What happens
to your data.
This site sets no cookies, runs no analytics and asks you for nothing. This policy covers the little that is processed when you visit, what happens when you email us, and where the open-positions links take you.
LAST UPDATED 25 September 2026
Who is responsible
PayTech Group AS is the data controller for personal data processed through this website. We are registered in Norway under organisation number [organisation number], with a registered address at [registered address], Oslo, Norway.
For any question about this policy or about your personal data, write to hello@paytechnexus.com and mark your message "Privacy".
This policy covers this website only. It does not cover our recruitment engagements or the Nexus platform itself, where the contract governing that work sets out how candidate and client data is handled, nor the other sites operated by companies in PayTech Group, each of which publishes its own policy.
What this site collects
Nothing you type, because there is nothing here to type into. This site has no forms, no search, no login and no account. It is a set of static pages, and it ships no JavaScript to your browser.
Two things are processed regardless. The first is the request your browser makes to our host in order to receive the page. The second is any email you choose to send us, because every button here opens your mail client rather than submitting a form.
- SERVER LOGS
- Our hosting provider records the usual technical details of a request: IP address, timestamp, the page requested, referring page, and browser and operating system strings. These are generated by the infrastructure, not by us, and we do not use them to build a profile of you.
- Whatever you put in the message — your name, address, employer, the role you are hiring for or applying to, and any CV or brief you attach.
Cookies and tracking
There are none. This site sets no cookies of any kind, so there is no consent banner to dismiss.
It also runs no analytics, no tag manager, no advertising or conversion pixels, no session recording and no A/B testing. Every asset the page needs — images, the logo, the stylesheet, the fonts it falls back to — is served from our own domain, so simply loading a page here makes no request to any third party and discloses your visit to no one but our host.
When you email us
Every call to action on this site — hiring a specialist, briefing our team, requesting client access, joining the network — opens a message to us. We read it, we reply, and we keep the correspondence so that the next person who picks up the thread has the context.
If you are a candidate, that message often carries a CV. We treat it as an application: it goes to the consultants working the relevant roles, and it is held so that we can consider you for openings as they arise. We do not publish it, sell it, or pass it to a client without telling you first.
Please do not send special category data — health, religion, political opinion, trade union membership, sexual orientation, or criminal record information — unless we have asked for it as part of a vetting process we have already explained to you. If you send it unprompted, we will delete it.
The open-positions site
Our live vacancies are not hosted here. Every "open positions" and "view roles" link on this site points to our careers site, which runs on a third-party applicant tracking platform.
Following that link takes you off this domain. From that point you are on their infrastructure, subject to their cookies and their privacy notice, and anything you submit through their forms is collected there rather than here. We remain responsible for what we do with an application once it reaches us.
Why we are allowed to do this
- LEGITIMATE INTERESTS
- Keeping the site available and secure, and replying to business correspondence. Running a recruitment practice means holding candidate and client contact details; we think you would expect that, and it is balanced against your rights.
- STEPS BEFORE A CONTRACT
- Where you approach us about a role or an engagement, handling your enquiry is part of deciding whether to work together.
- CONSENT
- Where you ask to join the Nexus specialist network so that we can consider you for future roles. You can withdraw it at any time by emailing us, and we will remove you.
- LEGAL OBLIGATION
- Where accounting, tax or employment law requires us to keep a record.
How long we keep it
- Server logs: retained by our host on their standard schedule, typically a short rolling window measured in weeks.
- Business correspondence: for as long as the relationship is live, and then for as long as we may need it for a legal or accounting record.
- Candidate details and CVs: while we are actively considering you, and then for a reasonable period so that we can approach you about relevant roles. Ask us to delete them and we will.
Who else sees it
We do not sell personal data, and we do not share it for anyone else's marketing.
- Our hosting and email providers, which process data on our instructions under a written agreement.
- The applicant tracking platform behind our careers site, for applications made there.
- A client, where you are a candidate and you have agreed to be introduced. Nexus is built so that identities stay protected until that point.
- Professional advisers, or an authority, where the law requires it.
Transfers outside the EEA
Some of the providers above operate outside the European Economic Area. Where personal data reaches them, we rely on an adequacy decision or on the European Commission's standard contractual clauses, together with whatever additional safeguards the transfer needs. Ask us and we will tell you which applies to a given provider.
Your rights
Under the GDPR you can ask us for a copy of your personal data, ask us to correct it, ask us to delete it, ask us to restrict or stop a particular use, object to processing we base on legitimate interests, and ask for your data in a portable form. Where we rely on consent, you can withdraw it without affecting what we did beforehand.
Write to hello@paytechnexus.com. We will respond within one month. There is no charge unless a request is clearly unfounded or excessive.
If you are not satisfied with our answer you can complain to Datatilsynet (the Norwegian Data Protection Authority), or to the authority in the EEA country where you live or work.
Security
The site is served over HTTPS. Because it is a static build with no database, no accounts and no user input, there is very little attack surface here: there is nothing stored on this site to breach.
Correspondence and candidate records live in our email and recruitment systems, which are access-controlled and restricted to the people who need them. No transmission over the internet is ever completely secure, and ordinary email is not encrypted end to end — bear that in mind before sending us anything highly sensitive.
Changes to this policy
If this policy changes we will update the page and move the date at the top. This version is effective from 25 September 2026.