Summary
- We collect little, and most of it comes straight from you.
- No analytics, advertising trackers or cookies on this site.
- We never sell personal data or use it to train AI.
- You can ask to see, correct or delete your data at any time.
This summary is here to help. The full policy below is what applies.
Who we are
This policy explains how Nexivius Ltd (“Nexivius”, “we”, “us”, “our”), a private limited company registered in Scotland (company number SC904698), collects and uses personal data when you visit nexivius.com, book a consultation, or deal with us as a client, supplier or business contact.
For that data we are the controller under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. If you’re in the EU, the EU GDPR may also apply. When we run our products for clients, the client is usually the controller instead: see When we act for our clients.
One of our directors is responsible for data protection. Questions about this policy or your data go to contact@nexivius.com.
What we collect
We collect only what we need, and most of it comes straight from you.
| Where it comes from | What it includes |
|---|---|
| The booking form | The products you’re interested in, your name, work email, organisation, role, organisation size and country, what you’re trying to solve, your timeline and budget range, and the call time and time zone you choose. |
| Emails and calls | What you write to us, and the notes we make during a consultation or project call. We don’t record or transcribe calls, including with AI note-takers, unless you’ve agreed. |
| Working with us | Names, job titles and contact details for you and your colleagues, plus contracts, invoices, billing details and project correspondence. |
| Other people | If a colleague introduces you, or your organisation works with us, we may receive your name, job title and work contact details from them. We may also use public sources, such as your organisation’s website or LinkedIn, to prepare for a conversation. |
| Visiting the site | Technical data our hosting provider records to deliver the site and keep it secure, such as your IP address, browser type, the pages requested and when. |
The booking form opens your own email app with your details filled in, and nothing reaches us until you send it. We don’t use analytics, advertising pixels or social media trackers, and we don’t buy data about you. Please don’t include sensitive details, such as health information, in the form: we don’t need them to arrange a call.
How we use it, and why
Data protection law says we need a lawful basis for each use of your data. Here are ours.
| What we do | Lawful basis |
|---|---|
| Reply to your enquiry and arrange your consultation | Legitimate interests: responding to people who contact us. If you’re asking about working with us yourself, also steps you’ve asked us to take before a contract. |
| Prepare proposals and deliver our work | Legitimate interests: working with the organisation you represent. Contract, if you deal with us yourself. |
| Invoicing, accounting, tax and record keeping | Legal obligation |
| Keep the site, our systems and your data secure, and prevent fraud and misuse | Legitimate interests |
| Follow up after a call and keep in touch about related work | Legitimate interests. You can object at any time and we’ll stop. |
| Send news and marketing emails | Legitimate interests, for business contacts at work addresses. Your consent, where the law requires it. Every marketing email tells you how to unsubscribe. |
Giving us your details is up to you, but we need the required fields in the booking form to arrange a call. Where we rely on legitimate interests, we’ve weighed them against your rights and what you’d reasonably expect; ask us and we’ll explain the balance. We don’t make decisions about you that have legal or similarly significant effects by automated means alone.
When we act for our clients
Attest, Prometheus and Nexidia process personal data for the organisations that use them: a university’s students and staff, the candidates a client interviews, or a business’s customers and team. For that data our client is the controller and decides how it’s used, and we act as their processor. If your data is held in one of our products, the organisation that uses it is responsible for telling you how it’s used, and is the first place to send requests about it. If you contact us instead, we’ll pass your request on and help them answer it.
When we act for a client, we:
- use their data only on their documented instructions, under a data processing agreement, and tell them if an instruction seems unlawful;
- make sure everyone with access is bound by confidentiality, and protect the data as that agreement sets out;
- store it where that agreement says, and only transfer it outside the UK with the safeguards UK law requires;
- use sub-processors, such as hosting, AI model and video avatar providers, only under written terms that protect the data, and tell clients before adding one so they can object;
- tell them without undue delay if a breach affects their data;
- help them answer people’s requests and carry out impact assessments, and support reasonable audits;
- delete or return the data when our work ends, as they choose;
- never sell it, use it for our own marketing or use it to train AI models, whether ours or our providers’.
Procurement and data protection teams can ask us for our data processing agreement and sub-processor list, and we’ll complete your supplier and security questionnaires.
AI in our products
Our products use AI to run interviews, mark answers, draft messages and automate work. We build them so that people stay in charge.
- People are told they’re talking to an AI before a session starts.
- AI marks and suggestions follow the client’s own rubric or rules, and a person at the client can review and change them.
- No admission, hiring or assessment decision has to be left to AI alone. If a client lets AI make a significant decision without meaningful human involvement, the client must tell people, hear their views, and offer human review and a way to challenge it. We help clients do this.
- Prometheus can give practice feedback on delivery, such as eye contact, pace and filler words. It isn’t designed to infer emotions or to identify people from their face or voice. We advise clients not to base decisions about people on delivery feedback, because it can disadvantage some disabled and neurodivergent people.
- AI can make mistakes, so its results should be checked before anyone relies on them.
International transfers
Some of our providers store or access data outside the UK, for example in the European Economic Area or the United States. When they do, we make sure your data stays protected. Either the destination is approved under UK law as giving adequate protection (such as the EEA, or US organisations certified under the UK Extension to the EU–US Data Privacy Framework), or we use the ICO’s International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses or another safeguard UK law recognises.
Ask us for a copy of the safeguards that apply to your data.
How long we keep it
| Data | How long |
|---|---|
| Enquiries that don’t lead to work | Up to 2 years after we last spoke, then deleted. |
| Client, contract and billing records | 6 years after the contract ends, to meet tax rules and deal with any legal claims. |
| Website security logs | Kept briefly by Cloudflare, our hosting provider. We don’t keep copies. |
| Marketing preferences | Until you unsubscribe. After that we keep a minimal record so we don’t email you again. |
When we no longer need data, we delete it or anonymise it so it can’t identify you.
Keeping it safe
We protect personal data with encryption in transit and at rest, multi-factor sign-in on our accounts and access only for the people who need it. No system is completely secure, but we work hard to prevent unauthorised access, loss or misuse. If a breach puts your data at risk, we’ll tell you and the ICO where the law requires.
Your rights
You have rights over your personal data. Some depend on the lawful basis we use, but you can always ask. Choose one below to start a request by email.
- AccessGet a copy of the data we hold about you.
- CorrectionHave inaccurate or incomplete data put right.
- DeletionAsk us to erase your data.
- RestrictionAsk us to limit how we use it.
- ObjectionObject to uses based on legitimate interests, and to marketing at any time.
- PortabilityReceive the data you gave us in a format you can reuse.
- Withdraw consentWhere we rely on consent, change your mind at any time.
- Human reviewAsk for a person to review any significant automated decision.
To use any of these rights, email contact@nexivius.com. It’s free, and we’ll reply within one month of your request, or of confirming your identity if we need to. Complex requests can take up to two months more, and we’ll tell you if so.
Complaints
If you’re unhappy with how we’ve handled your data, please tell us first at contact@nexivius.com. We’ll acknowledge your complaint within 30 days, look into it and tell you the outcome.
You also have the right to complain to the Information Commissioner’s Office, the UK’s data protection regulator, at ico.org.uk/make-a-complaint or on 0303 123 1113. If you live in the EU, you can also contact your local data protection authority.
Cookies
This site doesn’t set cookies or store anything in your browser, and it doesn’t track you. Our cookie policy explains the security measures our hosting provider may use.
Children
Our website and services are for organisations. The website isn’t aimed at children, and we don’t knowingly collect children’s data through it. Some clients use our products with under-18s, such as school students practising for interviews. The client is responsible for that data, and we build those products with the ICO’s Children’s code in mind.
Changes to this policy
We’ll update this policy when our services or the law change, and update the date and version at the top. If a change materially affects how we use your data, we’ll tell you directly where we can.
Version history
| Version | Date | Changes |
|---|---|---|
| 1.0 | 4 October 2026 | First published. |
Nexivius is the trading name of Nexivius Ltd, a private limited company registered in Scotland (company number SC904698).
Questions about your data?
Email us and a person on our team will reply.