Data Security &
Privacy Policy

NYXIUM — Data Security & Privacy Policy

Last updated: September 4, 2025
Version:1.0

  1. Introduction

NYXIUM ("NYXIUM", "we", "us", or "our") is committed to protecting the privacy and security of the personal data we hold. This policy explains what personal data we collect, why we collect it, how we use and protect it, and the rights available to you.

It applies to personal data we process about clients, prospective clients, partners, suppliers, website visitors, job applicants, and other individuals we deal with in the course of our business.

We process personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025 (DUAA), together with the Privacy and Electronic Communications Regulations 2003 (PECR) where applicable. Where we process the personal data of individuals in the European Economic Area, we also act in accordance with the EU GDPR (Regulation (EU) 2016/679).

  1. Who we are (Data Controller)

NYXIUM is the data controller responsible for your personal data.

  • Legal entity: NYXIUM LTD

  • Company number: 16693361

  • Contact for data protection matters: hr@nyxium.ai

  1. The personal data we collect

Depending on your relationship with us, we may collect and process the following categories of personal data:

  • Identity and contact data** — name, job title, employer, business email address, telephone number, postal address.

  • Commercial and relationship data — records of our correspondence and dealings, contract details, and information relevant to the services we provide or are discussing.

  • Recruitment data — where you apply for a role: CV, work history, qualifications, references, right-to-work information, and information provided during interviews.

  • Technical and usage data — when you use our website: IP address, device and browser type, pages visited, and similar information collected via cookies and analytics (see Section 11).

  • Communications data — the content of emails, messages, and other communications you send to us.

We do not seek to collect special category data (such as data revealing health, racial or ethnic origin, or political opinions) unless there is a specific lawful reason to do so, and we will tell you if that is the case.

  1. How we collect personal data

We collect personal data:

  • directly from you, when you contact us, enter into a contract, apply for a role, or otherwise engage with us;

  • automatically, through cookies and similar technologies when you visit our website;

  • from third parties and public sources, such as business directories, professional networks, and our partners, where they are lawfully able to share it.

  1. Lawful bases for processing

Under the UK GDPR we only process personal data where we have a lawful basis. The bases we rely on are:

  • Contract — where processing is necessary to enter into or perform a contract with you.

  • Legitimate interests — where processing is necessary for our legitimate business interests (such as managing client relationships, business development, securing our networks and systems, and intra-group administration), provided your interests and rights do not override those interests. Where we rely on legitimate interests we carry out and record a legitimate interests assessment.

  • Consent — where you have given clear consent, for example to certain marketing communications or non-essential cookies. You can withdraw consent at any time.

  • Legal obligation — where we must process data to comply with the law.

Where the DUAA's recognised legitimate interests apply (for example, processing necessary to ensure the security of our network and information systems, to prevent crime, or to safeguard individuals), we will rely on that basis and record our reasoning.

  1. How we use personal data

We use personal data to:

  • provide, manage, and improve our services;

  • communicate with you and respond to your enquiries;

  • manage our client, partner, and supplier relationships;

  • carry out business development and, where permitted, send relevant marketing;

  • assess job applications and manage recruitment;

  • maintain the security and integrity of our systems;

  • meet our legal, regulatory, and contractual obligations.

We will not use your personal data for a new, incompatible purpose without first informing you and, where required, obtaining your consent.

  1. Data security

Protecting personal data is central to how NYXIUM operates. We implement appropriate technical and organisational measures to protect personal data against unauthorised or unlawful processing, accidental loss, destruction, or damage, taking into account the state of the art, the nature of the data, and the risks involved.

Our security measures include:

  • Access control — access to personal data is restricted to authorised personnel on a need-to-know basis, governed by role-based permissions and strong authentication.

  • Encryption — personal data is encrypted in transit and, where appropriate, at rest.

  • Network and system security — firewalls, monitoring, logging, and patching to protect against unauthorised access and intrusion.

  • Vendor management — we assess the security posture of third-party providers before sharing data with them and bind them by written contracts.

  • People and process — staff confidentiality obligations, security awareness, and defined procedures for handling personal data.

  • Incident response — a documented process to detect, investigate, and respond to security incidents, including notifying the Information Commissioner's Office (ICO) and affected individuals where the law requires.

NYXIUM's information security management system is independently certified to ISO/IEC 27001:2022 (certificate no. [number], issued by [certification body]). NYXIUM also maintains a SOC 2 Type [I / II] report covering the Trust Services Criteria (security, availability, processing integrity, confidentiality, and privacy). Our ISO/IEC 27001:2022 certificate is available on request, and our SOC 2 report is available to clients and prospective clients under a non-disclosure agreement. We use continuous control-monitoring to maintain these standards on an ongoing basis.

No method of transmission or storage is completely secure; while we take all reasonable steps to protect your data, we cannot guarantee absolute security.

8. Sharing your personal data

We share personal data only where necessary and lawful, including with:

  • Service providers and sub-processors who provide IT, hosting, cloud infrastructure, communications, analytics, and professional services on our behalf, under contracts that require them to protect the data and process it only on our instructions;

  • Professional advisers such as lawyers, auditors, and accountants;

  • Authorities and regulators where required by law;

  • Group companies, partners, and a buyer (or prospective buyer) in connection with a corporate transaction, subject to appropriate safeguards.

We do not sell personal data.

9. International transfers

NYXIUM is based in the United Kingdom. Where we transfer personal data outside the UK, we ensure an appropriate level of protection by relying on one of the following safeguards:

  • transfer to a country covered by UK adequacy regulations (a "data bridge");

  • the UK International Data Transfer Agreement (IDTA) or the EU Standard Contractual Clauses together with the UK Addendum;

  • another lawful transfer mechanism recognised under the UK GDPR.

Following the DUAA, transfers are assessed against the data protection test — whether the destination provides protection that is not materially lower than that under UK law. We carry out transfer risk assessments where required.

10. Data retention

We keep personal data only for as long as necessary for the purposes for which it was collected, including to satisfy legal, accounting, regulatory, or reporting requirements. The retention period depends on the type of data and the reason we hold it; for example, contract and financial records are typically kept for six years to meet legal obligations. When data is no longer needed, we securely delete or anonymise it.

11. Cookies and similar technologies

Our website uses cookies and similar technologies to function correctly, to understand how the site is used, and — with your consent — for analytics and other non-essential purposes. We will not place non-essential cookies on your device without your consent, and you can manage your preferences at any time through our cookie banner or your browser settings.

12. Your rights

Under the UK GDPR you have the following rights in relation to your personal data:

  • the right to be informed about how we use your data;

  • the right of access to your data;

  • the right to rectification of inaccurate or incomplete data;

  • the right to erasure in certain circumstances;

  • the right to restrict processing in certain circumstances;

  • the right to data portability where applicable;

  • the right to object to processing based on legitimate interests, and to direct marketing at any time;

  • rights in relation to automated decision-making and profiling, including the right to be informed, to make representations, to contest a decision, and to obtain human intervention.

To exercise any of these rights, contact us at hr@nyxium.ai. We will respond within one month, although we may extend this where requests are complex or numerous, and we will tell you if we do. We may need to verify your identity before acting on a request. There is normally no charge.

13. Complaints

If you are concerned about how we have handled your personal data, you have the right to complain to us directly. Please contact us at hr@nyxium.ai with the details of your complaint.

We will:

  • acknowledge your complaint within 30 days of receiving it;

  • take appropriate steps to investigate and resolve it without undue delay;

  • keep you informed of progress and the outcome.

You also have the right to complain to the UK supervisory authority, the Information Commissioner's Office (ICO):

  • Website: ico.org.uk

  • Helpline: 0303 123 1113

  • Address: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

We would, however, appreciate the chance to address your concerns before you approach the ICO.

14. Changes to this policy

We may update this policy from time to time to reflect changes in our practices or in the law. We will post the updated version on our website and update the "Last updated" date above. Where changes are significant, we will take reasonable steps to notify you.

15. Contact us

For any questions about this policy or how we handle your personal data, contact:

NYXIUM [registered company name] Email: hr@nyxium.ai [registered address]