top of page

NIES MASTER PRIVACY POLICY

Effective date: 7 August 2026
Last updated: 7 August 2026

1. Who We Are

This Privacy Policy explains how NEXUS INDUSTRY ENGINEERING SERVICES LTD, trading as NEXUS INDUSTRIAL ENGINEERING SERVICES and NIES ("NIES", "we", "us" or "our"), collects, uses, stores, protects and otherwise processes personal information and customer data.

Company details

Registered company: NEXUS INDUSTRY ENGINEERING SERVICES LTD

  • Trading names: NEXUS INDUSTRIAL ENGINEERING SERVICES / NIES
  • Registered in England & Wales

  • Company number: 16954667

  • Registered office: Thornton-Cleveleys, Lancashire, FY5, United Kingdom

  • Privacy contact: contact@nexus-ies.co.uk

  • ICO registration reference: ZC217339

  • ICO registration application submitted and paid; final registration details are pending.

NIES has not currently appointed a formal Data Protection Officer. Privacy and data-protection enquiries should be sent to contact@nexus-ies.co.uk.

2. Scope of This Privacy Policy

This is the master Privacy Policy for NIES.

It applies, where referenced, to NIES-operated websites, software, applications and services, including:

  • The NIES corporate website;

  • NIES website accounts;

  • The NIES support portal;

  • PanelGuard;

  • panelguard.app;

  • panelguard.vercel.app;

  • nexuspanelguard.com;

  • PanelGuard mobile and web applications;

  • IRIS AI functionality;

  • Other NIES-owned software products;

  • Future NIES web and mobile applications;

  • Bespoke/custom software developed, hosted and operated by NIES for customers;

  • Associated support, hosting and cloud services.

Additional contractual terms, Data Processing Agreements or product-specific privacy information may supplement this policy where necessary.

3. Our Commitment to Customer and Industrial Data

NIES provides software and engineering technology to industrial and commercial organisations. We recognise that information entrusted to our systems may be commercially sensitive even where it is not legally classified as personal data.

NIES therefore treats customer operational and technical information as confidential customer data.

This may include:

  • Electrical drawings and schematics;

  • Engineering drawings;

  • Factory photographs;

  • Machinery information;

  • Equipment and asset records;

  • Electrical panel information;

  • Inspection records;

  • Maintenance history;

  • Defect information;

  • Actions and corrective work;

  • Reports;

  • Technical documentation;

  • Uploaded files;

  • Production-related technical information;

  • Parts information;

  • Site and facility information;

  • Customer-generated analytics;

  • Other commercially sensitive operational information.

Our core principles are:

  • Customers retain ownership of the customer and operational data they provide to NIES.

  • NIES does not claim ownership of customer operational data.

  • NIES does not sell customer data.

  • NIES does not provide customer data to unrelated third parties for their own advertising or marketing.

  • Identifiable customer data is not used to train NIES or third-party AI models.

  • Customer data is accessed by NIES personnel only where there is an appropriate operational, support, security, maintenance or legal reason.

  • Customer organisations are logically separated so users from one organisation are not authorised to access another organisation's workspace.

  • Confidentiality obligations continue after the customer relationship ends.

These principles apply to NIES standard software products and NIES-hosted bespoke software.

4. Our Role Under Data Protection Law

Depending on the circumstances, NIES may act as either a Data Controller or Data Processor.

Where NIES is a Data Controller

NIES will generally act as a Data Controller for personal information processed for its own purposes, including:

  • NIES website accounts;

  • Direct business enquiries;

  • Sales contacts;

  • Marketing;

  • Account administration where applicable;

  • Billing and accounting;

  • Security;

  • NIES support administration;

  • Website analytics;

  • Legal and regulatory compliance;

  • NIES's own business operations.

Where NIES is a Data Processor

Where a business customer uses PanelGuard or another NIES-hosted system to process information relating to its employees or other individuals:

  • The customer will generally be the Data Controller.

  • NIES will generally be the Data Processor.

  • The customer determines why the information is being processed.

  • NIES processes the information to provide the contracted service and in accordance with the customer's instructions and applicable law.

NIES can provide a Data Processing Agreement (DPA) to business customers where appropriate.

5. Information We May Collect

Depending on how you interact with NIES, we may process the following information.

Account and Profile Information

This may include:

  • Full name;

  • Email address;

  • Company email address;

  • Telephone number;

  • Job title or position;

  • Company or organisation;

  • Profile photograph;

  • Account role and permissions.

Authentication Information

NIES software may use:

  • Email address and password authentication;

  • Google sign-in;

  • Microsoft sign-in.

Authentication infrastructure may be provided through services such as Supabase and relevant identity providers.

NIES does not require access to a user's plaintext password.

Website Enquiry Information

When someone contacts NIES, requests information, submits an enquiry or requests support, we may collect:

  • Name;

  • Company;

  • Position/job title;

  • Email address;

  • Telephone number;

  • Message or enquiry contents.

Customer Operational Data

Our software may process information including:

  • Sites and facilities;

  • Areas;

  • Equipment;

  • Electrical panels;

  • Inspection answers;

  • Inspection results;

  • Reports;

  • Maintenance actions;

  • Defects;

  • Corrective actions;

  • Engineer/user attribution;

  • Notes and comments;

  • Parts information;

  • Photographs;

  • Attachments;

  • Audit history;

  • Dates and timestamps;

  • Customer-generated analytics;

  • Other records entered by authorised users.

Some of this information is purely business information. However, where it identifies or relates to an individual, it may constitute personal data.

Support Information

When customers contact NIES for support, we may process:

  • Support emails;

  • Support tickets;

  • Screenshots;

  • Photographs;

  • PDFs;

  • Technical drawings;

  • Diagnostic information;

  • Error descriptions;

  • Error logs;

  • Documents supplied by customers;

  • Correspondence concerning resolution of an issue.

Technical and Diagnostic Information

NIES may collect limited technical information necessary to operate, secure and troubleshoot its services, including:

  • Browser type/version;

  • Device type;

  • Operating system;

  • Application version;

  • IP address;

  • Login information;

  • Error messages;

  • Crash information;

  • Timestamps;

  • Affected feature;

  • Technical logs;

  • Relevant account identifiers.

NIES does not use this as permission to indiscriminately access unrelated information stored on a user's device.

6. Information We Do Not Intentionally Collect

NIES products are not designed to collect special-category personal information such as:

  • Health information;

  • Racial or ethnic origin;

  • Religious beliefs;

  • Political opinions;

  • Trade-union membership;

  • Sexual orientation;

  • Sex-life information;

  • Biometric information used for identification.

Users should not enter such information unless a future NIES service specifically requires it and appropriate safeguards have been implemented.

Users should also avoid entering unnecessary personal information, passwords, financial credentials, authentication details or other highly sensitive information into:

  • Notes;

  • Comments;

  • Action descriptions;

  • Support messages;

  • Free-text fields;

  • IRIS prompts.

7. How We Collect Information

Information may be collected:

  • Directly from you;

  • When you create a website account;

  • When a customer organisation creates your software account;

  • When you update your profile;

  • When you use NIES software;

  • When you perform inspections or actions;

  • When you upload photographs or documents;

  • When you communicate through NIES systems;

  • When you contact NIES support;

  • When you submit an enquiry;

  • Through authorised customer administrators;

  • Through authentication providers;

  • Through cookies and analytics technologies;

  • Through technical logs generated when our services operate.

8. Account Creation

On the NIES website, individual users may create their own accounts.

Website accounts may currently be used to:

  • Manage enquiries;

  • Access authorised downloads/documents;

  • Access the NIES support portal.

For commercial NIES software:

  • NIES generally establishes the customer organisation and initial user account(s).

  • Customers may subsequently create additional authorised user accounts in accordance with their subscription or licensing agreement.

NIES software accounts are intended to be assigned to individual authorised users.

Customers should not use generic or shared accounts where this would compromise security or audit traceability.

9. How We Use Personal Information

  • Provide contracted software and services;

  • Create and administer accounts;

  • Authenticate users;

  • Operate NIES websites and applications;

  • Provide customer support;

  • Investigate technical problems;

  • Maintain databases and infrastructure;

  • Generate reports;

  • Provide customer analytics;

  • Process inspections and maintenance records;

  • Deliver IRIS functionality;

  • Maintain audit trails;

  • Protect customer information;

  • Detect and investigate security incidents;

  • Prevent unauthorised access;

  • Improve NIES services;

  • Communicate with customers;

  • Send necessary service notifications;

  • Administer billing;

  • Maintain business and accounting records;

  • Meet legal or regulatory requirements;

  • Establish, exercise or defend legal claims;

  • Send marketing where permitted by law.

10. Lawful Bases for Processing

Where NIES acts as Data Controller, we process personal information only where we have an appropriate legal basis.Depending on the processing, this may include:

Contract

Where processing is necessary to provide a service, administer an account or fulfil contractual obligations.

Legitimate Interests

  • Where necessary for legitimate business purposes such as:

  • Operating and improving our services;

  • Protecting our systems;

  • Preventing fraud or abuse;

  • Providing appropriate customer support;

  • Communicating with business customers;

  • Maintaining service security.

  • We will consider individuals' rights and interests when relying on legitimate interests.

  • Legal Obligation

  • Where processing is necessary to comply with applicable law, regulatory obligations, accounting requirements or lawful orders.

  • Consent

  • Where consent is legally required, including certain:

  • Marketing activities;

  • Non-essential cookies;

  • Optional functionality.

  • Consent can be withdrawn where applicable.

11. Website Accounts and Privacy Acknowledgement

Where appropriate, users creating NIES accounts will be presented with links to:

  • This Privacy Policy;

  • Applicable Terms & Conditions.

Creating an account may require agreement to applicable contractual terms and acknowledgement of this Privacy Policy.

Marketing consent will be handled separately where required and will not be made a condition of creating an ordinary account where it is not necessary for the service.

12. IRIS and Artificial Intelligence

NIES provides AI-assisted functionality through IRIS.

IRIS currently uses the OpenAI API to process relevant requests.

IRIS Data Access

IRIS is designed to operate within a user's existing permissions.

This means:

  • IRIS should not provide users with information they are not otherwise authorised to access.

  • Users' access remains subject to organisation, role and permission controls.

  • NIES aims to minimise the information provided for AI processing to what is reasonably necessary to fulfil the request.

IRIS Conversation Storage

IRIS conversations are intended to exist only for the current user session and are not retained by NIES as persistent chat history.

Information may nevertheless need to be processed temporarily to generate and deliver the requested response and may be subject to limited technical/security processing by relevant service providers.

AI Training

NIES does not use identifiable:

  • Customer data;

  • Factory data;

  • Inspection records;

  • Photographs;

  • Reports;

  • Maintenance records;

  • Technical drawings;

  • Confidential customer information;

  • IRIS conversations

to train NIES or third-party AI models.

AI Human Oversight

IRIS is an assistive tool, not an autonomous decision-maker.

IRIS may:

  • Analyse information;

  • Summarise records;

  • Identify patterns;

  • Assist with searches;

  • Generate reports or drafts;

  • Provide recommendations.

AI-generated information may occasionally be incomplete or inaccurate.

Users must verify important information before relying upon it, particularly where decisions concern:

  • Engineering;

  • Electrical safety;

  • Mechanical safety;

  • Maintenance;

  • Compliance;

  • Personnel;

  • Business-critical operations.

NIES AI functionality is not intended to make significant employment or other similarly consequential decisions about individuals without appropriate human judgement and oversight.

13. Anonymised and Aggregated Information

NIES may create and use aggregated or properly anonymised information to:

  • Understand product usage;

  • Analyse trends;

  • Improve software;

  • Develop new functionality;

  • Improve workflows;

  • Measure service performance.

Such information must not reasonably identify an individual customer, factory, employee or specific confidential record.

Anonymised/aggregated analytics are separate from using identifiable customer information for AI training.

14. Camera and Photograph Access

NIES applications may request permission to access:

  • A device camera;

  • Existing photographs/photo libraries.

This may allow users to capture or upload evidence relating to:

  • Equipment;

  • Inspections;

  • Defects;

  • Maintenance;

  • Repairs;

  • Completed work.

Users should primarily photograph relevant equipment or work and should avoid deliberately capturing identifiable individuals unless there is a genuine and lawful business need.

Where people are incidentally captured, the image remains subject to applicable access controls and customer-data protections.

NIES does not currently require GPS/location tracking for its software and does not currently use background location tracking.

NIES does not currently require microphone access or collect voice recordings for IRIS.

15. Communications and Notifications

NIES software may provide service communications through:

  • In-app notifications;

  • Email;

  • Mobile push notifications where supported in future.

These may include:

  • Action assignments;

  • Inspection reminders;

  • Overdue inspection alerts;

  • Parts notifications;

  • Report notifications;

  • Account notices;

  • Security alerts;

  • System updates;

  • Other service-related communications.

Customers may also use NIES systems to send authorised internal messages, assignments, notes or notifications to their users.

Necessary service communications are separate from optional marketing communications.

16. Marketing

NIES may send information about its own products and services where legally permitted.

This may include:

  • Product updates;

  • New NIES software;

  • New features;

  • Offers;

  • News;

  • Relevant services;

  • Follow-ups to enquiries.

Recipients can opt out of marketing communications.

Opting out of marketing will not prevent necessary communications relating to:

  • Security;

  • Accounts;

  • Passwords;

  • Billing;

  • Assigned actions;

  • Inspections;

  • Service operation;

  • Other essential service matters.

NIES does not sell customer information or provide it to unrelated third parties for their own marketing purposes.

17. Cookies and Similar Technologies

NIES websites may use cookies and similar technologies for:

  • Authentication;

  • Security;

  • Remembering preferences;

  • Website functionality;

  • Performance;

  • Analytics;

  • Marketing and advertising.

Where required by law, non-essential analytics and advertising cookies will only be activated after appropriate consent has been obtained.

Users will be provided with appropriate mechanisms to manage or withdraw cookie preferences.

A separate Cookie Policy may provide additional detail.

18. Website and Product Analytics

NIES may use analytics to understand how its websites and services perform.

This may include:

  • NIES website analytics;

  • Vercel analytics and technical/performance information;

  • Other appropriately configured analytics services.

Analytics may be used to improve:

  • Website usability;

  • Performance;

  • Reliability;

  • Product design;

  • Security.

Operational analytics generated inside customer software are intended to be visible only to appropriately authorised users of that customer organisation.

They are not generated for third-party advertising purposes.

19. Payments and Billing

NIES may accept payment through:

  • Direct Debit;

  • Invoice;

  • Bank transfer.

Information necessary to establish or administer a Direct Debit may be processed where permitted and necessary.

Payment information will not be retained longer than necessary for that purpose unless NIES has another lawful requirement to retain it.

Where a Direct Debit is cancelled, information that is no longer operationally or legally required will be deleted in accordance with our retention practices.

Invoices, accounting records and transaction records may need to be retained for longer where required by law.

20. Cloud Infrastructure and Service Providers

NIES uses third-party infrastructure and service providers to operate its services.

Current or anticipated providers may include:

  • Supabase;

  • Vercel;

  • OpenAI;

  • Amazon Web Services (AWS);

  • Google cloud/storage services;

  • Authentication providers;

  • Email delivery providers;

  • Analytics providers;

  • Other vetted infrastructure providers.

NIES intends to maintain a current subprocessor/service-provider list separately so customers can understand which providers support NIES services.

Service providers are only permitted to process information as appropriate to provide their contracted services and subject to applicable contractual and data-protection requirements.

21. International Data Transfers

Some service providers may process information outside the United Kingdom.

Where personal information is transferred internationally, NIES will use an appropriate lawful transfer mechanism where required, which may include:

  • UK adequacy regulations;

  • Approved contractual safeguards;

  • Other mechanisms recognised by applicable UK data-protection law.

NIES will prefer UK or UK/EU hosting regions where reasonably available and commercially practical, but does not guarantee that all information will always be physically processed exclusively within the UK.

22. Organisation and Tenant Isolation

NIES operates business software using organisation-level access controls.

Users should only be able to access:

  • Organisations they are authorised to access;

  • Records permitted by their role;

  • Functions permitted by their assigned permissions.

Users from one customer organisation are not authorised to access another customer's:

  • Panels;

  • Equipment;

  • Reports;

  • Inspections;

  • Users;

  • Messages;

  • Actions;

  • Documents;

  • Photographs;

  • Analytics;

  • Other confidential information.

NIES authorised support access is a controlled exception and may occur only for appropriate purposes described in this policy.

23. Access by NIES Personnel

Authorised NIES personnel may access customer information where reasonably necessary for:

  • Technical support;

  • Troubleshooting;

  • Security investigations;

  • Database problems;

  • System maintenance;

  • Resolving faults;

  • Assisting the customer;

  • Meeting legal obligations.

NIES aims to follow least-privilege access principles.

Employees, developers, engineers, contractors and subcontractors authorised to access confidential customer information must be subject to appropriate confidentiality obligations and should receive only the access reasonably necessary for their role.

24. Customer Administrators

Customer administrators/managers may be able to access information about users within their organisation, including:

  • Names;

  • Job titles;

  • Roles;

  • Assigned actions;

  • Completed actions;

  • Inspections;

  • Activity history;

  • Audit information;

  • Operational performance information.

Customers are responsible for ensuring their use of employee information is lawful, fair and appropriately communicated to affected employees.

NIES software must not be used as an unlawful or covert employee-surveillance system.

25. Customer Responsibilities

Where a customer acts as Data Controller, it is responsible for:

  • Having an appropriate lawful basis for personal information it enters into NIES software;

  • Providing appropriate privacy information to its employees/users;

  • Ensuring uploaded information is lawful;

  • Maintaining accurate user information;

  • Removing or restricting accounts when employees leave;

  • Updating permissions when roles change;

  • Protecting exported information;

  • Using employee analytics lawfully;

  • Managing its authorised users appropriately.

Customers should not upload information they do not have the legal right or authority to process.

26. User Security Responsibilities

Users must take reasonable steps to protect their accounts and devices.

This includes:

  • Keeping credentials confidential;

  • Not sharing individual accounts;

  • Using appropriately secured devices;

  • Keeping relevant software reasonably up to date;

  • Reporting suspected account compromise;

  • Not attempting to bypass access controls.

Users must not attempt to:

  • Access another organisation's workspace without authorisation;

  • Circumvent permissions;

  • Probe protected databases or APIs without permission;

  • Scrape protected data;

  • Interfere with security controls;

  • Exploit vulnerabilities;

  • Obtain information they are not authorised to access.

NIES may temporarily suspend or restrict access where reasonably necessary to investigate or prevent suspected compromise, malicious activity, unauthorised access or serious security violations.

27. Security

NIES uses reasonable technical and organisational measures designed to protect information.

These may include:

  • HTTPS/encrypted communications;

  • Secure authentication;

  • Role-based permissions;

  • Organisation-level data separation;

  • Secure cloud infrastructure;

  • Database/storage security controls;

  • Audit logging;

  • Backups;

  • Restricted staff access;

  • Security monitoring;

  • Least-privilege access principles.

No internet-connected service can guarantee absolute security, but NIES will take reasonable measures appropriate to the nature of the information being processed.

28. Backups

Customer information may be included in backups maintained through infrastructure providers such as Supabase for:

  • Disaster recovery;

  • Business continuity;

  • Security;

  • System restoration.

Where information is deleted from active systems, residual copies may remain temporarily in protected backups until those backups expire or are overwritten according to applicable backup schedules.

Such backup copies are not intended to be treated as active customer data or routinely accessed.

29. Security Incidents and Data Breaches

If NIES becomes aware of a significant security incident or personal-data breach, NIES will take reasonable steps to:

  • Investigate it promptly;

  • Contain the incident;

  • Protect affected systems;

  • Remedy identified vulnerabilities;

  • Assess potential impact;

  • Notify affected customers where appropriate;

  • Notify the Information Commissioner's Office or another competent authority where legally required.

Customers and users should report suspected security incidents promptly to:

contact@nexus-ies.co.uk

Examples include:

  • Stolen devices;

  • Exposed passwords;

  • Suspected unauthorised access;

  • Accidentally disclosed customer information;

  • Compromised accounts.

30. Responsible Vulnerability Disclosure

Users, customers and security researchers who discover a potential vulnerability are encouraged to report it privately to:

contact@nexus-ies.co.uk

They should not:

  • Exploit the vulnerability;

  • Access unnecessary customer information;

  • Damage or disrupt services;

  • Retain customer data;

  • Publicly disclose the vulnerability before NIES has had a reasonable opportunity to investigate and remediate it.

NIES may publish a dedicated Responsible Disclosure Policy separately.

31. Data Retention — Active Customers

While a customer maintains an active subscription or service agreement, operational records may normally be retained for the duration of that relationship.

This can include:

  • Inspections;

  • Reports;

  • Actions;

  • Maintenance records;

  • Photographs;

  • Documents;

  • Audit history;

  • Customer analytics.

Authorised users may delete appropriate information where functionality permits, subject to restrictions necessary to protect important audit, inspection, maintenance, security, contractual or legal records.

32. Data Retention — Customer Cancellation

When a customer cancels an NIES software subscription or hosted service:

  • Access may be disabled or restricted;

  • Customer data will normally enter a 30-day retention/recovery period;

  • During this period, an authorised customer representative may request an appropriate export of customer data;

  • After the 30-day period, customer data will normally be deleted or anonymised from active NIES systems.

Exceptions may apply where information must be retained for:

  • Legal obligations;

  • Accounting;

  • Security investigations;

  • Fraud prevention;

  • Regulatory requirements;

  • Insurance matters;

  • Contractual disputes;

  • Establishing, exercising or defending legal claims.

An authorised customer may request confirmation that customer data has been deleted from active NIES systems.

Residual copies may remain temporarily in protected backups until normal backup cycles expire.

33. Historical Employee Records

Deleting or disabling an individual user's login does not necessarily require deletion of legitimate historical records associated with that person.

For example, NIES/customer systems may need to preserve records showing:

  • Who performed an inspection;

  • Who completed maintenance;

  • Who closed an action;

  • Who generated a report;

  • Who changed an important record.

Such information may remain where reasonably necessary for:

  • Safety;

  • Audit;

  • Maintenance traceability;

  • Compliance;

  • Security;

  • Legal purposes.

Where appropriate, information may instead be restricted or anonymised.

34. Support Record Retention

Support correspondence and associated troubleshooting material will normally be retained for up to 2 years after resolution.

A longer period may apply where necessary for:

  • Legal requirements;

  • Contractual obligations;

  • Security;

  • Ongoing technical investigations;

  • Disputes;

  • Legal claims.

35. Inactive Website Accounts

NIES website accounts that remain inactive for approximately 2 years may be scheduled for deletion.

Where reasonably practical, NIES may provide notice before deleting an inactive account.

Information may be retained where required for legitimate legal, contractual, security or dispute-related purposes.

36. Audit and Security Logs

Normal audit and security records may be retained for the lifetime of the customer's active subscription and ordinarily follow the same 30-day post-cancellation deletion process.

Specific records may be preserved for longer where necessary for:

  • Security investigations;

  • Legal obligations;

  • Fraud investigations;

  • Regulatory matters;

  • Disputes.

37. Data Export

During the 30-day post-cancellation period, authorised customer representatives may request an appropriate export of relevant customer information.

This is separate from an individual's statutory right of access to their personal information.

Once information is downloaded or exported from NIES systems, the customer becomes responsible for appropriately:

  • Securing it;

  • Storing it;

  • Sharing it;

  • Retaining it;

  • Disposing of it.

NIES remains responsible for information retained within NIES-controlled systems.

38. Individual Data Protection Rights

Depending on the circumstances and applicable law, individuals may have rights including:

  • The right to be informed;

  • The right to access personal information;

  • The right to correct inaccurate information;

  • The right to request deletion;

  • The right to restrict processing;

  • The right to object to certain processing;

  • The right to data portability where applicable;

  • The right to withdraw consent where processing relies on consent;

  • Rights relating to certain automated decision-making.

Requests may be submitted to:

contact@nexus-ies.co.uk

NIES will handle valid requests without undue delay and normally within one month, subject to lawful extensions or exceptions.

NIES may need to verify the identity of a requester before releasing or altering personal information.

39. Right to Erasure and Industrial Records

The right to erasure is not absolute.

NIES or the relevant customer may need to preserve certain information where there is a lawful reason to do so.

For example, an individual's name may need to remain associated with a historical inspection or maintenance record where attribution is reasonably necessary for:

  • Safety;

  • Compliance;

  • Audit;

  • Maintenance traceability;

  • Security;

  • Legal obligations;

  • Legal claims.

Where full deletion is inappropriate, restriction or anonymisation may be considered where appropriate.

40. Requests Relating to Customer-Controlled Data

Where NIES receives a privacy request concerning personal information for which a customer organisation is the Data Controller, NIES will normally:

  • Refer or forward the request to the relevant customer;

  • Inform the requester where appropriate;

  • Assist the customer in responding where required.

NIES will not ordinarily independently delete or alter customer-controlled records where it acts solely as Data Processor unless instructed by the customer or required by law.

41. Children's Privacy

NIES websites, PanelGuard and other NIES business software are intended for individuals aged 18 or over.

NIES services are not intentionally directed at children.

If NIES becomes aware that information relating to a child has been improperly collected, appropriate steps will be taken to address it.

42. Legal Disclosures

NIES may disclose information where required by:

  • Applicable law;

  • A valid court order;

  • Regulatory obligations;

  • Another legally binding requirement.

NIES will not voluntarily disclose confidential customer information to authorities or unrelated third parties without an appropriate lawful basis.

Where NIES is legally compelled to disclose customer information, NIES will aim to notify the affected customer where:

  • Legally permitted;

  • Reasonably practical;

unless NIES is prohibited from doing so by law, court order or another binding requirement.

43. Business Transfers

If NIES undergoes a:

  • Merger;

  • Acquisition;

  • Sale;

  • Corporate restructuring;

  • Transfer of business or assets,

personal information and customer information may form part of the transferred business assets where appropriate.

Any such transfer will remain subject to applicable data-protection law and appropriate confidentiality/data-protection safeguards.

44. Confidentiality After Termination

NIES's obligations concerning confidential customer information do not automatically end when a customer terminates its contract.

Former-customer information remains subject to applicable confidentiality and security obligations during the retention and deletion process and wherever information must lawfully be preserved afterwards.

NIES does not gain the right to exploit, disclose or sell former-customer confidential information simply because the commercial relationship has ended.-

45. Third-Party Integrations

NIES does not currently provide customer-controlled third-party software integrations at launch.

If integrations are introduced in future:

  • They may require customer/user authorisation;

  • Relevant privacy information will be provided where necessary;

  • This policy may be updated where processing materially changes.

46. Changes to This Privacy Policy

NIES may update this Privacy Policy as:

  • Products change;

  • New software is introduced;

  • Infrastructure changes;

  • New functionality is introduced;

  • Legal requirements change;

  • Our data-processing practices evolve.

The latest version will display an updated effective or "last updated" date.

Where a change materially affects how personal information is processed, NIES may provide additional notice where appropriate.

47. Complaints

Anyone with concerns about how NIES handles personal information is encouraged to contact us:

Email: contact@nexus-ies.co.uk

We will aim to investigate legitimate privacy concerns appropriately.

Individuals also have the right to complain to the UK Information Commissioner's Office (ICO) where applicable.

48. Contact NIES

Questions concerning this Privacy Policy, personal information, privacy rights or NIES's data-protection practices should be directed to:

NEXUS INDUSTRY ENGINEERING SERVICES LTD
Trading as NEXUS INDUSTRIAL ENGINEERING SERVICES / NIES

Registered in England & Wales
Company No. 16954667

Thornton-Cleveleys
Lancashire
FY5
United Kingdom

Privacy and data-protection enquiries:
contact@nexus-ies.co.uk

ICO registration reference: ZC217339

Policy Summary

Policy Summary

NIES's approach to privacy and customer information can be summarised by the following principles:

  • We collect only information reasonably necessary to operate our business and services.

  • Customers retain ownership of their operational data.

  • Industrial and technical customer information is treated as confidential.

  • We do not sell personal or customer data.

  • We do not provide customer data to unrelated third parties for their own advertising.

  • Identifiable customer data is not used to train AI models.

  • IRIS operates within user permissions and is designed as an assistive tool.

  • Customer organisations are logically separated.

  • NIES personnel access customer information only where appropriately required.

  • Customers can request data export before leaving NIES.

  • Customer data is normally retained for 30 days following cancellation before deletion from active systems.

  • Appropriate historical records may remain where required for safety, audit, legal or maintenance traceability.

  • We use reasonable technical and organisational security measures.

  • We expect customers and users to take reasonable steps to protect their accounts and information.

  • We respect applicable UK data-protection rights.

  • Confidentiality continues even after the customer relationship ends.

Effective date: 7 August 2026

bottom of page