Privacy Policy
Last updated 1 August 2026
This policy explains what personal data Nexourz collects through bi.nexourz.com and the Nexourz BI product, why we collect it, and what rights you have. It covers this website and the hosted product; it does not cover data you load into your own deployment on Enterprise, where you are the controller and we are a processor.
Who we are
Nexourz(“we”) is the data controller for the personal data described below. Registered address and company details: TODO(legal). Contact: privacy@nexourz.com.
What we collect
When you request access. Your name, work email, organization, team size, and anything you write in the message field. You give us these directly.
When you use the product. Your email and role, from your sign-in provider. We also record an audit trail of actions taken in the product — who viewed, exported or published a report — because customers need that record for their own governance.
Automatically. Standard server logs: IP address, user agent, timestamp, and the path requested. We keep them to operate and secure the service.
Your business data. Data you connect to Nexourz BI stays in the sources you connect. We cache computed aggregates to keep dashboards fast. On Enterprise, the whole system runs in your own AWS account and your data never reaches our infrastructure at all.
What we do NOT do
We do not sell personal data. We do not use your business data to train any machine-learning model. The AI features read pre-computed, access-scoped aggregates in order to answer a question, and those requests are not used for training by us or by our model provider under our commercial terms.
Why we’re allowed to (lawful basis)
Legitimate interests — responding to an access request you sent us, keeping the service secure, and maintaining the audit log customers rely on.
Contract — providing the product to a customer’s users.
Consent — analytics and any marketing email, which you can withdraw at any time.
Legal obligation — where we must retain records.
How long we keep it
Access requests: 24 months from last contact, then deleted. Product accounts: for the life of the customer relationship plus TODO(legal). Server logs: 90 days. Audit logs: as configured by the customer, since they are the customer’s compliance record.
Who else processes it (subprocessors)
Amazon Web Services — hosting, database, storage, email delivery, and identity via Amazon Cognito (US-East-1). Anthropic — the model behind the AI features; it receives the pre-computed aggregates needed to answer a question, never raw rows or credentials. Slack — only if you connect it, to deliver the digests and alerts you configure.
International transfers
Our infrastructure runs in the United States (AWS us-east-1). If you are in the UK, EEA or Switzerland, transfers rely on the Standard Contractual Clauses and the UK Addendum.
Your rights
Depending on where you live, you can ask us for a copy of your data, to correct it, to delete it, to restrict or object to processing, to receive it in a portable format, and to withdraw consent. California residents may additionally request disclosure of categories collected and opt out of “sharing” — we do not sell or share personal data as those terms are defined by the CCPA/CPRA.
Email privacy@nexourz.com. We respond within 30 days. If you are unhappy with the outcome you may complain to your local supervisory authority.
Security
Traffic is encrypted in transit. Credentials for your data sources are held in AWS Systems Manager as encrypted parameters and are never stored in our application database or source code. Access to the product is authenticated at the load balancer and authorized per role, and row-level policies are enforced in one place so exports, AI answers and Slack deliveries inherit the same limits as the dashboard. See our security page.
Changes
We will update the date at the top of this page when it changes, and notify customers by email for material changes.
Questions about this page? privacy@nexourz.com