Legal · Privacy

Privacy Policy

Your trust matters. This policy explains what we collect, why, how we protect it, and the control you have over your information.

Effective date: June 14, 2026

1. Overview

This Privacy Policy explains how NexaCore ERP ("NexaCore", "we", "us") collects, uses, discloses, and safeguards information when you visit our website, create an account, or use our enterprise resource planning platform (the "Service").

NexaCore is a multi-tenant SaaS platform. We act as a "data controller" for the account and usage information we collect about our customers, and as a "data processor" for the business data our customers store in their own isolated tenant environment. Where we process data on behalf of a customer, that customer is the controller and their own privacy notices govern their end users.

2. Information We Collect

We collect the following categories of information:

  • Account information — name, work email, phone number, company name, role, and authentication credentials when you register or are invited to a workspace.
  • Billing information — plan, billing contact, and transaction records. Card details are processed by our payment provider and are not stored on our servers.
  • Customer data — the business records you enter into the Service (e.g. invoices, inventory, employee or contact records). This resides in your isolated tenant schema and is controlled by you.
  • Usage and device data — log data, IP address, browser type, pages viewed, feature usage, and timestamps, collected to operate, secure, and improve the Service.
  • Cookies and similar technologies — used for authentication, preferences, and (where enabled) analytics. See "Cookies & Tracking" below.

3. How We Use Information

We use information to:

  • Provide, maintain, and secure the Service and your account.
  • Authenticate users and enforce role-based access controls.
  • Process subscriptions, billing, and related communications.
  • Respond to support requests and send service-related notices.
  • Monitor performance, detect abuse, and prevent fraud.
  • Improve features and develop new functionality, using aggregated or de-identified data where possible.
  • Comply with legal obligations and enforce our Terms of Service.

We do not sell personal information, and we do not use customer data to train third-party models without explicit instruction or consent.

Where the GDPR or similar laws apply, we rely on one or more of the following legal bases: performance of a contract (to provide the Service), legitimate interests (to secure and improve the Service), consent (for optional analytics and marketing), and compliance with legal obligations.

5. How We Share Information

We share information only as needed to run the Service:

  • Sub-processors — vetted vendors for hosting, email delivery, payments, and analytics, bound by data-protection agreements.
  • Within your organisation — with other authorised users of your workspace, according to the roles and permissions you configure.
  • Legal and safety — when required by law, to protect rights and safety, or in connection with a corporate transaction such as a merger or acquisition.

We never share customer data between tenants. Each company operates in a fully isolated database schema.

6. Data Retention

We retain account and usage data for as long as your account is active and as needed to provide the Service. Customer data is retained according to your configuration and is deleted, together with your tenant schema, after account closure subject to a short grace period and any legal retention requirements. You may request earlier deletion as described under "Your Rights".

7. Data Security

We protect information using schema-level tenant isolation, encryption in transit, role-based access control, and continuous monitoring. For full detail, see our Security page. No method of transmission or storage is completely secure, but we work continuously to protect your information and to notify affected parties of material incidents as required by law.

8. International Transfers

Your information may be processed in countries other than your own. Where we transfer personal data across borders, we use appropriate safeguards such as standard contractual clauses to ensure an adequate level of protection.

9. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal information we hold about you.
  • Request correction of inaccurate information.
  • Request deletion of your information ("right to be forgotten").
  • Object to or restrict certain processing.
  • Request a portable copy of your data.
  • Withdraw consent at any time, without affecting prior processing.

To exercise any of these rights, contact us through the link below. If we process your data on behalf of a customer, we will direct your request to that customer.

10. Cookies & Tracking

We use strictly necessary cookies for authentication and security, and — only where enabled by the platform operator — optional cookies for analytics and marketing. You can control non-essential cookies through your browser settings. Disabling necessary cookies may affect core functionality such as signing in.

11. Children’s Privacy

The Service is intended for business use and is not directed to children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us information, please contact us so we can remove it.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated through the Service or by email, and the "Effective date" above will be updated. Continued use of the Service after changes take effect constitutes acceptance of the revised policy.

13. Contact Us

For privacy questions or to exercise your rights, please reach out through our contact page. We aim to respond to all legitimate requests within the timeframe required by applicable law.

Questions about this page?

We're happy to clarify anything here or walk you through how it applies to your organisation.

Contact us