NEXUS Group — Public compliance documentation

Trust Center

Security, privacy and data protection documentation for NEXUS V2. This index is the entry point for marketplace and platform security reviews.

Document
NX-TRUST-00
Version
1.0
Effective date
Review cycle
At least annually, and after any material change to the service.

01What this platform is

NEXUS V2 is a private, single-tenant back-office used by NEXUS Group to manage its own marketplace operations: sales reconciliation, shipping, stock and SKU costing.

  • Single-tenant, internal use. The platform is operated by NEXUS Group for its own marketplace accounts. It is not a public sign-up product and does not host third-party end users.
  • One administrator account. Access is limited to the company administrator; every route other than the sign-in page and the health check requires an authenticated session.
  • Marketplace data only. Data is received from the official Mercado Livre and Shopee APIs after the seller authorizes the connection.
  • No advertising, no profiling, no data resale.Protected Data is used exclusively to operate the seller's own back office.

02Published documents

03Control summary

The table below summarises the controls most frequently assessed by marketplace security reviews. Each row links to the document that describes the control in full.

Summary of security and privacy controls
ControlIn placeWhere it is documented
Published information security policyYesInformation Security Policy
Published personal data protection standardYesPersonal Information Protection Standard
Published privacy noticeYesPrivacy Notice
Network segregation and perimeter controlsYesSecurity §3
Endpoint protection on company devicesYesSecurity §4
Daily security baseline (screen lock, password policy, MFA)YesSecurity §5
Access control policy and least privilegeYesSecurity §6
Data classification, encryption in transit and at restYesSecurity §7
Vulnerability and threat management procedureYesSecurity §8
Incident response policy and breach notificationYesIncident Response
Data subject rights processYesData Subject Rights
Retention schedule and deletion on deauthorizationYesData Retention and Deletion
Named privacy owner and published contact channelYesPrivacy Notice §8
ISO 27001 / ISO 27701 / SOC 2 Type 2 / ePrivacy certificationNoNot certified. See the statement below.
Statutory Data Protection Officer appointed under GDPR Art. 37NoPrivacy Notice §8

04Explicit statements

No industry certification

NEXUS Group does not hold ISO 27001, ISO 27701, SOC 2 Type 2, ePrivacy or any equivalent information security certification, and does not claim one. The controls described in this Trust Center are self-assessed and evidenced through configuration, code and operational records that can be shared with a platform reviewer on request.

No data breach and no regulatory complaint

In the last three years the platform has had no security breach leading to accidental or unlawful exposure of personal data, and has received no complaint, objection or notice from any data protection authority, customer or individual regarding the processing of personal data.

Where data is stored

Protected Data is stored and processed in Brazil, on single dedicated virtual private server (vps) managed by nexus group. No Protected Data is transferred to any other jurisdiction, except back to the originating marketplace APIs. The current list of third parties is published under Sub-processors.

05Contacts

Contact channels
PurposeChannelTarget first response
Privacy Owner / Data Protection Contactgianlucca.florencio@zeroholding.com.br5 business days
Security reports and incident notificationgianlucca.florencio@zeroholding.com.brAcknowledged within 24 hours

Document control

This Trust Center is published at https://v2.nexusgroup.app.br/trust and is publicly reachable without authentication so that reviewers can verify it at any time.

Approved and maintained by the NEXUS Group Privacy Owner. Reviewed at least annually, and after any material change to the service.