EXIVIUS Book a free consultation

Legal

Privacy policy.

What we collect, why we need it and the control you keep over it.

Summary

  • We collect little, and most of it comes straight from you.
  • No analytics, advertising trackers or cookies on this site.
  • We never sell personal data or use it to train AI.
  • You can ask to see, correct or delete your data at any time.

This summary is here to help. The full policy below is what applies.

01

Who we are

This policy explains how Nexivius Ltd (“Nexivius”, “we”, “us”, “our”), a private limited company registered in Scotland (company number SC904698), collects and uses personal data when you visit nexivius.com, book a consultation, or deal with us as a client, supplier or business contact.

For that data we are the controller under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. If you’re in the EU, the EU GDPR may also apply. When we run our products for clients, the client is usually the controller instead: see When we act for our clients.

One of our directors is responsible for data protection. Questions about this policy or your data go to contact@nexivius.com.

02

What we collect

We collect only what we need, and most of it comes straight from you.

Where it comes fromWhat it includes
The booking formThe products you’re interested in, your name, work email, organisation, role, organisation size and country, what you’re trying to solve, your timeline and budget range, and the call time and time zone you choose.
Emails and callsWhat you write to us, and the notes we make during a consultation or project call. We don’t record or transcribe calls, including with AI note-takers, unless you’ve agreed.
Working with usNames, job titles and contact details for you and your colleagues, plus contracts, invoices, billing details and project correspondence.
Other peopleIf a colleague introduces you, or your organisation works with us, we may receive your name, job title and work contact details from them. We may also use public sources, such as your organisation’s website or LinkedIn, to prepare for a conversation.
Visiting the siteTechnical data our hosting provider records to deliver the site and keep it secure, such as your IP address, browser type, the pages requested and when.

The booking form opens your own email app with your details filled in, and nothing reaches us until you send it. We don’t use analytics, advertising pixels or social media trackers, and we don’t buy data about you. Please don’t include sensitive details, such as health information, in the form: we don’t need them to arrange a call.

03

How we use it, and why

Data protection law says we need a lawful basis for each use of your data. Here are ours.

What we doLawful basis
Reply to your enquiry and arrange your consultationLegitimate interests: responding to people who contact us. If you’re asking about working with us yourself, also steps you’ve asked us to take before a contract.
Prepare proposals and deliver our workLegitimate interests: working with the organisation you represent. Contract, if you deal with us yourself.
Invoicing, accounting, tax and record keepingLegal obligation
Keep the site, our systems and your data secure, and prevent fraud and misuseLegitimate interests
Follow up after a call and keep in touch about related workLegitimate interests. You can object at any time and we’ll stop.
Send news and marketing emailsLegitimate interests, for business contacts at work addresses. Your consent, where the law requires it. Every marketing email tells you how to unsubscribe.

Giving us your details is up to you, but we need the required fields in the booking form to arrange a call. Where we rely on legitimate interests, we’ve weighed them against your rights and what you’d reasonably expect; ask us and we’ll explain the balance. We don’t make decisions about you that have legal or similarly significant effects by automated means alone.

04

When we act for our clients

Attest, Prometheus and Nexidia process personal data for the organisations that use them: a university’s students and staff, the candidates a client interviews, or a business’s customers and team. For that data our client is the controller and decides how it’s used, and we act as their processor. If your data is held in one of our products, the organisation that uses it is responsible for telling you how it’s used, and is the first place to send requests about it. If you contact us instead, we’ll pass your request on and help them answer it.

When we act for a client, we:

  • use their data only on their documented instructions, under a data processing agreement, and tell them if an instruction seems unlawful;
  • make sure everyone with access is bound by confidentiality, and protect the data as that agreement sets out;
  • store it where that agreement says, and only transfer it outside the UK with the safeguards UK law requires;
  • use sub-processors, such as hosting, AI model and video avatar providers, only under written terms that protect the data, and tell clients before adding one so they can object;
  • tell them without undue delay if a breach affects their data;
  • help them answer people’s requests and carry out impact assessments, and support reasonable audits;
  • delete or return the data when our work ends, as they choose;
  • never sell it, use it for our own marketing or use it to train AI models, whether ours or our providers’.

Procurement and data protection teams can ask us for our data processing agreement and sub-processor list, and we’ll complete your supplier and security questionnaires.

05

AI in our products

Our products use AI to run interviews, mark answers, draft messages and automate work. We build them so that people stay in charge.

  • People are told they’re talking to an AI before a session starts.
  • AI marks and suggestions follow the client’s own rubric or rules, and a person at the client can review and change them.
  • No admission, hiring or assessment decision has to be left to AI alone. If a client lets AI make a significant decision without meaningful human involvement, the client must tell people, hear their views, and offer human review and a way to challenge it. We help clients do this.
  • Prometheus can give practice feedback on delivery, such as eye contact, pace and filler words. It isn’t designed to infer emotions or to identify people from their face or voice. We advise clients not to base decisions about people on delivery feedback, because it can disadvantage some disabled and neurodivergent people.
  • AI can make mistakes, so its results should be checked before anyone relies on them.
06

Who we share it with

We share personal data only when we need to, and only with:

  • Service providers who run our website, email, calendars, video calls, files, accounts and AI tools, under contracts that require them to keep it safe and use it only for us. Our website is hosted by Cloudflare. We only use AI tools from business services that don’t train their models on what we send.
  • Professional advisers, such as accountants, lawyers and insurers, who are bound by confidentiality.
  • Authorities, regulators and courts, where the law requires it, or to establish, exercise or defend legal claims.
  • A buyer or successor, if all or part of our business is sold or reorganised, who must protect your data in the same way.

We never sell personal data, and we never share it with advertisers or data brokers.

07

International transfers

Some of our providers store or access data outside the UK, for example in the European Economic Area or the United States. When they do, we make sure your data stays protected. Either the destination is approved under UK law as giving adequate protection (such as the EEA, or US organisations certified under the UK Extension to the EU–US Data Privacy Framework), or we use the ICO’s International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses or another safeguard UK law recognises.

Ask us for a copy of the safeguards that apply to your data.

08

How long we keep it

DataHow long
Enquiries that don’t lead to workUp to 2 years after we last spoke, then deleted.
Client, contract and billing records6 years after the contract ends, to meet tax rules and deal with any legal claims.
Website security logsKept briefly by Cloudflare, our hosting provider. We don’t keep copies.
Marketing preferencesUntil you unsubscribe. After that we keep a minimal record so we don’t email you again.

When we no longer need data, we delete it or anonymise it so it can’t identify you.

09

Keeping it safe

We protect personal data with encryption in transit and at rest, multi-factor sign-in on our accounts and access only for the people who need it. No system is completely secure, but we work hard to prevent unauthorised access, loss or misuse. If a breach puts your data at risk, we’ll tell you and the ICO where the law requires.

10

Your rights

You have rights over your personal data. Some depend on the lawful basis we use, but you can always ask. Choose one below to start a request by email.

To use any of these rights, email contact@nexivius.com. It’s free, and we’ll reply within one month of your request, or of confirming your identity if we need to. Complex requests can take up to two months more, and we’ll tell you if so.

11

Complaints

If you’re unhappy with how we’ve handled your data, please tell us first at contact@nexivius.com. We’ll acknowledge your complaint within 30 days, look into it and tell you the outcome.

You also have the right to complain to the Information Commissioner’s Office, the UK’s data protection regulator, at ico.org.uk/make-a-complaint or on 0303 123 1113. If you live in the EU, you can also contact your local data protection authority.

12

Cookies

This site doesn’t set cookies or store anything in your browser, and it doesn’t track you. Our cookie policy explains the security measures our hosting provider may use.

13

Children

Our website and services are for organisations. The website isn’t aimed at children, and we don’t knowingly collect children’s data through it. Some clients use our products with under-18s, such as school students practising for interviews. The client is responsible for that data, and we build those products with the ICO’s Children’s code in mind.

14

Changes to this policy

We’ll update this policy when our services or the law change, and update the date and version at the top. If a change materially affects how we use your data, we’ll tell you directly where we can.

Version history

VersionDateChanges
1.04 October 2026First published.

Nexivius is the trading name of Nexivius Ltd, a private limited company registered in Scotland (company number SC904698).

Questions about your data?

Email us and a person on our team will reply.

contact@nexivius.com