NexusBOS

Legal

Privacy Policy

Last updated: 1 July 2026

1. Who we are

NexusBOS ("we", "us") provides a multi-tenant business operating system delivered as web, desktop and mobile applications. This policy explains what we collect, why, and the rights you have over it.

2. What we collect

3. How we protect it

All traffic is encrypted with TLS. Tenant data is isolated with PostgreSQL row-level security enforced by a non-superuser database role. Access inside the platform is controlled by role-based permissions, two-factor authentication is available, secrets are encrypted at rest, and every sensitive action is written to an append-only audit log.

4. Sharing

We do not sell your data. We share it only with processors required to run the service (hosting, payment providers such as PayHere, email delivery) under data-processing agreements, or when required by law.

5. Retention & your rights

Business data is retained while your subscription is active and for a limited period after cancellation so you can export it. You may request access, correction, export or deletion of your personal data at any time — the platform includes built-in data-subject request (DSAR) tooling, or you can email support@nexusbos.lk.

6. Cookies

The website uses only functional storage (your theme preference and session). We do not run third-party advertising trackers.

7. Changes

We will notify account owners by email of material changes to this policy at least 14 days before they take effect.