LEGAL · GLOBAL SERVICE

Privacy Policy

Updated September 20, 2026.

1. Scope & data roles

This policy covers the NexaFile AI website, accounts, workspaces, support, billing and connectors. Users decide which documents are submitted and for what purpose; NexaFile operates the service according to configured settings and granted permissions.

2. Data we process

Account, company and member information; documents and metadata; analysis outputs; audit/security logs; support tickets; security recovery case references and approval records; billing references; and technical data required to operate the service.

3. Private AI

When private/self-hosted mode is enabled, document inference uses AI infrastructure controlled by the NexaFile operator and document content is not sent to a third-party GenAI API. The SaaS still runs on selected infrastructure/cloud providers, so it does not claim that data never leaves the customer network.

4. Purposes

General service data is processed to operate document analysis, search/exports, collaboration, security, abuse prevention, support, service notices and billing. Data received from Google Workspace APIs is used solely to provide or improve the specific user-facing NexaFile functionality requested by the user. It is not used for advertising, advertising measurement, profiling, data brokerage, unrelated purposes, generalized product improvement, or training generalized AI/ML models.

NexaFile processes only the content needed to provide the user-requested feature. Where appropriate, the service applies data-minimization safeguards before transferring necessary content to a subprocessor.

Google Workspace API Data & Limited Use

NexaFile's use and transfer of information received from Google Workspace APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google Workspace user data is used only to provide user-requested, user-facing NexaFile functionality.

NexaFile does not sell Google Workspace user data, use it for advertising, or use raw, aggregated, anonymized, or derived Google Workspace user data to create, train, or improve generalized machine learning or artificial intelligence models.

When a user explicitly connects Google Drive and selects documents for analysis, NexaFile may transfer the necessary content to the configured AI API provider solely to perform the user-requested document analysis functionality. The current configured AI provider is the OpenAI API Platform. NexaFile does not opt in to API data-sharing programs for training or improving generalized models. Analysis requests use the OpenAI API non-storage option where supported.

5. Connectors & subprocessors

When a customer connects Drive/Cloud, NexaFile accesses data only within granted OAuth/credential permissions and user selections. OneDrive supports personal Microsoft and Microsoft 365 accounts. SharePoint uses organizational Microsoft 365 accounts with delegated read-only Sites.Read.All/Files.Read access; a tenant may require admin consent. Application admin consent does not grant employees SharePoint site access: each user account must already have the relevant SharePoint permission. NexaFile does not currently request Microsoft write permissions.

6. Retention, deletion & export

Retention follows the plan/contract and workspace configuration. Owners can directly export and delete their workspace using product controls; Members can directly delete their own accounts. Other privacy-rights requests may be submitted through support and are handled under applicable law. Backups may require a technical expiry period.

Personal and business workspace Owners may directly delete their entire workspace; Members may directly delete only their own accounts. After the user re-enters the password and email, types DELETE, and accepts the Privacy Policy and Terms, Delete now erases live data in the displayed scope without submitting a request for NexaFile to process. The user is responsible for reviewing billing, member impact, and exporting required data before deletion. Erased live data cannot be restored; legally required records and backups follow separate lifecycles.

7. Security & incidents

The service is designed around tenant isolation, least privilege, encryption in transit, access controls, audit logging, rate limiting and incident handling. No system can promise absolute security.

8. International privacy rights

Requests to access, correct, delete, export or object to processing are handled under applicable law and the parties’ controller/processor roles. A DPA, SCCs or other international transfer mechanism may be offered where appropriate for business customers.

9. Retention transparency

Data groupRetention principle
Documents and AI outputsBased on workspace configuration, plan or contract; Owners can delete the workspace in product.
Security and audit recordsRetained as needed for security, abuse prevention and applicable legal obligations.
BackupMay remain until technical expiry and are not used to arbitrarily restore user-deleted data.
Hồ sơ thanh toánAccording to the Merchant of Record, payment provider and applicable legal obligations.

10. Privacy requests

Send requests to [email protected] with the account, workspace, requested right and relevant country/region. NexaFile may require proportionate identity verification. Deadlines and exceptions follow applicable law; there is no single deadline across all data roles and regions.

11. Cookies and measurement

The service uses cookies/sessions needed for authentication, security and language. Product or website measurement depends on the active operating configuration.

12. Roles, legal bases and regional requests

For account, billing, security and service-operation data, NexaFile generally determines the purposes needed to provide and protect the service. For documents in a business workspace, the customer generally determines the purpose and NexaFile processes under valid instructions. Depending on region, legal bases may include contract performance, legitimate interests, consent and legal obligations.

13. Children, browser signals and complaints

The service is not directed to children, and users must not knowingly submit children’s data without lawful authority. Because no uniform standard exists, Do Not Track signals do not automatically alter every processing activity; displayed cookie choices and rights under applicable law remain available. Where the law provides, you may complain to the competent data-protection authority.

Contact

[email protected]

NexaFile AI assistant AI