Privacy Policy

Last updated: 9 September 2026 (draft)

Who we are

The public NexusOS website is operated by Cosmic Brokkoli UAB, J. Savickio g. 4-7, LT-01108 Vilnius, Lithuania (company code 307504828). Contact: the email published on the Contact page.

What this policy covers

This draft covers the public website only. The NexusOS application processes customer data under separate agreements and tenant configuration. Signing in to NexusOS is not offered on this site.

Information we collect

If you send the contact form we process first name, last name, work email, company, country, company size, tools you mention, the operational problem you describe, preferred contact method, and the time of submission. If you email us directly we process the content of that message. Server logs may include IP address, user agent and requested URL for security and rate limiting.

Why we process it

We use enquiry data to respond, to schedule a meeting if you ask for one, and to understand whether NexusOS is relevant to your organisation. Logs are used to keep the site available and to limit abuse of the form.

Legal basis (draft)

Responding to a business enquiry is typically legitimate interest and/or steps prior to a contract. Consent is collected for the form because you must acknowledge this policy before sending. Counsel should confirm the bases before publication.

Recipients

Messages are delivered to the Cosmic Brokkoli mailbox configured on the server (CONTACT_FORM_RECIPIENT). If MailerSend is configured, that provider processes the email in transit. We do not sell enquiry data. We do not write contact-form submissions into the NexusOS operational database.

Retention (draft)

Enquiry messages are kept as long as needed to handle the conversation and ordinary commercial follow-up, then deleted or archived according to internal policy. Exact periods must be confirmed legally.

Your rights

You may request access, correction, deletion or restriction of personal data we hold about an enquiry, and you may object to processing based on legitimate interest. You may lodge a complaint with the State Data Protection Inspectorate (VDAI) in Lithuania or your local authority.

Transfers

If an email or hosting provider processes data outside the EEA, appropriate safeguards must be documented before production. This draft does not assert that all subprocessors are already listed.