Your information.
A clear account.
What happens when you visit the website, get in touch or use a Nyxus licence.
READ THE NOTICE ↓Aman Karir, operating as Nyxus.
Nyxus is operated by Aman Karir, who is the data controller for the information described in this notice. For questions about this notice or your information, email support@nyxus.co.uk.
This notice covers the website, previews, correspondence and licence administration. Customers operate the self-hosted product in their own environments and are responsible for the information they process there.
When you visit the website.
Framer hosts nyxus.co.uk directly. Cloudflare provides DNS for this domain, rather than proxying the website. Hosting providers process network information, including IP addresses, to deliver requests.
Framer Analytics is active. Framer states that it uses neither cookies nor persistent identifiers. It hashes IP addresses and user agents using a daily rotating salt, which is reset and deleted each day, to calculate daily unique visitors. The published-site audit observed no cookies on the pages checked; this is not a guarantee about every provider or future configuration. Read Framer’s explanation.
Analytics reports include pageviews, unique and live visitor counts, bounce rate, average session duration, traffic sources, UTM parameters, referring sites, top pages, country, device type and browser. Framer describes country, device and referral information as estimates derived from browser-provided information. How Framer Analytics works.
Our website includes a preconnect hint to Google's font CDN but loads no fonts from it.
Framer does not publish a retention period for site analytics data in the documentation reviewed for this notice. Framer’s published privacy statement describes processing in the United States, with Standard Contractual Clauses and Data Privacy Framework arrangements covering international transfers.
Trying the preview.
Cloudflare Pages hosts preview.nyxus.co.uk. The preview uses bundled example data without a live application backend or visitor sign-in. Values entered into the demo stay in browser memory and are discarded on reload.
Cloudflare Web Analytics is not enabled on the preview, which makes no third-party requests. Browser storage remembers interface preferences, such as the selected colour. Cloudflare still processes visitor network information to serve the preview. Do not enter real credentials or sensitive information into a demonstration.
No log export is configured for our Cloudflare services. Cloudflare’s own retention of network information is governed by its privacy policy, which does not state a fixed period for these services.
Information you choose to send.
Contact is by email, not a website form. Zoho Mail, in the EU region, handles support@nyxus.co.uk. Correspondence includes your email address, name if supplied, message and any attachments you choose to send.
These details are used to answer enquiries and provide basic support. Customer environments are not managed or accessed by Nyxus. Please remove credentials and unnecessary personal information from screenshots and diagnostic material before sending them.
Report vulnerabilities through the private GitHub security advisory channel, not email or public issues.
We delete general enquiry correspondence 12 months after the last meaningful exchange and support correspondence 12 months after the case is closed. Deletion is carried out manually rather than automatically.
Deleted mail moves to Trash. Our cleanup interval is five days and is based on the message’s received date, so older correspondence may leave Trash sooner. Under Zoho’s standard deletion process, mail is then retained for a further 30 days for recovery before permanent purge: an outer window of up to 35 further days with this setting, rather than a fixed delay. Separate archival or eDiscovery policies, if applicable, can retain copies beyond this window. Zoho’s deletion and retention policy.
Your estate stays in your environment.
Findings, device records, people and tool names remain in customer infrastructure. The product does not send this estate information to Nyxus and has no product analytics or crash reporting. Customer-configured connectors communicate with their respective services from the customer’s environment.
Subscription checks and update requests are separate. Update requests include the installed version in the user agent. The budget view can request exchange rates from a third-party service using a currency code; the receiving service also necessarily processes the request’s network information.
Customer backups are encrypted with a customer-held key and written to customer-owned storage. Nyxus does not hold those backups. Information a customer voluntarily sends for support is handled as correspondence.
What the registry receives.
Every six hours, a subscription check sends a subscription reference, a twelve-character licence-key fingerprint, a random installation identifier and a fresh nonce. Cloudflare receives the source IP as part of the request.
Image and chart pulls authenticate using the signed licence key. It includes the organisation name entered during licence provisioning; the name is not discovered from the customer’s estate. It is returned inside the credential during pull authentication, not as a field in the six-hourly subscription check.
The registry stores licence status, organisation name, fingerprint, plan and deployment-related records. Network identifiers (ASNs), derived from request IPs, are recorded on image/chart pulls only.
Production Worker Logs and Traces are disabled, with no telemetry export destinations or stored Worker console logs configured. Console output can be viewed during a live tail session. Operational log statements no longer include organisation names; they can include subscription references, fingerprints and ASNs. Cloudflare still processes network information to operate its services.
Deletion follows the current operating process.
We keep a record of each licence issued, including its reference, the organisation name supplied at provisioning, key fingerprint, plan and deployment records. Network records help identify a key being used to pull software from unrelated networks. Licence records have no automatic expiry. Revoked subscriptions are closed at the next quarterly review, carried out by the operator of this service. Closure deletes both the licence and network records and verifies their removal from the store.
Network records expire 90 days after their last successful write. Successful image/chart pulls refresh this expiry. Entries for networks not seen for more than 90 days are pruned on a subsequent pull; individual entries are not guaranteed to disappear at the exact 90-day point.
Encrypted copies across two providers.
Administrative backups include signing material and licence records, not customer estate backups. One encrypted archive is kept on the working machine, with copies stored with two cloud providers for redundancy.
The archive uses AES-256 encryption with an operator-held passphrase. Each new archive is checked by restoring it before replacement. The plaintext snapshot is removed after verification.
Closing a subscription refreshes the snapshot used for subsequent backups. Previously created local or cloud archives can still contain the record until replaced. Cloud copies require a fresh manual upload; deletion does not propagate to them automatically.
Local and cloud archives are replaced at the quarterly review following a deletion. Deleted cloud files remain subject to the providers’ 30-day recovery periods. Previous file versions follow provider-specific rules; no fixed deletion period is stated for uploaded-file version history. Replacement of the current archive does not imply immediate deletion of every recoverable copy.
Where services are involved.
- Framer
- Website hosting, assets and built-in analytics. Framer uses US hosting with global edge infrastructure; an edge location does not establish data residency.
- Cloudflare
- DNS, static preview hosting and the registry Worker with KV storage.
- Zoho
- Email correspondence. Service data for our EU-region account is stored within the EU.
- GitHub
- Container image storage and private vulnerability disclosures.
- Encrypted administrative archives. The website also includes a preconnect hint to Google’s font CDN, but loads no fonts from it.
- Apple
- Encrypted administrative archives.
These providers are listed by their actual role. Encryption of archives does not remove them from this description. Cloudflare publishes a Data Processing Addendum covering Standard Contractual Clauses and Data Privacy Framework arrangements. GitHub publishes a Data Protection Agreement covering Standard Contractual Clauses and Data Privacy Framework arrangements. Framer’s published privacy statement describes processing in the United States and international-transfer arrangements. Framer privacy statement.
A UK Data Processing Addendum has been submitted to Zoho in the name of the individual operating Nyxus. It is awaiting Zoho’s legal review and countersignature; it is not yet described as an agreement in place.
The archive held with these two providers is encrypted before it leaves our machine, using a passphrase held only by us. Neither provider holds the passphrase needed to decrypt the archive. These are personal cloud storage accounts rather than business agreements.
Why we hold information, and what you can ask of us.
Nyxus is self-hosted, so findings, devices, people and tool names stay in our customers’ own infrastructure. The product does not send us estate information. Information you choose to send for support is handled as correspondence.
What we hold is this:
- Correspondence from people who email us: your address, your name if you give it, your message and anything you attach.
- A record of each licence we have issued, naming the organisation supplied at provisioning, along with its reference, a fingerprint of the key, the plan and which installations hold it.
- Network information our providers process to deliver a page or a message, and the networks a licence pulls software from. Website analytics are described in Section 02.
We use it for four purposes, and rely on the following bases in law.
Running the website and the preview.
Delivering pages and understanding in aggregate how the site is used. Our legitimate interests in operating a website. Analytics is measured without cookies or persistent identifiers.
Answering enquiries and providing support.
Replying to you and keeping a record of what was discussed. Our legitimate interests in responding to people who contact us, or steps you request before entering into a contract where you would personally be a party to it.
Administering and verifying licences.
Issuing, renewing and revoking subscriptions, confirming a licence is live, and noticing where one key is used across unrelated networks. Where you are personally a party to the contract, necessary processing relies on performance of that contract. For organisation contacts, we rely on our legitimate interests in administering the organisation’s licence. We also rely on our legitimate interests in preventing licence misuse.
Keeping backups.
Holding an encrypted copy of our operational records so they survive a failure. Our legitimate interests in continuity and recovery.
We do not rely on consent for these activities. You can object to processing based on legitimate interests, as explained below. We do not use personal information for profiling or solely automated decisions with legal or similarly significant effects on individuals. Licence status and misuse checks are automated as described elsewhere in this notice. We do not sell your information or use it for marketing.
Your rights
You can ask for a copy of the information we hold about you, ask us to correct it if it is wrong, delete it, restrict what we do with it, or provide it in a portable form. You can object to processing we carry out under legitimate interests. These rights are subject to the conditions in the legislation, and we will explain any applicable limits.
Email support@nyxus.co.uk. We respond without undue delay, normally within one month. If a permitted extension is necessary, we will explain why within the applicable initial deadline. We may need information to verify your identity.
If your information is held inside a deployment run by one of our customers, we cannot access it. That data stays in their infrastructure and they decide what happens to it — contact that organisation directly.
If you are unhappy with how we have handled your information, you can complain to the Information Commissioner’s Office. You are welcome to contact us first so we can try to put it right, but you do not have to do so before complaining to the ICO.
Your information.
A clear account.
What happens when you visit the website, get in touch or use a Nyxus licence.
READ THE NOTICE ↓Aman Karir, operating as Nyxus.
Nyxus is operated by Aman Karir, who is the data controller for the information described in this notice. For questions about this notice or your information, email support@nyxus.co.uk.
This notice covers the website, previews, correspondence and licence administration. Customers operate the self-hosted product in their own environments and are responsible for the information they process there.
When you visit the website.
Framer hosts nyxus.co.uk directly. Cloudflare provides DNS for this domain, rather than proxying the website. Hosting providers process network information, including IP addresses, to deliver requests.
Framer Analytics is active. Framer states that it uses neither cookies nor persistent identifiers. It hashes IP addresses and user agents using a daily rotating salt, which is reset and deleted each day, to calculate daily unique visitors. The published-site audit observed no cookies on the pages checked; this is not a guarantee about every provider or future configuration. Read Framer’s explanation.
Analytics reports include pageviews, unique and live visitor counts, bounce rate, average session duration, traffic sources, UTM parameters, referring sites, top pages, country, device type and browser. Framer describes country, device and referral information as estimates derived from browser-provided information. How Framer Analytics works.
Our website includes a preconnect hint to Google's font CDN but loads no fonts from it.
Framer does not publish a retention period for site analytics data in the documentation reviewed for this notice. Framer’s published privacy statement describes processing in the United States, with Standard Contractual Clauses and Data Privacy Framework arrangements covering international transfers.
Trying the preview.
Cloudflare Pages hosts preview.nyxus.co.uk. The preview uses bundled example data without a live application backend or visitor sign-in. Values entered into the demo stay in browser memory and are discarded on reload.
Cloudflare Web Analytics is not enabled on the preview, which makes no third-party requests. Browser storage remembers interface preferences, such as the selected colour. Cloudflare still processes visitor network information to serve the preview. Do not enter real credentials or sensitive information into a demonstration.
No log export is configured for our Cloudflare services. Cloudflare’s own retention of network information is governed by its privacy policy, which does not state a fixed period for these services.
Information you choose to send.
Contact is by email, not a website form. Zoho Mail, in the EU region, handles support@nyxus.co.uk. Correspondence includes your email address, name if supplied, message and any attachments you choose to send.
These details are used to answer enquiries and provide basic support. Customer environments are not managed or accessed by Nyxus. Please remove credentials and unnecessary personal information from screenshots and diagnostic material before sending them.
Report vulnerabilities through the private GitHub security advisory channel, not email or public issues.
We delete general enquiry correspondence 12 months after the last meaningful exchange and support correspondence 12 months after the case is closed. Deletion is carried out manually rather than automatically.
Deleted mail moves to Trash. Our cleanup interval is five days and is based on the message’s received date, so older correspondence may leave Trash sooner. Under Zoho’s standard deletion process, mail is then retained for a further 30 days for recovery before permanent purge: an outer window of up to 35 further days with this setting, rather than a fixed delay. Separate archival or eDiscovery policies, if applicable, can retain copies beyond this window. Zoho’s deletion and retention policy.
Your estate stays in your environment.
Findings, device records, people and tool names remain in customer infrastructure. The product does not send this estate information to Nyxus and has no product analytics or crash reporting. Customer-configured connectors communicate with their respective services from the customer’s environment.
Subscription checks and update requests are separate. Update requests include the installed version in the user agent. The budget view can request exchange rates from a third-party service using a currency code; the receiving service also necessarily processes the request’s network information.
Customer backups are encrypted with a customer-held key and written to customer-owned storage. Nyxus does not hold those backups. Information a customer voluntarily sends for support is handled as correspondence.
What the registry receives.
Every six hours, a subscription check sends a subscription reference, a twelve-character licence-key fingerprint, a random installation identifier and a fresh nonce. Cloudflare receives the source IP as part of the request.
Image and chart pulls authenticate using the signed licence key. It includes the organisation name entered during licence provisioning; the name is not discovered from the customer’s estate. It is returned inside the credential during pull authentication, not as a field in the six-hourly subscription check.
The registry stores licence status, organisation name, fingerprint, plan and deployment-related records. Network identifiers (ASNs), derived from request IPs, are recorded on image/chart pulls only.
Production Worker Logs and Traces are disabled, with no telemetry export destinations or stored Worker console logs configured. Console output can be viewed during a live tail session. Operational log statements no longer include organisation names; they can include subscription references, fingerprints and ASNs. Cloudflare still processes network information to operate its services.
Deletion follows the current operating process.
We keep a record of each licence issued, including its reference, the organisation name supplied at provisioning, key fingerprint, plan and deployment records. Network records help identify a key being used to pull software from unrelated networks. Licence records have no automatic expiry. Revoked subscriptions are closed at the next quarterly review, carried out by the operator of this service. Closure deletes both the licence and network records and verifies their removal from the store.
Network records expire 90 days after their last successful write. Successful image/chart pulls refresh this expiry. Entries for networks not seen for more than 90 days are pruned on a subsequent pull; individual entries are not guaranteed to disappear at the exact 90-day point.
Encrypted copies across two providers.
Administrative backups include signing material and licence records, not customer estate backups. One encrypted archive is kept on the working machine, with copies stored with two cloud providers for redundancy.
The archive uses AES-256 encryption with an operator-held passphrase. Each new archive is checked by restoring it before replacement. The plaintext snapshot is removed after verification.
Closing a subscription refreshes the snapshot used for subsequent backups. Previously created local or cloud archives can still contain the record until replaced. Cloud copies require a fresh manual upload; deletion does not propagate to them automatically.
Local and cloud archives are replaced at the quarterly review following a deletion. Deleted cloud files remain subject to the providers’ 30-day recovery periods. Previous file versions follow provider-specific rules; no fixed deletion period is stated for uploaded-file version history. Replacement of the current archive does not imply immediate deletion of every recoverable copy.
Where services are involved.
- Framer
- Website hosting, assets and built-in analytics. Framer uses US hosting with global edge infrastructure; an edge location does not establish data residency.
- Cloudflare
- DNS, static preview hosting and the registry Worker with KV storage.
- Zoho
- Email correspondence. Service data for our EU-region account is stored within the EU.
- GitHub
- Container image storage and private vulnerability disclosures.
- Encrypted administrative archives. The website also includes a preconnect hint to Google’s font CDN, but loads no fonts from it.
- Apple
- Encrypted administrative archives.
These providers are listed by their actual role. Encryption of archives does not remove them from this description. Cloudflare publishes a Data Processing Addendum covering Standard Contractual Clauses and Data Privacy Framework arrangements. GitHub publishes a Data Protection Agreement covering Standard Contractual Clauses and Data Privacy Framework arrangements. Framer’s published privacy statement describes processing in the United States and international-transfer arrangements. Framer privacy statement.
A UK Data Processing Addendum has been submitted to Zoho in the name of the individual operating Nyxus. It is awaiting Zoho’s legal review and countersignature; it is not yet described as an agreement in place.
The archive held with these two providers is encrypted before it leaves our machine, using a passphrase held only by us. Neither provider holds the passphrase needed to decrypt the archive. These are personal cloud storage accounts rather than business agreements.
Why we hold information, and what you can ask of us.
Nyxus is self-hosted, so findings, devices, people and tool names stay in our customers’ own infrastructure. The product does not send us estate information. Information you choose to send for support is handled as correspondence.
What we hold is this:
- Correspondence from people who email us: your address, your name if you give it, your message and anything you attach.
- A record of each licence we have issued, naming the organisation supplied at provisioning, along with its reference, a fingerprint of the key, the plan and which installations hold it.
- Network information our providers process to deliver a page or a message, and the networks a licence pulls software from. Website analytics are described in Section 02.
We use it for four purposes, and rely on the following bases in law.
Running the website and the preview.
Delivering pages and understanding in aggregate how the site is used. Our legitimate interests in operating a website. Analytics is measured without cookies or persistent identifiers.
Answering enquiries and providing support.
Replying to you and keeping a record of what was discussed. Our legitimate interests in responding to people who contact us, or steps you request before entering into a contract where you would personally be a party to it.
Administering and verifying licences.
Issuing, renewing and revoking subscriptions, confirming a licence is live, and noticing where one key is used across unrelated networks. Where you are personally a party to the contract, necessary processing relies on performance of that contract. For organisation contacts, we rely on our legitimate interests in administering the organisation’s licence. We also rely on our legitimate interests in preventing licence misuse.
Keeping backups.
Holding an encrypted copy of our operational records so they survive a failure. Our legitimate interests in continuity and recovery.
We do not rely on consent for these activities. You can object to processing based on legitimate interests, as explained below. We do not use personal information for profiling or solely automated decisions with legal or similarly significant effects on individuals. Licence status and misuse checks are automated as described elsewhere in this notice. We do not sell your information or use it for marketing.
Your rights
You can ask for a copy of the information we hold about you, ask us to correct it if it is wrong, delete it, restrict what we do with it, or provide it in a portable form. You can object to processing we carry out under legitimate interests. These rights are subject to the conditions in the legislation, and we will explain any applicable limits.
Email support@nyxus.co.uk. We respond without undue delay, normally within one month. If a permitted extension is necessary, we will explain why within the applicable initial deadline. We may need information to verify your identity.
If your information is held inside a deployment run by one of our customers, we cannot access it. That data stays in their infrastructure and they decide what happens to it — contact that organisation directly.
If you are unhappy with how we have handled your information, you can complain to the Information Commissioner’s Office. You are welcome to contact us first so we can try to put it right, but you do not have to do so before complaining to the ICO.
Your information.
A clear account.
What happens when you visit the website, get in touch or use a Nyxus licence.
READ THE NOTICE ↓Aman Karir, operating as Nyxus.
Nyxus is operated by Aman Karir, who is the data controller for the information described in this notice. For questions about this notice or your information, email support@nyxus.co.uk.
This notice covers the website, previews, correspondence and licence administration. Customers operate the self-hosted product in their own environments and are responsible for the information they process there.
When you visit the website.
Framer hosts nyxus.co.uk directly. Cloudflare provides DNS for this domain, rather than proxying the website. Hosting providers process network information, including IP addresses, to deliver requests.
Framer Analytics is active. Framer states that it uses neither cookies nor persistent identifiers. It hashes IP addresses and user agents using a daily rotating salt, which is reset and deleted each day, to calculate daily unique visitors. The published-site audit observed no cookies on the pages checked; this is not a guarantee about every provider or future configuration. Read Framer’s explanation.
Analytics reports include pageviews, unique and live visitor counts, bounce rate, average session duration, traffic sources, UTM parameters, referring sites, top pages, country, device type and browser. Framer describes country, device and referral information as estimates derived from browser-provided information. How Framer Analytics works.
Our website includes a preconnect hint to Google's font CDN but loads no fonts from it.
Framer does not publish a retention period for site analytics data in the documentation reviewed for this notice. Framer’s published privacy statement describes processing in the United States, with Standard Contractual Clauses and Data Privacy Framework arrangements covering international transfers.
Trying the preview.
Cloudflare Pages hosts preview.nyxus.co.uk. The preview uses bundled example data without a live application backend or visitor sign-in. Values entered into the demo stay in browser memory and are discarded on reload.
Cloudflare Web Analytics is not enabled on the preview, which makes no third-party requests. Browser storage remembers interface preferences, such as the selected colour. Cloudflare still processes visitor network information to serve the preview. Do not enter real credentials or sensitive information into a demonstration.
No log export is configured for our Cloudflare services. Cloudflare’s own retention of network information is governed by its privacy policy, which does not state a fixed period for these services.
Information you choose to send.
Contact is by email, not a website form. Zoho Mail, in the EU region, handles support@nyxus.co.uk. Correspondence includes your email address, name if supplied, message and any attachments you choose to send.
These details are used to answer enquiries and provide basic support. Customer environments are not managed or accessed by Nyxus. Please remove credentials and unnecessary personal information from screenshots and diagnostic material before sending them.
Report vulnerabilities through the private GitHub security advisory channel, not email or public issues.
We delete general enquiry correspondence 12 months after the last meaningful exchange and support correspondence 12 months after the case is closed. Deletion is carried out manually rather than automatically.
Deleted mail moves to Trash. Our cleanup interval is five days and is based on the message’s received date, so older correspondence may leave Trash sooner. Under Zoho’s standard deletion process, mail is then retained for a further 30 days for recovery before permanent purge: an outer window of up to 35 further days with this setting, rather than a fixed delay. Separate archival or eDiscovery policies, if applicable, can retain copies beyond this window. Zoho’s deletion and retention policy.
Your estate stays in your environment.
Findings, device records, people and tool names remain in customer infrastructure. The product does not send this estate information to Nyxus and has no product analytics or crash reporting. Customer-configured connectors communicate with their respective services from the customer’s environment.
Subscription checks and update requests are separate. Update requests include the installed version in the user agent. The budget view can request exchange rates from a third-party service using a currency code; the receiving service also necessarily processes the request’s network information.
Customer backups are encrypted with a customer-held key and written to customer-owned storage. Nyxus does not hold those backups. Information a customer voluntarily sends for support is handled as correspondence.
What the registry receives.
Every six hours, a subscription check sends a subscription reference, a twelve-character licence-key fingerprint, a random installation identifier and a fresh nonce. Cloudflare receives the source IP as part of the request.
Image and chart pulls authenticate using the signed licence key. It includes the organisation name entered during licence provisioning; the name is not discovered from the customer’s estate. It is returned inside the credential during pull authentication, not as a field in the six-hourly subscription check.
The registry stores licence status, organisation name, fingerprint, plan and deployment-related records. Network identifiers (ASNs), derived from request IPs, are recorded on image/chart pulls only.
Production Worker Logs and Traces are disabled, with no telemetry export destinations or stored Worker console logs configured. Console output can be viewed during a live tail session. Operational log statements no longer include organisation names; they can include subscription references, fingerprints and ASNs. Cloudflare still processes network information to operate its services.
Deletion follows the current operating process.
We keep a record of each licence issued, including its reference, the organisation name supplied at provisioning, key fingerprint, plan and deployment records. Network records help identify a key being used to pull software from unrelated networks. Licence records have no automatic expiry. Revoked subscriptions are closed at the next quarterly review, carried out by the operator of this service. Closure deletes both the licence and network records and verifies their removal from the store.
Network records expire 90 days after their last successful write. Successful image/chart pulls refresh this expiry. Entries for networks not seen for more than 90 days are pruned on a subsequent pull; individual entries are not guaranteed to disappear at the exact 90-day point.
Encrypted copies across two providers.
Administrative backups include signing material and licence records, not customer estate backups. One encrypted archive is kept on the working machine, with copies stored with two cloud providers for redundancy.
The archive uses AES-256 encryption with an operator-held passphrase. Each new archive is checked by restoring it before replacement. The plaintext snapshot is removed after verification.
Closing a subscription refreshes the snapshot used for subsequent backups. Previously created local or cloud archives can still contain the record until replaced. Cloud copies require a fresh manual upload; deletion does not propagate to them automatically.
Local and cloud archives are replaced at the quarterly review following a deletion. Deleted cloud files remain subject to the providers’ 30-day recovery periods. Previous file versions follow provider-specific rules; no fixed deletion period is stated for uploaded-file version history. Replacement of the current archive does not imply immediate deletion of every recoverable copy.
Where services are involved.
- Framer
- Website hosting, assets and built-in analytics. Framer uses US hosting with global edge infrastructure; an edge location does not establish data residency.
- Cloudflare
- DNS, static preview hosting and the registry Worker with KV storage.
- Zoho
- Email correspondence. Service data for our EU-region account is stored within the EU.
- GitHub
- Container image storage and private vulnerability disclosures.
- Encrypted administrative archives. The website also includes a preconnect hint to Google’s font CDN, but loads no fonts from it.
- Apple
- Encrypted administrative archives.
These providers are listed by their actual role. Encryption of archives does not remove them from this description. Cloudflare publishes a Data Processing Addendum covering Standard Contractual Clauses and Data Privacy Framework arrangements. GitHub publishes a Data Protection Agreement covering Standard Contractual Clauses and Data Privacy Framework arrangements. Framer’s published privacy statement describes processing in the United States and international-transfer arrangements. Framer privacy statement.
A UK Data Processing Addendum has been submitted to Zoho in the name of the individual operating Nyxus. It is awaiting Zoho’s legal review and countersignature; it is not yet described as an agreement in place.
The archive held with these two providers is encrypted before it leaves our machine, using a passphrase held only by us. Neither provider holds the passphrase needed to decrypt the archive. These are personal cloud storage accounts rather than business agreements.
Why we hold information, and what you can ask of us.
Nyxus is self-hosted, so findings, devices, people and tool names stay in our customers’ own infrastructure. The product does not send us estate information. Information you choose to send for support is handled as correspondence.
What we hold is this:
- Correspondence from people who email us: your address, your name if you give it, your message and anything you attach.
- A record of each licence we have issued, naming the organisation supplied at provisioning, along with its reference, a fingerprint of the key, the plan and which installations hold it.
- Network information our providers process to deliver a page or a message, and the networks a licence pulls software from. Website analytics are described in Section 02.
We use it for four purposes, and rely on the following bases in law.
Running the website and the preview.
Delivering pages and understanding in aggregate how the site is used. Our legitimate interests in operating a website. Analytics is measured without cookies or persistent identifiers.
Answering enquiries and providing support.
Replying to you and keeping a record of what was discussed. Our legitimate interests in responding to people who contact us, or steps you request before entering into a contract where you would personally be a party to it.
Administering and verifying licences.
Issuing, renewing and revoking subscriptions, confirming a licence is live, and noticing where one key is used across unrelated networks. Where you are personally a party to the contract, necessary processing relies on performance of that contract. For organisation contacts, we rely on our legitimate interests in administering the organisation’s licence. We also rely on our legitimate interests in preventing licence misuse.
Keeping backups.
Holding an encrypted copy of our operational records so they survive a failure. Our legitimate interests in continuity and recovery.
We do not rely on consent for these activities. You can object to processing based on legitimate interests, as explained below. We do not use personal information for profiling or solely automated decisions with legal or similarly significant effects on individuals. Licence status and misuse checks are automated as described elsewhere in this notice. We do not sell your information or use it for marketing.
Your rights
You can ask for a copy of the information we hold about you, ask us to correct it if it is wrong, delete it, restrict what we do with it, or provide it in a portable form. You can object to processing we carry out under legitimate interests. These rights are subject to the conditions in the legislation, and we will explain any applicable limits.
Email support@nyxus.co.uk. We respond without undue delay, normally within one month. If a permitted extension is necessary, we will explain why within the applicable initial deadline. We may need information to verify your identity.
If your information is held inside a deployment run by one of our customers, we cannot access it. That data stays in their infrastructure and they decide what happens to it — contact that organisation directly.
If you are unhappy with how we have handled your information, you can complain to the Information Commissioner’s Office. You are welcome to contact us first so we can try to put it right, but you do not have to do so before complaining to the ICO.