Where Nexim processes personal data on behalf of a customer, it acts as a data processor under Regulation (EU) 2016/679 (GDPR). Processing takes place on the customer’s documented instructions, under a data processing agreement, with confidentiality obligations on the people involved and with technical and organisational measures drawn from the controls of the certified ISO/IEC 27001:2022 management system.
Where Nexim processes personal data for its own purposes — a contact request, a contract, a supplier relationship — it acts as controller. What is collected, why, on which legal basis and for how long it is kept is set out in the privacy notice.
Sub-processors, where used, are engaged under the same obligations that bind Nexim, and changes are notified as the agreement and the Regulation require. Requests from data subjects that reach us in our role as processor are referred to the customer as controller; requests concerning data we hold as controller are handled under the privacy notice.
One caveat worth stating plainly: a certificate is not a substitute for your own assessment. Each certification states its scope, and the honest use of it is as evidence for your audit — which we will support with the documentation behind it — rather than as an answer to it.
Read the privacy notice