Privacy Policy

Last updated: July 29, 2026

Nectis Ltd (SC621729), 10 Colinton Rd, Edinburgh EH10 5DT, Scotland, operates the Nectis website and platform.

Who Controls Your Data

This policy covers two different relationships, and your rights differ between them.

  • Our website, and your own Nectis account. Nectis Ltd is the data controller. This policy applies directly.
  • Information held inside the platform about the people an organisation works with. The organisation that licences Nectis is the data controller; Nectis Ltd is its data processor, acting on that organisation's documented instructions under a Data Processing Agreement. Each licensing organisation is a separate controller, and their data is kept separate from every other organisation's.

So if you took part in a community programme and want to know what is held about you, or want it corrected or erased, contact the organisation that runs the programme. They are the controller, and we will act on their instruction. You can also contact us and we will help route the request.

Personal Data We Collect

We collect personal data that you provide directly, including your name, email address, organisation, and any information you enter into the platform (such as connections, assessments, and observations).

How We Use Your Data

UK GDPR Article 6 requires us to name a lawful basis for each purpose, not just to list the purposes. Ours are:

PurposeLawful basis
Providing and maintaining the Nectis service to youPerformance of a contract (Art. 6(1)(b))
Communicating with you about your account and the servicePerformance of a contract (Art. 6(1)(b))
Keeping the platform secure and investigating misuseLegitimate interests (Art. 6(1)(f)) — ours and yours, in a service that is not abused
Improving the platform and developing new featuresLegitimate interests (Art. 6(1)(f)) — you may object at any time
Meeting our legal and regulatory obligationsLegal obligation (Art. 6(1)(c))

Personal data that an organisation enters into the platform about other people is processed on that organisation’s instructions, under their lawful basis, not ours. See Who Controls Your Data above.

We do not rely on consent for any of the above, so there is no consent for you to withdraw here. Where we ever do rely on consent — an optional mailing list, say — we will tell you at the point we ask, and you can withdraw it at any time without affecting anything else.

Data Sharing

We do not sell your personal data. We share data only with service providers necessary to operate the platform:

Service Purpose Location
Railway Application hosting, database and backups EU
Google Analytics Website analytics (cookieless by default; cookies only with consent) US
Cloudflare Web Analytics Privacy-first, cookieless website analytics Global
Brevo Transactional email EU

Your Rights

Under the UK GDPR and the Data Protection Act 2018, both as amended by the Data (Use and Access) Act 2025, and under the EU GDPR if you are in the European Economic Area, you have the right to access, rectify, erase, restrict processing of, and port your personal data. You also have the right to object to processing and to withdraw consent at any time.

To exercise these rights over your own account or our website, contact us at hello@nectis.io. For information held inside the platform by an organisation you have worked with, see Who Controls Your Data above: that request goes to the organisation, and we will act on their instruction.

Where we erase a person at a controller's instruction, we also record a non-reversible marker so that a later data import cannot silently recreate them. The marker holds no personal data.

Data Residency

Application servers, databases, caches and backups are hosted in EU regions. We check this automatically and are alerted if any service moves outside the EU. Website analytics providers listed above operate outside the EU and receive no platform data.

Data Retention

We retain your personal data for as long as your account is active or as needed to provide you with the service. If you request deletion of your account, we will delete your personal data within 30 days, except where we are legally required to retain it.

For data held on behalf of a licensing organisation, retention is set by that organisation as controller. If a licence ends, their data remains available to them in read-only form; it is deleted on their instruction, or as set out in their agreement with us.

Cookies

We use essential cookies to operate the platform. For analytics we use privacy-first measurement that sets no cookies and needs no consent (Cloudflare Web Analytics, and Google Analytics running in cookieless Consent Mode). Google Analytics only stores cookies, for richer measurement, after you give explicit consent via our cookie banner; if you decline, analytics stays fully cookieless.

Security

We implement appropriate technical and organisational measures to protect your personal data, including encryption of data in transit (TLS 1.2 or higher) and at rest, application-level encryption of stored third-party credentials, role-based access control that is default-deny, separation of each organisation's data, automated dependency and security scanning, and regular security reviews.

Further detail for procurement, IT and data protection teams is on our Security and Compliance page. A Data Processing Agreement is available on request from hello@nectis.io.

Changes to This Policy

We may update this privacy policy from time to time. We will notify you of any changes by posting the new policy on this page and updating the "Last updated" date.

Contact

If you have any questions about this privacy policy, contact us at:

hello@nectis.io
Nectis Ltd (SC621729), 10 Colinton Rd, Edinburgh EH10 5DT, Scotland

If you are unhappy with how we have handled your personal data, tell us first at hello@nectis.io with “Data complaint” in the subject. We will acknowledge it within 5 working days and give you a substantive response within 30 days, or explain why we need longer and when you will hear from us. This route exists so problems get fixed rather than escalated, and the Data (Use and Access) Act 2025 expects us to offer it.

You do not have to use it. You can complain directly to the Information Commissioner's Office at ico.org.uk at any time, and you keep that right whatever we say in response.