How Torus Nexus Limited handles personal data
Torus Nexus Limited is a company registered in England and Wales, number 17280402.
Registered office: 167–169 Great Portland Street, London W1W 5PF, United Kingdom.
Data protection enquiries: contact@torusnexus.com
ICO registration number: [to be added on registration]
This notice covers two things: this website, and the Torus CCM service we operate for clients. It explains what personal data we hold, why, for how long, and what your rights are under the UK General Data Protection Regulation and the Data Protection Act 2018.
1. This website
This website is a set of static pages. It sets no cookies, runs no analytics, and loads nothing from advertising or tracking networks. We do not build profiles of visitors and we cannot identify you from your visit.
The site is served by Cloudflare, our hosting provider. Like any web host, Cloudflare processes the technical data your browser sends when it requests a page — your IP address, browser type and the pages requested — to deliver the site and protect it from abuse. Cloudflare acts as our processor for this purpose. We do not receive or retain individual visitor logs.
2. When you contact us
The only way to give us personal data through this site is to email us. If you do, we hold what you send — typically your name, email address, employer, job title and the content of your message — in our email system.
- Why: to answer you, and to discuss a pilot or purchase if that is what you asked about.
- Lawful basis: our legitimate interest in responding to enquiries about our product and, where a pilot or contract follows, taking steps at your request before entering into it.
- How long: for as long as the conversation is live and for up to twelve months after our last exchange, unless it leads to a contract, in which case the correspondence is kept with the contract records.
We do not add you to a mailing list, and we do not share enquiry details with anyone else.
3. The Torus CCM service
Torus CCM is a purchase requisition intake and compliance service. Each client has a dedicated instance that we host and operate. The instance is not shared with any other client.
Who is responsible for what
The personal data inside a client's instance belongs to that client's requisition process: the names, email addresses, job titles and departments of the client's staff who use the system; the names of approvers and reviewers recorded on each request; the activity timeline recording who submitted, coded, reviewed and processed each request and when; and any personal data the client's staff enter into a request or attach to it.
For that data, the client is the controller and Torus Nexus Limited is the processor. We process it only to provide the service, on the client's documented instructions, under a written data processing agreement that forms part of each client contract. Questions about how a client uses the service, or requests to exercise your rights over data held in a client's instance, should go to that client. We will help them respond.
For the account details of the people the client nominates to administer its instance, and for the client's own contract and billing contacts, we are the controller, and the sections on retention and rights below apply directly.
What the service records, and why
| Data | Purpose |
|---|---|
| User accounts: name, email, job title, department, role | To identify who is acting in the system and enforce role-based access. |
| Login credentials | Passwords are stored only as salted hashes. Where a client uses single sign-on, we hold the identifier the client's identity provider sends, not a password. |
| Activity timeline on every request | An append-only record of who did what and when. This is the audit trail the service exists to produce; entries cannot be edited or deleted. |
| Administration log | An append-only record of changes to rules and of role grants, and who made them. |
| Certificates of Compliance | Each names the people who submitted, coded, reviewed and processed the request. Certificates are signed with a key held by the client's own instance. |
| Session identifiers and IP addresses | To keep users signed in, to time sessions out after inactivity, and to rate-limit login, registration and password-reset attempts. |
| Email addresses for notifications | To send workflow notifications, where the client has configured them, and password-reset links. |
| Backups | Copies of the instance's data taken on the client's chosen schedule, kept for the retention period the client sets, so the instance can be restored. |
Public certificate verification
Anyone holding a Certificate of Compliance can enter its verification code on the instance's public verification page. The response confirms whether the certificate is genuine and unchanged and shows the request's identifying details, including the name of the person who processed it. That page holds no account, sets no cookie, and rate-limits attempts by IP address. No record of who checked a certificate is kept beyond the temporary rate-limit counter.
Where the data is held
Each instance runs on dedicated infrastructure that we operate. The hosting location and provider are set out in the client's agreement. We do not transfer client data outside the United Kingdom unless the client's agreement provides for it.
Who else sees it
Nobody, in the ordinary course. We do not sell, rent or share client data, and we do not use it to train models or for any purpose of our own. Our infrastructure provider processes it only as our sub-processor, under contract, to host the instance. We will name our sub-processors in each client's agreement and tell the client before any change.
How long we keep it
For the life of the client's contract, and then for a hand-over period the contract sets so the client can take a copy, after which the instance and its backups are deleted. Because the activity timeline and administration log are the audit record the client relies on, individual entries are not deleted on request during the contract; the client controls retention of the record as a whole.
4. Your rights
Where we are the controller, you have the right to ask us for a copy of the personal data we hold about you, to have it corrected, to have it deleted, to restrict or object to how we use it, and to receive it in a portable form. Email contact@torusnexus.com and we will respond within one month. We may ask you to confirm your identity first.
Where a client is the controller, please contact the client. We will help them meet the request.
You also have the right to complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113. We would welcome the chance to address any concern first.
5. Security
Client instances are single-tenant. Passwords are hashed, sessions expire on inactivity, authentication endpoints are rate-limited, and connections are encrypted in transit. Every certificate carries a cryptographic seal so that any later change to the underlying record is detectable. Backups are taken on a schedule with a retention limit and can be restored by the client's administrators.
6. Changes to this notice
We will update this page when our practices change and revise the version and date at the top. Material changes affecting clients will be notified to them directly.