1. Data controller
Daniel Jiménez is the data controller for personal data collected through Nexus Legal.
Identification: Individual / sole proprietor. Address: Dubai, United Arab Emirates.
Contact email for privacy and rights requests: support@nexusquantum.legal.
We have not formally appointed a Data Protection Officer (DPO), as none of the conditions of Article 37(1) of Regulation (EU) 2016/679 (GDPR) apply. Privacy inquiries are channelled through the email above.
2. Personal data we collect
During registration: email address, password (stored in irreversibly hashed form), entity type (individual or company), name or legal entity name, contact person (if applicable), full billing address, tax identifier (VAT, EIN, or country equivalent), phone (optional) and preferred language.
During service use: Analysis Mode (Zero Retention) — documents are processed entirely in RAM and are not persisted in database or storage of any kind. We only log execution metadata (job ID, analysis type, jurisdiction, final status, credits consumed), never content. Case File Mode — documents added to a digital Case File are stored encrypted at rest (AES-256): originals in a private Supabase Storage bucket (EU, London) protected by Row Level Security, and the extracted text for search in our database. You choose the case file's retention mode: persistent (documents are kept until you delete them) or ephemeral (source documents are automatically purged when you close the work or after the inactivity period you set, keeping only the analysis work product). You can click "Close and purge" at any time to remove them immediately, or delete the entire case file to also erase the analysis and metadata.
Billing and payment data: processed by our payment providers (Paddle, NOWPayments) under their own privacy notices. Daniel Jiménez does not store full credit card data.
Technical metadata: IP address, user agent (browser), timestamp of relevant actions. Used for security, consent proof (Art. 7(1) GDPR) and auditing.
3. Purposes and legal bases
Provision of the contracted service (multi-agent legal analysis). Legal basis: contract performance (Art. 6(1)(b) GDPR).
Billing and compliance with legal obligations (tax, accounting, AML). Legal basis: legal obligation (Art. 6(1)(c) GDPR).
Marketing communications about new services, improvements and related content. Legal basis: consent (Art. 6(1)(a) GDPR), withdrawable at any time.
Security and abuse prevention: rate limiting, bot detection, access auditing. Legal basis: legitimate interest (Art. 6(1)(f) GDPR).
Special categories of data (Art. 9 GDPR): the documents you upload may contain sensitive data (health, criminal records, beliefs, etc.). With respect to that content you act as the data controller and instruct us as a processor; the processing relies on your own Art. 9(2) GDPR legal basis (typically the establishment, exercise or defence of legal claims, Art. 9(2)(f)) and is governed by our Data Processing Agreement (DPA). Before any transmission to external models we apply the PII Gatekeeper anonymisation layer.
4. Recipients and international transfers
Supabase (database and authentication). Servers in the European Union (London, UK — recognised by adequacy decision of the European Commission).
Resend (transactional email delivery). Servers in the European Union (Ireland).
Cloudflare Turnstile (antibot protection). Processes minimal technical metadata (IP, user agent) at validation time.
Railway (application hosting). Servers in the European Union (Amsterdam).
Large Language Model providers: Anthropic, OpenAI, Google and NVIDIA, established in the United States; OpenRouter Inc. (United States) as routing intermediary for the Qwen (Alibaba Cloud) and Kimi (Moonshot AI) models; and DeepSeek, established in the People's Republic of China. Processing occurs exclusively in real time during analysis and, depending on the provider, contractual no-training and/or zero-retention commitments apply. The international transfer is covered by the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914; in the case of DeepSeek (PRC), transmission always takes place after PII Gatekeeper anonymization. Clients requiring strictly EU-based processing may use an «EU-only» mode under an enterprise agreement, or operate with their own LLM engine (BYO-LLM).
Voyage AI (generating embeddings for semantic search) and Deepgram (audio and video transcription), established in the United States. Processing occurs in real time during indexing or transcription, with no use of the data for training; the international transfer is likewise covered by the Standard Contractual Clauses (EU) 2021/914.
Before processing documents with these providers, we apply a PII Gatekeeper anonymisation layer that replaces direct identifiers with opaque codes. This layer reduces but does not entirely eliminate the possibility of residual personal data reaching US-based providers.
Payment providers (Paddle, NOWPayments): receive the data necessary to process payments. Both operate under international data protection standards (PCI-DSS, Standard Contractual Clauses).
Optional user-initiated integrations: if you connect your Google Calendar (Nexus → Deadlines → Add to Calendar), we apply additional Google-specific disclosures at /legal/google-api-data per the Google API Services User Data Policy. That integration is optional, revocable at any time, and limited to creating events that originate in Nexus Legal.
5. Retention periods
Account data (profile, consents): while the account remains active. After voluntary deletion, retained for up to 30 days to allow reactivation, unless immediate erasure is expressly requested.
Documents — Analysis Mode (Zero Retention): not retained. Once analysis is complete and the report delivered, documents disappear without possibility of recovery. — Case File Mode: under persistent retention, documents are kept while the case file is active in your account; under ephemeral retention, source documents are purged when you close the work or when the inactivity period expires. In both cases they are permanently deleted when you purge, delete the case file or request account erasure.
Execution metadata (job history): 24 months, for support, auditing and aggregated anonymous analytics.
Billing data: up to 6 years after invoice issuance, in accordance with Spanish tax and accounting legislation (LGT, LIS) and any applicable UAE tax rules.
Consent log (proof of consent, Art. 7(1) GDPR): while the legal basis persists and up to 3 years after account termination, matching the limitation period for GDPR infringement claims.
6. Data subject rights
You have the right to: access your data (Art. 15 GDPR); rectify inaccurate data (Art. 16); request erasure of your data (Art. 17, "right to be forgotten"); request restriction of processing (Art. 18); object to processing (Art. 21); receive your data in a portable format (Art. 20, portability); and not be subject to automated decisions with significant legal effects (Art. 22).
To exercise any of these rights, write to support@nexusquantum.legal stating your full name, the right you wish to exercise and a copy of your ID document. We will respond within one month.
You have the right to withdraw consent at any time, without affecting the lawfulness of processing prior to withdrawal.
You have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD) if you believe your rights have been violated: www.aepd.es. You may also contact the supervisory authority in your EU country of residence.
7. Security measures
TLS 1.3 encryption in transit for all client-server communications.
AES-256 encryption at rest in the Supabase database.
Passwords stored as bcrypt hashes with high cost factor; never in plaintext.
Two-factor authentication available (on the Phase 2 roadmap).
Password policy with minimum requirements (length, uppercase, digits, symbols).
Rate limiting and antibot protection (Cloudflare Turnstile) to prevent abuse.
Zero Retention isolation (Analysis Mode): client documents never touch disk or persistence; processed entirely in RAM during the active session. In Case File Mode, documents are stored encrypted (AES-256) in Supabase with Row Level Security (RLS) ensuring only the owner can access them.
Row Level Security (RLS) in Supabase to ensure each user can only access their own data.
9. Automated decisions and profiling
The service generates legal analyses using multi-agent artificial intelligence. These analyses are tools to support professional decision-making and do not constitute binding legal advice within the meaning of Article 22 GDPR.
The system does not adopt autonomous decisions with legal or significant effects on the user. Outputs are always reviewable by a qualified human professional (the user or their team).
If you nonetheless believe a specific analysis affects you significantly, you have the right to request human review by writing to support@nexusquantum.legal.
We do not conduct user profiling for advertising, scoring, or automated segmentation with legal effects.
10. EU representative
Daniel Jiménez is an entity established in the United Arab Emirates. As we offer services to persons in EU territory, Article 27 GDPR requires the written designation of an EU representative.
The designated EU representative of Daniel Jiménez is:
Ricardo González Álvaro
Calle Zorzaleño 15, La Raya del Palancar, Madrid, Spain
Email: quantumnexusventures@proton.me
The representative acts on behalf of the controller vis-à-vis supervisory authorities and data subjects in matters relating to data protection. This designation is made in compliance with Article 27 of Regulation (EU) 2016/679 (GDPR).
11. Minors
Nexus Legal is directed exclusively at persons over 18 years of age, given its professional nature. During registration, the user expressly declares being of legal age.
In compliance with Article 7 of the LOPDGDD, we do not knowingly process minors' data. If we detect an account created by a minor, we will proceed with its deletion.
12. Changes to this policy
We may modify this policy to adapt to regulatory changes, incorporate new providers or reflect service improvements.
Any substantial modification will be notified to registered users by email with reasonable advance notice. The current version will always be published at this URL with the last-updated date visible.
Continued use of the service after notification implies acceptance of the new version. If you disagree with the changes, you may request account cancellation at no cost.
13. Applicable law and jurisdiction
This policy is governed by Regulation (EU) 2016/679 (GDPR) and the Spanish Organic Law 3/2018 on Data Protection (LOPDGDD) insofar as we offer services to persons in EU territory.
As a company established in the United Arab Emirates, we also observe Federal Decree-Law No. 45 of 2021 on Personal Data Protection (UAE PDPL).
For EU user complaints, the competent jurisdiction is that of the supervisory authority in the data subject's country of residence, without prejudice to the competence of the Spanish AEPD.
14. Contact
For any question related to this policy or to the processing of your personal data, please write to:
Controller: Daniel Jiménez · Individual / sole proprietor · Dubai, United Arab Emirates.