Digital products, platforms, member areas, payments and support channels
This Policy transparently explains how Nexus collects, uses, shares, stores and protects personal data. It has been structured to comply with the Brazilian General Data Protection Law (LGPD) and, where applicable, the European Union General Data Protection Regulation (GDPR).
By using Nexus channels or purchasing a digital product, the data subject acknowledges that they have read this Policy. Consent will only be requested when it is the appropriate legal basis and will not be inferred merely from the use of the services.
This Privacy Policy applies to personal data processing activities carried out by Nexus Corporation LTDA, registered under Brazilian CNPJ No. 66.324.183/0001-09 and trading as Nexus Produtos Digitais LTDA, hereinafter referred to as “Nexus”, “we”, “us” or “our”.
It covers websites, sales pages, forms, checkout pages, member areas, digital products, campaigns, advertisements, communications by email, telephone, SMS or WhatsApp, support channels and other digital environments operated by or on behalf of Nexus.
Third-party services used throughout the customer journey, such as Stripe, hosting platforms, member-area providers, email tools and social networks, may also process data under their own policies and legal responsibilities.
This table of contents organizes our privacy practices, data subject rights, and regulatory frameworks for rapid reference.
For the activities described in this Policy, Nexus generally acts as the personal data controller because it determines the purposes and essential means of processing.
Controller: Nexus Corporation LTDA, trading as Nexus Produtos Digitais LTDA.
Brazilian CNPJ: 66.324.183/0001-09.
Privacy and data protection contact: support@nexuscorp.online
The contact channel above may be used for requests relating to the LGPD, the GDPR, cookies, marketing, security, data correction or deletion, as well as questions about this Policy.
Nexus may process the categories below depending on how the data subject interacts with our products and channels:
As a general rule, Nexus does not request sensitive personal data. Data subjects should not submit information concerning health, biometric data, racial or ethnic origin, religious beliefs, political opinions, trade union membership, sex life or other sensitive data unless this is strictly necessary, clearly disclosed and permitted by law.
| Category | Examples |
|---|---|
| Identity and contact data | Name, email address, telephone number, WhatsApp number, country, language and other information provided through forms or customer support. |
| Purchase and customer relationship data | Product purchased, date and time, amount, currency, coupons, order status, access history, refunds, cancellations, chargebacks, requests and support communications. |
| Payment and billing data | Transaction identifiers, payment status, billing country and limited payment method data, such as the card brand and last digits, when made available by Stripe. Full card numbers, expiry dates and card security codes are collected and processed by Stripe and are not stored on Nexus systems. |
| Checkout and incomplete purchase data | Information entered or generated before a purchase is completed, such as name, email address, telephone number, selected product, amount, currency, checkout-session identifier, consent status and abandonment or expiry status, where this information is made available through Stripe or another checkout provider. |
| Technical and usage data | IP address, access date and time, browser, operating system, device type, identifiers, pages visited, clicks, checkout-session events, browsing events, logs and security data. |
| Preferences and marketing data | Consents, opt-outs, contact preferences, campaign interactions, email opens and survey responses. |
| Content submitted by the data subject | Messages, files, reviews, testimonials, responses, comments and other information voluntarily submitted. |
| Third-party and integration data | Information received from payment platforms, member-area providers, affiliates, analytics tools, social networks or partners, where permitted by law and in accordance with the data subject’s settings. |
Data may be collected:
When Stripe Checkout or a similar payment flow is used, some information may be collected or generated before the purchase is completed. This may include contact details, the selected product, checkout-session identifiers, consent choices and technical events. Nexus only uses incomplete-checkout information for service administration, fraud prevention or checkout-recovery communications in accordance with applicable law. Promotional or abandoned-cart messages are sent only where a valid legal basis exists and, where required, after the customer has consented.
Nexus only processes personal data when it has a legitimate purpose and an applicable legal basis. The specific legal basis may vary according to the country, context and the data subject’s relationship with Nexus.
| Purpose | LGPD Legal Basis | GDPR Legal Basis |
|---|---|---|
| Process orders, deliver products and manage access | Performance of a contract or preliminary procedures; compliance with a legal obligation, where applicable. | Contract; pre-contractual measures. |
| Process payments, refunds, charges and tax documents | Performance of a contract; compliance with a legal or regulatory obligation. | Contract; legal obligation. |
| Provide support and respond to requests | Performance of a contract; legitimate interests; establishment, exercise or defence of legal claims. | Contract; legitimate interests; establishment, exercise or defence of legal claims. |
| Prevent fraud, abuse, chargebacks and incidents | Legitimate interests; compliance with a legal obligation; credit protection, where applicable; establishment, exercise or defence of legal claims. | Legitimate interests; legal obligation; establishment, exercise or defence of legal claims. |
| Maintain service security, stability and improvement | Legitimate interests, taking account of necessity, proportionality and the data subject’s reasonable expectations. | Legitimate interests; consent where required for non-essential technologies. |
| Send transactional communications | Performance of a contract; compliance with a legal obligation; legitimate interests. | Contract; legal obligation; legitimate interests. |
| Administer incomplete checkout sessions and, where permitted, recover abandoned carts | Performance of pre-contractual procedures; legitimate interests for strictly operational reminders; consent where required for promotional communications. | Pre-contractual measures; legitimate interests where permitted; consent and applicable electronic communications rules. |
| Send offers, news and campaigns | Consent or legitimate interests, depending on the channel, existing relationship and local law, always with the option to object or unsubscribe. | Consent; legitimate interests where permitted; applicable electronic communications rules. |
| Perform analytics, measurement and personalisation | Consent where necessary; legitimate interests in essential analytics and service improvement. | Consent; legitimate interests. |
| Comply with orders and legal obligations and protect rights | Compliance with a legal or regulatory obligation; establishment, exercise or defence of legal claims. | Legal obligation; establishment, exercise or defence of legal claims. |
| Corporate reorganisations, audits and business transactions | Legitimate interests; compliance with obligations; establishment, exercise or defence of legal claims, subject to appropriate safeguards. | Legitimate interests; legal obligation. |
Where processing is based on consent, the data subject may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal. Where processing is based on legitimate interests, Nexus will assess necessity, proportionality and the impact on the data subject’s rights.
Payments are processed through Stripe and its affiliates. During checkout, customers enter payment details into Stripe-controlled payment fields or a Stripe-hosted payment page. Stripe directly collects and processes information such as the full card number, expiry date, card security code, bank or payment-method details, billing information, device identifiers, transaction information and fraud-prevention signals.
Full payment card numbers and card security codes are transmitted directly to Stripe and are not collected or stored on Nexus systems. Nexus receives only the limited information required to administer the transaction, provide the digital product and handle support, refunds and disputes, which may include the transaction identifier and status, amount, currency, billing country, payment-method type, card brand and last digits of the card.
Depending on the activity, Stripe may act as a processor on Nexus’s instructions or as an independent controller when it determines its own purposes and means, including for payment-network operations, identity or account verification, security, fraud prevention, legal compliance and the provision and improvement of Stripe services.
Stripe may disclose payment and transaction data to banks, card networks, payment-method providers, fraud-prevention partners, regulators and other parties required to process or secure a payment. Stripe’s processing is governed by its own terms, privacy notices and data-processing arrangements. Customers should review those documents to understand Stripe’s activities and international processing practices.
Stripe Privacy Policy: stripe.com/privacy
Nexus may disclose personal data only to the extent necessary for the purposes described in this Policy. Depending on the service, disclosure may occur through access-controlled provider dashboards, secure technical integrations, APIs, encrypted network connections or other protected electronic channels. Access is limited to authorised personnel and service providers with a legitimate need to process the data.
Recipients may include:
Service providers must process data in accordance with contractual terms, instructions, compatible purposes and applicable legal requirements. Nexus seeks to limit sharing to the minimum necessary.
Nexus does not sell or rent personal data as a business model. Personal data is not disclosed for purposes unrelated to those described in this Policy unless the data subject has been informed and a valid legal basis applies.
Because Nexus sells digital products globally and uses international service providers, personal data may be stored in or accessed from countries other than the country in which the data subject is located.
For data subject to the LGPD, Nexus will use mechanisms permitted by applicable law and ANPD regulations, including adequacy decisions, standard contractual clauses, specific contractual clauses, binding corporate rules, certifications or other legally permitted grounds.
For data subject to the GDPR, transfers outside the European Economic Area will be made under valid mechanisms, such as an adequacy decision, the European Commission’s Standard Contractual Clauses, binding corporate rules or applicable derogations, together with supplementary measures where necessary.
Data subjects may request additional information about the applicable safeguards by emailing support@nexuscorp.online, subject to trade secrets, security obligations and third-party rights.
Data is retained only for as long as necessary to fulfil the stated purposes, perform contracts, comply with legal and regulatory obligations, prevent fraud, resolve disputes and establish, exercise or defend legal claims.
| Category | Retention criterion |
|---|---|
| Orders, transactions and tax documents | For the duration of the relationship and for the periods required by applicable tax, accounting, consumer, banking and limitation rules. |
| Product access and delivery data | While access remains active and for the period necessary to evidence delivery, provide support and protect rights. |
| Customer support and complaints | While the request is being handled and for the period necessary for record-keeping, quality assurance, abuse prevention and defence of legal claims. |
| Marketing and preferences | Until consent is withdrawn, an objection is made or the data subject unsubscribes, without prejudice to retaining a minimal suppression record to prevent further messages. |
| Cookies and browsing data | According to the purpose, configuration, cookie duration and security requirements stated in the preference centre, where available. |
| Privacy requests | For the period necessary to demonstrate that the request was handled and to meet accountability obligations. |
At the end of the applicable period, the data will be deleted, anonymised or retained in a restricted form where continued retention is required or permitted by law.
Nexus maintains a risk-based information security programme and adopts reasonable technical, administrative and organisational safeguards designed to protect personal data against unauthorised access, alteration, disclosure, loss or destruction. Depending on the system and risk, these safeguards include HTTPS/TLS encryption for data transmitted through Nexus websites and payment flows, restricted and role-based access, authentication controls for administrative accounts, permission management, security and access logging, backups and recovery procedures, supplier assessments, confidentiality and data-protection obligations, and documented incident-response procedures.
Payment security is further supported by using Stripe-controlled payment interfaces so that full card details are transmitted directly to Stripe and do not pass through or remain on Nexus systems. Nexus personnel and ordinary customer-support channels should never request a full card number or card security code.
No system is completely immune from risk. If a security incident occurs that may create a relevant risk or harm to data subjects, Nexus will take containment, investigation, documentation and mitigation measures and, where required, notify the competent authority and affected data subjects.
Data subjects must protect their credentials, avoid sharing passwords and immediately report any suspected unauthorised use.
Where the LGPD applies, the data subject may request, subject to legal requirements:
Where the GDPR applies, the data subject may exercise, subject to legal conditions:
These rights are not absolute. A request may be limited or refused where permitted or required by law, for example to comply with a legal obligation, protect trade secrets or third-party rights, prevent fraud, or establish, exercise or defend legal claims.
To exercise a right, email support@nexuscorp.online with the subject line “Privacy — Data Subject Request” and describe the request.
To protect the data subject and prevent improper disclosure, Nexus may request reasonable information to confirm identity, the authority of any representative and the relationship to the relevant data.
Requests will be assessed free of charge and answered within the time limits provided by applicable law. Manifestly unfounded, excessive or repetitive requests may be handled as permitted by law.
Where Nexus acts solely as a processor on behalf of another controller, the request may be forwarded to the responsible controller.
Nexus may send offers, news, content, surveys and checkout-recovery communications by email, telephone, SMS, WhatsApp or other channels only where a valid legal basis exists. Where required by law, Nexus will obtain the customer’s prior consent before sending promotional communications.
Data subjects may stop receiving marketing communications through the unsubscribe link, available preference settings or by emailing support@nexuscorp.online. Nexus will promptly honour valid opt-out requests. Marketing opt-out does not prevent essential transactional, security, access-delivery, billing or customer-support messages.
Abandoned-cart and similar checkout-recovery messages are treated as promotional communications where required by applicable law. Nexus will not use incomplete-checkout data for promotional follow-up unless the customer has received the required notice and, where applicable, has consented. Consent records and opt-out preferences may be retained to demonstrate compliance and prevent unwanted messages.
As a general rule, Nexus does not make solely automated decisions that produce legal effects or similarly significantly affect the data subject. However, payment processors and fraud-prevention services may use automated models to assess risk, authenticate transactions, decline payments or request additional verification.
Where applicable law provides this right, the data subject may request information about the criteria and procedures used and ask for human review, subject to trade secrets, security and fraud-prevention requirements.
Nexus sales channels are not directed at children. Purchases must be made by legally competent persons or by their parents or legal guardians.
Nexus does not knowingly collect children’s data without the required authorisation and safeguards. If a parent or legal guardian identifies inappropriate processing, they should contact support@nexuscorp.online so that the matter can be reviewed and appropriate measures taken.
If a particular product is specifically intended for children or adolescents, a supplementary notice may be provided with specific rules, age-appropriate language and measures designed to protect the child’s best interests.
Nexus channels may contain third-party links, embedded content or integrations. Nexus does not fully control the practices of those third parties and recommends reviewing their privacy policies before providing personal data.
This Policy does not replace the privacy notices of payment processors, banks, social networks, advertising platforms, member-area providers or other independent services.
Nexus may update this Policy to reflect legal, regulatory, technological, contractual or operational changes. The current version will state its last-updated date.
Material changes may be communicated through a notice on the relevant channels, by email or by another appropriate method. Where a new purpose requires consent, consent will be requested before processing begins.
Questions, requests and complaints concerning privacy may be sent to:
This Policy, Version 1.1, was last updated and takes effect on August 3, 2026. It remains valid until replaced by a later version.
| Organization Details | Information |
|---|---|
| Company | Nexus Corporation LTDA |
| Trading name | Nexus Produtos Digitais LTDA |
| CNPJ | 66.324.183/0001-09 |
| support@nexuscorp.online |
Data subjects in Brazil may also petition the ANPD or contact consumer protection authorities. Data subjects in the European Economic Area may lodge a complaint with the supervisory authority in the country where they reside, work or believe an infringement has occurred.
Access the complete, legally binding Privacy Policy in PDF format directly from our verified secure Google Drive repository in both Brazilian Portuguese and English.