Back to login

Nexus Connect AS

Privacy Policy

Last updated: 16 September 2026 · Effective: 16 September 2026

This privacy policy explains how Nexus Connect AS ("Nexus", "we", "us") collects, uses and protects personal data when you use the investor portal. We are committed to protecting your privacy in accordance with the GDPR, the Norwegian Personal Data Act and other applicable privacy legislation.

1. Who we are

Nexus Connect AS is the controller for personal data processed via the Portal in connection with account administration and communication. Where Nexus processes personal data (e.g. shareholder registers) on behalf of the Company, Nexus acts as a processor and the Company is the controller. Such processing is governed by a separate data processing agreement (DPA).

Nexus Connect AS

Email: hei@nexuscap.no

2. What information we collect

2.1 Information you provide

  • Identity data: name, national identity number and contact details verified via Vipps MobilePay (Norwegian BankID) at authentication
  • Contact details: email address and mobile number returned from Vipps after successful sign-in
  • Communications: the content of enquiries to our support

2.2 Information we collect automatically

  • Usage data: pages visited, features used, time spent and actions performed in the Portal — and, only if you accept analytics, session recordings in which all text and form inputs are masked (see section 9)
  • Device and log data: IP address, browser type and version, operating system and access times
  • Cookies: session cookies, and analytics cookies only if you accept them (see section 9)

2.3 Information from third parties

  • Vipps MobilePay: authentication tokens and basic profile information (name, phone number) returned after successful sign-in
  • The Company: shareholder data, transaction history and portfolio data entered into the platform by the Company

3. How we use the information

PurposeCategories of data used
Deliver and operate the PortalIdentity data, portfolio data, usage data
Authentication and securityIdentity data (Vipps), device and log data
Customer supportContact details, communications, usage data
Product improvement and analyticsWith your consent: usage data and masked session recordings linked to your account, without your name or email. Without it: visit counts without cookies
Legal compliance and fraud preventionIdentity data, device and log data

5. Sharing of information

We do not sell your personal data. We share data only in the following cases:

5.1 Service providers (sub-processors)

We use carefully selected third-party providers to deliver the Portal:

  • Supabase — database hosting and authentication (EU region)
  • Resend — transactional email delivery
  • Vipps MobilePay — user authentication
  • Vercel — cloud infrastructure (EU region where available)
  • PostHog — product analytics and session recordings (PostHog Cloud EU)

Each sub-processor is bound by a data processing agreement and may only process data on our instructions.

5.2 The Company

The company in which you are a shareholder has access to your portfolio data to the extent necessary to administer the shareholder register. We do not share your information with the Company beyond what follows from the data processing agreement.

5.3 Legal disclosure

We may disclose personal data if required by law, court order, or to protect the rights, property or safety of Nexus, our customers or others.

6. International data transfers

We aim to process personal data within the European Economic Area (EEA). Where data is transferred outside the EEA (e.g. to US sub-processors), we ensure that appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) adopted by the European Commission or based on an adequacy decision.

7. Retention period

We retain personal data only as long as necessary to fulfil the purposes described in this policy, or as required by law:

  • Contact details and identity data: for as long as you are an active Portal user plus 3 years after deactivation
  • Portfolio data: controlled by the Company as controller
  • Log and usage data, including product analytics and session recordings: at most 12 months rolling
  • Consent records: until consent is withdrawn plus 2 years

8. Security

Nexus implements appropriate technical and organisational measures to protect personal data, including:

  • TLS 1.2+ encryption for all data in transit
  • AES-256 encryption for data at rest
  • Role-based access control and the principle of least privilege
  • Multi-factor authentication for internal systems
  • Regular penetration tests and security reviews
  • Incident response and notification to the supervisory authority within 72 hours of a breach (GDPR Art. 33)

9. Cookies and tracking technologies

9.1 Necessary cookies

Strictly necessary for the Portal to function (e.g. session authentication tokens). These cannot be disabled.

9.2 Analytics

We use PostHog (EU region) to understand how the Portal is used. Nothing is collected until you make a choice in the analytics banner.

  • If you accept: PostHog stores an identifier in a cookie and in local storage (names starting with ph_), links your usage to your Portal account without your name or email, and records sessions with all text and form inputs masked, so your holdings and personal details are not recorded.
  • If you decline: visits are counted without cookies or local storage, using a server-side hash that PostHog rotates daily. They are not linked to your account.

Your choice is stored in the nexus_analytics_consent cookie for 12 months and applies to this portal address only. You can change it at any time here or on your profile page.

9.3 Managing cookies

You can control cookies via your browser settings. Disabling necessary cookies may prevent the Portal from working correctly.

10. Your rights under the GDPR

  • Right of access (Art. 15): request a copy of the personal data we hold about you
  • Right to rectification (Art. 16): request correction of inaccurate or incomplete data
  • Right to erasure (Art. 17): request deletion of your data where there is no overriding legal basis
  • Right to restriction (Art. 18): request that we restrict processing in certain cases
  • Right to data portability (Art. 20): receive your data in a structured, machine-readable format
  • Right to object (Art. 21): object to processing based on legitimate interest, including direct marketing
  • Right to withdraw consent: withdraw consent at any time where processing is consent-based

To exercise any of these rights, contact us at hei@nexuscap.no. We will respond within 30 days. You also have the right to lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet).

11. Children's privacy

The Portal is not directed at persons under 18 years of age. We do not knowingly collect personal data from children. If we become aware that a person under 18 has provided us with personal data, we will take steps to delete it promptly.

12. Changes to this policy

We may update this privacy policy from time to time. We will notify you of material changes by email or by displaying a prominent notice in the Portal at least 14 days before the changes take effect. The date at the top of this policy indicates when it was last revised.

13. Contact and data processing agreement

For privacy-related questions, requests, or to obtain a copy of our DPA, contact us:

Nexus Connect AS — Privacy

Email: hei@nexuscap.no

See also our Terms of Use that govern your use of the Portal.