Nexus

Data Processors

The outside services that handle your personal data for us, and what each one receives.

What this list is

A "sub-processor" is a third-party service provider that handles personal data on the Foundation's behalf in the course of operating the Services. This list identifies the Foundation's current sub-processors, the service each provides, the categories of personal data each handles, and the primary jurisdiction of processing. It is published as a transparency disclosure.

This list is not a substitute for, and the Foundation does not represent it as evidencing, formal data-processing contracts (such as Article 28 GDPR or analogous instruments) with each listed sub-processor. The Foundation is developing a fuller sub-processor governance program post-mainnet; this list is the basis from which that program builds.

This list includes only sub-processors that handle user personal data on the Foundation's behalf. Service providers used solely for internal operations (for example, billing and certain contractor engagements) are out of scope of this disclosure.

Note on third-party cookie providers. Third-party platforms whose cookies or tracking pixels are set on the Site (for example, Meta) operate as separate data controllers with their own privacy practices in that context, rather than as sub-processors of the Foundation. Those third parties are described in the Cookie Policy. Where the same platform also handles personal data on the Foundation's behalf in a different context — for example, X as a community-channel host — it is listed below as a sub-processor for that role.

Current sub-processors

Cloudflare

Service
DNS, content delivery network, edge worker (including OFAC geo-block on app.nexus.xyz)
Data handled
IP address, request metadata, geo-region
Primary location
United States (global edge)

Ghost (Ghost(Pro))

Service
Hosting platform for blog.nexus.xyz
Data handled
IP address, page-view metadata, browser metadata
Primary location
Republic of Ireland

Google Cloud Platform (GCP)

Service
Backend infrastructure (envoy gateway, RPC nodes, supporting services)
Data handled
IP address, request metadata, RPC request logs
Primary location
Multi-region

Firebase (Google)

Service
Backend services on selected Foundation surfaces (e.g., prove.nexus.xyz)
Data handled
Email address, account identifiers, usage metadata
Primary location
United States

MaxMind

Service
GeoIP database used for geo-restriction at the network edge
Data handled
IP address (resolved to country / region)
Primary location
United States

Snag

Service
Platform partner hosting Foundation loyalty / quest Programs and supporting Foundation engagement workflows
Data handled
Wallet address, email address (where collected), program-participation metadata
Primary location
United States

Mailchimp (Intuit)

Service
Email-marketing platform for opted-in user communications
Data handled
Email address, communication-preference metadata
Primary location
United States

SendGrid (Twilio)

Service
Email delivery (transactional and marketing)
Data handled
Email address, delivery metadata
Primary location
United States

Google Analytics

Service
Web analytics on the Site (including Google Tag Manager for tag management)
Data handled
IP address (truncated where supported), browser metadata, page-view metadata
Primary location
United States

PostHog

Service
Product analytics, error tracking, and masked session replay on the Exchange trading interface
Data handled
IP address, browser metadata, page-view and product-event metadata, error stack traces, pseudonymous account identifier (SHA-256 digest of the lower-case wallet address), masked session-replay recordings
Primary location
United States

Sentry

Service
Application error tracking and session replay
Data handled
IP address, browser metadata, error stack traces, session replay traces
Primary location
United States

Axiom

Service
Log analytics (application and request logs)
Data handled
IP address, request metadata, application logs
Primary location
United States

Dynamic Labs

Service
Wallet-based authentication and signup workflows on selected Foundation surfaces
Data handled
Email address, wallet address, signup metadata
Primary location
United States

Intercom

Service
In-product support messaging, and messages from the Foundation to signed-in users in the product and by email, on the Exchange trading interface
Data handled
Pseudonymous account identifier (SHA-256 digest of the lower-case wallet address), email address (where the sign-in method supplied one), support conversation content, IP address, browser metadata
Primary location
United States

Discord

Service
Community channel hosting — Foundation-operated server
Data handled
Member identifiers, public messages, direct messages to Foundation accounts
Primary location
United States

Telegram

Service
Community channel hosting — Foundation-operated group
Data handled
Member identifiers, public messages, direct messages to Foundation accounts
Primary location
United Arab Emirates

X (community account)

Service
Community channel hosting — Foundation-operated X account (distinct from X advertising pixel described in the Cookie Policy)
Data handled
Follower identifiers, public messages, direct messages to Foundation accounts
Primary location
United States

Note on the Intercom identifier. The Foundation does not send Intercom your wallet address. It sends the SHA-256 digest of that address in lower case, and Intercom uses it as the account identifier for your contact record, which is created when you sign in on the Exchange trading interface, and for your messages and support conversations. The digest is computed from the address alone, with nothing secret added, and wallet addresses are public. Anyone holding a list of addresses can therefore compute the same digests and match them back. The digest is a pseudonym, not anonymous data, and the Foundation treats it as personal data.

Note on the PostHog identifier. PostHog receives the same digest described for Intercom above, never the wallet address itself. It is attached once you connect a wallet, and events captured before that stay unlinked. The same reasoning applies: the digest is a pseudonym, not anonymous data.

The list above describes sub-processors known to the Foundation as of the Effective Date. The Foundation is conducting a more complete sub-processor inventory as part of its post-mainnet program, and will update this list as additional sub-processors are identified or as existing relationships are added, removed, or materially changed.

Updates and notification

The Foundation maintains this list and updates it when it adds, removes, or materially changes a sub-processor relationship that handles user personal data. Updates are reflected in this published list (with an updated "Last Updated" date in the header) and, where applicable, in the changelog at the bottom. Material changes are reflected in the Privacy Policy changelog as well, where applicable.

Contact

For questions about this Sub-processor List or about how the Foundation works with sub-processors, you may contact the Foundation at:

Nexus Foundation
c/o Walkers Corporate Limited
190 Elgin Avenue
George Town, Grand Cayman KY1-9008
Cayman Islands
Email: privacy@nexusfnd.org