Skip to content
Nexus
PlatformCapabilitiesComplianceArchitectureDeploymentResourcesHow to buy
Request Briefing
PlatformCapabilitiesComplianceArchitectureDeploymentResourcesHow to buyRequest Briefing
Home/Privacy Policy

Legal & privacy

Privacy Policy

How Inject Group Ltd collects, uses, stores, and protects personal data in connection with Nexus, in line with UK GDPR, EU GDPR, and Nigeria’s NDPR / NDPA.

Effective 17 August 2026 · Last updated 31 August 2026

On this page

  1. Who we are
  2. Scope
  3. Data we collect
  4. Purposes and lawful bases
  5. Sharing
  6. International transfers
  7. Retention
  8. Security
  9. Your rights
  10. Cookies
  11. Children
  12. Complaints
  13. Changes
  14. Contact

1. Who we are

This Privacy Policy is issued by Inject Group Ltd (“Inject Group”, “we”, “us”), the developer and licensor of the Nexus CB IMTO Transparency System.

  • Registered in England and Wales, company number 16282987
  • Registered office: Suite 15, Woodfield Business Centre, Carr Hill, Doncaster, South Yorkshire, DN4 8DE, United Kingdom
  • Privacy contact: governance@injectgroup.com

Inject Group Ltd is the data controller for personal data collected through this website and inquiry forms. Where Nexus is deployed inside a central bank or by an authorised integration partner, that institution is typically the controller of supervisory and IMTO operational data; this policy does not replace that institution’s own privacy notice.

2. Scope

This notice applies to personal data we process when you:

  • Visit the Nexus public website (including nexusimto.com and related landing pages)
  • Submit a briefing, demo, or access request
  • Submit a job application
  • Correspond with us by email about Nexus

It is designed to meet the transparency requirements of the UK GDPR and Data Protection Act 2018, and the EU General Data Protection Regulation (EU) 2016/679. Where a licensed deployment processes Nigerian personal data, we also apply NDPR / NDPA requirements in that deployment.

3. Data we collect

Information you provide

  • Identity and contact details: name, email, organisation, role, location
  • Inquiry or application content: message, briefing topics, LinkedIn or portfolio links, and any attachments you send
  • Correspondence: emails and follow-up notes related to your request

Information collected automatically

  • Technical logs such as IP address, browser type, device, and pages requested, used to operate and secure the site
  • Approximate timestamps of form submissions
  • If you accept analytics cookies: a tab session id, page path, title, referrer, time on page, addresses of links opened, and a company- or network-level label for your IP range (a known central-bank or partner institution when we can match it, otherwise the network or ISP). When you leave the site we may email our team a session summary. Alerts include a coarse location (country or region from the network, not GPS). We do not identify you by name, personal email, or LinkedIn profile from this matching.

We do not require special-category data (for example health or biometric data) through this website. Please do not include confidential supervisory or personal data about third parties in the inquiry form.

4. Purposes and lawful bases

We process personal data only where a lawful basis applies:

Purpose Lawful basis (UK / EU GDPR) NDPR / NDPA
Respond to briefing and access requests, including the auto-acknowledgement email Legitimate interests (Art. 6(1)(f)); steps toward a contract (Art. 6(1)(b)) Legitimate interest / performance of a contract
Review job applications and send an acknowledgement email Legitimate interests (Art. 6(1)(f)); steps toward a contract (Art. 6(1)(b)) Legitimate interest / performance of a contract
Operate, secure, and troubleshoot the public website Legitimate interests (security and service integrity) Legitimate interest
Comply with legal, accounting, or regulatory obligations Legal obligation (Art. 6(1)(c)) Legal obligation
Optional follow-up that is not strictly necessary to handle your request Consent (Art. 6(1)(a)), which you may withdraw at any time Consent
Company-level visitor alerts (a session summary after you accept analytics and leave the site, including pages viewed, links opened, and the organisation or network of the IP range) Consent (Art. 6(1)(a)). The public site stays behind the cookie notice until you accept. Privacy, terms, and security remain readable. Consent

Our legitimate interests are to evaluate and respond to institutional inquiries about licensed financial-market infrastructure, to protect our systems, and to keep a record of who requested access. Those interests are balanced against your rights, and you may object as described below.

5. Sharing

We may share personal data with:

  • Inject Group staff and contractors who need it to handle your inquiry
  • Authorised central bank-accredited integration partners, only where your request concerns an in-country deployment they support
  • Service providers who host email, infrastructure, or security logging, under written contracts
  • Professional advisers, auditors, or authorities where required by law

We do not sell personal data.

6. International transfers

Inject Group Ltd is established in the United Kingdom. Inquiry data may be processed in the UK and, where a hosting or email provider operates elsewhere, in other countries. For transfers from the UK or EEA we use an adequacy decision where one exists, or appropriate safeguards such as the UK International Data Transfer Agreement or EU Standard Contractual Clauses.

Where Nigerian personal data is transferred outside Nigeria, we apply NDPR/NDPA transfer rules, including adequacy, contractual safeguards, or another lawful transfer mechanism, and we keep the data limited to what is needed to handle the inquiry.

7. Retention

Access and briefing requests are retained for up to 24 months after last contact, unless a longer period is required for a live evaluation, contract, dispute, or legal obligation. Security logs are kept only as long as needed for incident investigation and service integrity, then deleted or anonymised.

8. Security

We apply organisational and technical measures appropriate to the risk, including access control, encrypted transport (HTTPS), least-privilege handling of inquiry mail, and audit logging. A fuller description is in our Security Notice. No method of transmission or storage is completely secure; we work to prevent unauthorised access and to respond if an incident occurs.

9. Your rights

Depending on your location, you may have the following rights. We will honour the strongest set of rights that applies to you.

UK GDPR and EU GDPR

  • Access a copy of your personal data
  • Rectify inaccurate or incomplete data
  • Erase data in the circumstances set out in law
  • Restrict or object to certain processing, including processing based on legitimate interests
  • Data portability for information you provided to us, where processing is based on consent or contract and is carried out by automated means
  • Withdraw consent where processing is based on consent, without affecting prior lawful processing
  • Not be subject to a solely automated decision with legal or similarly significant effects (we do not make such decisions on this website)

NDPR and NDPA (Nigeria)

  • Be informed that your personal data is being collected and of the purposes
  • Access and request correction or deletion of your personal data
  • Withdraw consent and object to processing that is not required by law
  • Data portability where technically feasible

To exercise these rights, email governance@injectgroup.com with “Privacy request” in the subject line. We may need to verify your identity. We aim to respond within one month.

10. Cookies

Cookie categories are selected by default. You can use this site after you accept cookies (except this policy, the terms, and the security page, which remain readable). Rejecting cookies leaves the notice on screen. A strictly necessary cookie, nexus_consent, stores an accepted choice for up to 180 days so we do not ask on every page. You can open Cookie settings from the footer at any time.

If you accept analytics, a first-party script stores a tab session id and sends the page path, title, referrer, time on page, and the addresses of links you open to our API on Google Cloud. The API reads your IP from the request and labels the network: a known central-bank or partner institution when the range is on our allowlist, otherwise the ISP or an unlisted network. When you leave the site we may email our team a session summary, including a coarse country or region. Until you accept, that script does not run. Bots are not stored for this purpose. We do not set advertising cookies, Google Analytics tags, or LinkedIn Insight tags on this public site.

11. Children

Nexus is offered to institutional users. We do not knowingly collect personal data from children. If you believe we have done so, contact us and we will delete it.

12. Complaints

Please contact us first so we can try to resolve the issue. You also have the right to complain to:

  • United Kingdom: Information Commissioner’s Office (ICO) — ico.org.uk
  • European Union / EEA: your local supervisory authority, via the European Data Protection Board list

13. Changes

We may update this policy to reflect legal, technical, or operational changes. The “last updated” date at the top of this page will change, and material updates will be posted here.

14. Contact

Data protection inquiries: governance@injectgroup.com
Postal: Inject Group Ltd, Suite 15, Woodfield Business Centre, Carr Hill, Doncaster, South Yorkshire, DN4 8DE, United Kingdom

Related documents: Terms of Service · Security Notice

We use cookies

Inject Group Ltd uses essential cookies to make this website work. With your consent, we also use analytics cookies to understand which organisations and networks visit our pages. That identifies the organisation or network and country, not you by name. We do not use cookies for advertising. Privacy Policy.

Rejecting analytics still lets you use the site. Accept if we may record organisation- or network-level visits.