NEXUS Group — Public compliance documentation

Data Retention and Deletion

Retention schedule and deletion procedures applied by NEXUS Group to Protected Data processed in NEXUS V2, including deauthorization and end-of-contract deletion.

Document
NX-RET-01
Version
1.0
Effective date
Review cycle
At least annually, and after any material change to the service.

01Principle

Protected Data is kept only while a defined purpose requires it. When the purpose ends, the data is deleted, unless a legal obligation requires it to be retained for a longer period — in which case processing is restricted to that obligation alone.

02Retention schedule

Retention schedule per data category
Data categoryRetention periodTrigger for deletion
Marketplace authorization tokens (access and refresh)While the seller account or shop remains connected.Immediately on disconnection, revocation of authorization, or end of the contractual relationship.
Order, item and settlement recordsRetained while required for reconciliation and for the accounting and tax retention period applicable to the transaction.Expiry of the legal retention period, or an authorised deletion request when no legal obligation applies.
Buyer identification and recipient dataSame period as the order it belongs to.Deleted together with the parent order record.
Product, SKU and cost records, including cost historyWhile the SKU is in use, plus the period needed to audit past sales.Removal of the SKU and expiry of the audit need.
Full stock snapshots and stock historyRolling operational history used for coverage analysis.Superseded snapshots are overwritten or removed automatically when the item is no longer reported by the marketplace.
Administrator session cookie1 day, or 30 days when 'remember me' is selected.Sign-out, expiry, or rotation of the session signing secret.
Database backupsKept for the backup rotation window and stored outside the production server.Expiry of the rotation window; deleted records disappear from backups as the window rolls forward.
Data subject request recordsRetained as evidence of compliance.Reviewed annually; kept only while needed to demonstrate that the request was handled.

03Deletion on deauthorization or disconnection

When a seller revokes the app authorization at the marketplace, or the integration is disconnected in the platform, the following steps are executed:

  • The stored access and refresh tokens for that account or shop are deleted from the database, so no further API call can be made on the seller's behalf.
  • Synchronisation for that account stops immediately.
  • Order and buyer records belonging to that account are deleted, except records still subject to a legal retention obligation, which are restricted and deleted at the end of that period.
  • The deletion is recorded with the date, the account identifier and the categories removed.
  • Backups taken before the deletion are not rewritten; the deleted data disappears as the backup rotation window expires.

Cascade at database level

Shopee order records are bound to the connected shop with a cascade relationship, so removing the shop removes its order records in the same operation. Mercado Livre records are deleted by account identifier.

04End of the contractual relationship

At the end of a contractual relationship with a marketplace, seller or partner, NEXUS Group deletes all data collected from that counterparty that remains in its possession.

Procedure

  • Revoke and delete every credential and token related to the counterparty.
  • Delete the counterparty's Protected Data from the production database.
  • Confirm that no export, spreadsheet or local copy of that data remains on company devices.
  • Allow the backup rotation window to expire so that the data is no longer recoverable from backups.
  • Issue a written confirmation of deletion to the counterparty on request, stating the categories deleted and the date.

Deadline

Deletion is completed within 30 calendar days of the end of the relationship, or within the shorter period required by the applicable agreement.

05Requesting deletion

Sellers, marketplace operators and individuals may request deletion at gianlucca.florencio@zeroholding.com.br. The procedure and the deadlines are published in Data Subject Rights.

Document control

Public URL: https://v2.nexusgroup.app.br/data-retention.

Approved and maintained by the NEXUS Group Privacy Owner. Reviewed at least annually, and after any material change to the service.