Official Legal Documentation

Privacy Policy

Digital products, platforms, member areas, payments and support channels

ControllerNexus Corporation LTDANexus Produtos Digitais LTDA
Registration (CNPJ)66.324.183/0001-09Brazil Jurisdiction
Support Contactsupport@nexuscorp.onlineOfficial Assistance Channel
Version & Effective DateVersion 1.1August 3, 2026

Our commitment to privacy

This Policy transparently explains how Nexus collects, uses, shares, stores and protects personal data. It has been structured to comply with the Brazilian General Data Protection Law (LGPD) and, where applicable, the European Union General Data Protection Regulation (GDPR).

Acknowledgement of terms

By using Nexus channels or purchasing a digital product, the data subject acknowledges that they have read this Policy. Consent will only be requested when it is the appropriate legal basis and will not be inferred merely from the use of the services.

1

About this Policy

This Privacy Policy applies to personal data processing activities carried out by Nexus Corporation LTDA, registered under Brazilian CNPJ No. 66.324.183/0001-09 and trading as Nexus Produtos Digitais LTDA, hereinafter referred to as “Nexus”, “we”, “us” or “our”.

It covers websites, sales pages, forms, checkout pages, member areas, digital products, campaigns, advertisements, communications by email, telephone, SMS or WhatsApp, support channels and other digital environments operated by or on behalf of Nexus.

Third-party services used throughout the customer journey, such as Stripe, hosting platforms, member-area providers, email tools and social networks, may also process data under their own policies and legal responsibilities.

2

Contents

This table of contents organizes our privacy practices, data subject rights, and regulatory frameworks for rapid reference.

  • 3. Who the controller is and how to contact us
  • 4. Personal data we may process
  • 5. How data is collected
  • 6. How we use data and the applicable legal bases
  • 7. Payments and data processing by Stripe
  • 8. How and with whom we disclose personal data
  • 9. International data transfers
  • 10. Cookies and similar technologies
  • 11. Data retention and deletion
  • 12. Information security and incidents
  • 13. Data subject rights
  • 14. How to exercise your rights
  • 15. Marketing communications
  • 16. Automated decision-making and fraud prevention
  • 17. Children and adolescents
  • 18. Third-party links and services
  • 19. Changes to this Policy
  • 20. Contact and complaints
3

Who the controller is and how to contact us

For the activities described in this Policy, Nexus generally acts as the personal data controller because it determines the purposes and essential means of processing.

Controller: Nexus Corporation LTDA, trading as Nexus Produtos Digitais LTDA.

Brazilian CNPJ: 66.324.183/0001-09.

Privacy and data protection contact: support@nexuscorp.online

The contact channel above may be used for requests relating to the LGPD, the GDPR, cookies, marketing, security, data correction or deletion, as well as questions about this Policy.

4

Personal data we may process

Nexus may process the categories below depending on how the data subject interacts with our products and channels:

Sensitive personal data

As a general rule, Nexus does not request sensitive personal data. Data subjects should not submit information concerning health, biometric data, racial or ethnic origin, religious beliefs, political opinions, trade union membership, sex life or other sensitive data unless this is strictly necessary, clearly disclosed and permitted by law.

CategoryExamples
Identity and contact dataName, email address, telephone number, WhatsApp number, country, language and other information provided through forms or customer support.
Purchase and customer relationship dataProduct purchased, date and time, amount, currency, coupons, order status, access history, refunds, cancellations, chargebacks, requests and support communications.
Payment and billing dataTransaction identifiers, payment status, billing country and limited payment method data, such as the card brand and last digits, when made available by Stripe. Full card numbers, expiry dates and card security codes are collected and processed by Stripe and are not stored on Nexus systems.
Checkout and incomplete purchase dataInformation entered or generated before a purchase is completed, such as name, email address, telephone number, selected product, amount, currency, checkout-session identifier, consent status and abandonment or expiry status, where this information is made available through Stripe or another checkout provider.
Technical and usage dataIP address, access date and time, browser, operating system, device type, identifiers, pages visited, clicks, checkout-session events, browsing events, logs and security data.
Preferences and marketing dataConsents, opt-outs, contact preferences, campaign interactions, email opens and survey responses.
Content submitted by the data subjectMessages, files, reviews, testimonials, responses, comments and other information voluntarily submitted.
Third-party and integration dataInformation received from payment platforms, member-area providers, affiliates, analytics tools, social networks or partners, where permitted by law and in accordance with the data subject’s settings.
5

How data is collected

Data may be collected:

  • directly from the data subject when they complete forms, make a purchase, create an account or access credentials, contact us or participate in a survey;
  • automatically during the use of websites and platforms through cookies, pixels, SDKs, logs and similar technologies;
  • from suppliers and partners, such as Stripe, checkout platforms, member-area providers, hosting services, customer service tools, email providers and analytics services;
  • from public or lawfully accessible sources when necessary for fraud prevention, the protection of rights or compliance with legal obligations.

Stripe Checkout & Abandoned Carts

When Stripe Checkout or a similar payment flow is used, some information may be collected or generated before the purchase is completed. This may include contact details, the selected product, checkout-session identifiers, consent choices and technical events. Nexus only uses incomplete-checkout information for service administration, fraud prevention or checkout-recovery communications in accordance with applicable law. Promotional or abandoned-cart messages are sent only where a valid legal basis exists and, where required, after the customer has consented.

7

Payments and data processing by Stripe

Payments are processed through Stripe and its affiliates. During checkout, customers enter payment details into Stripe-controlled payment fields or a Stripe-hosted payment page. Stripe directly collects and processes information such as the full card number, expiry date, card security code, bank or payment-method details, billing information, device identifiers, transaction information and fraud-prevention signals.

Full payment card numbers and card security codes are transmitted directly to Stripe and are not collected or stored on Nexus systems. Nexus receives only the limited information required to administer the transaction, provide the digital product and handle support, refunds and disputes, which may include the transaction identifier and status, amount, currency, billing country, payment-method type, card brand and last digits of the card.

Depending on the activity, Stripe may act as a processor on Nexus’s instructions or as an independent controller when it determines its own purposes and means, including for payment-network operations, identity or account verification, security, fraud prevention, legal compliance and the provision and improvement of Stripe services.

Stripe may disclose payment and transaction data to banks, card networks, payment-method providers, fraud-prevention partners, regulators and other parties required to process or secure a payment. Stripe’s processing is governed by its own terms, privacy notices and data-processing arrangements. Customers should review those documents to understand Stripe’s activities and international processing practices.

Stripe Privacy Policy: stripe.com/privacy

8

How and with whom we disclose personal data

Nexus may disclose personal data only to the extent necessary for the purposes described in this Policy. Depending on the service, disclosure may occur through access-controlled provider dashboards, secure technical integrations, APIs, encrypted network connections or other protected electronic channels. Access is limited to authorised personnel and service providers with a legitimate need to process the data.

Recipients may include:

  • payment processors, banks, card networks and fraud-prevention services, including Stripe;
  • checkout, hosting, cloud storage, member-area and digital content distribution platforms;
  • email, CRM, customer service, telecommunications, SMS, WhatsApp, automation and marketing providers;
  • analytics, performance, security, fraud-prevention and consent-management services;
  • accountants, auditors, lawyers, consultants, insurers and professional service providers subject to confidentiality obligations;
  • affiliates, distributors and business partners when necessary to provide the service or where another valid legal basis applies;
  • public authorities, regulators, courts or third parties where required by law or a valid order, or to protect rights and security;
  • prospective buyers, investors or successors in a reorganisation, merger, acquisition or asset transfer, subject to appropriate safeguards.

Strict Data Protection Guarantees

Service providers must process data in accordance with contractual terms, instructions, compatible purposes and applicable legal requirements. Nexus seeks to limit sharing to the minimum necessary.

Nexus does not sell or rent personal data as a business model. Personal data is not disclosed for purposes unrelated to those described in this Policy unless the data subject has been informed and a valid legal basis applies.

9

International data transfers

Because Nexus sells digital products globally and uses international service providers, personal data may be stored in or accessed from countries other than the country in which the data subject is located.

For data subject to the LGPD, Nexus will use mechanisms permitted by applicable law and ANPD regulations, including adequacy decisions, standard contractual clauses, specific contractual clauses, binding corporate rules, certifications or other legally permitted grounds.

For data subject to the GDPR, transfers outside the European Economic Area will be made under valid mechanisms, such as an adequacy decision, the European Commission’s Standard Contractual Clauses, binding corporate rules or applicable derogations, together with supplementary measures where necessary.

Data subjects may request additional information about the applicable safeguards by emailing support@nexuscorp.online, subject to trade secrets, security obligations and third-party rights.

10

Cookies and similar technologies

Nexus and its service providers may use cookies, pixels, tags, local storage, device identifiers and similar technologies to operate the services, maintain sessions, strengthen security, remember preferences, measure performance, understand how the channels are used and display relevant communications.

CategoryPurposeControl / legal basis
Strictly necessaryEnable essential functions, security, authentication, fraud prevention, checkout and privacy preferences.Cannot be disabled where they are essential to the service.
FunctionalRemember language, region, preferences and personalisation settings.Consent where required by applicable law.
Analytics and performanceMeasure traffic, source, navigation, errors and performance.Consent where required; in limited cases, legitimate interests for strictly necessary measurement.
Advertising and remarketingMeasure campaigns, frequency, attribution and advertising personalisation.Prior consent where required.

Cookie Consent & Preference Management

Where required by applicable law, non-essential cookies and similar technologies are not activated until the visitor has made a valid choice through the cookie banner or preference centre. Visitors may accept, reject or later change their preferences. Essential cookies may remain active where they are required for security, checkout, fraud prevention, session management or delivery of the requested service.

11

Data retention and deletion

Data is retained only for as long as necessary to fulfil the stated purposes, perform contracts, comply with legal and regulatory obligations, prevent fraud, resolve disputes and establish, exercise or defend legal claims.

CategoryRetention criterion
Orders, transactions and tax documentsFor the duration of the relationship and for the periods required by applicable tax, accounting, consumer, banking and limitation rules.
Product access and delivery dataWhile access remains active and for the period necessary to evidence delivery, provide support and protect rights.
Customer support and complaintsWhile the request is being handled and for the period necessary for record-keeping, quality assurance, abuse prevention and defence of legal claims.
Marketing and preferencesUntil consent is withdrawn, an objection is made or the data subject unsubscribes, without prejudice to retaining a minimal suppression record to prevent further messages.
Cookies and browsing dataAccording to the purpose, configuration, cookie duration and security requirements stated in the preference centre, where available.
Privacy requestsFor the period necessary to demonstrate that the request was handled and to meet accountability obligations.

Post-Retention Handling

At the end of the applicable period, the data will be deleted, anonymised or retained in a restricted form where continued retention is required or permitted by law.

12

Information security and incidents

Nexus maintains a risk-based information security programme and adopts reasonable technical, administrative and organisational safeguards designed to protect personal data against unauthorised access, alteration, disclosure, loss or destruction. Depending on the system and risk, these safeguards include HTTPS/TLS encryption for data transmitted through Nexus websites and payment flows, restricted and role-based access, authentication controls for administrative accounts, permission management, security and access logging, backups and recovery procedures, supplier assessments, confidentiality and data-protection obligations, and documented incident-response procedures.

Payment security is further supported by using Stripe-controlled payment interfaces so that full card details are transmitted directly to Stripe and do not pass through or remain on Nexus systems. Nexus personnel and ordinary customer-support channels should never request a full card number or card security code.

No system is completely immune from risk. If a security incident occurs that may create a relevant risk or harm to data subjects, Nexus will take containment, investigation, documentation and mitigation measures and, where required, notify the competent authority and affected data subjects.

Data subjects must protect their credentials, avoid sharing passwords and immediately report any suspected unauthorised use.

13

Data subject rights

13.1 Rights under the LGPD

Where the LGPD applies, the data subject may request, subject to legal requirements:

  • confirmation that processing exists;
  • access to personal data;
  • correction of incomplete, inaccurate or outdated data;
  • anonymisation, blocking or deletion of unnecessary or excessive data, or data processed unlawfully;
  • data portability, where regulated and technically applicable;
  • deletion of data processed on the basis of consent, subject to legally permitted retention;
  • information about public and private entities with which data has been shared;
  • information about the possibility of withholding consent and the consequences of doing so;
  • withdrawal of consent;
  • objection to processing based on a legal ground other than consent where the law has been breached;
  • review of decisions made solely on the basis of automated processing that affect their interests;
  • the right to petition the ANPD and consumer protection authorities.

13.2 Rights under the GDPR

Where the GDPR applies, the data subject may exercise, subject to legal conditions:

  • the right to information and access;
  • the right to rectification;
  • the right to erasure;
  • the right to restriction of processing;
  • the right to data portability;
  • the right to object, including to direct marketing;
  • the right to withdraw consent;
  • rights relating to solely automated decision-making and profiling;
  • the right to lodge a complaint with the competent supervisory authority.

Scope of Rights

These rights are not absolute. A request may be limited or refused where permitted or required by law, for example to comply with a legal obligation, protect trade secrets or third-party rights, prevent fraud, or establish, exercise or defend legal claims.

14

How to exercise your rights

To exercise a right, email support@nexuscorp.online with the subject line “Privacy — Data Subject Request” and describe the request.

To protect the data subject and prevent improper disclosure, Nexus may request reasonable information to confirm identity, the authority of any representative and the relationship to the relevant data.

Requests will be assessed free of charge and answered within the time limits provided by applicable law. Manifestly unfounded, excessive or repetitive requests may be handled as permitted by law.

Where Nexus acts solely as a processor on behalf of another controller, the request may be forwarded to the responsible controller.

15

Marketing communications

Nexus may send offers, news, content, surveys and checkout-recovery communications by email, telephone, SMS, WhatsApp or other channels only where a valid legal basis exists. Where required by law, Nexus will obtain the customer’s prior consent before sending promotional communications.

Data subjects may stop receiving marketing communications through the unsubscribe link, available preference settings or by emailing support@nexuscorp.online. Nexus will promptly honour valid opt-out requests. Marketing opt-out does not prevent essential transactional, security, access-delivery, billing or customer-support messages.

Abandoned-cart and similar checkout-recovery messages are treated as promotional communications where required by applicable law. Nexus will not use incomplete-checkout data for promotional follow-up unless the customer has received the required notice and, where applicable, has consented. Consent records and opt-out preferences may be retained to demonstrate compliance and prevent unwanted messages.

16

Automated decision-making and fraud prevention

As a general rule, Nexus does not make solely automated decisions that produce legal effects or similarly significantly affect the data subject. However, payment processors and fraud-prevention services may use automated models to assess risk, authenticate transactions, decline payments or request additional verification.

Where applicable law provides this right, the data subject may request information about the criteria and procedures used and ask for human review, subject to trade secrets, security and fraud-prevention requirements.

17

Children and adolescents

Nexus sales channels are not directed at children. Purchases must be made by legally competent persons or by their parents or legal guardians.

Nexus does not knowingly collect children’s data without the required authorisation and safeguards. If a parent or legal guardian identifies inappropriate processing, they should contact support@nexuscorp.online so that the matter can be reviewed and appropriate measures taken.

If a particular product is specifically intended for children or adolescents, a supplementary notice may be provided with specific rules, age-appropriate language and measures designed to protect the child’s best interests.

19

Changes to this Policy

Nexus may update this Policy to reflect legal, regulatory, technological, contractual or operational changes. The current version will state its last-updated date.

Material changes may be communicated through a notice on the relevant channels, by email or by another appropriate method. Where a new purpose requires consent, consent will be requested before processing begins.

20

Contact and complaints

Questions, requests and complaints concerning privacy may be sent to:

Effective date

This Policy, Version 1.1, was last updated and takes effect on August 3, 2026. It remains valid until replaced by a later version.

Organization DetailsInformation
CompanyNexus Corporation LTDA
Trading nameNexus Produtos Digitais LTDA
CNPJ66.324.183/0001-09
Emailsupport@nexuscorp.online

Supervisory Authorities

Data subjects in Brazil may also petition the ANPD or contact consumer protection authorities. Data subjects in the European Economic Area may lodge a complaint with the supervisory authority in the country where they reside, work or believe an infringement has occurred.

Arquivo Oficial no Google Drive

Download Official Privacy Policy PDFs

Access the complete, legally binding Privacy Policy in PDF format directly from our verified secure Google Drive repository in both Brazilian Portuguese and English.