Legal

Privacy Policy — NexaQore.ai

Status: Draft — not in effect (beta)
Template date: March 31, 2026

This Privacy Policy describes how NexaQore (“we,” “us,” or “our”) collects, uses, discloses, and protects information when you use our web application and related services (collectively, the “Service”). The Service is a laboratory information / laboratory execution software platform (“LIMS / LES”) offered at nexaqore.ai and associated domains.

We are committed to handling personal data responsibly. This policy is designed to align with the EU General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act (CCPA) as amended by the CPRA, and applicable privacy laws in India (including the Digital Personal Data Protection Act, 2023, where applicable). It should be read together with our Terms of Service.

1. Who we are (controller)

Data controller:

NexaQore

Formal legal entity name and registered address to be inserted after corporate and legal confirmation.

Email: privacy@nexaqore.ai

If you use the Service as an employee or contractor of a customer organization, your employer may be the controller of certain personal data, and we may act as a processor under their instructions. See Section 11.

2. Scope

This policy applies to:

  • Visitors to our website and marketing pages
  • Users who register for or access the Service (including administrators and lab personnel)
  • Individuals who contact us for support or sales

It does not govern third-party websites or services linked from the Service.

3. Personal data we collect

We collect data in the categories below. Exactly what we collect depends on how you use the Service and what your organization configures.

3.1 Account and identity data

DataTypical sourcePurpose
Name, work email, usernameRegistration / admin inviteAccount creation, authentication, communication
Organizational affiliation, role, permissionsCustomer/admin configurationAccess control, audit
Password or credential (hashed; we do not store plaintext passwords)Registration / password resetSecurity
Profile or contact details you choose to provideProfile / settingsService operation

3.2 Usage and technical data

DataTypical sourcePurpose
IP address, device/browser type, approximate location (derived from IP)Web server logs, application securitySecurity, fraud prevention, troubleshooting
Log data (timestamps, pages or API endpoints accessed, errors)Hosting / applicationReliability, security
Session identifiers (e.g., tokens; may be stored in cookies or browser storage)Login flowAuthentication

3.3 Communications

DataTypical sourcePurpose
Email content, support tickets, survey responsesYour messages to usSupport, product improvement (where permitted)

3.4 Customer content (“Customer Data”)

The Service is designed to store laboratory and operational records that your organization enters (e.g., samples, tests, equipment, inventory, workflows). Some of that content may constitute personal data (for example, if it relates to identifiable donors, patients, or staff) or special categories of data under GDPR if it concerns health or biometric data.

  • Who decides the purpose: Typically your organization determines what data is entered and why. We provide the platform.
  • Our role: We process Customer Data to provide the Service and as described in our agreement with the customer (including any Data Processing Agreement).

3.5 Cookies and similar technologies

We may use strictly necessary cookies (or equivalent technologies) for security and session management. Where we use non-essential cookies or similar tools (e.g., analytics, marketing), we will describe them in a Cookie Notice and, where required, obtain consent before use.

Update this section once you finalize your cookie inventory.

3.6 Third-party sign-in (if enabled)

If you use social or enterprise SSO (“Sign in with …”), the provider may share profile information with us according to their privacy policy and your settings.

4. How we collect data

  • Directly from you: forms, uploads, in-app actions
  • Automatically: logs, cookies/local storage, security monitoring
  • From your organization: user provisioning, directory integration
  • From third parties: authentication providers; payment processors ( if you add payments later)

We do not sell your personal information as that term is commonly defined under the CCPA/CPRA.

6. How we use personal data

We use personal data to:

  1. Provide, operate, and improve the Service
  2. Authenticate users and enforce access controls
  3. Communicate about the Service (security notices, updates, support)
  4. Comply with law and enforce our terms
  5. Protect the security and integrity of our systems

We do not use personal data for automated decision-making that produces legal or similarly significant effects unless we describe that processing separately and provide required safeguards.

7. Sharing and subprocessors

We may share personal data with:

RecipientPurpose
Service providers (hosting, email delivery, monitoring)Operating the Service under contract and confidentiality
Professional advisersLegal, audit, compliance
AuthoritiesWhen required by law or to protect rights and safety
Business transfersMerger, acquisition, or asset sale (with required notices where applicable)

We maintain a list of subprocessors (available on request from privacy@nexaqore.ai or in your admin console when we provide it there). We require subprocessors to protect personal data appropriately.

International transfers: If we transfer personal data outside the EEA, UK, or India (as applicable), we use appropriate safeguards such as Standard Contractual Clauses or other mechanisms permitted by law.

8. Retention

We retain personal data only as long as necessary for the purposes above:

  • Account data: For the life of the subscription plus a reasonable period for backups, disputes, and legal obligations
  • Logs: Typically days to months unless longer retention is needed for security or legal holds
  • Customer Data: As set by the customer (e.g., retention in the app) and our contract, unless law requires otherwise

After retention periods end, we delete or irreversibly anonymize data where feasible.

9. Security

We implement technical and organizational measures appropriate to the risk, which may include encryption in transit, access controls, logging, and secure development practices. No method of transmission or storage is 100% secure. We encourage customers to use strong passwords and SSO where available.

10. Your rights

Rights vary by jurisdiction. Depending on applicable law, you may have the right to:

GDPR / UK GDPR (individuals in the EEA/UK):

  • Access a copy of your personal data
  • Rectify inaccurate data
  • Erase (“right to be forgotten”) in certain cases
  • Restrict processing
  • Object to processing based on legitimate interests
  • Data portability where processing is based on contract or consent and is automated
  • Withdraw consent where processing is consent-based
  • Lodge a complaint with a supervisory authority

CCPA / CPRA (California residents):

  • Know what personal information we collect, use, disclose, and retain
  • Delete personal information (subject to exceptions)
  • Correct inaccurate personal information
  • Opt out of “sale” or sharing for cross-context behavioral advertising (we do not sell; update if practices change)
  • Limit use of sensitive personal information (where applicable)
  • Non-discrimination for exercising these rights

India (DPDPA, where applicable):

You may have rights to access, correction, erasure, grievance redressal, and nomination as provided under Indian law and our Data Protection Board / rules obligations.

How to exercise rights

Email privacy@nexaqore.ai with your request. We may need to verify your identity. If we act as a processor, we may direct you to your organization’s administrator.

Authorized agents (California): We will honor requests from authorized agents where permitted by law and after verification.

11. Controller vs. processor

  • If you are an employee or contractor of a NexaQore customer, your employer is usually the controller of your work-related personal data in the Service.
  • NexaQore is typically the controller for website visitors, account metadata we determine, and our own marketing (if any).
  • A Data Processing Agreement (DPA) governs our processing of Customer Data on behalf of customers.

12. Children

The Service is not directed at children under 16 (or the age required in your jurisdiction). We do not knowingly collect personal information from children. Contact us if you believe we have done so.

13. Changes to this policy

We may update this Privacy Policy. We will post the updated version with a new “Last updated” date and, where required, provide additional notice (e.g., email or in-app banner). Continued use after the effective date may constitute acceptance where permitted by law.

14. Contact

Privacy inquiries: privacy@nexaqore.ai

General: support@nexaqore.ai

EU/UK representative (if required): Add name and address if you appoint a representative under Articles 27 GDPR / UK GDPR.