NEXUS Group — Public compliance documentation
Trust Center
Security, privacy and data protection documentation for NEXUS V2. This index is the entry point for marketplace and platform security reviews.
- Document
- NX-TRUST-00
- Version
- 1.0
- Effective date
- Review cycle
- At least annually, and after any material change to the service.
01What this platform is
NEXUS V2 is a private, single-tenant back-office used by NEXUS Group to manage its own marketplace operations: sales reconciliation, shipping, stock and SKU costing.
- Single-tenant, internal use. The platform is operated by NEXUS Group for its own marketplace accounts. It is not a public sign-up product and does not host third-party end users.
- One administrator account. Access is limited to the company administrator; every route other than the sign-in page and the health check requires an authenticated session.
- Marketplace data only. Data is received from the official Mercado Livre and Shopee APIs after the seller authorizes the connection.
- No advertising, no profiling, no data resale.Protected Data is used exclusively to operate the seller's own back office.
02Published documents
03Control summary
The table below summarises the controls most frequently assessed by marketplace security reviews. Each row links to the document that describes the control in full.
| Control | In place | Where it is documented |
|---|---|---|
| Published information security policy | Yes | Information Security Policy |
| Published personal data protection standard | Yes | Personal Information Protection Standard |
| Published privacy notice | Yes | Privacy Notice |
| Network segregation and perimeter controls | Yes | Security §3 |
| Endpoint protection on company devices | Yes | Security §4 |
| Daily security baseline (screen lock, password policy, MFA) | Yes | Security §5 |
| Access control policy and least privilege | Yes | Security §6 |
| Data classification, encryption in transit and at rest | Yes | Security §7 |
| Vulnerability and threat management procedure | Yes | Security §8 |
| Incident response policy and breach notification | Yes | Incident Response |
| Data subject rights process | Yes | Data Subject Rights |
| Retention schedule and deletion on deauthorization | Yes | Data Retention and Deletion |
| Named privacy owner and published contact channel | Yes | Privacy Notice §8 |
| ISO 27001 / ISO 27701 / SOC 2 Type 2 / ePrivacy certification | No | Not certified. See the statement below. |
| Statutory Data Protection Officer appointed under GDPR Art. 37 | No | Privacy Notice §8 |
04Explicit statements
No industry certification
No data breach and no regulatory complaint
Where data is stored
05Contacts
| Purpose | Channel | Target first response |
|---|---|---|
| Privacy Owner / Data Protection Contact | gianlucca.florencio@zeroholding.com.br | 5 business days |
| Security reports and incident notification | gianlucca.florencio@zeroholding.com.br | Acknowledged within 24 hours |
Document control
This Trust Center is published at https://v2.nexusgroup.app.br/trust and is publicly reachable without authentication so that reviewers can verify it at any time.
Approved and maintained by the NEXUS Group Privacy Owner. Reviewed at least annually, and after any material change to the service.