← Back to PCI-Nexus

Privacy Policy

Last updated: [EFFECTIVE DATE]
Draft — pending legal review. Replace all bracketed placeholders before production.

This Privacy Policy explains how [Company legal name] (“we,” “us,” or “PCI-Nexus”) collects, uses, and protects personal information when you use the PCI-Nexus platform (the “Service”). It works alongside our Data Handling page and Terms of Service.

Information we collect

We collect account information you provide (such as name, email, organization, and role), the content you and your clients enter into the Service, and technical information generated as you use the platform (such as log data and audit records). We do not collect cardholder data.

How we use information

We use personal information to provide and secure the Service, to authenticate users, to communicate with you about your account, to provide support, and to improve the platform. We do not sell personal information.

Legal bases & your choices

Where required by law, we process personal information on the basis of your agreement to these terms, our legitimate interest in operating the Service, and compliance with legal obligations. Depending on your location, you may have rights to access, correct, export, or delete your personal information. To exercise these, contact [contact email].

Sharing

We share personal information only with service providers that help us operate the platform (for example, hosting, authentication, and email delivery), and where required by law. These providers are bound to handle data consistently with this Policy. See our Data Handling page for sub-processors.

Security

We use technical and organizational measures — including encryption in transit, tenant isolation, and role-based access — to protect personal information. No system is perfectly secure, but we work to safeguard your data and to notify affected parties of incidents as required by law.

Retention

We retain personal information for as long as your account is active and as needed to provide the Service, then as required to meet legal, regulatory, or contractual obligations.

Children

The Service is intended for business use and is not directed to children. We do not knowingly collect personal information from children.

Changes

We may update this Policy from time to time. Material changes will be communicated through the Service or by email.

Contact

For privacy questions or requests, contact [contact email], [Company legal name], [mailing address].