Legal

Privacy Policy

What we collect, what we do not collect, and what you can ask us to do about it.

Short version: this website sets no cookies, runs no analytics, embeds no third-party content and tracks nothing. The only personal data we handle from this site is what you choose to put in an email to us. Because our work is cross-border, that correspondence may be read by advisers working outside the United Kingdom — we explain below exactly when, why, and on what legal footing.

Who we are

Nexus Notabu provides international market expansion services: go-to-market strategy, entity setup, tax, legal, hiring and office sourcing. Nexus Notabu and Nomos Notabu are operated by the same legal entity.

Nexus Notabu is currently completing a corporate restructuring. The registered operating entity, address, EIN and filing numbers are being updated and will be published in our Legal Notice shortly.

For any question about this policy or about your data, write to contact@nexusnotabu.com.

We are the data controller for the personal data described in this policy. We have not appointed a data protection officer, as we are not required to do so.

What this website does not do

  • No cookies. This site sets none, and stores nothing in your browser's local or session storage, so there is no consent banner and nothing to agree to.
  • No analytics. We do not use Google Analytics or any other tracking or measurement tool. We receive no visitor statistics of any kind.
  • No contact form. There is no form on this site, so no form data reaches any third-party processor.
  • No advertising or social pixels. No Meta pixel, no LinkedIn Insight Tag, nothing comparable.
  • No third-party fonts, scripts, maps or videos. Everything is served from our own domain, so your browser does not contact an outside service while you read these pages.

Server logs

Our website is hosted by statichost.eu, operated from Sweden within the EU. Their infrastructure records standard technical information when a page is requested: typically your IP address, the time of the request, the page requested, and your browser and operating system. This is processed so that the site can be delivered securely and reliably, under our legitimate interest in running a functioning website.

To be clear about the limits of this: the only personal data reaching our host is the technical information any website needs in order to serve a page. No client files, correspondence or case details are held there — the site is a set of static pages with no database and no user accounts.

If you email us

We ask you to contact us by email rather than through a form, deliberately: it means no third-party service sits between you and us. When you write to us we receive whatever you choose to include — typically your name, email address, your company, your target markets and what you are trying to achieve.

Our email is provided by Proton AG in Switzerland, which the UK recognises as providing an adequate level of data protection. Messages sitting in our mailbox are held with zero-access encryption, meaning Proton cannot read them.

What that does and does not mean for your message is worth stating plainly. If you also use Proton Mail, your email to us is end-to-end encrypted and nobody in between can read it. If you write from Gmail, Outlook or most other providers, your message is encrypted in transit but is not end-to-end encrypted, and your own email provider can read it. Subject lines and email addresses are never end-to-end encrypted, whichever provider you use.

So if you need to send us something genuinely sensitive — financial statements, personal data about your staff, anything commercially confidential — tell us first and we will set up a password-protected exchange or PGP, either of which is end-to-end encrypted regardless of your provider.

For calls we use Proton Meet, where the audio, video, screen sharing and chat are end-to-end encrypted by default, so the provider cannot access the content of the meeting. Proton's servers still see basic connection metadata, such as when a meeting took place and how long it lasted. If you would rather use a different platform, tell us and we will accommodate it.

Why we use it, and on what basis

We use what you send us to reply to you and to discuss whether we can help. If you become a client, we use it to deliver the work and to meet our own legal and accounting obligations.

Which lawful basis applies under the UK GDPR depends on how we came to be in contact.

  • You contacted us. The basis is the taking of steps at your request before entering into a contract, and performance of that contract once we are working together (Article 6(1)(b)).
  • We approached you. Where we contact a company directly about our services as part of our own business development, the basis is our legitimate interests in offering services relevant to that business (Article 6(1)(f)). You can object at any time and we will stop.
  • Record keeping. Where professional, tax or accounting rules require us to retain records, the basis is legal obligation (Article 6(1)(c)).
  • Server logs. Our legitimate interest in operating a secure and functioning website (Article 6(1)(f)).

Who else sees your data

We do not sell personal data, we do not share it for marketing, and we do not use it to build profiles of you.

Our providers

Our website host (statichost.eu, Sweden) and our email and meeting provider (Proton AG, Switzerland) process data on our behalf under contract. Both are inside the EU or covered by UK adequacy regulations, so no additional transfer safeguards are needed for them.

Local specialists

We are an international firm. We work through vetted local specialist firms rather than a single office, and some of them are outside the United Kingdom and outside the European Economic Area.

In practice this means your correspondence and the details of your expansion may be read, and your matter discussed, from a country outside the UK. This is not incidental to the service — it is the service. If you ask us how to enter Brazil, the person best placed to answer is usually qualified in, and working from, Brazil. We tell you who is involved in your matter, and we share only what that person needs in order to advise you.

Where a local lawyer, tax adviser or accountant advises you in their own name, they act as an independent controller of your data, bound by their own professional confidentiality rules and their own privacy notice rather than ours. We will tell you when that is the case. Where a partner instead processes data on our behalf, we put a written agreement in place first.

Sending data outside the United Kingdom

Where personal data is made available outside the UK in the course of your matter, we rely on one of the following, depending on the circumstances.

  • Adequacy. Where the destination country is covered by UK adequacy regulations, we rely on those.
  • Appropriate safeguards. Where a partner processes personal data on our behalf and the country has no adequacy finding, we put a written agreement in place incorporating the UK International Data Transfer Agreement, or the UK Addendum to the European Commission's Standard Contractual Clauses, with a transfer risk assessment where one is required.
  • Necessary for your contract. Where the transfer is necessary to perform the engagement you have entered into with us, or to take steps at your request before entering one, we rely on Article 49(1)(b) UK GDPR. This covers most of our work, because the cross-border element is the reason you came to us.
  • Necessary for a contract made in your interest. Where we instruct a local firm on your behalf — to incorporate an entity, make a filing, or complete a tax or payroll registration in another country — we rely on Article 49(1)(c) UK GDPR.
  • Your explicit consent. Where none of the above applies and a transfer would still be useful to you, we will ask you first and explain the risks, under Article 49(1)(a) UK GDPR.

You should understand what this means in practice. Countries outside the UK and the EEA do not all provide an equivalent level of protection, and in some the authorities have broader powers of access to data than a UK court would allow. Where we rely on a derogation rather than on adequacy or appropriate safeguards, you have fewer enforceable remedies in the destination country than you would here. If you would prefer your matter to be handled only within the UK or the EEA, tell us at the outset and we will say honestly whether that is possible for the market you want.

How long we keep it

Enquiries that do not become engagements are deleted within two years. Records relating to actual engagements are kept for as long as the professional, tax and legal record-keeping rules that apply to us require, and then deleted.

Your rights

Under the UK GDPR you can ask us to give you a copy of the personal data we hold about you, correct it if it is wrong, delete it, restrict or object to how we use it, or send it to another provider in a portable form. Where we rely on legitimate interests, you can object at any time.

Email contact@nexusnotabu.com and we will respond within one month. There is no charge.

If you are unhappy with how we have handled your data, you can complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113. We would rather you came to us first so we can put it right.

Changes to this policy

If we add anything to this site that collects data — analytics, a booking tool, a contact form — we will update this policy before it goes live, and change the date at the top.