Back to homeNexorsource

Privacy Policy

Last updated: 29 July 2026

This Privacy Policy explains how Nexorsource (“Nexorsource,” “we,” “us,” or “our”) collects, uses, shares, and protects personal data when you use our B2B procurement platform, websites, and related services (together, the “Services”). It applies to buyers, distributors, their staff, and visitors who interact with the Services.

The platform is operated by Nexorsource, which acts as the data controller for personal data processed through the Services, except where a buying company or distributor determines how and why data is processed within its own account, in which case that organization is the controller and we act as its processor on its behalf.

1. Who this policy covers

The Services connect three types of users: buying companies and their managers and employees, distributors (sellers) and their staff, and the platform operator. Depending on your role, some of the processing below may not apply to you. Where a buying company or distributor decides how and why your data is processed within their own account, that organization acts as the controller and we act as a processor on their behalf.

2. Information we collect

We collect the following categories of information:

  • Account and profile data: name, work email address, password (stored only as a salted hash), preferred language, role, and the organization you belong to.
  • Organization data: company or distributor name, logo, business details, assigned market sections, subscription plan, seat allocation, and branding settings.
  • Procurement and transaction data: product catalogs, carts, purchase requests, approvals, orders, invoices, delivery records, budgets, spending, quotes, and messages exchanged between buyers and distributors.
  • Payment data: subscription and payment processing is handled by our payment processor (Stripe). We do not store full card numbers on our servers; we receive limited billing metadata (e.g. status, last four digits, and identifiers) needed to manage your subscription.
  • Communications: messages, support requests, and notifications you send or receive through the Services, and email we send you (e.g. sign-in alerts, approvals).
  • Technical and usage data: log data such as IP address, browser type, timestamps, actions taken in the app, and audit records used for security and reliability.
  • Cookies and similar technologies: a session cookie required to keep you signed in, and local storage used for essential preferences (see “Cookies” below).

3. How we use information

  • To provide, operate, and maintain the Services and your account.
  • To process purchase requests, approvals, orders, invoices, and deliveries.
  • To manage subscriptions, seats, and billing.
  • To send service and security communications (such as new sign-in alerts).
  • To secure the platform, prevent fraud and abuse, and enforce our terms.
  • To provide support and respond to your requests.
  • To improve and develop the Services, and to comply with legal obligations.

4. Legal bases for processing

Where data-protection law (such as the GDPR) applies, we rely on the following legal bases: performance of a contract (to deliver the Services you or your organization signed up for); legitimate interests (to secure, maintain, and improve the Services); consent (where required, e.g. for certain communications); and legal obligation (to comply with applicable law).

5. How we share information

We share personal data only as needed to run the Services:

  • Between buyers and distributors: to fulfil procurement, an order and its related details are shared with the distributor supplying it, and order status is shared with the buying company. Each distributor sees only data relating to its own customers and orders.
  • Service providers (processors): hosting and database providers, our payment processor (Stripe), and email delivery providers, acting under contract and only on our instructions.
  • Legal and safety: where required by law, regulation, legal process, or to protect the rights, property, or safety of our users or the public.
  • Business transfers: in connection with a merger, acquisition, or sale of assets, subject to this policy.

We do not sell your personal data.

6. Data retention

We keep personal data for as long as your account is active and as needed to provide the Services, then retain it only as required to meet legal, accounting, tax, or reporting obligations, resolve disputes, and enforce our agreements. When data is no longer needed, we delete or anonymize it.

7. Security

We use technical and organizational measures to protect personal data, including encrypted transport, hashed passwords, role-based access controls, tenant isolation between distributors, rate limiting, and audit logging. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

8. International transfers

Your data may be processed in countries other than the one in which you are located. Where we transfer personal data across borders, we take steps to ensure it receives an adequate level of protection, such as relying on appropriate safeguards recognized under applicable law.

9. Your rights

Subject to your local law, you may have the right to access, correct, update, or delete your personal data; to object to or restrict certain processing; to data portability; and to withdraw consent where processing is based on consent. If your data is managed within your organization’s account, please contact that organization first; we will assist them as their processor. To exercise your rights with us directly, contact us using the details below. You also have the right to lodge a complaint with your local supervisory authority.

10. Cookies and local storage

We use a strictly necessary session cookie to keep you signed in, and browser local storage for essential preferences (such as a remembered email address and language). We do not use these for advertising. You can clear cookies and local storage in your browser settings, but doing so may sign you out and reset preferences.

11. Children

The Services are intended for business use and are not directed to children. We do not knowingly collect personal data from children.

12. Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, notify you through the Services. Your continued use of the Services after an update means you accept the revised policy.

13. Contact us

If you have questions about this policy or how we handle your data, contact us at support@nexorsource.com.

© 2026 Nexorsource · B2B Procurement