1. Who we are and how to reach us
DSS Nexus is operated by DeSouza Strategic Systems LLC, a Texas limited liability company doing business as DSS Advisory Group ("we," "us," "our"). You can reach us at info@dssadvisorygroup.com or DeSouza Strategic Systems LLC, Houston, Texas, United States.
The Service is offered worldwide. For personal data we handle to run our own business - your account, billing, and our own marketing - we are the controller (GDPR) or business (CCPA). For personal data contained in the Customer Content you submit to your workspace, you are the controller and we are the processor or service provider acting on your instructions. Our Data Processing Addendum governs that relationship and is incorporated into our Terms.
Where we have not appointed a representative under GDPR Article 27 or UK GDPR, individuals in those regions may contact us directly at info@dssadvisorygroup.com. We respond to rights requests from every jurisdiction on the same terms.
2. Information we collect
- Account information - name, business email address, organization name, and a password stored only as a salted scrypt hash. We never store your password in a readable form.
- Customer Content - the company profile, opportunity records, pursuit data, notes, documents, and prompts you or your users submit to the Service.
- Billing information - billing contact and subscription status. Payment card data is collected and processed directly by Stripe on a hosted payment page. Card numbers never reach our servers.
- Usage and device data - IP address, browser type, pages viewed, feature events, timestamps, and request identifiers, used to operate, secure, and improve the Service.
- Support and communications - messages you send us, and records of transactional email we send you.
- Public federal procurement data - we ingest publicly available records from SAM.gov, USAspending.gov, FPDS. This data is public and is not collected from you.
3. What we do not collect
We do not knowingly collect Social Security numbers, government-issued identification numbers, financial account numbers, precise geolocation, biometric identifiers, health information, or information from anyone under 18.
You are contractually prohibited from submitting classified information, Controlled Unclassified Information (CUI), Federal Contract Information (FCI), source-selection sensitive information, export-controlled technical data, or personal information of consumers to the Service. See the Acceptable Use Policy.
4. How we use information
- To provide, operate, secure, and support the Service.
- To authenticate you, prevent fraud and abuse, and enforce our Terms.
- To process payments and manage subscriptions.
- To send transactional email you cannot opt out of while you hold an account (verification, password reset, billing, security, and material service notices).
- To send marketing email only where you have opted in. Every marketing message includes a one-click unsubscribe, honored within ten business days, per the CAN-SPAM Act.
- To generate aggregated, de-identified statistics about how the Service is used. We do not attempt to re-identify de-identified data, and we contractually prohibit our vendors from doing so.
- To comply with law and to establish, exercise, or defend legal claims.
5. Artificial intelligence and your content
AI features send the prompt content you submit to our model provider (see Subprocessors) to generate a response. Under the API terms that govern our account, that provider does not use API inputs or outputs to train or improve its models; this is the default for API customers and we have not opted in to any data-sharing programme.
The provider may retain those inputs and outputs for a limited period - up to thirty days at the time of writing - for abuse monitoring and to deliver the service, after which they are deleted. That retention is the provider's, not ours, and it is separate from the retention schedule below, which governs the data we hold.
We do not use Customer Content to train, fine-tune, or improve any machine-learning model - ours or anyone else's. Product improvement relies on aggregated, de-identified usage metrics only.
Where the Service builds a memory or knowledge graph from your data, that memory is scoped to your organization and enforced at the database level by row-level security. It is never surfaced to another customer.
DSS Nexus produces decision support, not decisions. Outputs are drafts and analyses that a qualified human must review before any external use. DSS Nexus does not guarantee any award, win rate, contract, ranking, revenue, or procurement outcome, and does not provide legal, financial, accounting, investment, tax, or procurement-law advice.
AI systems can produce inaccurate or incomplete output. Every AI-generated claim in the Service is presented with its source so you can verify it. Verification remains your responsibility.
5a. Lawful bases for processing (GDPR/UK GDPR Art. 6)
Where the GDPR or UK GDPR applies to our processing as a controller, we rely on the following lawful bases. Where we rely on legitimate interests, we have carried out a balancing assessment and will provide a summary on request.
| Purpose | Lawful basis |
|---|---|
| Creating and administering your account | Performance of a contract (Art. 6(1)(b)) |
| Processing payments and preventing fraud | Contract; legal obligation (Art. 6(1)(b), (c)) |
| Securing the Service; abuse and intrusion prevention | Legitimate interests (Art. 6(1)(f)) |
| Aggregated, de-identified product analytics | Legitimate interests (Art. 6(1)(f)) |
| Transactional and service email | Contract (Art. 6(1)(b)) |
| Marketing email | Consent (Art. 6(1)(a)); withdrawable at any time |
| Non-essential cookies, where used | Consent (ePrivacy Directive; Art. 6(1)(a)) |
| Responding to legal process; defending claims | Legal obligation; legitimate interests (Art. 6(1)(c), (f)) |
5b. AI transparency (EU AI Act Art. 50)
You are interacting with an artificial-intelligence system. Content in the Service that is generated or materially assisted by AI is labelled as such at the point it is produced.
DSS Nexus is not an AI system intended to be used for any purpose classified as prohibited or high-risk under the EU AI Act. It performs no biometric categorisation, emotion inference, social scoring, or automated decision-making producing legal or similarly significant effects on a natural person.
No decision that produces a legal or similarly significant effect on any individual is made by automated means without human involvement. You retain the right under GDPR Art. 22 not to be subject to such a decision.
6. When we disclose information
We do not sell personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under the California Consumer Privacy Act. We have not done so in the preceding twelve months.
- Subprocessors - vendors who process data on our behalf under written contracts limiting their use to our instructions. The current list is published and maintained.
- Business transfers - in a merger, acquisition, financing, or sale of assets, subject to this policy.
- Legal process - where required by law, subpoena, or court order, or to protect rights, safety, and property. Where lawfully permitted, we will notify you first.
- At your direction - when you instruct us to share data, including with your own teammates.
6a. People who are not our customers
We also process personal data about individuals who have never used the Service: business contacts we identify for outreach, and people who subscribe to our weekly briefing. This section is about you.
Where we send marketing email, we rely on your consent in every jurisdiction that requires it for that message - including the EEA, the United Kingdom, and Canada. Elsewhere we may rely on our legitimate interest in business-to-business outreach to a professional at their business address, having balanced that interest against your rights. You may object at any time, for any reason, and we stop.
| What | Detail |
|---|---|
| Categories | Name, business email address, employer, role, and publicly recorded federal procurement activity. |
| Sources | Public federal procurement data (SAM.gov, USAspending.gov, FPDS), business-contact enrichment providers, and information you give us directly. |
| Purposes | Business-to-business outreach and delivery of the weekly briefing you requested. |
| Lawful basis | Consent where required for the message (EEA/UK ePrivacy; Canada CASL). Otherwise legitimate interests (GDPR Art. 6(1)(f)); balancing summary on request. |
| Retention | Suppression-listed permanently on unsubscribe, so we never contact you again. Enrichment data is deleted after 18 months without engagement. |
| Your rights | Unsubscribe from any message, honored within ten business days and in practice immediately. Access, correction, and deletion on request to info@dssadvisorygroup.com. |
7. Retention
Each row below is enforced by a named, scheduled job or delegated to the named processor. A retention schedule without a job behind it is a statement we could not keep.
| Data | Retention | Enforced by |
|---|---|---|
| Account records | Life of the account, then 90 days after closure, then deleted or de-identified | job: purge-closed-accounts |
| Customer Content | Deleted within 30 days of a verified deletion request; within 90 days of account closure | job: purge-customer-content |
| Prospect enrichment data | 18 months without engagement; suppression list retained indefinitely | job: purge-stale-prospects |
| Security and audit logs | 12 months | job: purge-audit-logs |
| Application logs | 90 days | delegated: hosting provider |
| Payment records | 7 years, for tax and accounting obligations | delegated: Stripe, Inc. |
| Backups | Rolling 35-day cycle; deleted content persists in encrypted backups until the cycle completes | job: rotate-backups |
7a. International data transfers
We operate from the United States and our subprocessors are located in the United States. If you access the Service from outside the United States, your personal data will be transferred to, stored in, and processed in the United States, whose data-protection laws may differ from those of your country.
Where we transfer personal data out of the EEA, the United Kingdom, or Switzerland, we rely on the mechanisms below and, in each case, on supplementary technical measures including encryption in transit, encryption at rest, tenant isolation enforced at the database layer, and a policy of challenging any unlawful government demand for data.
- EEA → United States: the European Commission's Standard Contractual Clauses (Decision 2021/914), Module Two (controller to processor) or Module Three (processor to processor), incorporated by reference into our Data Processing Addendum.
- United Kingdom → United States: the UK International Data Transfer Addendum (version B1.0) to the EU SCCs.
- Switzerland → United States: the SCCs as amended for Swiss FADP, with the Swiss Federal Data Protection and Information Commissioner as competent authority.
- We conduct a transfer impact assessment for each subprocessor and make a summary available on request.
- We do not currently self-certify under the EU-US Data Privacy Framework. We say so rather than imply coverage we do not have.
8. Your privacy rights
We honor the rights below for every user, in every country, regardless of whether a particular law compels it. Where a right conflicts with a legal retention obligation, we tell you which obligation applies.
To exercise a right, email info@dssadvisorygroup.com. We verify the request against your account credentials. We respond within 30 days (GDPR/UK GDPR, extendable by 60 days for complex requests) or within 45 days (US state laws, extendable once by 45 days), with notice in either case. An authorised agent may act for you with written permission. We do not charge a fee unless a request is manifestly unfounded or excessive.
- Access - a copy of your personal data and the information in this policy.
- Rectification - correction of inaccurate or incomplete data.
- Erasure - deletion of your personal data, subject to legal retention obligations.
- Portability - your data in a structured, commonly used, machine-readable format.
- Restriction - of processing, in the circumstances set out in GDPR Art. 18.
- Objection - to processing based on legitimate interests, and to direct marketing at any time and without justification.
- Withdraw consent - at any time, without affecting the lawfulness of processing before withdrawal.
- Automated decisions - not to be subject to a decision based solely on automated processing producing legal or similarly significant effects. We make no such decisions.
- Opt out of sale, sharing, or targeted advertising - we do none of these, so there is nothing to opt out of, and a Global Privacy Control signal has no processing for us to stop.
- Non-discrimination - we will not degrade the Service because you exercised a right.
- Appeal - if we deny a request, you may appeal by replying to our decision.
8a. Regional supplements
The following supplement, and where inconsistent override, the rest of this policy for individuals in the named regions.
| Region | Supplemental rights and disclosures |
|---|---|
| EEA / UK / Switzerland | GDPR, UK GDPR, and FADP rights above. You may lodge a complaint with your national supervisory authority, the UK Information Commissioner's Office, or the Swiss FDPIC. We are not required to appoint a Data Protection Officer and have not appointed one; privacy questions go to info@dssadvisorygroup.com. |
| California | CCPA/CPRA rights to know, delete, correct, and to limit use of sensitive personal information. We collect no sensitive personal information as defined by the CPRA, do not sell or share personal information, and have not done so in the preceding 12 months. Categories collected, purposes, and disclosures appear in sections 2, 4, and 6. |
| Other US states | Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and comparable statutes: access, correction, deletion, portability, opt-out of targeted advertising and profiling, and appeal. We conduct no targeted advertising or profiling with legal effects. |
| Canada | PIPEDA rights of access and correction; you may complain to the Office of the Privacy Commissioner of Canada. We do not disclose personal information for consideration. |
| Brazil | LGPD rights of confirmation, access, correction, anonymisation, portability, deletion, information about sharing, and revocation of consent. Complaints may be made to the ANPD. |
| Australia | Australian Privacy Principles: access, correction, and complaint to the OAIC. We will notify eligible data breaches under the Notifiable Data Breaches scheme. |
| Japan | APPI rights of disclosure, correction, and cessation of use. We do not provide personal data to third parties in Japan without the consent the APPI requires. |
| Singapore | PDPA rights of access and correction; withdrawal of consent on reasonable notice. |
9. Cookies and similar technologies
We use one strictly-necessary cookie, `nexus_session`, which holds a signed, httpOnly session token. It is required to keep you signed in and cannot be disabled while you use an account. Under the ePrivacy Directive, strictly-necessary cookies do not require consent, which is why you do not see a consent banner.
We do not use advertising cookies, third-party tracking pixels, cross-site trackers, or session-replay tools. If we ever introduce a non-essential cookie or similar storage, we will obtain prior opt-in consent from users in the EEA, the UK, and every other jurisdiction that requires it, before it is set.
Signed-in users' browsers also hold three items of local storage, and no others. `dss-nexus:onboarding-tour-seen` records that you dismissed the product tour. `dss-nexus-academy-completed` records which Academy modules you finished. `nexus.outcomes` caches the pursuit outcomes you record, so they survive a reload. None is read by a third party, none is used to profile you, and all three are erased when you sign out.
The third of these, `nexus.outcomes`, is your Customer Content rather than interface state. We name it here rather than describe it vaguely, because a shared computer is a real place and you are entitled to know what is left on it. It is deleted from the device at sign-out; clearing site data removes it at any time.
Because we neither sell nor share personal information, a Global Privacy Control signal has no processing for us to stop. We record that we received it and take no adverse action either way.
10. Security and breach notification
We maintain administrative, technical, and physical safeguards described on our Security page. No system is perfectly secure, and we do not represent that the Service is impenetrable.
Where we act as processor, we notify the affected customer without undue delay after becoming aware of a personal data breach, so that the customer can meet its own notification deadlines. Where we act as controller, we notify the competent supervisory authority within 72 hours where GDPR Art. 33 requires it, and affected individuals without undue delay where Art. 34 requires it. We also comply with applicable US state breach-notification statutes and the Australian Notifiable Data Breaches scheme. Report a suspected vulnerability to info@dssadvisorygroup.com.
11. Children
The Service is a business tool, is sold only to organisations, and is not directed to children. We do not knowingly collect personal data from anyone under 18, and in no case from a child below the age of digital consent in their country (13-16 across the EEA). If we learn that we have, we delete it.
12. Changes
We will post any change here and update the effective date. For material changes we will give at least 30 days' advance notice by email to account administrators before the change takes effect.