Privacy Policy

Effective date: 22 September 2026  ·  Last updated: 22 September 2026

1. Who we are

This website, nexus-optronics.com (the “Site”), is operated by NEXUS OPTRONICS EOOD, a company registered in the Republic of Bulgaria (“NEXUS”, “we”, “us”, “our”). We design and supply optoelectronic and night-vision systems to professional, institutional and distribution partners.

We are the data controller for the personal data described in this policy, meaning we decide why and how it is processed.

Contact point for privacy matters:
Email: d.atanasov@nexus-optronics.com
Registered office: 4120 Katunitsa, Bulgaria
Company registration number (EIK): 208945155
VAT number: BG208945155

We have not appointed a Data Protection Officer, because our processing does not meet the thresholds that require one. Privacy questions are handled at the contact point above.

2. What this policy covers

This policy explains what personal data we collect through the Site, why we collect it, how long we keep it, who we share it with, and what rights you have. It applies to visitors of the Site and to people who contact us through it.

If you are looking specifically for information about cookies and similar technologies, please also read our Cookie Policy, which forms part of this policy.

3. What data we collect

3.1 Information you give us

Our Site has a single business enquiry form. If you use it, we collect the information you enter:

  • organisation name
  • business email address
  • country
  • your role (distributor, integrator, government or other)
  • mission role of interest (helmet, weapon, handheld or full ecosystem)
  • the content of your message

If you contact us by email instead, we receive your email address and whatever you include in your message.

3.2 Information collected automatically

Like any website, the Site is served by a hosting provider. Our hosting infrastructure records standard technical data in server logs, including your IP address, the date and time of the request, the page requested and your browser’s user-agent string. These logs are used to keep the Site available, secure and functioning, and for no other purpose.

3.3 Cookies and similar technologies

The Site uses a very small number of cookies and similar storage technologies, almost all of them strictly necessary for the Site to work. You can see the full list, with durations and purposes, in our Cookie Policy.

3.4 What we do not collect

We want to be explicit about this, because it is not the norm:

  • We do not use website analytics or traffic-tracking tools. We do not build profiles of how you browse.
  • We do not use advertising, retargeting or social-media tracking pixels.
  • We do not sell, rent or trade personal data to anyone.
  • We do not operate user accounts, a newsletter or an online shop on this Site, so we do not collect passwords, payment details or marketing-consent data here.

4. Why we process your data, and our legal basis

PurposeData usedLegal basis (GDPR Art. 6)Retention
Responding to your enquiry and assessing whether there is a business fitThe information you submit in the form or emailSteps taken at your request prior to entering into a contract – Art. 6(1)(b); and our legitimate interest in handling business enquiries – Art. 6(1)(f)24 months from the last contact
Keeping the Site available, secure and free of abuseServer log data (IP address, timestamp, requested URL, user-agent)Our legitimate interest in operating a secure website – Art. 6(1)(f)30 days
Remembering your cookie choices so the consent banner does not reappearA single consent cookieStrictly necessary, and compliance with our legal obligations under the ePrivacy rules – Art. 6(1)(c)1 year
Keeping records of consent, to be able to demonstrate complianceAn anonymous consent identifier, your choices, and a timestampCompliance with a legal obligation – Art. 6(1)(c)As required by the record-keeping obligations we are subject to
Meeting our export-control, sanctions and end-use screening obligations where an enquiry concerns controlled goodsOrganisation, country and the content of the enquiryCompliance with a legal obligation – Art. 6(1)(c); and our legitimate interest in lawful trade – Art. 6(1)(f)The statutory period required for export-control and sanctions records.

Where we rely on legitimate interests, we have weighed those interests against your rights and freedoms and consider the processing to be proportionate, in particular because the data involved is business contact data submitted by you voluntarily.

5. Cookies

Our consent banner lets you accept, reject or fine-tune cookie categories. Only strictly necessary cookies are set before you make a choice; the other categories are currently not in use on this Site. You can change or withdraw your choice at any time using the Consent Preferences button on our Cookie Policy page, or the small revisit button in the corner of the screen.

6. Who we share data with

We do not sell or rent personal data. We use a small number of service providers who process data on our behalf, under contract and only on our instructions:

ProviderWhat it doesWhat it can see
Hosting and CDN provider (Hostinger)Hosts and serves the SiteServer logs, including IP addresses
CookieYes (consent management platform)Shows the consent banner and records consent choicesA consent identifier, your cookie choices and a timestamp — not your identity
Our email providerDelivers and stores enquiry emailsYour email address and the content of your message

We may also disclose data where we are legally required to do so, for example in response to a lawful request from a competent authority, or where necessary to enforce our rights or to comply with export-control or sanctions obligations.

7. International transfers

We are established in the European Union. Some of the service providers listed above process data outside the European Economic Area (EEA), and the safeguards described below apply to those transfers:

  • Hosting and CDN (Hostinger) — the Site is hosted in a data centre located in North America (United States, Arizona), with backups stored in the United States (Boston). Server logs, including IP addresses, are therefore processed outside the EEA. These transfers are covered by the European Commission’s Standard Contractual Clauses and, where applicable, by the provider’s certification under the EU–US Data Privacy Framework.
  • Email delivery and storage — enquiry emails are delivered and stored by our email provider, Hostinger Email, which may process data outside the EEA under the same transfer safeguards.
  • Consent records held by our consent management provider may be stored outside the EEA under an equivalent transfer mechanism.

8. How long we keep data

We keep personal data only as long as we need it for the purpose it was collected, or as long as the law requires. Indicative periods are shown in the table in section 4. When data is no longer needed, we delete it or irreversibly anonymise it.

9. Your rights

If you are in the European Economic Area, Switzerland or the United Kingdom, you have the following rights in relation to your personal data:

  • Access — to be told whether we hold data about you and to receive a copy.
  • Rectification — to have inaccurate or incomplete data corrected.
  • Erasure — to have your data deleted where there is no continuing lawful reason for us to keep it.
  • Restriction — to have processing limited while a concern is being resolved.
  • Portability — to receive the data you provided to us in a structured, commonly used, machine-readable format.
  • Objection — to object to processing carried out on the basis of our legitimate interests.
  • Withdraw consent — where processing is based on consent, to withdraw it at any time, without affecting the lawfulness of processing carried out before the withdrawal.
  • Complain — to lodge a complaint with a supervisory authority.

To exercise any of these rights, email d.atanasov@nexus-optronics.com. We will respond within one month, and may ask you to verify your identity first. Exercising your rights is free of charge.

Our lead supervisory authority is the Commission for Personal Data Protection of the Republic of Bulgaria (cpdp.bg). You may also complain to the supervisory authority in your own country of residence, place of work or place of the alleged infringement.

10. Security

We use appropriate technical and organisational measures to protect personal data against unauthorised access, loss or alteration. These include encrypted transport (HTTPS) across the Site, restricted administrative access, and keeping the software that runs the Site up to date. No method of transmission or storage is perfectly secure, but we review our measures as the Site evolves.

11. Sensitive and controlled information

This Site is intended for general business enquiries only. Please do not send us classified, export-controlled, restricted or otherwise sensitive operational information through the enquiry form or by email. If your enquiry concerns controlled goods, we may need to ask for additional information for screening purposes, and we will do so through an appropriate channel.

12. Children

The Site is directed at businesses and professional users. It is not intended for children, and we do not knowingly collect personal data from children.

13. Changes to this policy

We may update this policy from time to time, for example if we change a service provider or add a new feature to the Site. The effective date at the top of this page shows when the current version took effect. Material changes will be highlighted on this page.

14. How to contact us

For any question about this policy or about how we handle your personal data, contact us at d.atanasov@nexus-optronics.com.