LEGAL · GLOBAL SERVICE

Privacy Policy

Product policy draft — counsel for the selling legal entity should review it before production billing goes live.

1. Scope & data roles

This policy covers the NexaFile AI website, company workspaces, support, billing and connectors. For business documents, the customer decides what is submitted and why; NexaFile operates the service according to configured settings and granted permissions.

2. Data we process

Account, company and member information; documents and metadata; analysis outputs; audit/security logs; support tickets; billing references; and technical data required to operate the service.

3. Private AI

When private/self-hosted mode is enabled, document inference uses AI infrastructure controlled by the NexaFile operator and document content is not sent to a third-party GenAI API. The SaaS still runs on selected infrastructure/cloud providers, so it does not claim that data never leaves the customer network.

4. Purposes

To provide document analysis, search/exports, collaboration, security, abuse prevention, support, service notices, billing and reliability improvements. Business documents are not sold to advertisers.

5. Connectors & subprocessors

When a customer connects Drive/Cloud, NexaFile accesses data only within granted OAuth/credential permissions and user selections. Infrastructure, email, payment and monitoring subprocessors should be published before production and updated when they change.

6. Retention, deletion & export

Retention follows the plan/contract and workspace configuration. Owners/Admins may request export or deletion through product controls and subject to legal obligations. Backups may require a technical expiry period.

7. Security & incidents

The service is designed around tenant isolation, least privilege, encryption in transit, access controls, audit logging, rate limiting and incident handling. No system can promise absolute security.

8. International privacy rights

Requests to access, correct, delete, export or object to processing are handled under applicable law and the parties’ controller/processor roles. A DPA, SCCs or other international transfer mechanism may be offered where appropriate for business customers.

Contact

[email protected]

Last updated: 8 September 2026

AI