Privacy Policy
Product policy draft — counsel for the selling legal entity should review it before production billing goes live.
1. Scope & data roles
This policy covers the NexaFile AI website, company workspaces, support, billing and connectors. For business documents, the customer decides what is submitted and why; NexaFile operates the service according to configured settings and granted permissions.
2. Data we process
Account, company and member information; documents and metadata; analysis outputs; audit/security logs; support tickets; billing references; and technical data required to operate the service.
3. Private AI
When private/self-hosted mode is enabled, document inference uses AI infrastructure controlled by the NexaFile operator and document content is not sent to a third-party GenAI API. The SaaS still runs on selected infrastructure/cloud providers, so it does not claim that data never leaves the customer network.
4. Purposes
To provide document analysis, search/exports, collaboration, security, abuse prevention, support, service notices, billing and reliability improvements. Business documents are not sold to advertisers.
5. Connectors & subprocessors
When a customer connects Drive/Cloud, NexaFile accesses data only within granted OAuth/credential permissions and user selections. Infrastructure, email, payment and monitoring subprocessors should be published before production and updated when they change.
6. Retention, deletion & export
Retention follows the plan/contract and workspace configuration. Owners/Admins may request export or deletion through product controls and subject to legal obligations. Backups may require a technical expiry period.
7. Security & incidents
The service is designed around tenant isolation, least privilege, encryption in transit, access controls, audit logging, rate limiting and incident handling. No system can promise absolute security.
8. International privacy rights
Requests to access, correct, delete, export or object to processing are handled under applicable law and the parties’ controller/processor roles. A DPA, SCCs or other international transfer mechanism may be offered where appropriate for business customers.
Contact
Last updated: 8 September 2026