Privacy

Privacy Policy

Public legal and informational pages should feel clear and lightweight, not like another landing-page hero.

Page content

Privacy Policy

Nexus Social
Effective date: 7 August 2026
Last updated: 7 August 2026

Contents

1. Introduction

This Privacy Policy explains how NEXUS SENTRY LTD ("Nexus Sentry", "we", "us", "our") collects, uses, stores, shares and protects personal data when you use Nexus Social (the "Service"), the social media management platform available at nexussocial.uk.

The Service allows you to connect your own social media accounts and pages, create and schedule content, publish that content to those accounts, review performance information, collaborate with colleagues, and use optional AI-assisted content tools.

We are the data controller for the personal data described in this policy, except where we act as a data processor on behalf of a business customer, as explained in section 4.

This policy should be read together with our Terms and Conditions.

Our details

  • Legal entity: NEXUS SENTRY LTD
  • Company number: 14957041
  • Incorporated: 23 June 2023, England and Wales
  • Company type: Private limited company
  • Registered office: 124 City Road, London, England, EC1V 2NX
  • ICO registration: ZC189098
  • Privacy enquiries: privacy@nexussentry.uk
  • Data protection contact: dpo@nexussentry.uk
  • General support: support@nexussentry.uk

We are established in the United Kingdom and process personal data in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and, where applicable to users in the European Economic Area, the EU GDPR.

2. Summary

We collect the information you give us to run your account, the information the social platforms give us when you choose to connect an account, and basic technical information about how the Service is used.

We never sell your personal data or your social platform data. We do not share it with data brokers, advertising networks or monetisation services.

We only ask the social platforms for the permissions we need to publish and manage the content you ask us to publish.

Access tokens are stored so we can act on your instructions, and are deleted as soon as you disconnect the account.

We do not use your content, your prompts or your social platform data to train any artificial intelligence model, and our AI providers are contractually prevented from doing so.

You can export or delete your data at any time from within the Service, or by emailing privacy@nexussentry.uk.

3. Who this policy applies to

This policy applies to account holders, meaning individuals and businesses who register for and use the Service; to team members invited into a workspace by an account holder; to visitors who browse our public website, blog or support pages without an account; and to affiliates participating in our referral programme.

It also describes how we handle information about third parties whose data appears in the Service, for example the names and profile images of pages you administer, or the public engagement data returned by a social platform.

4. Controller and processor roles

We act as the data controller for your account registration, billing, security and support, and for our website, marketing communications and analytics.

We act as a data processor, on the instructions of you or your organisation, for the content you create, schedule and publish through the Service, and for data retrieved from your connected social accounts. Where a business customer creates a team workspace, that customer is the controller and we are the processor.

Where we act as a processor, our processing is governed by our Data Processing Agreement, which forms part of the Terms and Conditions. Business customers may request a signed copy at privacy@nexussentry.uk.

5. Personal data we collect

5.1 Information you provide directly

  • Account identity: your name, username, email address, password (stored only as a salted hash), profile picture, locale and timezone. We hold this to create and secure your account.
  • Security data: your two-factor authentication secret and recovery codes, session tokens, "remember me" tokens and password reset tokens. We hold this to authenticate you and protect your account.
  • Subscription data: your selected plan, plan start and expiry dates, credit balance and top-up history, and any coupon codes redeemed. We hold this to provide the plan you have paid for.
  • Billing data: billing name, billing address, country, VAT or tax identifier, invoice history and transaction references. We hold this to take payment and meet UK tax obligations.
  • Content: posts, captions, campaigns, labels, comments, drafts, scheduled items, bulk upload spreadsheets, watermarks and RSS feed URLs. This is the core function of the Service.
  • Media: images, videos and documents you upload to the media library, along with file names, sizes, dimensions, formats and any notes you add.
  • Team data: team names, invitations, member roles, internal messages, post comments and approval decisions, used to run collaborative workspaces.
  • Support data: support tickets, their category and labels, message contents, and any attachments or screenshots you send.
  • Affiliate data: your referral code, referred users, commission balance, withdrawal requests and payout details.

We do not ask you for special category data, meaning data about health, race, religion, political opinions, biometrics, genetics, sex life or sexual orientation, and you should not upload it to the Service unless it is content you are lawfully entitled to publish.

5.2 Information we receive from connected social platforms

When you choose to connect a social media account, the platform asks you to authorise specific permissions. Only after you approve does the platform return data to us. The exact data varies by platform and is set out in section 6, but generally includes:

  • Your platform user or page identifier.
  • The account or page display name, username or handle, and profile picture.
  • The list of pages, business accounts or organisations you administer, so you can choose which to connect.
  • An access token and, where the platform issues one, a refresh token, together with the permissions granted and the token's expiry.
  • The identifier and permalink of each post we published on your instruction, and whether it succeeded or failed.
  • Where you have enabled it and the platform permits it, aggregate performance metrics for content published through the Service.

We do not request, collect or store your social media passwords, your private or direct messages, your friends, followers or connections lists as personal records, contact lists or address books, location data beyond what you deliberately attach to a post, or any data about people who have not interacted with the accounts you administer.

5.3 Information collected automatically

  • Technical data: IP address, browser type and version, operating system, device type, screen size and referring page, kept for 90 days in server logs.
  • Audit trail: security-relevant actions such as logins, permission changes, account connections and disconnections and deletions, recorded with the acting user, timestamp, route, IP address and user agent, kept for 12 months.
  • Session data: session identifier, authentication state and last activity time, kept until the session expires or you log out.
  • Delivery data: whether an email we sent was delivered, and any bounce or complaint notices, kept for 12 months.
  • Diagnostics: error messages, stack traces and failed background job records, kept for 30 days.

We use first-party cookies and equivalent storage as described in section 13.

5.4 Information from other sources

Payment processors confirm whether a payment succeeded, the last four digits and brand of the card, and the billing country. We never receive or store full card numbers.

If you sign up through an affiliate link, we record which referral code was used.

Where CAPTCHA is enabled on registration or login, the provider returns a risk score for the attempt.

6. Platform-specific disclosures

This section describes exactly what we obtain from each social platform, why, and what we do with it. In every case, the data is obtained only after you complete that platform's own authorisation flow and explicitly grant the listed permissions, and it is used only to provide the Service to you.

6.1 Meta, covering Facebook Pages and Instagram

We use the Facebook Login for Business and Instagram Graph API products.

Permissions we request:

  • pages_show_list, to display the list of Pages you administer so you can choose which to connect.
  • pages_read_engagement, to read the connected Page's name, profile picture and the basic engagement data shown in your dashboard.
  • pages_manage_posts, to create, schedule, publish and delete posts on the Page you connected, on your instruction.
  • business_management, to identify the Business Portfolio a Page or Instagram account belongs to, so the correct assets are listed.
  • instagram_basic, to read the connected Instagram Business or Creator account's identifier, username, profile picture and media.
  • instagram_content_publish, to publish images, videos, carousels, Reels and Stories to the connected Instagram account, on your instruction.
  • email and public_profile, to identify you at sign-in and match the authorisation to your Nexus Sentry account.

What we store: the Page or Instagram account identifier, name, username and profile picture URL, the Business Portfolio identifier where returned, the access token with its granted permissions and expiry, and the identifier and permalink of each post we publish for you.

What we do with it: we publish only the content you create or schedule. We display your connected assets and their published content back to you inside your own workspace. We do not display your Meta data to any other Nexus Sentry customer.

Our commitments to Meta users, in line with the Meta Platform Terms and Developer Policies:

  • We only request permissions necessary for the features you use, and we request them at the point you connect an account.
  • We do not sell, licence or rent Platform Data, and we do not transfer it to data brokers, advertising networks, ad exchanges, data management platforms, monetisation services or any similar intermediary.
  • We do not use Platform Data to build or enrich user profiles, to make eligibility decisions about people, or for surveillance of any kind.
  • We do not use Platform Data to train machine learning or AI models.
  • We keep Platform Data only for as long as needed to provide the Service, and we delete it when you disconnect the account, close your account, or ask us to.
  • We honour Meta's data deletion requirements, as set out in section 12.
  • Access tokens are never exposed in our interface, our logs or our API responses.

6.2 X, formerly Twitter

We use the X API v2 with OAuth 2.0.

Scopes we request:

  • users.read and users.email, to identify the connected X account and display its handle and profile picture.
  • tweet.read, to read back posts published through the Service and confirm their status.
  • tweet.write, to publish and delete posts on your instruction.
  • media.write, to upload images and video attached to your posts.
  • offline.access, to obtain a refresh token so scheduled posts can be published without asking you to reconnect.

What we store: your X user identifier, username, display name and profile picture URL, the access and refresh tokens with their scopes and expiry, and the identifier and permalink of each post we publish for you.

Our commitments to X users, in line with the X Developer Agreement and Policy:

  • X Content obtained through the API is displayed only to the user who connected the account and to the team members that user has invited into their own workspace.
  • We do not sell, rent or sub-licence X Content, and we do not provide it to data brokers, advertisers or any third party for their own purposes.
  • If content is deleted, made private, made protected or otherwise becomes unavailable on X, we delete or cease displaying our stored copy of it. Where we cannot detect this automatically we act on notification.
  • We do not match X Content or X user data with data from off-X sources except where the user has expressly consented.
  • We do not use X data for surveillance purposes, nor do we provide it to any government or law enforcement body for such purposes, other than as compelled by valid legal process.
  • We do not use X data to train machine learning or AI models.

6.3 LinkedIn

We use the LinkedIn Share on LinkedIn and Community Management products.

Scopes we request: openid, profile and email to identify you; w_member_social to post as you; and, for organisation pages, r_organization_social, w_organization_social and rw_organization_admin to list the organisations you administer, publish to them, and read back what was published.

What we store: your member or organisation URN, name and profile picture URL, the access token with its scopes and expiry, and the identifier of each post we publish for you.

6.4 TikTok

We use the TikTok Content Posting API and Login Kit.

Scopes we request: user.info.basic and user.info.profile to identify and display the connected account; user.info.stats to show follower and engagement counts where you enable it; and video.upload and video.publish to upload and publish videos on your instruction.

What we store: your TikTok open identifier, display name and avatar URL, the access and refresh tokens, and the identifier of each video published through the Service.

Videos you schedule are processed on our servers, including validation and, where you have configured it, watermarking, before being transferred to TikTok. TikTok's own review and posting rules apply to everything published.

7. How we use personal data, and our legal bases

We create and administer your account, publish and schedule your content, retrieve performance information for your connected accounts, take payment and manage plans and credits, and operate the affiliate programme, all on the basis of performance of our contract with you. Taking payment and keeping the associated records is also a legal obligation.

We provide support, secure the Service, prevent fraud and abuse, maintain and improve the Service, and send service messages such as security alerts, billing notices and downtime notifications, on the basis of our legitimate interests in running a reliable and secure service, and in some cases performance of our contract with you.

We operate the optional AI features on the basis of performance of our contract with you, using only the prompt and context you submit.

We meet accounting, tax and other legal obligations, and retain what we need to establish, exercise or defend legal claims, on the basis of legal obligation and our legitimate interests.

We send marketing emails about our products on the basis of your consent, or where you are an existing customer, on the basis of our legitimate interests, and you may opt out at any time.

Where we rely on legitimate interests, we have carried out a balancing assessment and concluded that our interest does not override your rights and freedoms. You may object at any time, as described in section 11. Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.

8. Artificial intelligence features

The Service includes optional AI tools for drafting captions, generating and repurposing content, suggesting posting times, producing images and video, and reviewing drafts.

When you use an AI feature, the prompt you write, plus any context you attach such as a draft caption, a brand description or the account the post is for, is sent to a third-party AI provider over an encrypted connection, and the generated result is returned to you.

The providers we may use are OpenAI, Google (Gemini), Anthropic, DeepSeek and ElevenLabs. The provider used depends on the feature and on the model selected in your workspace settings.

  • AI features are optional. If you do not use them, no content is sent to an AI provider.
  • We use these providers under commercial API terms which prohibit them from using submitted data to train their models.
  • We do not send social platform access tokens, payment data or account credentials to any AI provider.
  • We do not send data obtained from Meta, X, LinkedIn or TikTok APIs to AI providers for model training, profiling or any purpose other than generating the output you requested.
  • We store a history of your prompts and generated outputs in your workspace for 12 months so you can reuse them. You can delete individual entries or the whole history at any time.

AI output is generated by a statistical model and may be inaccurate, outdated or unsuitable. You remain responsible for reviewing everything before it is published, as set out in clause 10 of the Terms and Conditions.

9. Who we share personal data with

We share personal data only where it is necessary, and only with the categories of recipient below. We never sell personal data.

9.1 Social platforms

When you instruct us to publish, we transmit the content and media to the relevant platform, meaning Meta, X, LinkedIn or TikTok. Once transmitted, that platform processes the content as an independent controller under its own privacy policy.

9.2 Service providers

  • Hosting and infrastructure providers, who run the application, database and file storage, located in the United Kingdom and the European Economic Area.
  • Payment processors, who take payment. Depending on the method you choose, these may include Stripe, PayPal, Paystack, Razorpay, Flutterwave, 2Checkout, CCAvenue, Instamojo, iyzico, PayTR, PayU, Paytm, SSLCommerz and YooMoney.
  • Email delivery providers, who send transactional and notification email.
  • AI providers, who power the optional AI features described in section 8.
  • URL shortening services, where you enable them, using your own account credentials. These may include Bitly, Rebrandly, Short.io, Shorte.st or TinyURL.
  • Anti-abuse providers, who verify CAPTCHA challenges at registration and login.
  • Error monitoring providers, who help us diagnose faults.

Every provider is engaged under a written contract that meets Article 28 of the UK GDPR, restricts them to our documented instructions, and requires appropriate security measures. A current list is available on request from privacy@nexussentry.uk.

9.3 Your own team

If you are part of a team workspace, other members can see the content, media, comments and approval history within that workspace, according to the role assigned to them by the workspace owner.

9.4 Webhooks and automation you configure

If you create an automation webhook or an API key, data about the events you selected is sent to the destination you specify. You are responsible for that destination and for anything it does with the data. Requests are signed so the receiver can verify them.

9.5 Legal and corporate disclosures

We may disclose personal data where we are required to do so by law, court order or a valid request from a competent authority, where necessary to establish, exercise or defend legal claims, or to protect the rights, property or safety of Nexus Sentry, our users or the public. If we are involved in a merger, acquisition or sale of assets, personal data may be transferred to the acquirer, who will remain bound by this policy or provide equivalent protection. We will notify you before this happens.

10. International transfers

Our primary infrastructure is located in the United Kingdom and the European Economic Area. Some providers, notably certain AI providers, payment processors and the social platforms themselves, process data outside the UK.

Where personal data leaves the UK, we rely on an adequacy regulation made by the UK Secretary of State, which covers the EEA and a number of other countries; on the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses; or on another lawful transfer mechanism recognised under the UK GDPR.

We also carry out a transfer risk assessment where required, and apply supplementary measures such as encryption in transit and restricted access. You may request details of the safeguards applied to a specific transfer at privacy@nexussentry.uk.

11. Your rights

Under the UK GDPR you have the right to:

  • Obtain confirmation that we process your data, and a copy of it.
  • Have inaccurate data corrected and incomplete data completed.
  • Have your data deleted where there is no continuing lawful basis to keep it.
  • Require us to restrict processing in certain circumstances.
  • Receive the data you provided in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible.
  • Object to processing based on legitimate interests, and to direct marketing at any time and without reason.
  • Withdraw consent where consent is the basis for processing.
  • Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects.

Most rights can be exercised directly in the Service. Your profile settings allow you to correct your details, export your data, disconnect social accounts and delete your account. For anything else, email privacy@nexussentry.uk.

We will respond within one month. If your request is complex or you have made several, we may extend this by up to two further months and will tell you why. There is no charge unless a request is manifestly unfounded or excessive. We may ask you to verify your identity before we act.

If you are unhappy with how we have handled your data, please tell us first so we can put it right. You also have the right to complain to the Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, telephone 0303 123 1113, ico.org.uk/make-a-complaint. If you are in the EEA, you may complain to your local supervisory authority instead.

12. Deleting your data and disconnecting accounts

12.1 Disconnecting a single social account

Go to Channels, select the account, and choose Disconnect. On disconnection we immediately and permanently delete the stored access token, refresh token, granted permissions and cached profile information for that account. Where the platform provides a token revocation endpoint, we also call it so the token is invalidated at source.

You may additionally revoke our access from the platform's own settings at any time:

  • Facebook: Settings, then Business Integrations.
  • Instagram: Settings, then Website Permissions, then Apps and Websites.
  • X: Settings, then Security and account access, then Apps and sessions, then Connected apps.
  • LinkedIn: Settings, then Data privacy, then Other applications, then Permitted services.
  • TikTok: Settings, then Security and permissions, then Manage app permissions.

If you revoke access at the platform, our stored token stops working, we detect the failure, and we purge the credential.

12.2 Deleting your whole account

Go to Profile, then Account, then Delete account, or email privacy@nexussentry.uk from the address registered to the account. We will:

  • Immediately revoke and delete every stored social platform token.
  • Delete your content, media library, scheduled posts, AI prompt history, team messages and support history within 30 days.
  • Remove your data from routine backups within a further 90 days, after which backups holding it will have been overwritten in the normal rotation.
  • Retain only what the law requires us to keep, principally billing and tax records kept for 7 years, along with anything needed to defend a legal claim.

12.3 Meta data deletion requests

We support Meta's data deletion requirements. If you remove our app from your Facebook or Instagram settings, Meta sends us a signed deletion request. We process it, delete the associated Platform Data, and return a confirmation URL and code so you can check the status. You can also make the request directly to us at any time.

13. Cookies and similar technologies

We use a small number of first-party cookies. We do not use advertising or cross-site tracking cookies, and we do not permit third parties to track you across other websites through our Service.

  • Session cookie. Keeps you signed in and maintains your session. Strictly necessary, lasting for the session or until you log out.
  • CSRF token. Protects against cross-site request forgery. Strictly necessary, lasting for the session.
  • "Remember me" cookie. Keeps you signed in between visits if you choose it. Lasts up to 12 months.
  • Preferences cookie. Stores your language, timezone and interface choices. Lasts up to 12 months.
  • CAPTCHA cookie. Distinguishes humans from automated abuse at sign-in. Strictly necessary, lasting for the session.

Session cookies are marked Secure, HttpOnly and SameSite, and are transmitted only over HTTPS.

Strictly necessary cookies do not require consent under the Privacy and Electronic Communications Regulations 2003. Where we deploy any non-essential cookie we will ask for your consent first, and you may change or withdraw it through the cookie banner or your browser settings. Blocking strictly necessary cookies will prevent you from signing in.

14. Data retention

We keep personal data only as long as we need it.

  • Account profile and settings: for the life of the account, then deleted within 30 days.
  • Social platform access and refresh tokens: until disconnection, revocation or account closure, then deleted immediately.
  • Cached social profile data such as name, handle and avatar: until disconnection, then deleted immediately.
  • Published post records and permalinks: 24 months, or until you delete them.
  • Scheduled, draft and failed posts: until you delete them, or 30 days after account closure.
  • Media library files: until you delete them, or 30 days after account closure.
  • Performance and insight data: 13 months.
  • AI prompt and generation history: 12 months.
  • Team messages, comments and approvals: for the life of the workspace, then 30 days.
  • Support tickets: 24 months after closure.
  • Security audit logs: 12 months.
  • Server and access logs: 90 days.
  • Error diagnostics and failed job records: 30 days.
  • Billing, invoice and tax records: 7 years, as required by UK law.
  • Marketing suppression list, holding minimal data so that we do not contact you again: indefinitely.
  • Backups: a rolling 90-day cycle, after which they are overwritten.

Where we are required to keep data for legal reasons, we restrict processing to that purpose alone.

15. Security

We apply technical and organisational measures appropriate to the risk.

The entire Service is served over HTTPS with TLS, with HTTP Strict Transport Security enabled and modern cipher suites only.

Passwords are stored only as salted, one-way hashes and are never recoverable. Two-factor secrets and recovery codes are encrypted. Social platform access and refresh tokens are held in a database that is not reachable from the public internet, accessible only to the application through a dedicated least-privilege database user, and are never displayed in our interface, written to our logs, or returned by our API.

Access inside the Service is controlled by role-based permissions. Administrative access to production systems is restricted to named personnel, protected by key-based authentication and multi-factor authentication, and logged.

Our network is hardened with a host firewall restricting inbound traffic to required ports, automated intrusion prevention against repeated authentication failures, and a database user scoped to the application only.

The application uses CSRF protection, parameterised database queries, output escaping, secure and HTTP-only session cookies, rate limiting on authentication endpoints, and holds secrets outside the public web root.

Two-factor authentication is available on all accounts and we strongly recommend enabling it.

Backups are encrypted, taken regularly and tested for restorability. Operating system, runtime and dependency updates are applied on a routine schedule and promptly for security releases.

We request only the minimum API permissions needed from each platform, and review them when features change.

No system can be guaranteed completely secure. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner's Office within 72 hours of becoming aware of it, and will notify you without undue delay where the risk is high.

You are responsible for keeping your password confidential, for using a unique password, and for telling us promptly at security@nexussentry.uk if you believe your account has been compromised.

16. Children

The Service is a business tool and is not intended for anyone under 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact privacy@nexussentry.uk and we will delete it. The social platforms impose their own minimum ages, which you must also meet.

17. Automated decision-making and profiling

We do not make decisions producing legal or similarly significant effects about you based solely on automated processing.

Some features involve automated processing that does not have such effects, for example suggesting a posting time based on historic engagement, or flagging an account for review where automated systems detect behaviour consistent with spam or abuse. Where an automated abuse signal would lead to suspension, a person reviews the case before the decision takes effect, and you may contest the outcome by contacting support@nexussentry.uk.

18. Marketing communications

We send service messages covering security alerts, billing notices, publishing failures, scheduled maintenance and material changes to these terms. These are necessary to the contract and cannot be opted out of while you hold an account.

We send marketing messages about product news and offers only with your consent, or to existing customers about closely related products in reliance on the soft opt-in permitted by the Privacy and Electronic Communications Regulations 2003. Every marketing email carries a one-click unsubscribe link, and you can change your preference at any time in your profile settings.

19. Third-party links

The Service contains links to third-party sites and platforms. We are not responsible for their content or privacy practices, and this policy does not apply to them. Read their policies before providing them with personal data. The main ones are:

20. Changes to this policy

We may update this policy to reflect changes to the Service, to our providers, or to the law. When we do, we will change the "Last updated" date and publish the new version at this address.

If a change materially affects how we use your personal data, we will give you at least 30 days' notice by email and, where the law requires it, ask for your consent before the change takes effect. Historic versions are available on request.

21. Contact us

NEXUS SENTRY LTD is registered in England and Wales, company number 14957041. ICO registration ZC189098.