Privacy Policy
Last updated on 20 September 2026. What data we collect, why, who we share it with, how long we keep it — and how to access or delete it, including when you sign in with Google.
Important notice — Student project
Nexus System is a student project built for educational purposes. Although we follow security best practices, the data we collect is limited to what the service strictly needs in order to work.
01 Data controller and scope
The data controller is Nexus System, a student project developed as part of the Epitech curriculum. You can reach us by email at info@nexus-system.fr or through the site's contact page.
The public website nexus-system.fr is freely browsable: no sign-up and no sign-in are required to explore our products, read our articles or write to us. An account is only needed to control a device from the Nexus System app.
This document covers all of our services:
- the public website nexus-system.fr;
- the Nexus System mobile app (iOS and Android);
- the account portal account.nexus-system.fr;
- the professional portal pro.nexus-system.fr;
- the APIs and services behind them.
02 Data we collect
We collect the minimum the service needs in order to work. We never buy data from data brokers.
| Category | Data | Source |
|---|---|---|
| Sign-in identity | Email address, display name, public profile picture URL, stable Google identifier sub | Google, when you sign in |
| Account | Internal identifier, language, creation date, notification preferences, sign-in history | You and your use of the service |
| Devices | Device serial numbers, the names you give them, sensor readings (pH, ORP, temperature, water level, pump status) and their timestamps | Your Pool Nexus and Garden Nexus devices |
| Support and forms | Name, email address, message content, any attachments | You (contact, beta test, newsletter, support tickets) |
| Technical data | IP address, User-Agent header, TLS fingerprint, request timestamps, error logs | Automatic, for security and monitoring |
| Push notifications | Device token | Your phone, if you enable notifications |
We collect no special category data within the meaning of Article 9 GDPR: no ethnic origin, no opinions, no health data, no biometrics.
03 Signing in with Google: permissions we request
Nexus System offers Google sign-in (OAuth 2.0 / OpenID Connect) so you don't have to create and remember yet another password. We request only these three minimal scopes:
| Scope | Data obtained | Why we need it |
|---|---|---|
openid | A stable, opaque Google identifier sub | Link your sign-in to the right Nexus System account, even if your email address changes |
email | Your email address and its verification status | Primary account identifier, delivery of alerts and service messages |
profile | Your display name and public profile picture URL | Personalise your space: display name and avatar |
We request no sensitive and no restricted scopes. We have no access to Gmail, your contacts, your calendar, Google Drive or any other Google service. We never receive your Google password.
The token issued by Google is handled by our internal authentication service to open your Nexus System session. It is passed to no third party and is not kept beyond what the session requires.
04 Purposes and legal bases
Every processing activity serves a specific purpose and rests on an identified legal basis:
| Purpose | Data used | Legal basis (GDPR) |
|---|---|---|
| Create your account, authenticate you and secure access | Sign-in identity, account, technical data | Performance of a contract (Art. 6(1)(b)) |
| Link your devices to your account and display their readings | Account, devices | Performance of a contract (Art. 6(1)(b)) |
| Alert you about your installation (pH, chlorine, failure, water level) | Account, devices, notification token | Performance of a contract (Art. 6(1)(b)) |
| Answer your support requests | Support and forms | Legitimate interest (Art. 6(1)(f)) |
| Secure the service, prevent fraud and automated submissions | Technical data | Legitimate interest (Art. 6(1)(f)) |
| Send you the newsletter | Email address | Consent (Art. 6(1)(a)), withdrawable at any time |
| Measure the site's audience in order to improve it | Pages viewed, IP address, browser and device information | Consent (Art. 6(1)(a)), given through the cookie banner and revocable |
| Improve the product from aggregate statistics | Aggregated, non-identifying data | Legitimate interest (Art. 6(1)(f)) |
We never sell, rent or trade personal data. We run no targeted advertising and make no solely automated decisions producing legal effects concerning you.
05 Use of data received from Google APIs
Nexus System's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
In practice, data obtained through your Google account:
- is used only to provide and improve the user-facing features of Nexus System described in this document;
- is transferred to third parties only where necessary to provide those features, to comply with applicable law, or as part of a merger or acquisition carried out with your consent;
- is never used for advertising, profiling, resale or data brokerage;
- is never read by a human, unless you explicitly authorise it so we can resolve an incident, the law requires it, or the data has been aggregated and anonymised for security or statistical purposes;
- is never used to train artificial intelligence models, whether generalised or specialised.
06 Data sharing and processors
Your data stays with us and with a small number of technical providers acting as processors: each is bound by contract, accesses only what is strictly necessary, and cannot reuse your data for its own purposes.
| Provider | Role | Data involved |
|---|---|---|
| Cloudflare, Inc. | Hosting of the public website (Cloudflare Pages), content delivery network, attack protection and bot verification (Turnstile) | Pages viewed and technical data: IP address, User-Agent, TLS fingerprint |
| Resend | Transactional email delivery: address verification, password reset, alerts | Email address, display name, message content |
| Google LLC (Firebase Cloud Messaging) | Delivery of push notifications to your phone | Device token and notification content |
| Google Ireland Limited (Google Analytics 4) | Audience measurement for the site, loaded only after your consent | Measurement cookies, IP address, pages viewed, browser and device information |
| OVHcloud (OVH SAS) | Hosting of our application servers, databases and backups, which we operate ourselves in containers. Data centres located in France | All of the categories described above |
Your accounts, your readings and our backups are hosted in France, with OVHcloud. The supporting providers (Cloudflare, Resend, Google) run networks that may process some data outside the European Union: those transfers are governed by the European Commission's Standard Contractual Clauses and, where applicable, the Data Privacy Framework.
We may also disclose data where the law requires it (court order, legal obligation) or to establish and defend our rights. We will tell you when we do, unless we are legally barred from doing so.
07 Retention periods
We keep your data only as long as the purposes described above require:
| Data | Retention period |
|---|---|
| Account and sign-in identity | For as long as the account exists, then deleted within 30 days of your request |
| Sensor readings | A rolling 24 months, then kept only as non-identifying averages |
| Technical and security logs | 12 months |
| Support messages and form submissions | 24 months after the last exchange |
| Newsletter subscription | Until you unsubscribe, then 3 years at most as proof of consent |
| Audience measurement (Google Analytics), if you accepted it | 14 months |
| Encrypted backups | 30 days, on rotation |
Once these periods expire, the data is irreversibly deleted or anonymised.
08 Storage and security
Traffic to our services is encrypted in transit (HTTPS and TLS, MQTT over TLS for the devices). Databases and backups are encrypted at rest.
Access to production systems is restricted to the team members who need it, protected by strong authentication and logged. Services are isolated in containers on separate networks, behind an API gateway that enforces authentication and origin policies.
Signing in with Google strengthens your account's security: no password specific to our platform is created or stored on our side, so none can be compromised here.
Should a data breach be likely to result in a risk to your rights, we notify the CNIL within 72 hours and, where the risk is high, we notify you directly.
09 Your rights
Under the GDPR you have the right to access, rectify, erase, restrict, object to and port your data, as well as the right to withdraw your consent at any time.
To exercise them, write to info@nexus-system.fr or use the contact page. We reply within one month, extended to three months for complex requests, and we may ask you for proof of identity where there is reasonable doubt.
If you believe your rights are not being respected, you may lodge a complaint with the CNIL, the French supervisory authority, or with the authority of your country of residence.
10 Deleting your account and your data
You can permanently delete your account, your devices and their history yourself, at any time and without going through us, from the dedicated page: account.nexus-system.fr/delete.
Deletion takes effect within 30 days on live systems, then disappears from encrypted backups as they rotate, within a further 30 days. Some data may be kept longer where the law requires it.
You can also revoke Nexus System's access to your Google account from the third-party apps page of your Google account. Revoking prevents any further sign-in through Google but does not, on its own, delete your Nexus System account.
12 Bot protection
Our forms (contact, beta test, newsletter) are protected by Cloudflare Turnstile, a tool that tells human visitors from bots in order to prevent automated submissions. Depending on how the widget is configured, the check may happen entirely in the background, with nothing displayed and nothing for you to do.
To do so, Turnstile processes technical signals: your IP address, your browser's TLS fingerprint, the User-Agent header, plus the site key and originating domain. Cloudflare states that it cannot directly identify a person from these signals, which are strictly necessary for bot detection.
Cloudflare acts as a processor when it handles these signals to protect our site, and as a controller when it uses them to improve its own detection capabilities.
This processing is described in Cloudflare's Turnstile Privacy Addendum, which supplements its privacy policy.
13 Children
Nexus System is not intended for people under 16 and we do not knowingly collect their data. If you hold parental responsibility and believe your child has sent us information, write to info@nexus-system.fr and we will delete it.
14 Changes to this policy
This document may change to reflect changes in the service or in the law. The date it was last updated appears at the top of the page.
For any substantial change — a new purpose, a new category of collected data, a significant new processor — we will tell you by email or through an in-app notification before it takes effect.
15 Contact us
For any question about this document or about how we process your data: info@nexus-system.fr, or through the contact page.
Related document: Terms of Service.