Skip to main content
NexusTheoryContact
Legal

Privacy Policy

NexusTheory respects your privacy and is committed to protecting your personal data. This policy explains what we collect when you visit our website, contact us or work with us, why we collect it, who we share it with and the rights you have. It is written for the people we deal with in business: prospective and existing clients, suppliers, partners, candidates and visitors to our site.

Effective
Last updated

A plain-English summary. The full text below is what applies.

  • We are a business-to-business consultancy. Most of the personal data we hold is work contact information for people at client, prospect, supplier and partner organisations.
  • We collect what you give us (for example through the contact form), basic technical data generated when you visit the site, and limited information from public and professional sources.
  • We do not sell personal data. This site currently uses no analytics, advertising or third-party tracking cookies.
  • We are headquartered in the United Arab Emirates and also operate from the United Kingdom, so personal data moves between the two, protected by the safeguards described in the international transfers section.
  • Data we handle inside client systems during an engagement belongs to the client. We process it as their processor, under a written data-processing agreement, and this policy does not cover it.
  • You can ask us to access, correct, delete or stop using your data at any time by emailing privacy@nexustheory.com.
On this page
01

Who we are and what this policy covers

NexusTheory (we, us or our) is a digital transformation consultancy delivering solution architecture, design, engineering, cloud and applied-AI services to governments and enterprises, headquartered in Dubai, United Arab Emirates, with an office in London, United Kingdom. For the purposes of data-protection law, we are the controller of the personal data described in this policy.

This policy applies to personal data we collect and use when you:

  • visit our website at nexustheory.com (the Site);
  • contact us through the Site, by email, by telephone, at an event or through a social-media platform;
  • represent a client, prospective client, supplier, partner or other organisation we deal with in the course of our business;
  • receive marketing communications from us, such as insights or event invitations; or
  • apply to work with us.

We are subject to the United Arab Emirates Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (the UAE PDPL), together with the data-protection regimes of the UAE financial free zones where they apply to a particular engagement; the UK General Data Protection Regulation and the Data Protection Act 2018 (together the UK GDPR) in relation to our London office and the people in the United Kingdom we deal with; and the EU General Data Protection Regulation (the EU GDPR) where we offer services to, or monitor the behaviour of, people in the European Economic Area. Where those laws differ, we apply the standard that gives you the greater protection.

02

The personal data we collect

Personal data means any information that relates to an identified or identifiable individual. Depending on how you interact with us, we may collect and use the following categories:

  • Identity and contact data: your name, job title, employer or organisation, work email address, work telephone number and postal address, and the professional profile you make available to us.
  • Enquiry data: the subject and content of any message you send us through the contact form, by email or otherwise, together with the date and time you sent it.
  • Business relationship data: records of our correspondence, meetings and calls with you; proposals, contracts, statements of work and related commercial documents; billing and payment contact details; and notes we make about the requirements and preferences of the organisation you represent.
  • Technical data: the Internet Protocol (IP) address, browser type and version, operating system, device type, referring website, pages visited, and the date and time of each request, which our hosting infrastructure records automatically in server logs when you use the Site.
  • Marketing and preference data: your preferences about receiving communications from us, and records of what we have sent you and how you have interacted with it.
  • Recruitment data: if you apply to work with us, your CV, covering letter, employment history, qualifications, references, right-to-work documentation and interview notes.

We do not ask for, and do not want to receive, special-category personal data (such as information about health, religion, political opinions, ethnicity or trade-union membership) or data about criminal convictions through the Site. Please do not include it in enquiries. Where it is genuinely necessary for a recruitment process or an engagement, we will explain separately how we handle it.

The Site is aimed at businesses and public-sector organisations and is not directed at children. We do not knowingly collect personal data from anyone under the age of 18. If you believe we have done so, please contact us and we will delete it.

03

How we collect your data

  • Directly from you, when you fill in the contact form, email or call us, exchange business cards or connect with us on a professional network, attend a meeting or event, sign an agreement with us, or apply for a role.
  • Automatically, when you use the Site, through the server logs described above. See Cookies and similar technologies for how the Site uses cookies.
  • From your organisation or colleagues, for example when a client names you as a stakeholder, approver or billing contact for an engagement, or when someone introduces you to us.
  • From public and professional sources, such as your organisation's website, LinkedIn, published company registers, procurement portals and event delegate lists, where we use them to identify and research organisations we believe may benefit from our services.
  • From partners and referrers, including technology partners, professional advisers and existing clients who refer you to us.
04

How we use your data and our legal bases

Data-protection law requires us to have a lawful basis for each way we use personal data. Under the UK GDPR and EU GDPR the bases we rely on are: performance of a contract with you, or steps taken at your request before entering one; our legitimate interests (or those of a third party), provided your interests and fundamental rights do not override them; compliance with a legal obligation; and your consent, which you may withdraw at any time. Where the UAE PDPL applies, we rely on the equivalent lawful grounds it provides. The table below sets out our purposes, the data involved and the basis we rely on.

PurposeData usedLawful basis
Responding to enquiries, holding discovery conversations and preparing proposalsIdentity and contact; enquiry; business relationshipSteps taken at your request before entering a contract; legitimate interests (responding to people who contact us and developing our business)
Negotiating, delivering, managing and invoicing engagements, including day-to-day communication with client, supplier and partner personnelIdentity and contact; business relationshipPerformance of a contract; legitimate interests (delivering services to the organisation you represent and managing our commercial relationships)
Sending insights, event invitations and information about our services to business contactsIdentity and contact; marketing and preferenceLegitimate interests (promoting our services to organisations likely to be interested in them); consent where required by the UK Privacy and Electronic Communications Regulations or equivalent law
Operating, securing and improving the Site, and detecting and preventing abuse, fraud and security incidentsTechnicalLegitimate interests (running a secure and reliable website); compliance with legal obligations
Measuring how the Site is used, if and when we introduce analyticsTechnical; cookie identifiersConsent, obtained through a cookie banner before any non-essential cookies are set
Recruiting and assessing candidatesRecruitment; identity and contactSteps taken at your request before entering a contract; legitimate interests (assessing suitability for a role); compliance with legal obligations (for example, right-to-work checks)
Keeping business records, managing our finances and insurance, and complying with legal, regulatory, audit and tax requirementsAll categories, as relevantCompliance with legal obligations; legitimate interests (running our business responsibly)
Establishing, exercising or defending legal claims, and protecting our rights, property and peopleAll categories, as relevantLegitimate interests; compliance with legal obligations
Evaluating or completing a merger, acquisition, financing or sale of all or part of our businessAll categories, as relevantLegitimate interests (carrying out a business transaction)

Where we rely on legitimate interests, we have assessed that our use of your data is necessary for the purpose described and is proportionate, taking into account the reasonable expectations of a person in a business relationship with us. You may ask us for more information about that assessment, and you have the right to object as described in Your rights.

We do not use personal data to make decisions about you by automated means that have legal or similarly significant effects, and we do not profile individuals. We do not use personal data collected through the Site or in the course of our business relationships to train AI or machine-learning models.

05

Marketing communications

We may send occasional communications to business contacts about our insights, events and services where we believe they are relevant to your role. We rely on our legitimate interests to do this for corporate email addresses, and we obtain consent where the law requires it, for example for individual subscribers under the UK Privacy and Electronic Communications Regulations.

You can stop receiving marketing communications at any time by using the unsubscribe link in any email we send, or by emailing privacy@nexustheory.com. We will action your request promptly. Opting out of marketing does not affect communications relating to an engagement you or your organisation are involved in.

We do not sell, rent or trade personal data, and we do not share your details with third parties for their own marketing purposes.

06

Cookies and similar technologies

Cookies are small text files placed on your device by a website. They can be strictly necessary for the site to work, or used for analytics, personalisation or advertising.

At the date of this policy, the Site does not use analytics, advertising or third-party tracking cookies, and does not set any cookies that require your consent. Our hosting provider may set strictly necessary cookies, or use similar techniques, that are needed to deliver the Site securely, for example to protect against automated abuse. These do not track you across other websites.

If we introduce analytics or other non-essential cookies in future, we will update this section, explain the cookies we use and their purpose, and ask for your consent through a cookie banner before they are set, where the law requires it.

You can control cookies through your browser settings, including by blocking or deleting them. Blocking strictly necessary cookies may affect how the Site works.

07

Who we share your data with

We share personal data only where it is necessary for the purposes described in this policy, and only with the following categories of recipient:

  • Service providers that process data on our behalf, including providers of web hosting and content delivery, email and productivity tools, customer-relationship management, document management and e-signature, video conferencing, accounting and invoicing, cybersecurity and IT support, and recruitment platforms. Each of these providers is bound by a written contract that requires them to act only on our instructions, keep the data secure and confidential, and meet the requirements of data-protection law.
  • Our teams in Dubai and London, and any group company we may establish, so that we can deliver engagements across the United Kingdom, the European Union and the Gulf region.
  • Professional advisers, including lawyers, accountants, auditors, bankers and insurers, where they provide services to us.
  • Clients, partners and subcontractors involved in an engagement, to the extent needed to deliver it, for example when we share the names and roles of our delivery team or coordinate with a client's other suppliers.
  • Regulators, law-enforcement bodies, courts and other authorities, where we are required to do so by law, by a court order or by a valid request, or where disclosure is necessary to protect our rights, property or safety or those of others.
  • Buyers, investors and their advisers in connection with an actual or proposed merger, acquisition, financing or sale involving our business, subject to confidentiality obligations.

We will also share personal data with other third parties where you have asked us to, or have given your consent.

08

International transfers

We are headquartered in the United Arab Emirates and also operate from the United Kingdom, and some of the service providers we use store data in other countries, including the European Economic Area and the United States. This means that personal data we hold may be transferred to, and stored and accessed in, countries outside the one in which it was collected.

Neither the United Kingdom nor the European Commission has decided that the United Arab Emirates as a whole provides an adequate level of protection for personal data. Where we transfer personal data from the United Kingdom or the European Economic Area to the United Arab Emirates, or to any other country without an adequacy decision, we rely on appropriate safeguards recognised by the UK GDPR and EU GDPR: the UK International Data Transfer Agreement or the UK Addendum to the European Commission's Standard Contractual Clauses, or the Standard Contractual Clauses themselves, supported by a transfer risk assessment and by additional technical and organisational measures where needed.

Transfers between the United Kingdom and the European Economic Area take place under the adequacy decisions each has adopted in respect of the other. Transfers to service providers in the United States take place under the Standard Contractual Clauses or the International Data Transfer Agreement, or under the EU-US Data Privacy Framework and its UK Extension where the provider is certified.

Where the UAE PDPL applies, we transfer personal data out of the United Arab Emirates only to countries the UAE Data Office recognises as providing adequate protection, or under contractual safeguards, or with your consent or on another ground the UAE PDPL permits.

You can request a copy of the safeguards we rely on for a particular transfer by emailing privacy@nexustheory.com.

09

How long we keep your data

We keep personal data only for as long as we need it for the purposes described in this policy, including to satisfy legal, accounting, regulatory or reporting requirements, and to establish, exercise or defend legal claims. Our standard retention periods are:

DataRetention period
Enquiries that do not lead to an engagementUp to 24 months from our last contact with you, after which we delete or anonymise the enquiry.
Business relationship records for clients, suppliers and partnersFor the duration of the relationship and for 7 years after it ends, reflecting limitation periods for contractual claims and record-keeping obligations.
Marketing contact details and preferencesUntil you unsubscribe or ask us to stop, or until we have had no meaningful contact with you for 24 months, whichever is sooner. We keep a minimal record of any opt-out so that we can honour it.
Technical data in server logsUp to 12 months, unless a specific log is needed for longer to investigate a security incident.
Recruitment data for unsuccessful candidates6 months from the date of our decision, unless you agree to us keeping your details for future opportunities.

In some circumstances we anonymise personal data so that it can no longer be associated with you, in which case we may use that information indefinitely without further notice. When we no longer need personal data, we securely delete or destroy it.

10

How we protect your data

We apply technical and organisational measures appropriate to the risk to protect personal data against accidental or unlawful loss, alteration, disclosure or access. These include encrypting data in transit, restricting access to personal data to the people who need it for their role, protecting our business systems with multi-factor authentication, carrying out due diligence on the service providers we use, applying secure-development practices to the systems we build, and training our people in data protection and information security.

We have procedures for handling suspected personal-data breaches. Where a breach is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within the period the law requires and, where the risk is high, inform you as well.

No transmission of information over the internet, and no method of electronic storage, is completely secure. We cannot guarantee absolute security, but we work continuously to protect your data and keep our measures under review.

11

Data we process on behalf of clients

Many of our engagements involve building, migrating or operating systems that contain our clients' data, including personal data about their customers, citizens, employees or users. In those engagements our client determines the purposes and means of processing and is the controller; we act as their processor or, in some cases, as a sub-processor.

That processing is governed by the engagement contract and a written data-processing agreement, which set out the subject matter and duration of the processing, its nature and purpose, the types of personal data and categories of individuals, and the obligations we owe the client. Those obligations include confidentiality, security, assistance with individuals' rights and breach notification, restrictions on sub-processing and international transfers, and the return or deletion of data at the end of the engagement.

If you are an individual whose data is held in a system we build or operate for a client, that client's privacy notice explains how your data is used and how to exercise your rights. Please direct any request to the client. If a request reaches us directly, we will pass it to the client without undue delay and assist them in responding.

12

Your rights

Subject to certain conditions and exemptions, you have the following rights in relation to your personal data under the UK GDPR and EU GDPR. The UAE PDPL provides substantially similar rights.

  • Access: to be told whether we are processing your data and, if so, to receive a copy of it together with information about how we use it.
  • Rectification: to have inaccurate data corrected and incomplete data completed.
  • Erasure: to have your data deleted in certain circumstances, for example where it is no longer needed for the purpose for which it was collected.
  • Restriction: to require us to limit how we use your data in certain circumstances, for example while we verify its accuracy after you have contested it.
  • Portability: to receive data you have provided to us, which we process by automated means on the basis of your consent or a contract, in a structured, commonly used and machine-readable format, and to have it transmitted to another controller where technically feasible.
  • Objection: to object to processing based on our legitimate interests, in which case we will stop unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms. You have an absolute right to object to direct marketing.
  • Withdrawal of consent: to withdraw consent at any time where we rely on it, without affecting the lawfulness of processing carried out before withdrawal.
  • Automated decisions: not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. As explained above, we do not make decisions of that kind.

To exercise any of these rights, email privacy@nexustheory.com. We may need to ask for specific information to confirm your identity and to ensure that data is not disclosed to someone who has no right to receive it. We will respond within one month of receiving a valid request. If a request is particularly complex, or you have made several requests, we may extend that period by up to two further months and will tell you if so. We do not charge a fee unless a request is manifestly unfounded or excessive, in which case we may charge a reasonable fee or decline to act on it.

You also have the right to lodge a complaint with a supervisory authority. In the United Arab Emirates the relevant authority is the UAE Data Office, or the data-protection regulator of the relevant financial free zone where its law applies. In the United Kingdom it is the Information Commissioner's Office (ICO), which you can contact at ico.org.uk or on 0303 123 1113. In the European Economic Area you may complain to the supervisory authority in the member state where you live, work or believe an infringement has occurred. We would welcome the opportunity to address your concerns before you approach a regulator, so please contact us first.

13

Third-party websites and social media

The Site contains links to other websites, including those of technology partners, standards bodies and social-media platforms. We are not responsible for the privacy practices or content of those sites, and this policy does not apply to them. We encourage you to read the privacy notice of every website you visit.

If you interact with us on LinkedIn, X or YouTube, the platform's own privacy policy governs how it processes your data. We may see information you make available to us through those platforms, such as your public profile and any messages you send us, and we use it in accordance with this policy.

14

Changes to this policy

We keep this policy under review and may update it to reflect changes in our business, the services we use or the law. When we do, we will publish the revised version on this page and update the dates at the top. Where a change materially affects how we use your data and we hold contact details for you, we will notify you directly. Previous versions are available on request.

15

How to contact us

Questions, comments or requests relating to this policy or to your personal data should be sent to our privacy team at privacy@nexustheory.com. You can also write to us at our Dubai head office. For general enquiries, please use the contact page.

Please include enough detail for us to identify you and understand your request. If you are writing on behalf of someone else, we will ask for evidence that you are authorised to act for them.

Questions

To exercise any of your rights, ask about how we handle your data or raise a concern, contact our privacy team. We aim to respond to every request within one month.

NexusTheory

©2026 All Rights Reserved by NexusTheory