Privacy Policy

Who We Are

NEXISEC LTD (“we”, “us”, “our”) is the data controller responsible for your personal data. This means we are responsible for deciding how and why your personal information is used, and for making sure it is kept safe, secure and handled in accordance with the law.

  • Company Name: NEXISEC LTD
  • Registered Address: Yeoford Way, Marsh Barton Trading Estate, Exeter, United Kingdom, EX2 8LB
  • Email: [email protected]

At NEXISEC, we are fully committed to protecting your privacy and security. We process personal information in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 (DPA 2018), the Privacy and Electronic Communications Regulations (PECR) as amended by the Data (Use and Access) Act 2025, and any other applicable privacy laws.

This privacy policy explains how we collect, use, share and protect your personal data when you visit our website, place an order with us, create an account, or contact us.

The Personal Data We Collect

We collect and process the following categories of personal data:

Personal Details – your name, email address, billing address, delivery address and phone number.

Account Data – if you register an account with us, we collect your username, password and account preferences.

Order Data – details of the products you purchase from us, including order history and transaction information.

Payment Data – your payment information, which is processed through our own secure payment channel. (We do not retain full payment card details beyond what is necessary to complete your transaction.)

Communications Data – any correspondence between you and us, including emails, messages and customer service interactions.

Technical Data – your internet protocol (IP) address, browser type and version, time zone setting, operating system and platform, device information, and other technical data collected when you interact with our website.

Usage Data – information about how you use our website, including pages visited, products viewed and search queries.

How We Collect Your Personal Data

We collect personal data in the following ways:

  • Direct interactions. You give us your personal data when you place an order, create an account, contact customer support, or communicate with us by email or phone.
  • Automated technologies. As you browse our website, we automatically collect technical and usage data through cookies and similar technologies.
  • Third parties. We may receive technical data from analytics providers and advertising networks, subject to your consent where required by law.

How We Use Your Personal Data

We will only use your personal data when the law allows us to. Most commonly, we use your personal data in the following circumstances: where it is necessary for the performance of a contract with you (for example, to process your order), where it is necessary for our legitimate interests and your interests do not override those interests, where we need to comply with a legal or regulatory obligation, or where you have given your consent.

Specifically, we use your personal data for the following purposes:

  • To process and fulfil your orders, including taking payment and communicating with you about your order.
  • To manage your account (if you choose to register one).
  • To provide customer support and respond to your enquiries.
  • To administer and protect our website and our business (including troubleshooting, data analysis, testing and fraud prevention).
  • To improve our website, products and services using data analytics.
  • To send you marketing communications, but only where we have your consent or where we are otherwise permitted to do so by law.

Marketing communications. We will only send you marketing emails or SMS messages if you have given us your consent to do so, or where we are relying on the “soft opt-in” (for example, if you have made a purchase from us and did not opt out of marketing at the time). You have the right to withdraw your consent or opt out of marketing at any time by clicking the unsubscribe link in any marketing email or by contacting us directly.

Legal Bases for Processing

Under UK data protection law, we must have a legal basis to process your personal data. The legal bases we rely on are:

PurposeLegal Basis
Processing and fulfilling your ordersContractual necessity
Managing your accountContractual necessity
Customer support and communicationsLegitimate interests
Website administration, security and fraud preventionLegitimate interests and legal obligation
Improving our website and servicesLegitimate interests
Marketing communications (where consent is required)Consent

Cookies and Similar Technologies

Our website uses cookies and other tracking technologies (such as pixels and web storage). The Privacy and Electronic Communications Regulations (PECR) govern how we use these technologies.

What are cookies? Cookies are small text files that are placed on your device when you visit our website. They help us remember your preferences, understand how you use our site, and improve your browsing experience.

Types of cookies we use:

  • Strictly necessary cookies. These cookies are essential for our website to function properly. They enable core features such as security, shopping basket functionality and checkout. These cookies do not require your consent.
  • Functional cookies. These cookies remember your preferences (such as language or region) to enhance your experience. Following the Data (Use and Access) Act 2025, these cookies may be placed without active consent, but we must provide you with a clear opt-out mechanism.
  • Statistical (analytics) cookies. These cookies collect information about how you use our website (for example, which pages you visit most often). They help us improve our website. Following the 2026 changes, these cookies may be placed without active consent, but we are required to provide a simple and free opt-out mechanism.
  • Marketing cookies. These cookies track your browsing activity across websites to help us deliver more relevant advertising. These cookies require your explicit opt-in consent before they are placed. We will not deploy marketing cookies unless you have given us your consent.

Managing your cookie preferences. When you first visit our website, you will see a cookie banner that allows you to accept or reject non-essential cookies. You can change your cookie preferences at any time through our cookie settings page. You can also manage or delete cookies through your browser settings, although please note that disabling certain cookies may affect the functionality of our website.

Under UK law, continuing to browse our website or interacting with content does not constitute valid consent. Only a clear, affirmative action (such as clicking “Accept” on our cookie banner) will be treated as consent for non-essential cookies.-

Data Sharing

We do not sell your personal data to third parties. However, we may share your personal data with the following categories of recipients as an essential part of being able to provide our services to you:

  • Service providers. We work with third-party companies that help us run our business, such as delivery couriers, IT service providers, website hosting providers, analytics platforms and customer support tools.
  • Professional advisors. We may share your data with lawyers, accountants, auditors and insurers where necessary to manage our legal and business affairs.
  • Law enforcement and regulators. We may disclose your personal data if required to do so by law, or if we believe such disclosure is necessary to comply with a legal obligation, protect our rights or the safety of others.

When we share your data with third-party service providers, we require them to respect the security of your personal data and to treat it in accordance with the law. We do not allow our service providers to use your personal data for their own purposes and only permit them to process your data for specified purposes in accordance with our instructions.

International Transfers

As NEXISEC LTD serves customers worldwide, we may need to transfer your personal data to countries outside the United Kingdom. Some of these countries may not offer the same level of data protection as the UK. Where we transfer your personal data outside the UK, we will take appropriate steps to ensure that your data is protected to UK standards. This may include using data transfer agreements that incorporate UK-approved standard contractual clauses or ensuring that the recipient country has an adequacy decision from the UK government.

If you would like further information about how we protect your personal data when it is transferred internationally, please contact us at [email protected].

Data Security

We have implemented appropriate security measures to protect your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. We limit access to your personal data to those employees, agents, contractors and other third parties who have a legitimate business need to access it. They will only process your personal data on our instructions and are subject to a duty of confidentiality.

We have put in place procedures to deal with any suspected personal data breach. Where we are required to do so by law, we will notify you and any applicable regulator (including the Information Commissioner’s Office) of a breach.

Data Retention

We will only keep your personal data for as long as reasonably necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying any legal, accounting or reporting requirements.

In general:

  • Order and account data is kept for as long as you have an active account with us, and for a reasonable period afterwards (typically up to six years) to comply with legal obligations such as tax and consumer protection laws.
  • Marketing data is kept until you withdraw your consent or opt out of marketing communications.
  • Technical and usage data is kept for a shorter period (typically up to 26 months for analytics data), unless it is required for a specific legal or business purpose.

When we no longer need your personal data, we will securely delete or anonymise it.

Your Legal Rights

Under UK data protection law, you have a number of important rights in relation to your personal data.- These include:

  • The right to be informed – you have the right to know how we use your personal data (which is what this privacy policy is for).
  • The right of access – you have the right to request a copy of the personal data we hold about you (commonly known as a “data subject access request”).
  • The right to rectification – you have the right to ask us to correct any inaccurate or incomplete personal data we hold about you.
  • The right to erasure (also known as the right to be forgotten) – you have the right to ask us to delete your personal data in certain circumstances, for example where it is no longer needed for the purpose for which it was collected.
  • The right to restrict processing – you have the right to ask us to suspend the processing of your personal data in certain circumstances, for example if you contest its accuracy.
  • The right to data portability – you have the right to ask us to transfer your personal data to another organisation, or directly to you, in a structured, commonly used and machine-readable format.
  • The right to object – you have the right to object to the processing of your personal data where we are relying on a legitimate interest (or those of a third party) as the legal basis for processing.
  • Rights in relation to automated decision-making – you have the right not to be subject to a decision based solely on automated processing (including profiling) that produces legal effects concerning you or similarly significantly affects you. We do not currently make significant automated decisions about you using your personal data.

How to exercise your rights. To exercise any of your rights, please contact us at [email protected]. We will respond to your request within one month (or within three months where the request is complex or you have made several requests, in which case we will notify you of the extension). You will not usually have to pay a fee to exercise your rights, although we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive.

Right to withdraw consent. Where we are relying on your consent to process your personal data (for example, for marketing cookies or direct marketing), you have the right to withdraw that consent at any time. Withdrawing your consent will not affect the lawfulness of any processing we carried out before your withdrawal.

Third-Party Links

Our website may contain links to other websites operated by third parties. Please note that this privacy policy applies only to the personal data we collect through our website. We cannot be responsible for the privacy practices of other websites, and we encourage you to read the privacy policy of each website you visit carefully.

Children’s Privacy

Our website and services are not intended for children under the age of 16. We do not knowingly collect personal data from children under 16. If you are a parent or guardian and believe that your child has provided us with personal data without your consent, please contact us and we will take steps to delete that information.