Privacy Policy

Last updated: June 2026

Who we are

Nexo Mechanics Ltd is a company registered in England and Wales (Company No. 14928917). We operate the website nexomechanics.com and provide bespoke software engineering, algorithmic trading, and AI integration services. We act as the data controller for personal information collected through this site and in the course of our business.

Our dedicated privacy contact is: privacy@nexomechanics.com. For general enquiries you may also reach us at mail@nexomechanics.com.

What we collect

We collect only the information necessary to provide our services. Depending on how you interact with us, this may include:

  • Contact and identity information — name, email address, phone number, company name.
  • Project materials — source code, technical specifications, documentation, business requirements, and files you share with us in the course of a project.
  • Account and platform credentials — where necessary to perform contracted services (e.g. GitHub usernames, repository access, API credentials, server access details). These are handled with strict access controls and never stored beyond project completion unless expressly agreed.
  • Infrastructure information — server configurations, environment details, or deployment information shared for the purpose of delivering services.
  • Communications — emails, messages, and meeting notes exchanged during the course of a project or enquiry.
  • Newsletter subscription — email address where you have consented to receive our insights and updates.

We apply the principle of data minimisation: we collect only what is genuinely required and do not request or retain information beyond what is necessary for the agreed purpose.

We do not knowingly store IP addresses, browser fingerprints, or other technical identifiers for our own purposes outside of anonymised analytics described below.

Legal bases for processing

We process personal data under the following legal bases:

  • Contract — processing is necessary to take steps at your request before entering into a contract, or to perform an existing contract (e.g. delivering a project, responding to a quotation request).
  • Consent — where you have given explicit consent, such as subscribing to our newsletter or accepting analytics cookies. You may withdraw consent at any time.
  • Legitimate interests — where processing is necessary for our legitimate business interests, such as improving our services, maintaining security, preventing fraud, or communicating with existing clients, provided those interests are not overridden by your rights.
  • Legal obligation — where processing is required to comply with applicable law, such as retaining invoices and financial records under UK company law.

Confidentiality of project materials

We treat all project materials, source code, technical documentation, business information, and client data as strictly confidential. Such information is accessed only by personnel who require it to deliver the agreed services and is never used for any other purpose. All team members and approved subcontractors are bound by confidentiality obligations.

Subcontractors and personnel

We may engage approved subcontractors or freelance developers to assist in delivering contracted services. Where this occurs, we share only the minimum information necessary for that purpose. All subcontractors are required to maintain confidentiality and are bound by obligations consistent with this policy. We do not sell or rent personal data to any third party.

Service providers and transfers

We use carefully selected third-party service providers, development platforms, hosting providers, and where relevant, AI providers, all acting as processors under appropriate contractual safeguards. These may include:

  • Resend — email delivery for contact form submissions and newsletters, bound by a data-processing agreement incorporating the UK International Data Transfer Addendum.
  • GitHub — source code hosting and version control.
  • Cloud infrastructure providers — including DigitalOcean, AWS, Google Cloud, Railway, and Cloudflare, used for hosting and deployment.
  • AI service providers — where AI-assisted development or tooling is used during a project (see AI Processing section below).
  • Google Analytics 4 and Microsoft Clarity — analytics, subject to your cookie consent (see Cookies section).

Some providers may process information outside the United Kingdom. Where this occurs, we ensure appropriate safeguards are in place, including adequacy regulations, approved standard contractual clauses, or the UK International Data Transfer Addendum.

AI processing

Where requested by clients or where it assists in delivering contracted services, we may use AI tools to support software development, documentation, code review, or analysis. We minimise the personal data submitted to such services and apply the principle of least exposure. We recommend that clients avoid including unnecessary personal or sensitive information in project materials unless expressly agreed and documented. Where AI processing involves personal data, we ensure appropriate contractual safeguards are in place with the relevant provider.

Data retention

We retain personal data only for as long as necessary for the purposes for which it was collected:

  • Enquiries and contact form submissions — up to 24 months from the date of last contact.
  • Client project records, contracts, and communications — for the duration of the project and up to 6 years thereafter, in accordance with UK limitation periods and company law obligations.
  • Financial records and invoices — 6 years from the end of the relevant financial year, as required by UK law.
  • Newsletter subscriptions — until you unsubscribe or withdraw consent.
  • Credentials and access details — securely deleted upon project completion unless continued access is required under a managed services agreement.

When data is no longer required, it is securely deleted or anonymised.

Security

We implement technical and organisational measures aligned with recognised security standards, including:

  • All data in transit is protected by TLS encryption.
  • Access to personal data and project materials is restricted on a least-privilege basis — personnel access only what they need to perform their role.
  • Credentials and secrets are never stored in plaintext; we use appropriate secrets management practices.
  • Administrative access is subject to authentication controls and regular access reviews.
  • No Internet transmission is completely secure; we cannot guarantee absolute security, but we are committed to maintaining appropriate safeguards proportionate to the risk.

Security incidents

In the event of a personal data breach, we will assess the risk and, where required, notify the Information Commissioner's Office within 72 hours of becoming aware. Where a breach is likely to result in a high risk to your rights and freedoms, we will also notify you without undue delay, in accordance with UK GDPR Article 34.

Your rights

Under UK GDPR you have the right to:

  • Access the personal data we hold about you.
  • Rectify inaccurate or incomplete data.
  • Request erasure of your data where it is no longer necessary or where you withdraw consent.
  • Restrict processing in certain circumstances.
  • Data portability where processing is based on consent or contract.
  • Object to processing based on legitimate interests.
  • Lodge a complaint with the Information Commissioner's Office (ico.org.uk).

To exercise any of these rights, contact us at privacy@nexomechanics.com. We will respond within one calendar month.

Cookies and analytics

We use cookies and similar technologies for analytics purposes only. No advertising or tracking-for-profile cookies are set. On first visit you can accept or reject analytics cookies through our cookie banner. Your choice is stored for 12 months and can be cleared from your browser at any time.

When you accept, the following services load:

  • Google Analytics 4 (provider: Google Ireland Limited). Cookies: _ga, _ga_*. Purpose: aggregated visit and engagement metrics. Retention: 14 months.
  • Microsoft Clarity (provider: Microsoft Corporation). Cookies: _clck, _clsk, CLID, ANONCHK, MUID. Purpose: anonymised heatmaps and session recordings to improve site usability. Retention: up to 12 months.

You can opt out at any time by clearing the cookie-consent cookie in your browser and reloading the page, which will display the banner again. You may also use the Google Analytics Opt-out Browser Add-on or your browser's Do Not Track settings.

Changes to this notice

We may amend this notice from time to time. The latest version will always appear on this page and, where the change is material, we will notify registered subscribers by e-mail.