Legal

Privacy Policy

This is a courtesy translation provided for convenience. The Spanish version prevails in case of discrepancy.

This policy explains what personal data we process when you visit nexus-ai.lat or write to us, for what purposes and on what legal bases, how long we keep it, who else is involved in the processing, and how to exercise your rights. It is written to be read in full: there are no empty categories and no filler clauses.

1. Data controller

The controller of the personal data collected through this site is Néstor David Fleitas, a natural person operating under the trade name Nexus AI, professionally based in the Argentine Republic. Nexus AI provides professional consulting services in automation, security and AI governance, and develops NexusOS, an AI-agent governance software product.

Single point of contact for any privacy matter: hola@nexus-ai.lat.

2. What data we process and where it comes from

We process only three categories of data, all of which originate on this site:

  • Data you submit through our forms. The contact form and the NexusOS early-access form collect: name, email address, company, area of interest and the message you write. The forms are processed through Google Forms and the responses are stored in Google Sheets (Google LLC), which acts as a service provider processing data on our behalf.
  • Site usage data, only with your consent. If you accept the analytics category, we use Google Analytics 4 to measure, in aggregate, which pages are visited and from what type of device. We operate under Google's Consent Mode v2 in basic mode: the measurement tags are not loaded at all until you give consent; before that decision, no signal is sent — not even an anonymous one.
  • Technical infrastructure logs. The site is hosted on GitHub Pages (GitHub Inc.). As part of operating the hosting service, GitHub may record IP addresses and technical request metadata in its infrastructure logs for security and availability purposes. We do not routinely access those logs.

What we do not process matters just as much: the interactive NexusOS demo runs entirely in your browser and sends no data to any server; the site's fonts are served from our own domain, with no third-party requests; and we use no advertising pixels, no fingerprinting techniques and no purchased databases. We never sell personal data.

3. Purposes of processing

  • Responding to business inquiries and requests for a demo or early access to NexusOS.
  • Qualifying and following up on B2B business opportunities, including preparing service proposals.
  • Measuring aggregate site usage to improve its content (only with consent).
  • Ensuring the security and availability of the infrastructure that serves the site.

In Argentina, the applicable framework is Personal Data Protection Act No. 25,326. For visitors from the European Economic Area and the United Kingdom we apply the GDPR and the UK GDPR, on the following bases:

  • B2B inquiries and requests — Art. 6(1)(b) GDPR (pre-contractual steps taken at the data subject's request: you write to us, and we respond and prepare a proposal) and Art. 6(1)(f) GDPR (legitimate interest in developing the business relationship initiated by your inquiry). We have carried out the balancing test that legitimate interest requires: the data consists of professional contact details volunteered in a B2B context, the processing matches the reasonable expectations of the person sending the inquiry, and you may object at any time with immediate effect.
  • Analytics — Art. 6(1)(a) GDPR (consent). You may withdraw it at any time from the site's privacy preferences, without affecting the lawfulness of processing carried out before withdrawal.
  • Infrastructure logs — Art. 6(1)(f) GDPR (legitimate interest in the security and continuity of the service), processing performed by our hosting provider.

5. Retention periods

We document the full lifecycle of inquiry data:

  1. Receipt. Your inquiry arrives through the form and is stored in our response log.
  2. Qualification. We assess whether we can help and with which service; we reply within 24 business hours.
  3. Commercial follow-up. While an active conversation exists, we keep the data to sustain it (proposals, meetings, scoping).
  4. Resolution. If the inquiry leads to a contract, the data becomes governed by that contract and by the associated legal obligations (tax, accounting). If it does not, the record becomes an inactive prospect.
  5. Deletion or anonymization. Inactive prospect data is deleted or irreversibly anonymized 24 months after the last meaningful contact, unless a legal or contractual obligation requires keeping it longer.

Analytics data is retained for the cookie lifetimes described in the cookie policy. Your consent decision is stored for 182 days in the cc_cookie cookie.

6. Processors and recipients

We do not disclose personal data to third parties for their own purposes. The only providers that process data on our behalf are:

  • Google LLC (United States) — Google Forms and Google Sheets for receiving and storing form submissions; Google Analytics 4 for usage measurement, only with your consent. Google Privacy Policy.
  • GitHub Inc. (United States) — site hosting through GitHub Pages, including technical infrastructure logs. GitHub General Privacy Statement.

We may also disclose data if a competent authority lawfully requires it, in which case we will limit the disclosure to what is strictly required.

7. International transfers

Both of our providers process data in the United States. Google LLC and GitHub Inc. are certified under the EU-U.S. Data Privacy Framework (including its UK Extension) and, depending on the service, additionally offer the European Commission's Standard Contractual Clauses (SCCs) as a safeguard. With respect to Argentina's Act No. 25,326, these same instruments constitute adequate contractual safeguards in line with what that law requires for international transfers.

8. Your rights

You may at any time exercise the rights of access, rectification, erasure, restriction of processing, data portability, objection and withdrawal of consent (GDPR and UK GDPR), as well as the access, rectification, updating and deletion rights provided by Act No. 25,326.

How to exercise them: write to hola@nexus-ai.lat stating which right you want to exercise. We respond within the applicable statutory timeframes (in Argentina, those set by Act No. 25,326) and, in any event, within a maximum of 30 days. If we have reasonable doubts about your identity, we will ask for proportionate verification before acting; we will never ask for more data than is needed to verify it.

Right to lodge a complaint: if you believe the processing infringes the applicable rules, you may lodge a complaint with the Agencia de Acceso a la Información Pública (the supervisory authority for Act No. 25,326 in Argentina) or, if you are in the European Union or the United Kingdom, with the supervisory authority of your place of residence.

9. Regulations addressed by design

Our audience is business-focused and mostly Latin American and European, but we designed the processing to also be compatible with California's CCPA/CPRA and Brazil's LGPD. We do not claim certifications or formal applicability where none exists; what we guarantee is operational: the analogous rights those laws recognize (to know, correct, delete, object) are honored through the same channel and within the same timeframes stated in the previous section. For CCPA/CPRA purposes: we do not sell or share personal data.

10. Children

This is a B2B site aimed at professionals and companies. It is not directed at anyone under 18 years of age, and we do not knowingly collect data from minors. If we detect that a form was submitted by a minor, we will delete the data.

11. Cookies

The complete detail of the site's cookies — there are only two families — is in the cookie policy. You can review or change your decision at any time from the privacy preferences.

12. Changes to this policy

Each version of this policy carries a number and an effective date; the current version is 1.0, effective as of July 12, 2026. If we make material changes — new data categories, new processors, new purposes — we will announce them visibly on the site and, where a change affects consent-based processing, we will ask for consent again.

13. Privacy as an engineering principle

NexusOS, our product, imposes four rules on AI agents: least-privilege permissions, approval before execution, auditable evidence of every action and human control over anything irreversible. This site applies the same rules to its visitors: we collect the minimum necessary, no measurement tool runs before your consent, every consent decision is recorded and reversible, and this policy is versioned the way any engineering artifact would be. We are not asking you to trust a statement: the site's behavior can be verified from your browser's developer tools.