Legal
Data protection & security
Our engagements are advisory. We work from documents, interviews and aggregated management information rather than bulk personal or customer data — which keeps our data footprint deliberately small.
Last updated September 2026
Data minimisation by design
- We ask for the least information needed to answer the question in front of us — normally strategy documents, architecture and cost information, and aggregated or anonymised reporting.
- We do not request production access, customer databases or bulk personal data as a matter of course.
- Where an engagement genuinely requires access to personal data, we agree it in writing first, limit it to named individuals and a defined period, and put appropriate data processing terms in place.
Our role under UK GDPR
For our own business records — enquiries, contracts, correspondence — Nyxa acts as a data controller. In the limited cases where we handle personal data on a client's instruction, we act as a processor under that client's written terms.
Confidentiality
- Client material is treated as confidential and used only for the engagement.
- We are happy to work under a client's own NDA, information security schedule or supplier terms.
- Findings are anonymised before being used in any general commentary, and named references are only given with written permission.
Working practices
- Correspondence and documents are held in Microsoft 365 with multi-factor authentication.
- Devices are encrypted, password protected and kept up to date.
- Access to client material is limited to the people working on the engagement.
- Client material is returned or deleted at the end of an engagement on request, subject to any records we must retain by law.
- Where a client prefers it, we work inside their own environment and tooling rather than taking copies out.
Sub-processors
Our current supporting providers are Microsoft (email, documents and collaboration) and our website hosting provider. We will notify clients before introducing a new provider that would handle their information.
Incidents
If we become aware of an incident affecting client or personal information, we will contain it, inform the affected client without undue delay, and support any regulatory notification the client needs to make. Report a suspected issue to contact@nyxa.tech.
Related policies
See the privacy notice for personal information we hold, and the terms of use for how engagements are contracted. We do not currently claim any formal certification such as ISO 27001 or Cyber Essentials; where a client requires one, we will say so openly.
These policies are provided for information and will be updated with Nyxa Advisory's formal company registration details once available. They are not legal advice and should be reviewed by a qualified adviser before publication of any contractual commitments.