Nexus AI Consulting Limited — Privacy Policy

Notice: This Privacy Policy describes how Nexus AI Consulting Limited (the “Company” or “Nexus”) collects, uses, discloses, retains, transfers across borders, and protects personal data. By accessing the Company’s website, registering for the Services, or otherwise interacting with the Company, you acknowledge that you have read and understood this Policy. For data subjects who are registered Customers, this Policy operates in conjunction with the Company’s customer-verification standards and is incorporated by reference into the Terms of Service per ToS Section 8.


1. Purpose and Scope

1.1 Purpose

This Privacy Policy (the “Policy”) sets forth the standards by which the Company processes personal data in compliance with: (a) the Hong Kong Personal Data (Privacy) Ordinance (Cap. 486) (“PDPO”); (b) the Personal Information Protection Law of the People’s Republic of China (“PIPL”); and (c) any other applicable data protection law in the jurisdictions in which the Company operates.

1.2 Scope of Application

This Policy applies to three categories of data subjects: - (a) Website Visitors — natural persons who access the Company’s website (nexusaistart.com) prior to registration; - (b) Registered Customers — business entities and their authorized natural-person representatives who have completed the Company’s customer verification; and - (c) Refused Applicants — natural persons or entities whose applications were refused or withdrawn, whose data is processed per the Company’s verification-refusal standards.

1.3 Relationship to Other Documents

This Policy is a public-facing document complementing the Company’s internal customer-verification standards. Where this Policy overlaps with those standards (such as data retention, cross-border transfer architecture, and customer rights), the substantive standards are identical. This Policy is the authoritative public statement; the internal verification standards provide additional operational detail to registered Customers. The Cookie Policy is incorporated by reference for matters relating to cookies and similar tracking technologies.

The Company processes personal data in compliance with: - The Hong Kong PDPO and the six Data Protection Principles (DPP1-DPP6); - The PRC PIPL (including Articles 13, 17, 38-40, 44-50); - Applicable laws of the Hong Kong Special Administrative Region; and - Other applicable laws where data subjects or operations are located.


2. Information We Collect

The Company collects three categories of personal data, with the categories and specific data elements varying by data subject type.

2.1 Category A — Website Visitor Data

Collected from all visitors to the Company’s website prior to KYC registration: - IP address (and approximate geo-location derived from IP); - Browser User-Agent string and screen resolution; - Pages visited, time spent, referring URL, and exit URL; - Date and time of access; - Cookies and similar local-storage data (described in the Cookie Policy); - Contact-form submission contents (name, business email, country, business description); and - Other technical metadata necessary for the secure operation of the website.

2.2 Category B — KYC Data (Registered Customers)

Collected from Customers during and after verification, as part of the Company’s customer-verification process: - Entity identification: business registration certificate, articles of incorporation, ultimate beneficial owner (“UBO”) information, professional licence (for self-employed Customers); - Business authenticity evidence: under one of six pathways including formal qualifications, business records, industry identity, social credibility, historical transactions, or stated business purpose; - Service-commitment records: service-use commitment, prohibition commitment, and default-recovery provision; - Authorized representative information: identification document, contact information, and authorization-of-signatory evidence; and - Communication records between the Company and the Customer relating to verification matters.

2.3 Category C — Service Operational Data (Registered Customers)

Generated through the Customer’s use of the Services: - Dashboard activity logs: login timestamps, configuration changes, support-ticket submissions; - Bridge Equipment heartbeat records: uptime, firmware version, traffic-ceiling triggers, geo-location of equipment (per KYC-disclosed address); - Traffic metadata (not the substantive content of communications): aggregate bandwidth use by time window, protocol categories, port categories, IP-blacklist triggers; - R1 behavioural audit logs: as defined in the Company’s internal verification standards and the AUP; - Payment records: transaction timestamps, amounts, payment method category (without storing complete card numbers, which are handled by PCI-DSS-compliant payment processors); and - Support and communication records: emails, tickets, escalation history.

2.4 Information We Do Not Collect

The Company expressly does not collect: - The substantive content of communications transmitted via the Services (the Company does not inspect, store, or analyse the content of Customer traffic); - Personal information of the Customer’s end users; - Sensitive personal information categories (per PIPL Article 28): biometric data, religious beliefs, specific identity (e.g., sexual orientation), medical or health data, financial-account-number content beyond payment-method category, location-tracking data beyond KYC-disclosed equipment address, and personal information of minors; - Personal information of any natural person under eighteen (18) years of age (the Services are B2B-only and KYC verifies the legal age of authorized representatives); and - Data through unlawful means or in excess of what is reasonably necessary for the purposes set forth in Section 3.


3. How We Use Your Information

The Company uses personal data only for the following purposes, in alignment with the Company’s internal verification standards (Data Protection Principle 3 — Purpose Limitation):

3.1 Eligibility Verification

Confirming Customer identity, business authenticity, and ongoing compliance per the Company’s customer-verification standards.

3.2 Service Operation

Provisioning Bridge Equipment, operating the Control Plane and dashboard, monitoring heartbeat and traffic metadata for service-quality and capacity management, and providing customer support.

3.3 Regulatory Compliance

Satisfying obligations under the applicable telecommunications regulatory framework, HK PDPO, PRC PIPL, anti-money-laundering law, and other applicable regulatory requirements.

3.4 Lawful Authority Cooperation

Responding to lawful requests from competent authorities per Section 5.3 of this Policy, including the provision of supporting evidence such as R1 logs, heartbeat records, IP-blacklist database entries, and behavioural audit trails.

3.5 Fraud Prevention and Abuse Detection

Maintaining IP blacklists, analysing behavioural patterns to detect abuse of the Services or violations of the AUP, and protecting upstream-provider relationships.

3.6 Customer Communication

Sending account-related notifications, service updates, security alerts, billing reminders, and responding to support inquiries.

3.7 Uses We Do Not Engage In

The Company expressly does not: - Sell, rent, or trade personal data to third parties; - Use personal data for behavioural-advertising or marketing-profiling purposes (except direct marketing of the Company’s own Services to existing Customers, subject to opt-out per Section 9.1); - Use personal data to train artificial-intelligence models (the Company does not operate AI-model-training business lines); - Use personal data for purposes unrelated to the Services or unauthorized by this Policy or the Company’s customer-verification standards.


The Company processes personal data on the following legal bases, in alignment with PIPL Article 13 and HK PDPO DPP1:

The Customer’s express consent provided during the KYC process, including consent to cross-border data transfer per Section 6.

4.2 Contract Necessity

Processing necessary to perform the Service Documents (Terms of Service, Order Form, Master Lease).

Processing necessary to satisfy the applicable telecommunications regulatory framework, HK PDPO, PRC PIPL, anti-money-laundering law, and tax-record-retention obligations.

4.4 Vital Interests

In limited circumstances, processing necessary to protect the vital interests of the Company, the Customer, upstream providers, or other natural persons (e.g., preventing imminent harm from abuse of the Services).

4.5 Legitimate Interests

Processing necessary for the Company’s legitimate interests in fraud prevention, security monitoring, and service-quality assurance, balanced against the data subject’s rights and reasonable expectations.

Where processing is based on consent, the Customer may withdraw consent at any time per Section 9.1, subject to the Company’s right to retain data necessary for regulatory or contractual purposes.


5. How We Share Your Information

The Company does not sell personal data. Sharing is limited to the following categories:

5.1 Service Providers

The Company shares personal data with the following categories of service providers, each bound by a data-processing agreement incorporating safeguards equivalent to the PDPO and PIPL standards: - Upstream residential-IP providers: traffic metadata (without communication content) and Bridge Equipment identifiers necessary for supply-chain compliance; - VPS service provider: dashboard and Control Plane hosting infrastructure; - Payment processor: payment transaction processing (PCI-DSS-compliant; the Company does not retain complete card numbers); - Email delivery service: for transactional and operational email; - Customer-support and legal-counsel partners: as needed, subject to confidentiality and data-protection obligations.

5.2 Affiliated Compliance-Review Function

KYC documentation is reviewed by the Company’s affiliated compliance-review function per the cross-border architecture described in Section 6.1.

5.3 Lawful Authority Requests

The Company shall cooperate with lawful authority requests, including from the Hong Kong courts, the applicable telecommunications regulator, the Privacy Commissioner for Personal Data (PCPD), and the competent law-enforcement and judicial authorities of any relevant jurisdiction. Cooperation includes provision of: - R1 behavioural audit logs; - Bridge Equipment heartbeat and configuration records; - IP-blacklist database entries; - Behavioural audit trails; - Service-commitment records; - Other supporting evidence as required by lawful process.

The Company will not voluntarily provide non-public Customer data absent lawful process, except where Customer consent has been provided or where vital interests are involved.

5.4 Business Transfers

In the event of a merger, acquisition, reorganization, or sale of substantially all assets, personal data may be transferred to the receiving entity, which shall be bound by obligations equivalent to those in this Policy. Customers will be notified of any such transfer.

5.5 Aggregated or De-Identified Data

The Company may share aggregated or de-identified data (data not reasonably identifiable to any individual) for industry-research, operational-improvement, or public-reporting purposes.

Any other sharing requires the Customer’s express prior consent.


6. Cross-Border Data Transfer

The Company’s Services involve cross-border processing of personal data. The data flow architecture, legal basis, recipient identity, and Customer rights are described in this Section 6.

6.1 Data Flow Architecture

This architecture is restated here for public-facing transparency:

    1. The Customer uploads KYC documentation to the dashboard, which is hosted on a Virtual Private Server (the “VPS”) deployed in an overseas jurisdiction;
    1. The documentation is stored temporarily on the VPS solely for verification purposes;
    1. The Company’s authorized compliance-review personnel complete identity, business-authenticity, and compliance verification;
    1. Upon verification, the documentation is backed up to a secure long-term storage system, isolated from external networks, located in a relevant jurisdiction for long-term retention; and
    1. The temporary VPS copy is purged at the conclusion of verification and is not retained on the VPS for long-term storage.

6.2 Design Principles

  • Data minimization — the VPS does not retain KYC data for long-term storage, reducing cross-border exposure surface;
  • Customer privacy protection — long-term storage is isolated from external networks to prevent leakage; and
  • Regulatory traceability — the long-term backup is available for regulatory inspection, dispute resolution, and lawful law-enforcement cooperation.

This cross-border processing relies on: - The Customer’s express consent provided during the KYC process (PIPL Article 39); - A data-processing agreement between the Company and its infrastructure service providers incorporating safeguards equivalent to the PDPO and applicable data protection standards; - The cross-border transfer mechanism prescribed by applicable data protection law, appropriate to the Company’s current operating scale; and - HK PDPO Section 33 conditions for cross-border transfer (consent provided / equivalent protection in recipient jurisdiction / contract necessity / lawful authority requirement, as applicable).

6.4 Recipient Identity Disclosure

This Policy is the public-facing statement of the Company’s cross-border data practices. In keeping with PIPL Article 39, the specific identity and contact details of each overseas recipient and any affiliated compliance-review function — together with the purpose, method, and categories of data transferred — are disclosed in full to each Customer at the point of registration, within the data-processing terms the Customer reviews and consents to before any cross-border transfer occurs. In summary, the recipients fall into the following categories: - Affiliated compliance-review function: performs identity, business-authenticity, and compliance verification; - Infrastructure service providers: provide overseas hosting for the dashboard and Control Plane; - Purpose of processing: eligibility verification, service operation, regulatory cooperation, anti-fraud, and customer communication; - Categories of data: as described in Section 2.2 (Category B KYC Data); and - Customer rights: as described in Section 9. The Company reserves the right to change infrastructure providers or jurisdictions, with prior notice to active Customers and updated disclosure in the registration data-processing terms.

6.5 Customer Rights in Cross-Border Context

Cross-border processing does not diminish the Customer’s rights under this Policy or applicable law. The Customer retains all rights set forth in Section 9 with respect to data processed across borders. Requests may be submitted to privacy@nexusaistart.com.


7. Data Retention

The Company retains personal data only for as long as necessary for the purposes for which it was collected, in compliance with HK PDPO DPP2 and PIPL Article 47.

7.1 Retention Schedule

Data Category Retention Period Legal Basis
Entity identification (KYC) Seven (7) years from termination HK Companies Ordinance record-retention / PIPL Article 47
Business authenticity evidence Seven (7) years from termination Same as above
Service-commitment records Seven (7) years from termination Anti-fraud and dispute resolution
Authorized representative information Seven (7) years from termination KYC integrity
Service operational data (traffic metadata) twelve (12) months from generation Telecommunications regulatory requirement and minimization
Payment records Seven (7) years from transaction HK Inland Revenue Ordinance / anti-money-laundering
R1 behavioural audit logs twenty-four (24) months from generation Fraud prevention and lawful authority cooperation
Website visitor logs ninety (90) days from collection Security operation and analytics
Cookies Per Cookie Policy Consent withdrawal terminates immediately
Contact-form submissions twenty-four (24) months from submission Service inquiry response and follow-up
Refused-applicant records five (5) years from refusal Prevention of re-application by malicious actors

7.2 Post-Termination Treatment

On termination of the service relationship: - Identity and KYC records are retained until the expiry of the applicable retention period above; - Service operational data may be deleted earlier upon written request from the Customer, subject to the Company’s retention of the minimum necessary data for legal-obligation purposes; and - After the retention period expires, data is securely deleted or anonymized.

7.3 Refusal-Database Entries

The Company retains records of refused applicants in an internal database to prevent circumvention by malicious actors. Such records contain the minimum necessary identifiers (entity name, registration number, UBO name) and do not retain full verification documentation beyond the retention period in Section 7.1.


8. Data Security

8.1 Technical Safeguards

  • Encryption at rest (AES-256 or equivalent) for KYC documentation and other sensitive data;
  • Encryption in transit (TLS 1.3 with HSTS for web-facing endpoints);
  • Role-based access control with multi-factor authentication for administrative access;
  • Activity logs for administrative access, retained per Section 7;
  • Network isolation: long-term storage is physically and logically isolated from external networks;
  • Regular vulnerability scanning and security review.

8.2 Organizational Safeguards

  • Confidentiality obligations imposed on employees, contractors, and the compliance-review function;
  • Data-access minimization principle (least privilege);
  • Immediate revocation of access upon termination of employment or engagement;
  • Annual data-protection training for personnel with data-access privileges.

8.3 Incident Response

In the event of a personal-data breach or unauthorized access: - (a) the Company will investigate and contain the incident promptly; - (b) affected Customers and data subjects will be notified within seventy-two (72) hours of confirmation, where the incident is reasonably likely to result in harm; - (c) the Hong Kong PCPD and other applicable regulators will be notified where required by law; and - (d) corrective and preventive measures will be documented and implemented.

8.4 No Absolute Guarantee

While the Company implements reasonable safeguards, no system can be guaranteed to be one-hundred-percent secure. The Company does not warrant absolute security and disclaims liability to the fullest extent permitted by applicable law (per ToS Section 10).


9. Your Rights

This Section 9 mirrors the Company’s internal customer rights standards for registered Customers and extends those rights to Website Visitors and Refused Applicants. The Company will respond to verified requests within forty (40) calendar days per the PDPO standard.

9.1 Rights Available to All Data Subjects

Right Description Legal Basis
Right of Access Obtain confirmation and a copy of personal data held about you PDPO DPP6 / PIPL Article 44
Right of Correction Correct inaccurate or incomplete data PDPO DPP6 / PIPL Article 46
Right to Withdraw Consent Withdraw consent to processing based on consent (with consequence) PIPL Article 15
Right to Complain File a complaint with HK PCPD or other competent authority PDPO Section 37
Direct-Marketing Opt-Out Opt out of direct marketing without affecting Services PDPO Section 35G
Right to Data Portability Receive data in a structured, machine-readable format (limited cases) PIPL Article 45
Right to Erasure / Deletion Request deletion in defined circumstances PIPL Article 47
Right to Explanation Receive explanation of automated decision-making affecting you PIPL Article 24 (not currently applicable; the Company does not engage in automated decision-making with legal effect)

9.2 How to Exercise Your Rights

Submit requests to privacy@nexusaistart.com with the following: - Website Visitors: email address used in any prior interaction with the Company, approximate timestamp of interaction, and contact-form reference (if applicable); - Registered Customers: Customer identifier and verification of the authorized representative’s identity; - Refused Applicants: applicant identifier and verification of identity.

9.3 Response Timeline

  • The Company will acknowledge receipt within seven (7) business days;
  • The Company will respond substantively within forty (40) calendar days of receipt of a verified request, per the PDPO standard;
  • For complex requests, the Company may extend the response period by an additional thirty (30) days with written explanation of the reason for the extension.

9.4 Limitations on Rights

  • Withdrawal of consent may necessitate termination of the Services where consent is the legal basis for processing necessary to the service relationship;
  • Requests for deletion are subject to the Company’s right to retain data necessary for: regulatory compliance (e.g., 7-year retention under HK law); lawful authority cooperation; legal-defence; or contractual obligation;
  • The Company may decline manifestly unfounded or excessive requests, or charge a reasonable fee for repetitive requests, per the standard permitted by applicable law.

9.5 Complaints to HK PCPD

Data subjects who are dissatisfied with the Company’s response may complain to the Hong Kong Privacy Commissioner for Personal Data: - Website: https://www.pcpd.org.hk/ - The PCPD complaint process is the Company’s preferred external escalation pathway under HK PDPO Section 37.


10. Cookies and Tracking

The Company’s website uses cookies and similar technologies. Detailed information is provided in the Cookie Policy (incorporated by reference into this Policy).

In summary: - The Company uses only strictly-necessary cookies (session token and CSRF protection) at present; - The Company does not currently use third-party analytics cookies (such as Google Analytics) or behavioural-advertising cookies; - The Company does not engage in cross-site tracking; - The Customer may disable cookies in the browser, which may affect login and authenticated-session functionality; - The Cookie Policy provides specific cookie details, third-party provider relationships, and consent-management mechanisms.


11. Children’s Privacy

The Services are intended for business-to-business use only. The Company: - Does not knowingly collect personal information of any natural person under eighteen (18) years of age; - Verifies the legal age of authorized representatives during KYC; - Promptly deletes any information identified as relating to a person under eighteen (18) years of age upon discovery; and - Maintains a policy of refusing applications from natural persons unable to enter into a binding business contract under applicable law.

If a parent or guardian believes their child has provided personal information to the Company, please contact privacy@nexusaistart.com.


12. Modifications to This Policy

12.1 Modification Right

The Company may modify this Policy at any time to reflect changes in: applicable law; the Company’s services; technical infrastructure; or best practices.

12.2 Notice of Material Changes

Material changes will be communicated to active Customers with at least fourteen (14) days’ prior notice via the registered email address, consistent with ToS Section 2.3. Website visitors will be notified via a prominent notice on the website.

12.3 Termination Right

Where a material change reduces Customer-protective provisions, the Customer may terminate the subscription without penalty within thirty (30) days following the effective date of the change, per ToS Section 2.3.

12.4 Version History

Substantive versions of this Policy are archived. Prior versions are available upon request to privacy@nexusaistart.com.


13. Contact and Governing Law

13.1 Privacy Contact

For all privacy and data-rights matters: - Email: privacy@nexusaistart.com - Postal address: Room 1508, 15/F, Argyle Centre Tower 2, 625 Nathan Road, Mong Kok, Kowloon, Hong Kong - Subject-line convention: “Privacy — [Request Type]” (e.g., “Privacy — Access Request”)

13.2 General Contact

For non-privacy inquiries: support@nexusaistart.com

13.3 External Complaint Authority

  • Hong Kong Privacy Commissioner for Personal Data: https://www.pcpd.org.hk/
  • The competent data-protection authority of any other relevant jurisdiction, as applicable.

13.4 Governing Law

This Policy is governed by and construed in accordance with the laws of the Hong Kong Special Administrative Region of the People’s Republic of China.

13.5 Jurisdiction

The Hong Kong courts have exclusive jurisdiction over disputes arising under this Policy. Privacy-related complaints may additionally be raised with the Hong Kong Privacy Commissioner for Personal Data.

13.6 Language

This Policy is executed in English. The Chinese Summary below is provided for convenience only; in the event of conflict, the English text controls.


中文摘要(Chinese Summary — Non-Binding Reference)

本中文摘要仅供参考,与英文条款发生歧义时以英文条款为准。

文档定位

本《隐私政策》(Privacy Policy)是 Nexus AI Consulting Limited 关于个人数据处理的对外公开声明,与服务条款、可接受使用政策、Cookie 政策共同构成对外透明层。

适用三类主体

    1. 网站访客(pre-KYC)
    1. 注册客户及法人代表
    1. 申请被拒申请人

关键内容摘要

1. 数据收集(§2)三类: - A 类网站访客:IP / UA / 访问行为 / cookie / 联系表单内容 - B 类 KYC 数据:主体 + 业务真实性(6 路径 A-F)+ 服务承诺 + 法人代表 - C 类服务运行:dashboard 操作 / 心跳 / 流量元数据(不含通信内容)/ R1 行为日志 / 支付记录元数据

不收集:通信内容 / 终端用户信息 / 敏感个人信息 / 未成年人信息

2. 使用目的(§3)六类:资格核验 / 服务运营 / 监管合规 / 配合执法 / 反欺诈 / 客户沟通

绝不:出售数据 / 行为画像营销 / 训练 AI 模型 / 与服务无关用途

3. 法律基础(§4):HK PDPO DPP1 + PIPL §13 五类(同意 / 合同必要 / 法定义务 / 重大利益 / 合法利益)

4. 共享范围(§5):上游 IP 供应商 / 基础设施服务商 / 支付商 / 邮件商 / 关联合规审核职能 / 配合执法 / 业务转让 / 经客户同意。不出售给第三方

5. 跨境数据传输(§6):5 步数据流(dashboard → VPS 临时存储 → 授权合规审核人员核验 → 相关司法辖区内安全长期存储 → VPS 副本清理)。法律基础:客户明示同意 + 适用数据保护法的跨境传输机制 + HK PDPO §33。境外接收方的具体身份与联系方式,于客户注册时在其审阅并同意的数据处理条款中完整披露。

6. 数据保留(§7):身份资料 7 年 / 用量元数据 12 月 / 支付 7 年 / R1 日志 24 月 / 访客日志 90 日 / cookie 详见 Cookie Policy。

7. 数据安全(§8):AES-256 加密存储 / TLS 1.3 / 角色分级 + MFA / 长期存储外网物理隔离 / 定期漏洞扫描。事件响应 72 小时通知。

8. 客户权利(§9)8 项:访问 / 更正 / 撤回同意 / 投诉 / 直销退订 / 数据可携 / 删除 / 自动决策解释(公司目前不进行自动决策)。响应时限 40 日(PDPO 标准)。

9. Cookie(§10):详见 Cookie Policy,无 GA 等分析 cookie,无跨网站追踪。

10. 未成年人保护(§11):B2B 服务唯一。KYC 验证法定代表年龄。

11. 修改(§12):重大修改提前 14 日邮件通知 + 网站显著公告;削减保护性条款时 30 日内无责终止权(与 ToS §2.3 一致)。

12. 联系方式(§13):privacy@nexusaistart.com / 投诉 PCPD https://www.pcpd.org.hk/ / HK 法院专属管辖。

客户权利行使方式

请发邮件至 privacy@nexusaistart.com,主题写”Privacy — [请求类型]“。公司将在 7 日内确认 + 40 日内实质回复。

客户权利一致性

本政策 §9 规定的客户权利与公司内部验证标准在实质标准上一致。本政策是对外公开层(含网站访客),内部验证标准提供注册客户的运营细节