Skip to main content
Privacy Policy — Nexus Gaming Hub / Nexus Networks Group

PRIVACY POLICY & DATA PROTECTION STATEMENT

Compliant with the UK General Data Protection Regulation (UK GDPR) & Data Protection Act 2018
Applies to Nexus Gaming Hub, all emergency services divisions, Roblox servers, Discord communities & websites
Last Updated: 14 September 2026 • Effective: 14 September 2026 • Version 1.1

I. Controller & Scope II. Data We Collect III. Lawful Basis & Purpose IV. Data Sharing & Disclosure V. Data Retention & Security VI. Your Rights VII. Cookies & Tracking VIII. Children & Minors IX. Third-Party Platforms X. Contact & Complaints

SECTION I — DATA CONTROLLER & SCOPE

1. Identity & Jurisdiction

Data Controller: Nexus Networks Group Ltd (operating through Nexus Gaming Hub)
Jurisdiction: United Kingdom (Scotland)
Legislation: UK General Data Protection Regulation (UK GDPR) & Data Protection Act 2018
Scope: This Privacy Policy applies to all data processing across our Roblox experiences, Discord servers, websites, applications, training systems, and emergency services roleplay frameworks. It applies to members, personnel, applicants, visitors, and all users of our services.

This policy explains how personal data is processed. Where we rely on consent, consent will be requested separately and may be withdrawn. Using a service does not by itself create consent for optional processing.

SECTION II — DATA WE COLLECT

2. Categories of Personal Data

We collect and process only the minimum data necessary to provide our services. We do not collect more than we need.

A. Data You Provide Directly

  • Identity and account information: Usernames, platform IDs, profile links, legal name, date of birth, contact details, and other identity information supplied through applications or verification processes.
  • Application & personnel data: Rank, role, training records, promotion history, conduct logs, appointment status, service records, eligibility evidence, and DBS/PVG declarations or verification information where a role requires enhanced safeguarding checks.
  • Communications: Messages, support tickets, reports, grievance submissions, and correspondence sent to staff or designated channels.
  • Content you publish: Text, images, voice, or other material shared in public or private channels within our services.

B. Data Collected Automatically

  • Usage & technical data: Platform-provided account metadata, timestamps, join/leave times, interaction logs, and device/basic technical information provided by Roblox, Discord, or web browsers.
  • Operational logs: Radio communications, incident reports, roleplay activity logs, command decisions, and oversight records — maintained for service integrity, accountability, and training purposes.
  • Website analytics: Anonymous traffic statistics, page visits, and navigation patterns — used to improve website performance and user experience.

RESTRICTED DATA: We do not request identity documents, National Insurance information, criminal-offence information, health information, or other sensitive data unless it is genuinely required for a clearly stated application, safeguarding, legal, or operational purpose. Where required, access is restricted, the reason is explained, and the information is retained only for as long as necessary. Do not post this information in public channels.

SECTION III — LAWFUL BASIS & PURPOSE OF PROCESSING

3. Why & How We Use Your Data

We process personal data only where one or more of the following lawful bases applies under UK GDPR:

  1. Legitimate Interests: To operate, secure, and improve our community; to maintain governance, oversight, and accountability within our emergency services framework; to ensure safety, enforce rules, and prevent abuse — where these interests do not override your privacy rights.
  2. Contractual Necessity: To administer membership, process applications, manage ranks, deliver training, maintain personnel records, and provide the services you have requested.
  3. Consent: Where you have given clear, specific, informed, and unambiguous consent — which you may withdraw at any time. Consent is required for all non-essential processing.
  4. Legal Obligation: To comply with applicable laws, platform Terms of Service, lawful requests, and regulatory obligations.

Specific Purposes

  • Verifying identity and eligibility for membership, roles, and promotions
  • Maintaining accurate personnel, rank, training, and conduct records
  • Providing governance, oversight, grievance, and disciplinary processes
  • Facilitating communications, incident response, and operational coordination
  • Investigating reports, enforcing rules, and protecting the safety of members
  • Delivering training, certifications, and professional development programmes
  • Responding to enquiries, support requests, and subject access applications
  • Complying with legal obligations and protecting our legal rights

SECTION IV — DATA SHARING, DISCLOSURE & THIRD PARTIES

4. Who May Receive Your Data

We do NOT sell, rent, or trade your personal data. We share information only in the limited circumstances listed below:

A. Internal Recipients

Authorised Nexus Gaming Hub personnel who have a legitimate operational need — and who are bound by strict confidentiality obligations — may access necessary data. Access is granted on a strict need-to-know basis only.

B. Third-Party Platform Providers

Data is processed through platforms including Roblox and Discord. Their respective Privacy Policies apply to data handled through their services. We encourage you to review:

C. Legal & Safety Disclosures

We may disclose information if required by law, court order, or government authority; or to protect the rights, property, or safety of ourselves, our users, or the public — provided such disclosure is lawful and proportionate.

NO PUBLIC DISCLOSURE: Personnel records, disciplinary records, application details, and internal communications are confidential and will NOT be disclosed publicly without explicit consent or lawful court order. Operational and governance data is treated as confidential information.

SECTION V — DATA RETENTION & SECURITY

5. How Long & How Protected

Retention Periods

We do not keep personal data longer than necessary. Standard retention periods:

  • Active membership: Retained while you remain an active member/personnel plus 90 days after departure or removal.
  • Personnel & governance records: Rank, training, promotion, and conduct records retained for the duration of service plus 90 days after departure in good standing. Records of serious misconduct may be retained up to 12 months for safety and compliance purposes.
  • Communications & operational logs: Retained as needed for context, safety, and accountability; routinely reviewed and cleared when no longer required. Voice and radio logs are not permanently archived.
  • Website & analytics: Anonymous statistical data retained indefinitely in aggregated non-personally identifiable form.

Security Measures

We implement appropriate technical and organisational measures to protect your data:

  • Access restricted to authorised personnel only, verified and audited periodically
  • Platform-native security (Discord server permissions, Roblox server security) enforced to limit data exposure
  • Confidentiality obligations binding all staff and governance members
  • Minimisation — we keep only what is needed, and delete when no longer required
  • Breach procedures in place to notify relevant authorities and affected persons as required by law

However, no method of transmission or electronic storage is 100% secure. We cannot guarantee absolute security but follow all reasonable and industry-standard practices.

SECTION VI — YOUR RIGHTS UNDER UK GDPR

6. What You Are Entitled To

Under UK law, you have the following rights. To exercise any right, contact us using the details in Section X. We will respond within one calendar month (extendable by up to two months for complex requests).

  1. Right of Access: Request a copy of all personal data we hold about you — free of charge for reasonable requests.
  2. Right to Rectification: Request correction of inaccurate, outdated, or incomplete information held about you.
  3. Right to Erasure: Request deletion of your personal data ("right to be forgotten") — where there is no compelling legal reason for us to retain it.
  4. Right to Restriction of Processing: Request limitation or suspension of how we use your data — for example while accuracy is verified.
  5. Right to Data Portability: Request your data in a structured, commonly used, machine-readable format — where processing is based on consent or contract.
  6. Right to Object: Object to processing based on legitimate interests or direct marketing — on grounds relating to your particular situation.
  7. Right to Withdraw Consent: Where processing is based on consent, withdraw it at any time. Withdrawal does not affect lawfulness prior to withdrawal.
  8. Rights Related to Automated Decision-Making: We do NOT use fully automated decision-making or profiling with legal or significant effects.

Note: Some rights are not absolute. We may decline requests only where permitted by law and will explain our reasoning. Requests that are repetitive, excessive, or prejudice the rights of others may be subject to a reasonable fee or declined.

SECTION VII — COOKIES & ONLINE TRACKING

7. Website & Analytics Technologies

Our websites may use cookies and similar technologies to improve user experience and analyse usage patterns.

  • Essential Cookies: Required for website functionality — cannot be disabled.
  • Analytics Cookies: Help us understand how visitors use our site — data is aggregated and anonymous. You may decline non-essential cookies.

We do NOT use third-party advertising cookies, tracking pixels, or cross-site profiling technologies. Third-party embedded content (YouTube, etc.) may set its own cookies — refer to those providers' policies.

SECTION VIII — CHILDREN & MINORS

8. Age Protection & Special Safeguards

Our community services are intended for users aged 13 or over. This is our community eligibility rule and is separate from any age-specific account experience or protections provided by Roblox or Discord.

  • We do not knowingly collect personal data from anyone below the applicable minimum age without verifiable parental consent.
  • If we become aware that we hold personal data of a user below the age threshold, we will take steps to delete such information promptly.
  • Parents/guardians who believe we hold data about a child should contact us immediately using the details in Section X.

Users between ages 13–16 should review this policy with a parent or guardian. We encourage all members to respect age restrictions and platform safety guidelines.

SECTION IX — THIRD-PARTY PLATFORMS & EXTERNAL LINKS

9. External Services & Jurisdiction

Our services operate through platforms owned and operated by third parties — primarily Roblox Corporation and Discord Inc. These platforms have their own privacy policies independent of us. Nexus Networks Group does not control how these platforms process your data.

Our website or communications may contain links to external sites. We are not responsible for the privacy practices or content of external sites. We encourage you to review the privacy policy of every site you visit.

SECTION X — CONTACT, UPDATES & RIGHT TO COMPLAIN

10. How to Contact Us

Data Controller: Nexus Networks Group Ltd
Contact Method: Through the designated “Data Protection & Privacy Enquiries” channel in our official Discord support system, or through the official website contact centre. A representative acting for another person must provide valid written authority before a request can be processed.

Policy Updates

We may update this Privacy Policy periodically. Material changes will be notified through our standard announcement channels. Your continued use of our services after changes take effect constitutes acceptance of the updated policy.

Right to Complain

If you believe we have not handled your data in accordance with UK GDPR, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) — the UK's independent data protection regulator — at:

Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Website: ico.org.uk

We encourage you to contact us first — we will make every effort to resolve concerns directly and amicably before matters escalate to the ICO.