Legal
Privacy Policy
How we handle information from this website and the client portal. Effective August 3, 2026. Last updated August 14, 2026.
1. Who We Are and What This Policy Covers
This policy explains how Advisor Nexus ("Advisor Nexus," "we," "us," or "our") handles personal information. It covers our public website and our client portal at https://portal.advisor-nexus.com, which is the sign-in area for authorized users at firms with an active Advisor Nexus engagement.
It does not replace the agreements that govern client work. Where we design, build, or operate workflows for a client firm, the signed client agreement, statement of work, and any data-processing or security addendum control how information from that firm's systems is handled, and control over this policy in the event of a conflict.
This website and portal are for businesses: registered investment advisers, wealth-management firms, and the people who work at them. They are not directed to consumers seeking personal financial products, and not to children.
2. The Two Roles We Play
This distinction determines who is responsible for what, so it is worth stating plainly.
We are the controller (or “business”) for information you give us directly through the public website, and for the account information we hold about portal users. We decide why and how that information is handled, and this policy governs it.
We are a processor (or “service provider”) for operational information that belongs to a client firm and reaches us because we are doing work for that firm: records in the firm's systems, workflow and onboarding information, documents, and anything relating to that firm's own clients. We handle it on the firm's instructions, for that engagement, under the applicable client agreement.
A client firm remains responsible for deciding whether it has the authority to give us particular information, and for meeting its own regulatory, privacy, supervisory, and recordkeeping obligations. That allocation does not relieve us of the obligations we owe under this policy or under applicable law, and we do not attempt to disclaim duties that cannot be disclaimed.
3. Information You Give Us Through the Website
We only receive what you choose to submit. Two forms on this site send information to us.
- Consultation request (Contact page). The form asks for six things and nothing else: your name, work email, firm name, firm type, employee-count range, and a free-text description of the operational friction you want to address. All six are required; there are no optional fields. Submitted with it: your consent confirmation, the marketing-attribution values described in Section 6, the anti-spam signals in Section 8, and, if you arrived from a specific service or pricing page, which one.
- Readiness Scorecard results by email (Scorecard page). Required: your work email. Optional: your first name and firm name. Sent with it: the answers you selected, your category scores, overall score, maturity stage, and the recommendations generated for you.
4. Please Do Not Send Confidential Client Information
The public forms on this site are not a secure channel. Please do not submit client names, account numbers, login credentials, Social Security numbers, financial account information, health information, or other confidential client information through them. Describe the workflow, not the client.
If you send us information of that kind anyway, we will delete it when we identify it.
5. Tools That Do Not Send Us Anything
The ROI Savings Calculator runs entirely in your browser. Every figure you enter (volumes, hours, hourly costs, headcount) stays on your device and is not transmitted to us. The analytics described in Section 7 record that you visited the calculator page, and an event records which workflow modules and which scenario you selected, never the figures you entered.
The Readiness Scorecard shows your full results without any contact details. Your answers are scored in your browser. We receive them only if you separately ask us to email you a copy.
6. Cookies and Browser Storage
Our website sets first-party cookies through Google Analytics and Microsoft Clarity, both described in Section 7. We set no advertising or retargeting cookies, and no cookie on this site is used for cross-context behavioral advertising.
These cookies are set for every visitor; this site does not show a cookie consent banner. Google and Microsoft set how long each of their cookies lasts. You can clear or block all of them at any time through your browser settings or a content-blocking extension; the site works normally without them.
Until August 14, 2026, this site also set HubSpot analytics cookies (__hstc, hubspotutk, __hssc, __hssrc, and the __hs_cookie_cat_pref banner-choice cookie). The HubSpot tracking and its banner have been removed, so those cookies are no longer set or read by this site; any still in your browser from an earlier visit do nothing here and can be cleared.
- _ga and _ga_N557MJQ1JV: set by Google Analytics, described in Section 7, to distinguish one visitor from another and to hold the state of the current session.
- _clck and _clsk: set by Microsoft Clarity, described in Section 7, to tie the pages of one visit together into a single session recording and to recognize a returning browser. Microsoft may also set its own cookies on its domains when Clarity runs.
- Readiness Scorecard progress: stored in localStorage so a refresh does not lose your place. It holds only question identifiers and 0–3 answer scores, is scoped to a single scorecard version, and is treated as abandoned after 30 days. No contact details and no free text are stored.
- First-touch marketing attribution: UTM parameters, landing page, and referring URL, stored in sessionStorage and cleared by your browser when the tab closes. It is submitted with a consultation request so we know how an inquiry reached us.
7. Analytics and Visitor Tracking
This website measures visits with Google Analytics 4 and Microsoft Clarity. Both run for every visitor: this site does not show a cookie consent banner. If you prefer not to be measured, Section 6 describes how to block or clear the cookies involved through your browser, and content-blocking extensions stop both tools entirely; the site works normally either way.
Google Analytics 4 runs on the public pages of this website under Google Consent Mode v2, with analytics storage enabled and with advertising storage, advertising user data, and advertising personalization denied permanently, because this site runs no advertising or retargeting tags of any kind.
Google Analytics receives the page address, the page title, the referring address, general device and browser information, and your IP address, which Google uses to derive an approximate location. It does not receive your name, email address, phone number, firm name, or anything you type into a form; the application strips identity and free-text values before any event can be sent, and form contents are never passed to it.
Alongside page views, the site sends Google Analytics a small number of named events describing what was used rather than who used it: which page a call-to-action was clicked on, which ROI calculator modules and which scenario were selected, and, if you complete the Readiness Scorecard, your overall score, maturity stage, strongest category, and largest opportunity. The application strips identity and free-text values (name, email, phone, company, job title, and any message, challenge, or platform text) before an event can be sent, and that filtering is implemented in the application rather than left to individual judgment. Your individual scorecard answers, the figures you type into the ROI calculator, and the contents of any form are never sent.
Microsoft Clarity provides behavioural analytics on the public pages of this website, and it is the one tool here that records more than page counts. It builds heatmaps showing where visitors click, move, and how far down a page they scroll, and it captures session recordings: a replay of a visit, reconstructed from your interactions with the page, that we can watch back to see where a page is confusing or where people give up.
A recording reproduces the page as you saw it, so what it captures matters. Every form on this site is marked so that Clarity records the shape of the interaction but never the characters you type. Your name, work email, firm name, and everything you write in a free-text field are masked out of the recording. We do not use Clarity's identification feature, so no recording is ever labelled with your name or email address: sessions reach us as anonymous replays, not as a named person's activity.
Neither Google Analytics nor Clarity is loaded on the client-portal sign-in page.
8. Spam and Abuse Prevention
Form submissions pass through a hidden field a real visitor never sees, and a timing check that catches instant automated posts. Neither collects anything extra about you, and neither uses a third-party service.
The site also includes optional support for Cloudflare Turnstile bot protection. It is not currently enabled. If we enable it, your browser will exchange a token with Cloudflare so it can distinguish automated traffic from real visitors, and we will update this policy first.
9. Client Portal
The portal at https://portal.advisor-nexus.com is available only to individual users authorized by a firm with an active Advisor Nexus engagement. There is no public sign-up; accounts are arranged as part of an engagement, and they are personal to the user rather than shared.
Advisor Nexus currently authenticates portal users directly, without a third-party identity provider. When you sign in, the email address and password you enter are transmitted over an encrypted (HTTPS) connection to systems that Advisor Nexus operates, and a session is established so you are not asked to sign in again on every page.
If you select “Forgot password?” and enter your email address, we send a password-reset link to that address if an account exists for it.
The portal is a separate application from this website. The specific arrangements for it, including session duration, what portal activity is recorded, which Advisor Nexus personnel may access portal information and on what basis, how accounts are created and removed, and how long portal information is kept, are set out in the agreement between Advisor Nexus and your firm. If you would like those details for your firm's vendor-review file, ask us using the contact details in Section 20 and we will share what we are able to, subject to confidentiality and the terms of the applicable agreement.
Access is removed when your firm asks us to remove it, when we are notified that you have left the firm that authorized your account, or when the engagement ends. Because we rely on the client firm to tell us about personnel changes, please ask your firm to notify us promptly when someone should no longer have access.
Where the portal contains information about your firm's own clients, that information belongs to your firm: your firm is the controller and Advisor Nexus is a processor acting on your firm's instructions under the client agreement.
Portal information is not used for advertising, is not sold, and is not shared for cross-context behavioral advertising.
10. Client-Controlled Operational Information
When we design, build, or operate workflows for a client firm, we work inside the systems that firm already controls, using credentials the firm issues and can revoke. Information in those systems belongs to the firm.
The specific arrangements (where things run, who has access, what is logged, how long information is kept, and which providers are involved) vary by engagement and are documented for that firm in the applicable agreement, statement of work, and any data-processing or security addendum, rather than being fixed by this policy.
11. Information Collected Automatically
Every request to our servers produces standard technical information: IP address, browser and device type, the URL requested, the referring URL, response status, and timing. Our web server records this in its access logs, and we use it to deliver the site, keep it working, and prevent abuse.
Your IP address is also used to enforce a submission rate limit on our two form endpoints: five submissions per ten minutes. That counter is held in server memory rather than a database, and resets when the service restarts.
12. How We Use Information, and On What Basis
We use the information described above to:
- Evaluate and respond to your inquiry, and prepare for a conversation about your firm's operations. Submitting the consultation form also sends an automatic acknowledgement to the email address you gave us, confirming we received it.
- Deliver material you asked for, such as a copy of your scorecard results.
- Provide and support the client portal to authorized users.
- Perform, support, and improve work under a client engagement.
- Operate, secure, and troubleshoot the website and portal, including preventing spam and abuse.
- Understand which operational problems bring firms to us, so we can improve how we describe our services.
- Measure how visitors reach and move through this website, using the analytics described in Section 7.
- Meet legal obligations and enforce our Terms of Service.
13. Artificial Intelligence
No AI or machine-learning provider processes information submitted through this public website. No such integration exists in it.
Advisor Nexus does implement supervised AI agents for client firms as a service. Where that happens, the providers involved, what each one receives, and the terms that apply are reviewed with the client firm and documented before the agent is built. Supervised AI outputs are designed to be reviewed by a person before they are relied on. We do not use a client firm's information to train models of our own, and where an approved provider offers a setting that excludes inputs from provider model training, or offers zero data retention, we configure it and record that configuration for the engagement.
We do not claim that every provider in every possible configuration excludes all retention or training. That depends on the provider, the plan, and the terms in force for that engagement, and it is documented per engagement rather than promised globally here. This policy does not replace the client agreement governing any specific implementation.
14. Service Providers
We use a small number of providers, and we would rather name them than describe them vaguely. As of the date above they are: Amazon Web Services, for website hosting and infrastructure in the United States; HubSpot, as the customer-relationship platform where we manage inquiries after they reach us (since August 14, 2026 it receives nothing from your browser on this site); Google, for the Google Analytics measurement described in Section 7; Microsoft, for the Clarity behavioural analytics, heatmaps, and session recordings described in Section 7; Resend, for the transactional email that delivers form submissions to us and sends you material you requested; Let's Encrypt, for TLS certificates, which receives only our domain name; and GitHub, for source control and deployment, which receives no visitor information. The client portal is supported by its own hosting, database, and email providers, which we will identify on request. Providers may change as our infrastructure changes, and we will update this section when they do.
Google and Microsoft are the providers on that list that receive information directly from your browser rather than from us. Both are engaged as service providers, processing that information on our behalf and under their contracts with us rather than for their own marketing purposes. Each provider's own privacy notice governs how it handles information as a company.
We may also disclose information to professional advisors such as lawyers and accountants under confidentiality; to a successor in a merger, acquisition, or sale of assets, subject to this policy; and to law enforcement or others where we are legally required to, or where it is necessary to protect our rights, safety, or property.
Where this policy describes a capability as available but not enabled (bot protection, an automation webhook, a scheduling tool), it is not receiving your information, and we will update this policy before enabling it.
15. We Do Not Sell or Share Your Information
We do not sell personal information. We do not share it for cross-context behavioral advertising, and we run no advertising or retargeting tags of any kind. The analytics described in Section 7 measure visits to this website for us; they are not advertising networks, and we do not use them to target you with advertising elsewhere. We do not use portal or client information for advertising. To be precise about the terms used in United States state privacy laws:
- Sale: we do not disclose personal information for money or other valuable consideration.
- Sharing for cross-context behavioral advertising: we do not do this.
- Disclosure to service providers: we do disclose information to the providers named in Section 14, under contract, only so they can perform services for us.
- Disclosure at your direction: when you ask us to email your scorecard results, we send them where you asked.
- Disclosure in connection with an engagement: during client work, information moves between systems the client firm has approved, as documented for that engagement.
16. How Long We Keep Information
How long we keep information depends on why we hold it. We apply four criteria: the nature of the information, the purpose it was collected for, whether the relationship it relates to is still active, and any legal, tax, accounting, or dispute-resolution obligation that applies to it. When information is no longer needed for the purpose it was collected for, and no obligation requires us to keep it, we delete it.
Consultation requests and scorecard report requests are delivered to our business email. We keep them while we are in contact with you, and afterwards for as long as they remain relevant to an active or prospective business relationship.
Website analytics information held by Google Analytics and Microsoft Clarity (including the cookies in Section 6, the visit records in Section 7, and the session recordings and heatmaps Clarity produces) is retained under those providers' retention settings for our accounts rather than by a period fixed in this policy. You can ask us what we hold about you, and ask us to delete it, using Section 20.
Web server logs, which include IP addresses, are kept on our hosting infrastructure only for as long as they remain useful for operating and securing the site. Rate-limit counters last ten minutes and are lost whenever the service restarts. Browser storage on your device lasts as described in Section 6 and is under your control.
Retention of client portal information, and of information we process on behalf of a client firm, is set out in the agreement with that firm, as described in Sections 9 and 10. Contract, invoicing, and tax records are kept for the periods those obligations require.
You can ask us to delete information you submitted at any time using Section 20. We will do so unless we are required or permitted by law to keep it for legal, tax, or dispute-resolution purposes, in which case we will tell you.
Deleting information from our live systems does not immediately remove it from backup copies. Backups age out on their own cycle, and we do not restore deleted information from a backup except where we are legally required to.
17. How We Protect Information, and the Limits of That
We use administrative, technical, and organizational safeguards designed to protect information. These include encryption in transit using HTTPS across the website and the portal; server-side validation, size limits, and IP rate limiting on every form endpoint; a deliberate practice of not writing submitted names, email addresses, phone numbers, firm names, or free-text fields into application logs; and limiting access to submitted inquiries to the Advisor Nexus personnel who need it in order to respond. Access is limited based on role and business need.
Specific hosting, access, retention, and logging arrangements may vary by engagement and are documented in the applicable client agreement.
No method of transmission or storage is completely secure, and we cannot guarantee that information will never be accessed without authorization. We do not hold SOC 2, ISO 27001, or any other security certification, and we do not claim any specific audit or regulatory compliance status.
18. Security Incidents
If we become aware of a security incident affecting personal information we hold, we will investigate, take steps to contain and remediate it, and notify affected individuals, client firms, and regulators where applicable law or our agreements require, within the timeframes those require. Where an incident affects information we process on behalf of a client firm, we will notify that firm without undue delay so the firm can meet its own notification obligations. Please report a suspected security issue to isaac@advisor-nexus.com.
19. Where Information Is Processed
Advisor Nexus operates in the United States, and information submitted through this website is processed there. Our website hosting is in the United States.
If you access our website or portal from outside the United States, your information will be transferred to and processed in the United States, whose data-protection laws may differ from those where you live.
Privacy rights and obligations vary by jurisdiction and may depend on factors such as where an individual resides, the context in which information is collected, and whether applicable statutory thresholds are met. Advisor Nexus provides the rights described in this Policy where required by applicable law and may honor reasonable requests more broadly. Nothing in this Policy is intended to state that a particular privacy law applies when its jurisdictional requirements have not been met.
20. Your Privacy Rights
Depending on where you live and which laws apply, you may have the right to know what personal information we hold about you and why, to obtain a copy of it in a portable format, to correct it, to delete it, to opt out of sale, sharing for cross-context behavioral advertising, or targeted advertising (none of which we conduct), to limit the use of sensitive personal information (we do not request any), to withdraw consent you previously gave, to appeal a decision we make about your request where applicable law provides that right, and not to be treated differently for exercising any of these rights.
To make a request, email isaac@advisor-nexus.com and tell us what you would like, with enough detail for us to find your information. For most requests we will verify you by corresponding at the email address associated with the information and may ask for additional detail matching what we hold; we will not ask for more sensitive information than the request requires, and if we cannot verify you we will explain why. An authorized agent may make a request on your behalf with written proof of authorization, and we may still contact you directly to confirm.
We respond within the timeframe applicable law requires, and will tell you if we need an extension that law permits. If we decline your request and applicable law gives you a right of appeal, you may appeal by replying to our decision; we will respond in writing with our reasoning within the period that law allows and tell you how to contact the relevant regulator. If you are in the European Economic Area or the United Kingdom, you may also lodge a complaint with your local supervisory authority.
If you have a portal account, some requests may need to go through your firm. For example, the information may belong to your firm rather than to you personally, or deletion would end your access to a system your employer administers. We will tell you when that is the case and coordinate with your firm.
Where the EU or UK GDPR applies, we rely on taking steps at your request before entering a contract, performance of a contract for portal users at client firms, our legitimate interests in responding to business inquiries and securing our systems, your consent where we ask for it, and compliance with legal obligations. You may withdraw consent at any time.
21. Business Contacts, Children, and Other Sites
Almost everyone who uses this website does so in a professional capacity on behalf of a firm. Some privacy laws treat business-contact information differently from consumer information; we apply the practices in this policy to everyone regardless.
This website and portal are for business professionals and are not directed to anyone under 18. We do not knowingly collect information from children. If you believe a child has given us information, contact us and we will delete it.
Our website links to third-party sites and may rely on third-party services. We do not control them and are not responsible for their content, availability, security, or privacy practices. Their own terms and privacy policies govern your use of them.
22. Changes to This Policy
When we change this policy we will update the effective and last-updated dates above and summarize what changed.
August 14, 2026: HubSpot's website tracking and the HubSpot cookie consent banner were removed from this website. HubSpot no longer receives any information from your browser here, its cookies are no longer set, and it remains in Section 14 only as the platform where we manage inquiries after they reach us. With the banner gone, this site no longer asks for cookie consent: the Google Analytics and Microsoft Clarity measurement described in Section 7 now runs for every visitor, with advertising signals still denied permanently. Sections 6, 7, 12, 14, 15, 16, and 19 were updated accordingly.
August 6, 2026 (third update): Microsoft Clarity was added to the public website. This is a material change: the site now produces heatmaps and session recordings (replays of a visit) where previously it counted page views only. Recording happens only after analytics cookies are accepted, every form is masked so typed characters are never captured, and Clarity's identification feature is not used, so recordings are not linked to a named person. Microsoft has been added to the providers in Section 14 and its cookies to Section 6.
August 6, 2026 (second update): Google Analytics 4 was enabled on the public website under Google Consent Mode v2. Every visitor now starts with analytics storage denied worldwide, and advertising storage, advertising user data, and advertising personalization are denied permanently. Analytics storage becomes granted only when the consent banner reports that analytics cookies were accepted. Google has been added to the providers in Section 14 and its cookies to Section 6. Google Analytics does not load on the client-portal page.
August 6, 2026: HubSpot website analytics was enabled across the public website. This is a material change: the site previously set no cookies and ran no analytics, and it now sets the HubSpot cookies listed in Section 6 and sends the visit information described in Section 7. HubSpot has been added to the providers named in Section 14. HubSpot also provides the consent banner that governs whether those cookies are set.
August 4, 2026: the consultation form was simplified to a single step and no longer asks for the optional firm-context details it previously offered (phone number, job title, firm website, assets under management, CRM, other platforms, timing, automation maturity, and security-stakeholder involvement). Section 3 was updated accordingly. Transactional email delivery through Resend, described in Section 14, is now active.
If we make a material change, for example adding a new category of information, enabling analytics or bot protection, engaging a new type of provider, or changing how portal information is handled, we will describe the change clearly on this page before or when it takes effect, and where we hold your email address because of a form submission or a portal account, we will notify you by email. We will not rely on your continued use of the website as the only way of telling you about a material change.
23. Contact Us
Questions about this policy, requests to access, correct, or delete information, and reports of suspected security issues can all be sent to isaac@advisor-nexus.com. Please include enough detail for us to locate your submission.