Privacy Policy
Applies to all users of the SAL Nexus readiness and transaction network.
1. Data we collect
Account data: name, work email, role category and organisation membership.
Organisation data: entity name, type, verification status and supporting evidence you submit.
Project and transaction data: project passports, milestones, documents, mandates, matches, diligence requests, procurement bids and fee records.
Security and audit data: sign-in events, MFA enrolment and verification results, document access requests and administrative actions.
2. How we use it
To operate the platform: authenticate you, apply role-based permissions, compute readiness scores and route matches between projects and mandates.
To maintain network integrity: verify organisations, detect duplicate projects, flag stale or expired evidence and investigate security events.
To communicate: transactional alerts, diligence and procurement notifications, and administrative correspondence. Alert categories can be muted in your notification preferences; security-critical alerts cannot.
3. Confidentiality and disclosure
Project data rooms are private by default. Counterparties see only what your organisation authorises, and only for the access window granted.
Blind matching exposes de-identified project characteristics until the project owner authorises disclosure.
We do not sell personal data or share it with advertisers. Data is disclosed to service providers strictly to run the platform, and to authorities where legally required.
4. Storage and security
Data is held in managed cloud infrastructure with encryption in transit and at rest, row-level access policies, private document storage and full audit logging.
Multi-factor authentication is available to all users and is enforced for sensitive data room access.
5. Retention
Account, project and transaction records are retained while your organisation remains active and thereafter for the period required for legal, audit and regulatory purposes.
Security and audit logs are retained as immutable records for compliance review.
6. Your rights
You may access, correct or export your account and organisation data from the Account and Organization settings areas, and request deletion where no legal retention obligation applies.
Requests and privacy questions can be sent to privacy@leanengineering.io.