KYC Data (Registered Customers)
Collected from Customers during and after verification, as part of the Company’s customer-verification process: - Entity identification: business registration certificate, articles of incorporation, ultimate beneficial owner (“UBO”) information, professional licence (for self-employed Customers); - Business authenticity evidence: under one of six pathways including formal qualifications, business records, industry identity, social credibility, historical transactions, or stated business purpose; - Service-commitment records: service-use commitment, prohibition commitment, and default-recovery provision; - Authorized representative information: identification document, contact information, and authorization-of-signatory evidence; and - Communication records between the Company and the Customer relating to verification matters.
2.3 Category C — Service Operational Data (Registered Customers)
Generated through the Customer’s use of the Services: - Dashboard activity logs: login timestamps, configuration changes, support-ticket submissions; - Bridge Equipment heartbeat records: uptime, firmware version, traffic-ceiling triggers, geo-location of equipment (per KYC-disclosed address); - Traffic metadata (not the substantive content of communications): aggregate bandwidth use by time window, protocol categories, port categories, IP-blacklist triggers; - R1 behavioural audit logs: as defined in the Company’s internal verification standards and the AUP; - Payment records: transaction timestamps, amounts, payment method category (without storing complete card numbers, which are handled by PCI-DSS-compliant payment processors); and - Support and communication records: emails, tickets, escalation history.
2.4 Information We Do Not Collect
The Company expressly does not collect: - The substantive content of communications transmitted via the Services (the Company does not inspect, store, or analyse the content of Customer traffic); - Personal information of the Customer’s end users; - Sensitive personal information categories (per PIPL Article 28): biometric data, religious beliefs, specific identity (e.g., sexual orientation), medical or health data, financial-account-number content beyond payment-method category, location-tracking data beyond KYC-disclosed equipment address, and personal information of minors; - Personal information of any natural person under eighteen (18) years of age (the Services are B2B-only and KYC verifies the legal age of authorized representatives); and - Data through unlawful means or in excess of what is reasonably necessary for the purposes set forth in Section 3.
3. How We Use Your Information
The Company uses personal data only for the following purposes, in alignment with the Company’s internal verification standards (Data Protection Principle 3 — Purpose Limitation):
3.1 Eligibility Verification
Confirming Customer identity, business authenticity, and ongoing compliance per the Company’s customer-verification standards.
3.2 Service Operation
Provisioning Bridge Equipment, operating the Control Plane and dashboard, monitoring heartbeat and traffic metadata for service-quality and capacity management, and providing customer support.
3.3 Regulatory Compliance
Satisfying obligations under the applicable telecommunications regulatory framework, HK PDPO, PRC PIPL, anti-money-laundering law, and other applicable regulatory requirements.
3.4 Lawful Authority Cooperation
Responding to lawful requests from competent authorities per Section 5.3 of this Policy, including the provision of supporting evidence such as R1 logs, heartbeat records, IP-blacklist database entries, and behavioural audit trails.
3.5 Fraud Prevention and Abuse Detection
Maintaining IP blacklists, analysing behavioural patterns to detect abuse of the Services or violations of the AUP, and protecting upstream-provider relationships.
3.6 Customer Communication
Sending account-related notifications, service updates, security alerts, billing reminders, and responding to support inquiries.
3.7 Uses We Do Not Engage In
The Company expressly does not: - Sell, rent, or trade personal data to third parties; - Use personal data for behavioural-advertising or marketing-profiling purposes (except direct marketing of the Company’s own Services to existing Customers, subject to opt-out per Section 9.1); - Use personal data to train artificial-intelligence models (the Company does not operate AI-model-training business lines); - Use personal data for purposes unrelated to the Services or unauthorized by this Policy or the Company’s customer-verification standards.
4. Legal Basis for Processing
The Company processes personal data on the following legal bases, in alignment with PIPL Article 13 and HK PDPO DPP1:
4.1 Consent
The Customer’s express consent provided during the KYC process, including consent to cross-border data transfer per Section 6.
4.2 Contract Necessity
Processing necessary to perform the Service Documents (Terms of Service, Order Form, Master Lease).
4.3 Legal Obligation
Processing necessary to satisfy the applicable telecommunications regulatory framework, HK PDPO, PRC PIPL, anti-money-laundering law, and tax-record-retention obligations.
4.4 Vital Interests
In limited circumstances, processing necessary to protect the vital interests of the Company, the Customer, upstream providers, or other natural persons (e.g., preventing imminent harm from abuse of the Services).
4.5 Legitimate Interests
Processing necessary for the Company’s legitimate interests in fraud prevention, security monitoring, and service-quality assurance, balanced against the data subject’s rights and reasonable expectations.
4.6 Withdrawal of Consent
Where processing is based on consent, the Customer may withdraw consent at any time per Section 9.1, subject to the Company’s right to retain data necessary for regulatory or contractual purposes.
5. How We Share Your Information
The Company does not sell personal data. Sharing is limited to the following categories:
5.1 Service Providers
The Company shares personal data with the following categories of service providers, each bound by a data-processing agreement incorporating safeguards equivalent to the PDPO and PIPL standards: - Upstream residential-IP providers: traffic metadata (without communication content) and Bridge Equipment identifiers necessary for supply-chain compliance; - VPS service provider: dashboard and Control Plane hosting infrastructure; - Payment processor: payment transaction processing (PCI-DSS-compliant; the Company does not retain complete card numbers); - Email delivery service: for transactional and operational email; - Customer-support and legal-counsel partners: as needed, subject to confidentiality and data-protection obligations.
5.2 Affiliated Compliance-Review Function
KYC documentation is reviewed by the Company’s affiliated compliance-review function per the cross-border architecture described in Section 6.1.
5.3 Lawful Authority Requests
The Company shall cooperate with lawful authority requests, including from the Hong Kong courts, the applicable telecommunications regulator, the Privacy Commissioner for Personal Data (PCPD), and the competent law-enforcement and judicial authorities of any relevant jurisdiction. Cooperation includes provision of: - R1 behavioural audit logs; - Bridge Equipment heartbeat and configuration records; - IP-blacklist database entries; - Behavioural audit trails; - Service-commitment records; - Other supporting evidence as required by lawful process.
The Company will not voluntarily provide non-public Customer data absent lawful process, except where Customer consent has been provided or where vital interests are involved.
5.4 Business Transfers
In the event of a merger, acquisition, reorganization, or sale of substantially all assets, personal data may be transferred to the receiving entity, which shall be bound by obligations equivalent to those in this Policy. Customers will be notified of any such transfer.
5.5 Aggregated or De-Identified Data
The Company may share aggregated or de-identified data (data not reasonably identifiable to any individual) for industry-research, operational-improvement, or public-reporting purposes.
5.6 With Customer Consent
Any other sharing requires the Customer’s express prior consent.
6. Cross-Border Data Transfer
The Company’s Services involve cross-border processing of personal data. The data flow architecture, legal basis, recipient identity, and Customer rights are described in this Section 6.
6.1 Data Flow Architecture
This architecture is restated here for public-facing transparency:
- The Customer uploads KYC documentation to the dashboard, which is hosted on a Virtual Private Server (the “VPS”) deployed in an overseas jurisdiction;
- The documentation is stored temporarily on the VPS solely for verification purposes;
- The Company’s authorized compliance-review personnel complete identity, business-authenticity, and compliance verification;
- Upon verification, the documentation is backed up to a secure long-term storage system, isolated from external networks, located in a relevant jurisdiction for long-term retention; and
- The temporary VPS copy is purged at the conclusion of verification and is not retained on the VPS for long-term storage.
6.2 Design Principles
- Data minimization — the VPS does not retain KYC data for long-term storage, reducing cross-border exposure surface;
- Customer privacy protection — long-term storage is isolated from external networks to prevent leakage; and
- Regulatory traceability — the long-term backup is available for regulatory inspection, dispute resolution, and lawful law-enforcement cooperation.
6.3 Legal Basis for Cross-Border Transfer
This cross-border processing relies on: - The Customer’s express consent provided during the KYC process (PIPL Article 39); - A data-processing agreement between the Company and its infrastructure service providers incorporating safeguards equivalent to the PDPO and applicable data protection standards; - The cross-border transfer mechanism prescribed by applicable data protection law, appropriate to the Company’s current operating scale; and - HK PDPO Section 33 conditions for cross-border transfer (consent provided / equivalent protection in recipient jurisdiction / contract necessity / lawful authority requirement, as applicable).
6.4 Recipient Identity Disclosure
This Policy is the public-facing statement of the Company’s cross-border data practices. In keeping with PIPL Article 39, the specific identity and contact details of each overseas recipient and any affiliated compliance-review function — together with the purpose, method, and categories of data transferred — are disclosed in full to each Customer at the point of registration, within the data-processing terms the Customer reviews and consents to before any cross-border transfer occurs. In summary, the recipients fall into the following categories: - Affiliated compliance-review function: performs identity, business-authenticity, and compliance verification; - Infrastructure service providers: provide overseas hosting for the dashboard and Control Plane; - Purpose of processing: eligibility verification, service operation, regulatory cooperation, anti-fraud, and customer communication; - Categories of data: as described in Section 2.2 (Category B KYC Data); and - Customer rights: as described in Section 9. The Company reserves the right to change infrastructure providers or jurisdictions, with prior notice to active Customers and updated disclosure in the registration data-processing terms.
6.5 Customer Rights in Cross-Border Context
Cross-border processing does not diminish the Customer’s rights under this Policy or applicable law. The Customer retains all rights set forth in Section 9 with respect to data processed across borders. Requests may be submitted to privacy@nexusaistart.com.
7. Data Retention
The Company retains personal data only for as long as necessary for the purposes for which it was collected, in compliance with HK PDPO DPP2 and PIPL Article 47.
7.1 Retention Schedule
| Data Category | Retention Period | Legal Basis |
|---|---|---|
| Entity identification (KYC) | Seven (7) years from termination | HK Companies Ordinance record-retention / PIPL Article 47 |
| Business authenticity evidence | Seven (7) years from termination | Same as above |
| Service-commitment records | Seven (7) years from termination | Anti-fraud and dispute resolution |
| Authorized representative information | Seven (7) years from termination | KYC integrity |
| Service operational data (traffic metadata) | twelve (12) months from generation | Telecommunications regulatory requirement and minimization |
| Payment records | Seven (7) years from transaction | HK Inland Revenue Ordinance / anti-money-laundering |
| R1 behavioural audit logs | twenty-four (24) months from generation | Fraud prevention and lawful authority cooperation |
| Website visitor logs | ninety (90) days from collection | Security operation and analytics |
| Cookies | Per Cookie Policy | Consent withdrawal terminates immediately |
| Contact-form submissions | twenty-four (24) months from submission | Service inquiry response and follow-up |
| Refused-applicant records | five (5) years from refusal | Prevention of re-application by malicious actors |
7.2 Post-Termination Treatment
On termination of the service relationship: - Identity and KYC records are retained until the expiry of the applicable retention period above; - Service operational data may be deleted earlier upon written request from the Customer, subject to the Company’s retention of the minimum necessary data for legal-obligation purposes; and - After the retention period expires, data is securely deleted or anonymized.
7.3 Refusal-Database Entries
The Company retains records of refused applicants in an internal database to prevent circumvention by malicious actors. Such records contain the minimum necessary identifiers (entity name, registration number, UBO name) and do not retain full verification documentation beyond the retention period in Section 7.1.
8. Data Security
8.1 Technical Safeguards
- Encryption at rest (AES-256 or equivalent) for KYC documentation and other sensitive data;
- Encryption in transit (TLS 1.3 with HSTS for web-facing endpoints);
- Role-based access control with multi-factor authentication for administrative access;
- Activity logs for administrative access, retained per Section 7;
- Network isolation: long-term storage is physically and logically isolated from external networks;
- Regular vulnerability scanning and security review.
8.2 Organizational Safeguards
- Confidentiality obligations imposed on employees, contractors, and the compliance-review function;
- Data-access minimization principle (least privilege);
- Immediate revocation of access upon termination of employment or engagement;
- Annual data-protection training for personnel with data-access privileges.
8.3 Incident Response
In the event of a personal-data breach or unauthorized access: - (a) the Company will investigate and contain the incident promptly; - (b) affected Customers and data subjects will be notified within seventy-two (72) hours of confirmation, where the incident is reasonably likely to result in harm; - (c) the Hong Kong PCPD and other applicable regulators will be notified where required by law; and - (d) corrective and preventive measures will be documented and implemented.
8.4 No Absolute Guarantee
While the Company implements reasonable safeguards, no system can be guaranteed to be one-hundred-percent secure. The Company does not warrant absolute security and disclaims liability to the fullest extent permitted by applicable law (per ToS Section 10).
9. Your Rights
This Section 9 mirrors the Company’s internal customer rights standards for registered Customers and extends those rights to Website Visitors and Refused Applicants. The Company will respond to verified requests within forty (40) calendar days per the PDPO standard.
9.1 Rights Available to All Data Subjects
| Right | Description | Legal Basis |
|---|---|---|
| Right of Access | Obtain confirmation and a copy of personal data held about you | PDPO DPP6 / PIPL Article 44 |
| Right of Correction | Correct inaccurate or incomplete data | PDPO DPP6 / PIPL Article 46 |
| Right to Withdraw Consent | Withdraw consent to processing based on consent (with consequence) | PIPL Article 15 |
| Right to Complain | File a complaint with HK PCPD or other competent authority | PDPO Section 37 |
| Direct-Marketing Opt-Out | Opt out of direct marketing without affecting Services | PDPO Section 35G |
| Right to Data Portability | Receive data in a structured, machine-readable format (limited cases) | PIPL Article 45 |
| Right to Erasure / Deletion | Request deletion in defined circumstances | PIPL Article 47 |
| Right to Explanation | Receive explanation of automated decision-making affecting you | PIPL Article 24 (not currently applicable; the Company does not engage in automated decision-making with legal effect) |
9.2 How to Exercise Your Rights
Submit requests to privacy@nexusaistart.com with the following: - Website Visitors: email address used in any prior interaction with the Company, approximate timestamp of interaction, and contact-form reference (if applicable); - Registered Customers: Customer identifier and verification of the authorized representative’s identity; - Refused Applicants: applicant identifier and verification of identity.
9.3 Response Timeline
- The Company will acknowledge receipt within seven (7) business days;
- The Company will respond substantively within forty (40) calendar days of receipt of a verified request, per the PDPO standard;
- For complex requests, the Company may extend the response period by an additional thirty (30) days with written explanation of the reason for the extension.
9.4 Limitations on Rights
- Withdrawal of consent may necessitate termination of the Services where consent is the legal basis for processing necessary to the service relationship;
- Requests for deletion are subject to the Company’s right to retain data necessary for: regulatory compliance (e.g., 7-year retention under HK law); lawful authority cooperation; legal-defence; or contractual obligation;
- The Company may decline manifestly unfounded or excessive requests, or charge a reasonable fee for repetitive requests, per the standard permitted by applicable law.
9.5 Complaints to HK PCPD
Data subjects who are dissatisfied with the Company’s response may complain to the Hong Kong Privacy Commissioner for Personal Data: - Website: https://www.pcpd.org.hk/ - The PCPD complaint process is the Company’s preferred external escalation pathway under HK PDPO Section 37.
10. Cookies and Tracking
The Company’s website uses cookies and similar technologies. Detailed information is provided in the Cookie Policy (incorporated by reference into this Policy).
In summary: - The Company uses only strictly-necessary cookies (session token and CSRF protection) at present; - The Company does not currently use third-party analytics cookies (such as Google Analytics) or behavioural-advertising cookies; - The Company does not engage in cross-site tracking; - The Customer may disable cookies in the browser, which may affect login and authenticated-session functionality; - The Cookie Policy provides specific cookie details, third-party provider relationships, and consent-management mechanisms.
11. Children’s Privacy
The Services are intended for business-to-business use only. The Company: - Does not knowingly collect personal information of any natural person under eighteen (18) years of age; - Verifies the legal age of authorized representatives during KYC; - Promptly deletes any information identified as relating to a person under eighteen (18) years of age upon discovery; and - Maintains a policy of refusing applications from natural persons unable to enter into a binding business contract under applicable law.
If a parent or guardian believes their child has provided personal information to the Company, please contact privacy@nexusaistart.com.
12. Modifications to This Policy
12.1 Modification Right
The Company may modify this Policy at any time to reflect changes in: applicable law; the Company’s services; technical infrastructure; or best practices.
12.2 Notice of Material Changes
Material changes will be communicated to active Customers with at least fourteen (14) days’ prior notice via the registered email address, consistent with ToS Section 2.3. Website visitors will be notified via a prominent notice on the website.
12.3 Termination Right
Where a material change reduces Customer-protective provisions, the Customer may terminate the subscription without penalty within thirty (30) days following the effective date of the change, per ToS Section 2.3.
12.4 Version History
Substantive versions of this Policy are archived. Prior versions are available upon request to privacy@nexusaistart.com.
13. Contact and Governing Law
13.1 Privacy Contact
For all privacy and data-rights matters: - Email: privacy@nexusaistart.com - Postal address: Room 1508, 15/F, Argyle Centre Tower 2, 625 Nathan Road, Mong Kok, Kowloon, Hong Kong - Subject-line convention: “Privacy — [Request Type]” (e.g., “Privacy — Access Request”)
13.2 General Contact
For non-privacy inquiries: support@nexusaistart.com
13.3 External Complaint Authority
- Hong Kong Privacy Commissioner for Personal Data: https://www.pcpd.org.hk/
- The competent data-protection authority of any other relevant jurisdiction, as applicable.
13.4 Governing Law
This Policy is governed by and construed in accordance with the laws of the Hong Kong Special Administrative Region of the People’s Republic of China.
13.5 Jurisdiction
The Hong Kong courts have exclusive jurisdiction over disputes arising under this Policy. Privacy-related complaints may additionally be raised with the Hong Kong Privacy Commissioner for Personal Data.
13.6 Language
This Policy is executed in English. The Chinese Summary below is provided for convenience only; in the event of conflict, the English text controls.
中文摘要(Chinese Summary — Non-Binding Reference)
本中文摘要仅供参考,与英文条款发生歧义时以英文条款为准。
文档定位
本《隐私政策》(Privacy Policy)是 Nexus AI Consulting Limited 关于个人数据处理的对外公开声明,与服务条款、可接受使用政策、Cookie 政策共同构成对外透明层。
适用三类主体
- 网站访客(pre-KYC)
- 注册客户及法人代表
- 申请被拒申请人
关键内容摘要
1. 数据收集(§2)三类: - A 类网站访客:IP / UA / 访问行为 / cookie / 联系表单内容 - B 类 KYC 数据:主体 + 业务真实性(6 路径 A-F)+ 服务承诺 + 法人代表 - C 类服务运行:dashboard 操作 / 心跳 / 流量元数据(不含通信内容)/ R1 行为日志 / 支付记录元数据
不收集:通信内容 / 终端用户信息 / 敏感个人信息 / 未成年人信息
2. 使用目的(§3)六类:资格核验 / 服务运营 / 监管合规 / 配合执法 / 反欺诈 / 客户沟通
绝不:出售数据 / 行为画像营销 / 训练 AI 模型 / 与服务无关用途
3. 法律基础(§4):HK PDPO DPP1 + PIPL §13 五类(同意 / 合同必要 / 法定义务 / 重大利益 / 合法利益)
4. 共享范围(§5):上游 IP 供应商 / 基础设施服务商 / 支付商 / 邮件商 / 关联合规审核职能 / 配合执法 / 业务转让 / 经客户同意。不出售给第三方。
5. 跨境数据传输(§6):5 步数据流(dashboard → VPS 临时存储 → 授权合规审核人员核验 → 相关司法辖区内安全长期存储 → VPS 副本清理)。法律基础:客户明示同意 + 适用数据保护法的跨境传输机制 + HK PDPO §33。境外接收方的具体身份与联系方式,于客户注册时在其审阅并同意的数据处理条款中完整披露。
6. 数据保留(§7):身份资料 7 年 / 用量元数据 12 月 / 支付 7 年 / R1 日志 24 月 / 访客日志 90 日 / cookie 详见 Cookie Policy。
7. 数据安全(§8):AES-256 加密存储 / TLS 1.3 / 角色分级 + MFA / 长期存储外网物理隔离 / 定期漏洞扫描。事件响应 72 小时通知。
8. 客户权利(§9)8 项:访问 / 更正 / 撤回同意 / 投诉 / 直销退订 / 数据可携 / 删除 / 自动决策解释(公司目前不进行自动决策)。响应时限 40 日(PDPO 标准)。
9. Cookie(§10):详见 Cookie Policy,无 GA 等分析 cookie,无跨网站追踪。
10. 未成年人保护(§11):B2B 服务唯一。KYC 验证法定代表年龄。
11. 修改(§12):重大修改提前 14 日邮件通知 + 网站显著公告;削减保护性条款时 30 日内无责终止权(与 ToS §2.3 一致)。
12. 联系方式(§13):privacy@nexusaistart.com / 投诉 PCPD https://www.pcpd.org.hk/ / HK 法院专属管辖。
客户权利行使方式
请发邮件至 privacy@nexusaistart.com,主题写”Privacy — [请求类型]“。公司将在 7 日内确认 + 40 日内实质回复。
客户权利一致性
本政策 §9 规定的客户权利与公司内部验证标准在实质标准上一致。本政策是对外公开层(含网站访客),内部验证标准提供注册客户的运营细节。