Privacy Policy
Nexus Technology LLC — the Nexus Platform and the systems deployed at our customers’ sites
Introduction
Nexus Technology LLC, a company incorporated in Mongolia (“Nexus Technology”, “we”, “us”, “our”), builds and operates the Nexus Platform: a single signed-in system through which mining and industrial organisations run enterprise administration, live operations, engineering, customs, security, logistics, market analysis and tenant control. We also deploy and maintain the on-site equipment that feeds it, including cameras, edge servers, weighbridge terminals and tracking devices.
This Privacy Policy explains what personal data we process, why we process it, how long we keep it, who else can see it, and what you can do about any of that. It applies to the Nexus Platform, its mobile application, the public website at nexus-technology.live and every package host under it, and the equipment we operate at customer sites.
We process personal data in accordance with the Law of Mongolia on Personal Data Protection, the Labour Law of Mongolia, the Law of Mongolia on Cyber Security, and the other Mongolian legislation that applies to our activities and to our customers’ operations. Where a customer is subject to a foreign data protection regime by virtue of its own group structure, we support that customer in meeting it under the terms of our contract with them, but this policy is written to Mongolian law.
Please read this policy together with our Terms of Service, which govern use of the Platform itself. If you do not accept this policy, do not use the Platform; where your employer has provisioned your account, speak to your employer, because some of the processing described here is carried out on their instructions and not ours.
Who and What This Covers
This policy covers four groups of people. First, Platform users: anyone who signs in, whether an administrator, a manager, an operator, a driver, an engineer or an external reviewer. Second, site personnel: workers, contractors, drivers and visitors whose presence, activity or vehicle is recorded by equipment we operate, whether or not they ever sign in. Third, people named inside customer records: the colleagues, counterparties, suppliers and contacts who appear in work items, rosters, procurement documents, weighbridge tickets and correspondence held in the Platform. Fourth, visitors to our public website.
It covers every environment in which that data lives: the cloud services that run the Platform, the edge servers installed in mine and office buildings, the private network that links them, the mobile application, and the backups and logs each of those produces.
It does not cover a third party’s own site or service that you reach from ours, even where we have linked to it. It does not cover what your employer does with data it exports from the Platform into its own systems. And it does not cover data that has been irreversibly aggregated or anonymised so that no person can be identified from it, directly or indirectly, which we no longer treat as personal data.
Our Role: Controller and Processor
Our role changes depending on whose data it is and why we hold it, and your rights follow that role. For our own business data — the accounts we create, our billing and correspondence with a customer, the security and audit logs we keep to protect the Platform, and the visitors to our public website — Nexus Technology decides the purposes and means of processing and is the controller.
For the operational data a customer puts into the Platform or generates through it — rosters, shift sheets, work items, weighbridge tickets, documents, camera footage, detection events and location traces from that customer’s site — the customer decides why that processing happens and Nexus Technology acts on its instructions as a processor. The customer is the controller of that data and is responsible for having a lawful basis for it, for telling its own workers about it, and for answering their requests.
In practice this means a request about your employment records, your shifts, your location trace or footage of you at work should go first to your employer. We will help them answer it, and we will answer it ourselves if they instruct us to or if the law requires us to. A request about your Nexus Platform account itself, or about our website, comes to us directly.
Where we determine our own purposes for data that originated with a customer — for example, using aggregated and de-identified system telemetry to keep the Platform reliable and secure — we act as a controller for that limited purpose and this policy governs it.
Personal Data We Process
Identity and account data: full name, preferred name in Mongolian and Latin script, work email address, telephone number, employee or seat identifier, job title, organisation and site assignment, role and permission grants, profile photograph or generated avatar, chosen language and interface preferences, account creation date and last-active timestamp.
Authentication and session data: a hashed password held by our authentication provider, session and refresh tokens, the “remember me” choice and its expiry, sign-in and sign-out events, the IP address and user agent a session was created from, and failed sign-in attempts.
Employment and workforce data, processed on behalf of an employer: roster pattern and rotation site, shift assignments and attendance, leave and handover requests, training and certification records where a customer records them, disciplinary or incident references attached to a work item, and reporting lines within the organisation directory.
Operational and activity data: work items you create, are assigned or comment on; approvals you grant or refuse; documents, drawings, spreadsheets and photographs you upload; reports you submit; messages you send in the Platform’s inbox and support desk; and the audit trail of the changes you make to records, which records who changed what and when.
Location data: latitude, longitude, accuracy, speed, heading, battery level and timestamp from worker handsets and vehicle tracking devices, where the customer has deployed them and the person has been informed. Vehicle telemetry may also include engine state, odometer and fuel figures reported by the vehicle or entered manually.
Camera and detection data: video and still images recorded by cameras at customer sites; automatically generated detection events describing what a model believes it saw, including the class of object (for example a person, a vehicle, a hard hat or a high-visibility vest), the position and size of the detection within the frame, a confidence score, the camera, and the time; and vehicle registration plate text produced by our plate recognition models at weighbridges and gates.
Weighbridge and logistics data: ticket records containing gross, tare and net weights, material, direction, customer and carrier, plate number, driver name where recorded, and the operator who issued the ticket.
Device, network and diagnostic data: application version, operating system, device model, screen size, connection type, crash reports, error traces, performance timings, and the server-side request logs the Platform writes for every page and action.
Communications and support data: messages you send us, tickets you raise, the content and metadata of notifications we send you, and, where a customer has enabled it, the security summaries delivered to an operational messaging group.
We do not process special categories of data — such as health, biometric templates for the purpose of uniquely identifying a person, political opinions, religious belief, trade union membership or sexual life — unless a customer expressly instructs us to for a purpose permitted by Mongolian law and we have agreed to it in writing. Our camera models detect the presence and class of an object; they are not configured to recognise a person’s face or to produce a biometric identifier.
Where the Data Comes From
From you: what you type, upload, photograph, record or select while using the Platform, and what you tell us when you contact support.
From your employer or the organisation that provisioned your account: your identity, role, site, reporting line, roster pattern and permission grants, and any employment records it chooses to hold in the Platform.
From equipment operating at a site: cameras, network video recorders, edge inference servers, weighbridge indicators, gate controllers and tracking devices, all of which report automatically and continuously.
From your device: the diagnostic, performance and network data described above, and — only with your permission, given through the operating system — precise location and camera access in the mobile application.
From third parties we rely on: authentication, hosting, network protection, mapping, weather and messaging providers, which return data to us as part of delivering their service.
We do not buy personal data, we do not enrich our records from data brokers, and we do not build profiles of you from sources outside the Platform.
Lawful Basis
Under the Law of Mongolia on Personal Data Protection we must have a lawful basis for every processing activity, and that statute grounds processing principally in your consent, in a requirement of law, or in a decision of a competent authority. What follows describes how each of our activities fits those; where we go further than the statute requires, we say so rather than dress a commercial choice as a legal one. Where we are the controller, we rely on the following.
Performance of a contract: to create and maintain your account, to make the Platform work, to provide support, and to administer our agreement with the organisation you belong to.
Compliance with a legal obligation: to keep the accounting, tax, employment, occupational safety and mineral-sector records Mongolian law requires us or our customers to keep, and to respond to a lawful request from a competent authority.
Our own legitimate interests, so far as Mongolian law allows us to rely on them and only where they are not overridden by your rights and freedoms: securing the Platform against intrusion and abuse, detecting and investigating incidents, keeping the service reliable, improving it, and bringing or defending legal claims. Mongolian law does not frame this ground as broadly as some foreign regimes do, so where an activity would rest on it alone we look for consent or a duty in law first. We assess each case before relying on it and will describe that assessment to you on request.
Consent, which you may withdraw at any time without affecting processing already carried out: for precise location from a personal handset, for camera and microphone access on a mobile device, and for any optional communication you have opted into. Withdrawing consent may mean a feature stops working; it will never cost you access to the rest of the Platform.
Where we act as a processor for a customer, the lawful basis is the customer’s to establish, most commonly the performance of your employment contract, the employer’s legal obligations in occupational safety and working time, or the employer’s legitimate interest in the security of a hazardous industrial site. We require every customer to confirm that it has a lawful basis and has informed the people concerned before we switch monitoring on.
Why We Process It
To operate the Platform: to authenticate you, to decide what you are allowed to see and do, to render the pages and data you ask for, to deliver notifications, and to keep your work synchronised across the web and mobile applications.
To run our customers’ operations: to plan and record mining activity, to issue and reconcile weighbridge tickets, to manage fleets, rosters, inventory, procurement, customs declarations and logistics, to produce reports, and to give supervisors a live view of the site.
To keep people safe: to monitor compliance with personal protective equipment rules, to detect hazards, unauthorised access and unsafe vehicle movement, to locate a worker in an emergency, and to support the investigation of an accident or near miss.
To protect the Platform: to detect and prevent unauthorised access, credential abuse, data exfiltration and denial-of-service, to maintain an audit trail of privileged actions, and to satisfy ourselves that access controls are working.
To support and improve the service: to diagnose faults, to measure performance, to understand which features are used and where they fail, and to develop new ones. Wherever this is possible we work with aggregated or de-identified data rather than records about identifiable people.
To meet our legal and contractual obligations: to keep the records the law requires, to respond to lawful requests, to enforce our Terms of Service, and to establish, exercise or defend legal claims.
We do not use your personal data for advertising, we do not sell it, we do not share it for another organisation’s marketing, and we do not train general-purpose artificial intelligence models on customer content.
Cameras and Automated Detection
Customer sites are monitored by fixed cameras. Recording is continuous at most locations and is accompanied by automated analysis that runs on servers physically located at the site. This is a material intrusion and we describe it plainly rather than burying it.
Automated analysis produces detection events, not identifications. A model reports that it believes it has seen an object of a particular class at a particular place at a particular time, with a confidence score. Where plate recognition is deployed at a gate or weighbridge, it produces the characters of a vehicle registration plate. Neither is facial recognition, and we do not operate facial recognition on customer sites.
Cameras are placed to observe operational areas: pits, haul roads, gates, weighbridges, workshops, stockpiles, warehouses and office approaches. They are not placed in changing rooms, sanitary facilities, rest areas designated as private, or medical rooms. If you believe a camera is positioned somewhere it should not be, tell us or your employer and we will investigate.
Covert recording is not a feature of this Platform. Every site operating cameras through it is contractually required to post visible notice at every entrance and in every monitored area, to tell its workers what is recorded and why before monitoring begins, and to consult its workforce where the Labour Law of Mongolia or a collective agreement requires it. We may suspend monitoring at a site that has not met those obligations.
Access to live and recorded video is restricted by role, is limited to the sites a person is assigned to, and is logged. Footage is reviewed for security, safety and incident investigation. We build no productivity-scoring feature into it and will not configure it to rank or rate individuals. What a customer does with the access it lawfully holds is its own responsibility as controller, and our Terms of Service forbid using an automated output as the sole basis for a decision about a person.
Location and Vehicle Tracking
Where a customer has deployed them, worker handsets and vehicle devices report their position periodically. On a vehicle, this is tracking of the asset. On a handset, it is tracking of the person carrying it, and we treat it accordingly.
Precise location from a mobile device is collected only after you have granted permission at the operating system level, and only while the feature that needs it is in use. You can withdraw that permission at any time in your device settings. Withdrawing it stops location reporting; it does not disable your account.
Customers are required to limit worker location tracking to working time and to the site perimeter, and to tell workers before it starts. Where our software can enforce that limit we do. Tracking a worker outside working hours is not a use we support, and a customer that requires it is in breach of our Terms of Service.
Location data is used for dispatch and fleet management, for emergency response, for reconstructing the movement of a vehicle around an incident, and for operational analysis at the level of the site rather than the individual. Historical traces are retained for a limited period and then deleted, as set out below.
Where Data Is Stored
Video and detection events are stored first on edge servers installed at the site that produced them. Keeping footage local means the bulk of the most sensitive material never leaves the customer’s premises, and that a network outage does not interrupt recording. These servers sit on a private network, are reachable only over an authenticated encrypted overlay, and are physically in the customer’s care.
Records, documents, messages and the operational database are stored in managed cloud infrastructure operated by our providers. The Platform itself is hosted on Vercel; the database, authentication and file storage are provided by Supabase; network routing and protection are provided by Cloudflare. Backups are held by those providers under their own encryption and retention arrangements.
Server-side logs, which may contain identifiers, IP addresses and the outcome of an action, are written both to the hosting provider’s log store and to a retained log directory used for diagnosis. We keep secrets, credentials and message bodies out of those logs deliberately, and we redact fields whose names suggest a secret as a backstop.
Our data is logically separated by tenant. A tenant boundary is enforced in the database itself, not only in the application, so that a fault in one layer does not expose one customer’s records to another.
How Long We Keep It
Video footage is retained on site for a rolling period, by default seven days, after which it is overwritten automatically. Footage relevant to an open incident, dispute, safety investigation or legal claim is preserved for as long as that matter is live and for a reasonable period afterwards.
Detection events are retained alongside footage and, in summary form, for longer where they feed safety statistics. Plate recognition results attached to a weighbridge ticket are retained with the ticket.
Location traces are retained for thirty days in raw form. Aggregated movement summaries, which do not identify an individual, may be retained longer.
Operational records — tickets, reports, work items, rosters, documents and correspondence — are retained for as long as the customer’s account is active, and afterwards for the period that Mongolian accounting, tax, employment, occupational safety and mineral-sector law requires the customer to keep them.
Account data is retained while your account is active. When an account is closed we deactivate it and retain the record for a limited period so that the audit trail of what that person did remains intelligible, then delete or anonymise it. Audit and security logs are retained for up to twelve months unless a longer period is required for an investigation.
We do not hard-delete customer data on a whim. Deletion inside the Platform moves a record to a recoverable state first, so that a mistake can be undone, and only a deliberate, authorised purge removes it permanently.
Who We Share It With
Your own organisation: your employer and the administrators it appoints can see the data that belongs to it, within the limits of the permissions they hold. Your manager can see your shifts, your work items and, where deployed, your working-time location and the footage of the area you work in. This is the single largest category of access and you should assume it applies.
Other organisations in a customer group: where a customer is part of a holding structure and has configured the Platform that way, a parent organisation may see data for the subsidiaries beneath it. Access always follows the organisation tree; it never crosses to an unrelated tenant.
Our service providers, acting on our instructions under written terms: hosting (Vercel), database, authentication and storage (Supabase), network and DNS protection (Cloudflare), mapping and imagery for the digital twin (including Esri), weather data for operational forecasts, and, where a customer has enabled security notifications to a messaging group, Meta Platforms as the operator of WhatsApp Business. Each is bound to process data only as instructed and to protect it.
Our own staff: a small number of engineers hold administrative access for support, maintenance and incident response. That access is role-restricted, is used only when there is a reason, and is logged. We do not browse customer data out of curiosity and we treat doing so as a disciplinary matter.
Authorities: we disclose personal data to a court, regulator, inspector or law enforcement body where Mongolian law obliges us to. We check that a request is lawful and properly issued, we disclose only what is called for, and, unless we are legally prohibited, we tell the affected customer before we comply.
A successor: if our business or a part of it is sold, merged or reorganised, data may transfer to the acquirer, who will be bound by commitments no weaker than these. We will tell affected customers before that happens.
We do not share personal data with anyone else, and we never sell it.
Transfers Outside Mongolia
Some of the infrastructure we rely on is operated outside Mongolia. In practice this means that records, documents, messages and backups held in our cloud database and hosting may be processed in data centres in other countries, and that support requests you send us may be handled by a provider abroad.
Video footage and raw detection events are the deliberate exception: they stay on the edge servers at the site and are not exported to cloud storage in the ordinary course. A clip exported for an investigation is a specific, logged act.
A transfer out of Mongolia needs its own basis under the Law of Mongolia on Personal Data Protection, and we treat that as the starting point rather than as something a contract can substitute for. On top of it, we transfer only to a recipient bound by written protections no weaker than those we apply ourselves, and only where the transfer is necessary for the purposes described in this policy. We assess each provider before we adopt it and we review that assessment when its terms change.
If a customer requires that a category of data never leaves Mongolia, tell us. Depending on the category we can often meet that with an on-site or in-country deployment, and it is a question best settled before a system is installed rather than after.
How We Protect It
Access is controlled by role and by organisation. Every request is authorised on the server against the permissions of the signed-in person and the tenant they belong to; the interface hiding a button is a convenience, never the control. Privileged and cross-tenant access is held by a deliberately small number of identities.
Data is encrypted in transit everywhere, using current TLS. Data at rest is encrypted by our storage providers. The private link between our servers and the equipment at a site runs over an authenticated encrypted overlay network, not over the open internet.
Credentials are never stored in our source code and never written to logs. Passwords are hashed by our authentication provider and are not visible to us. Sessions expire, and the “remember me” choice extends that only for a bounded period on devices where you have asked for it.
We keep an audit trail of significant actions, we monitor for anomalies, we review dependencies for known vulnerabilities, and we run automated code analysis and an automated test suite before a change reaches production. Changes to production are made through a reviewed process, not by hand.
No system is perfectly secure, and we do not claim otherwise. What we commit to is proportionate technical and organisational measures, honest disclosure when something goes wrong, and continuous improvement rather than a fixed checklist.
Data Breaches
If personal data we hold is lost, altered without authority, disclosed to someone who should not have seen it, or accessed unlawfully, we treat it as a security incident from the moment we suspect it.
We investigate immediately, contain the incident, and record what happened, what data was affected, how many people are involved and what the consequences may be. Where we act as a processor we notify the affected customer without undue delay so that it can meet its own obligations as controller.
Where we are the controller and the incident is likely to harm the people concerned, we notify the competent Mongolian authority and the affected individuals without undue delay, describing what happened, what we have done, and what they can do to protect themselves.
We will not conceal an incident, minimise it, or delay telling you in the hope that it turns out to be smaller than it looked.
Your Rights
The Law of Mongolia on Personal Data Protection gives you the right to know whether we hold personal data about you and to obtain a copy of it, to have inaccurate data corrected and incomplete data completed, to have data deleted where there is no lawful ground to keep it, and to withdraw a consent you previously gave. Beyond what that statute requires — as our own commitment, not because the law compels it — we will also restrict processing while a dispute about accuracy or lawfulness is resolved, consider an objection to processing we base on our own interests, and give you the data you provided in a structured, commonly used, machine-readable format.
These rights are not absolute. We may refuse or limit a request where the law requires us to keep the data, where it concerns an ongoing investigation, where it would reveal another person’s data, or where it is manifestly unfounded or excessive. If we refuse, we will tell you why and how to challenge it.
To exercise a right, write to us at the address in the Contact section, from the email address on your account where you have one, telling us what you want and enough detail for us to find the records. We may need to verify your identity before we act; we will ask for no more than is necessary to do that.
We respond without undue delay, and in any case within thirty days of receiving a request we can act on, or sooner where Mongolian law sets a shorter period. If a request is complex enough to need longer, we will tell you within those thirty days and give you a date. Exercising a right is free. If a request is repetitive or excessive we may charge a reasonable fee or decline, and we will say which and why.
If the data concerns your employment, your shifts, your location at work or footage of you at a site, your employer is the controller. Send the request to your employer. If you send it to us instead, we will tell you so and forward it — unless you ask us not to. A request can itself be sensitive, and we will not put one in front of your employer against your wishes; where you ask us not to forward it, we will tell you what we can do without them.
If you are not satisfied with how we have handled a request, you may complain to us first — we would rather fix it — and you may in any case complain to the National Human Rights Commission of Mongolia or another competent supervisory body, and seek a remedy through the Mongolian courts.
Automated Processing
The Platform runs automated analysis: models detect objects in camera frames, read registration plates, flag missing protective equipment, raise alerts on thresholds, and rank items for attention. These outputs are signals for a person to act on.
We do not make decisions that produce a legal effect on you, or something similarly significant, by automated means alone. A detection does not by itself discipline anyone, refuse anyone entry, dock anyone’s pay or end anyone’s engagement. A human being reviews the underlying evidence and decides, and that person is accountable for the decision.
Automated detection is imperfect. Models miss things, invent things, and perform worse in poor light, heavy dust, rain and snow — conditions that are ordinary at a Mongolian open-pit mine. A detection is evidence to be checked, never proof.
If an automated output has been used to your detriment, you are entitled to be told that it was used, to see the evidence behind it, to put your own account, and to have a person review the decision. Ask your employer, or ask us and we will route it.
Children
The Nexus Platform is a workplace system. We do not knowingly create an account for anyone below the minimum working age under the Labour Law of Mongolia. Where a customer lawfully employs someone aged under eighteen, it must confirm before we provision the account that the engagement, and the work the Platform will record, are lawful at that age.
If we learn that we hold personal data about a child in an account context, we will delete it promptly unless the law requires otherwise. If you believe a child’s data is held in the Platform, tell us and we will act.
This does not change the position where a child appears incidentally in footage recorded at a site — for example, a visitor at a gate. That footage is subject to the same retention and access rules as all other footage, and is deleted on the same rolling cycle.
Changes to This Policy
We update this policy when what we do changes, when the law changes, or when we can say something more clearly. The date at the top of the page always reflects the current version.
For a material change — a new category of data, a new purpose, a new recipient, a longer retention period, or anything that narrows your rights — we give notice before it takes effect, through the Platform and, where we hold your address, by email. Where the change requires your consent, we will ask for it rather than assume it.
Continuing to use the Platform after a change takes effect means you have been informed of it; it does not substitute for a consent the law requires us to obtain separately.
This policy is published in English, Mongolian, Russian and Chinese. We take care that the translations agree. If they do not, the English text governs the meaning, except where Mongolian law requires the Mongolian text to prevail, in which case it does.
Contact
For any privacy question, data request or complaint, write to us. Requests about your employment records, shifts, work-time location or site footage should go to your employer first, as the controller of that data.


