Legal
Privacy Policy
Effective date: July 9, 2026 · Last updated: July 25, 2026
This policy describes how NEXUS by CommEnder LLC collects, uses, shares, retains, and protects information across our website and the NEXUS platform, and the rights and choices available to you.
1. Who We Are; Scope of This Policy
This Privacy Policy is published by CommEnder LLC, a Virginia limited liability company ("CommEnder," "we," "us," or "our"). It applies to: (a) our public website at www.commender.nexus and its subpages (the "Site"); and (b) the NEXUS platform, including its lockout/tagout, maintenance and work-control, quality, and administrative modules, the application available at app.commender.nexus, any application programming interfaces, and any dedicated or on-premise deployment provided under a subscription or services agreement (the "Service").
Our role depends on the data. For information collected through the Site, for business contact information, and for account information of Service users, CommEnder determines how and why the information is processed (acting as a "controller" or "business" under applicable privacy laws). For data, files, drawings, records, and content that a customer organization or its authorized users submit to or generate in the Service ("Customer Data"), CommEnder processes that data on behalf of, and under the instructions of, the customer (acting as a "processor" or "service provider"). If your information is contained in Customer Data, the privacy practices of the customer organization (for example, your employer) govern, and you should direct requests about that information to that organization; we will assist the customer as required by our agreement with it and applicable law.
2. Information We Collect
Contact and business information. When you request a walkthrough, ask a question, or otherwise contact us, we receive the information you choose to provide, such as your name, work email address, organization, role, and the contents of your message. The Site's walkthrough request form composes an email in your own mail application; the information you send reaches us as an email message.
Account information (Service). When a customer provisions authorized users of the Service, we collect and maintain user account information such as name, work email address, role and permission assignments, authentication credentials, and account settings.
Records generated in the Service. The Service is a workflow and recordkeeping tool. As part of its core function, it records procedures, drawings, work and maintenance records, quality records, review and authorization actions, and append-only audit events (who did what, and when). These records are Customer Data owned by the customer, as described in the End-User License Agreement.
Technical and log data. When you visit the Site or use the Service, our hosting infrastructure and application logs automatically record technical information such as IP address, browser and device metadata, pages or resources requested, timestamps, and approximate location inferred from IP address. We use this information for security, diagnostics, and operations.
Support and other communications. We retain communications you send us, including support requests and related correspondence.
What we do not collect. We do not run third-party advertising trackers or social-media tracking pixels on the Site, and we do not collect advertising identifiers.
3. How We Use Information
We use the information described above to: provide, operate, secure, and support the Site and the Service; respond to walkthrough requests and other inquiries; create and administer user accounts; maintain the operational and audit records the Service is designed to keep; monitor for and prevent fraud, abuse, and security incidents; analyze and improve the Site, the Service, and our product planning; communicate with you about the Service, including service notices and, where permitted, product updates you can opt out of; enforce our agreements; and comply with legal obligations.
We do not sell personal information, and we do not share personal information for cross-context behavioral advertising or targeted advertising.
We do not use Customer Data to train shared or global machine-learning models unless the customer expressly authorizes that use in writing under an applicable agreement or program.
4. Basis for Our Processing
CommEnder operates in the United States and directs the Site and the Service to users in the United States, and we process personal information in accordance with applicable U.S. federal and state privacy laws. We process the information described in this policy to provide, secure, and support the Site and the Service, to respond to your requests, to carry out the legitimate business operations described here, and to comply with our legal obligations; and, where a law requires consent for a specific use, we process on the basis of your consent, which you may withdraw at any time. We do not offer the Site or the Service to individuals located in the European Union or the United Kingdom; see Section 10 (International Visitors).
5. How We Share Information
We share personal information only as follows: with service providers and subprocessors that host and support our systems (for example, Microsoft Azure, which hosts the Service in the United States) and that process information on our behalf under contractual confidentiality and data-protection obligations; with professional advisers such as lawyers, accountants, and insurers where reasonably necessary; to comply with law, legal process, or a governmental request, or to protect the rights, property, safety, or security of CommEnder, our customers, or others; in connection with a merger, acquisition, financing, or sale of assets, in which case we will require appropriate protections for personal information; and, for Customer Data, as directed by the customer organization.
We do not sell personal information to data brokers or anyone else.
We use vetted service providers to host, secure, and support the Service. A current list of subprocessors, including their locations and functions, is available to customers and prospective customers on request. Where a data-processing addendum applies, we provide advance written notice of material additions or replacements and an opportunity to object as stated in that addendum.
Artificial-intelligence and machine-learning features. Where the Service provides AI- or ML-assisted features, the related processing occurs within our hosting environment (Microsoft Azure, United States) or through subprocessors that CommEnder engages under contractual confidentiality and data-protection obligations. Any such subprocessor may process personal information and Customer Data only to provide the feature to us, and is prohibited from using it for its own purposes, including to train its own or any shared or global models; and, consistent with Section 3, we do not use Customer Data to train shared or global machine-learning models unless the customer expressly authorizes that use in writing under an applicable agreement or program.
6. Cookies and Similar Technologies
The Site is a static informational website and does not set third-party analytics or advertising cookies. The Service uses strictly necessary cookies and similar technologies to sign you in, keep your session secure (for example, anti-forgery protection), and remember essential settings. You can control cookies through your browser, but blocking essential cookies will prevent sign-in to the Service.
Because we do not sell personal information or share it for targeted advertising, there is no such activity to opt out of through browser signals such as Global Privacy Control or "Do Not Track"; we treat all visitors consistently with that practice.
7. Security
We maintain administrative and technical safeguards designed to protect personal information, including encryption of data in transit, role-based access controls, tenant isolation designed to keep each customer's data scoped to that customer, append-only audit logging of record changes in the Service, and hosting on Microsoft Azure with security monitoring. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If you believe you have found a security vulnerability, please report it to support@commender.nexus.
8. Retention
We keep personal information only as long as needed for the purposes described in this policy, and then delete or de-identify it. Retention periods differ by data type: contact inquiries are kept as long as needed to respond and for reasonable follow-up; account information is kept for the life of the applicable subscription plus any period required for legal or contractual purposes; and Customer Data, including audit, safety, quality, and maintenance records, is retained as specified in the customer agreement and applicable legal requirements. Because the Service is designed for record integrity, certain safety-, quality-, and maintenance-related records are voided and preserved rather than destroyed while retention obligations apply. Residual copies may persist in backups for a limited period before being overwritten in the ordinary course.
9. Your Rights and Choices
Depending on where you live, you may have rights under applicable privacy laws (such as the Virginia Consumer Data Protection Act, the California Consumer Privacy Act, or similar laws of other U.S. states), including the right to: know or access the personal information we hold about you; correct inaccurate personal information; delete personal information; obtain a portable copy of personal information; opt out of the sale of personal information, sharing for targeted advertising, or certain profiling (we do not engage in these activities); and not receive discriminatory treatment for exercising your rights.
To exercise these rights, email support@commender.nexus with your request. We will verify your identity using reasonable means before acting, and we will respond within the time required by applicable law. Where the law of your state permits, you may use an authorized agent to submit a request; we may require proof of the agent's authority and direct verification with you.
Appeals. If we decline to act on your request, you may appeal by replying to our response with the word "Appeal." We will review and respond as applicable law requires. Depending on your state, you may also contact your state Attorney General if you have concerns about the outcome.
Marketing choices. You may opt out of non-essential communications at any time by using the unsubscribe mechanism in the message or by contacting us.
If your information is Customer Data. If your personal information was submitted to the Service under your employer's or another organization's subscription, please direct your request to that organization; we will assist it in responding as its service provider.
10. International Visitors
CommEnder operates from the United States, and the Site and the Service are intended for users in the United States. Information we collect is processed and stored in the United States, where privacy protections may differ from those in your jurisdiction. If you access the Site or the Service from outside the United States, you do so on your own initiative, you are responsible for compliance with local law, and you understand that your information will be transferred to and processed in the United States.
11. Changes to This Policy
We may update this policy from time to time. We will post the updated policy on this page with a revised "Last updated" date, and for material changes we will provide more prominent notice, such as a notice on the Site or, for Service users, an in-product or email notice.
12. Contact Us
Privacy requests and questions may be sent to support@commender.nexus. Legal notices may be sent to legal@commender.nexus. CommEnder LLC is a Virginia limited liability company, United States.