Privacy Policy
1. Data Controller
NEXXIO SA, registered in Geneva, Switzerland, is the data controller for the personal data collected through the Service.
2. Data We Collect
| Category | Examples | Purpose |
|---|---|---|
| Identity | Name, email, company | Account creation, communication |
| Billing | Payment method, address | Invoicing, compliance |
| Usage | IP, browser, pages visited | Security, analytics |
| Content | Data you input into the platform | Service delivery |
3. Legal Basis
We process your data under the following legal bases:
- Contract: to provide the Service you subscribed to.
- Consent: for marketing communications (revocable at any time).
- Legitimate interest: for security, fraud prevention, and service improvement.
- Legal obligation: for tax, accounting, and regulatory compliance.
4. Data Retention
We retain your personal data for as long as your account is active, plus a maximum of 90 days after account deletion, unless a longer retention period is required by law (e.g., 10 years for accounting records).
5. Your Rights (GDPR)
You have the following rights:
- Right of access: obtain a copy of all your personal data.
- Right to rectification: correct inaccurate data.
- Right to erasure ("right to be forgotten"): delete your data.
- Right to portability: export your data in a machine-readable format.
- Right to restrict processing: limit how we use your data.
- Right to object: object to processing based on legitimate interest.
- Right to lodge a complaint with a supervisory authority.
To exercise any of these rights, email [email protected]. We respond within 30 days.
6. Data Sharing
We do not sell your data. We share it only with:
- Sub-processors: cloud hosting, payment processing, email delivery (see our DPA for the list).
- Legal authorities: when required by law.
7. International Transfers
Your data may be transferred outside the EU/EEA. When this occurs, we ensure appropriate safeguards (Standard Contractual Clauses, adequacy decisions).
8. Security
We implement industry-standard security measures: encryption in transit and at rest, access controls, monitoring, and regular audits. See our Security page.
9. Cookies
We use cookies as described in our Cookie Policy.
10. Changes
We may update this policy. Material changes will be notified by email or through the Service at least 30 days before they take effect.
11. Contact
Data Protection Officer: [email protected]