Legal
Privacy Policy — NexaQore.ai
Status: Draft — not in effect (beta)
Template date: March 31, 2026
This Privacy Policy describes how NexaQore (“we,” “us,” or “our”) collects, uses, discloses, and protects information when you use our web application and related services (collectively, the “Service”). The Service is a laboratory information / laboratory execution software platform (“LIMS / LES”) offered at nexaqore.ai and associated domains.
We are committed to handling personal data responsibly. This policy is designed to align with the EU General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act (CCPA) as amended by the CPRA, and applicable privacy laws in India (including the Digital Personal Data Protection Act, 2023, where applicable). It should be read together with our Terms of Service.
1. Who we are (controller)
Data controller:
NexaQore
Formal legal entity name and registered address to be inserted after corporate and legal confirmation.
Email: privacy@nexaqore.ai
If you use the Service as an employee or contractor of a customer organization, your employer may be the controller of certain personal data, and we may act as a processor under their instructions. See Section 11.
2. Scope
This policy applies to:
- Visitors to our website and marketing pages
- Users who register for or access the Service (including administrators and lab personnel)
- Individuals who contact us for support or sales
It does not govern third-party websites or services linked from the Service.
3. Personal data we collect
We collect data in the categories below. Exactly what we collect depends on how you use the Service and what your organization configures.
3.1 Account and identity data
| Data | Typical source | Purpose |
|---|---|---|
| Name, work email, username | Registration / admin invite | Account creation, authentication, communication |
| Organizational affiliation, role, permissions | Customer/admin configuration | Access control, audit |
| Password or credential (hashed; we do not store plaintext passwords) | Registration / password reset | Security |
| Profile or contact details you choose to provide | Profile / settings | Service operation |
3.2 Usage and technical data
| Data | Typical source | Purpose |
|---|---|---|
| IP address, device/browser type, approximate location (derived from IP) | Web server logs, application security | Security, fraud prevention, troubleshooting |
| Log data (timestamps, pages or API endpoints accessed, errors) | Hosting / application | Reliability, security |
| Session identifiers (e.g., tokens; may be stored in cookies or browser storage) | Login flow | Authentication |
3.3 Communications
| Data | Typical source | Purpose |
|---|---|---|
| Email content, support tickets, survey responses | Your messages to us | Support, product improvement (where permitted) |
3.4 Customer content (“Customer Data”)
The Service is designed to store laboratory and operational records that your organization enters (e.g., samples, tests, equipment, inventory, workflows). Some of that content may constitute personal data (for example, if it relates to identifiable donors, patients, or staff) or special categories of data under GDPR if it concerns health or biometric data.
- Who decides the purpose: Typically your organization determines what data is entered and why. We provide the platform.
- Our role: We process Customer Data to provide the Service and as described in our agreement with the customer (including any Data Processing Agreement).
3.5 Cookies and similar technologies
We may use strictly necessary cookies (or equivalent technologies) for security and session management. Where we use non-essential cookies or similar tools (e.g., analytics, marketing), we will describe them in a Cookie Notice and, where required, obtain consent before use.
Update this section once you finalize your cookie inventory.
3.6 Third-party sign-in (if enabled)
If you use social or enterprise SSO (“Sign in with …”), the provider may share profile information with us according to their privacy policy and your settings.
4. How we collect data
- Directly from you: forms, uploads, in-app actions
- Automatically: logs, cookies/local storage, security monitoring
- From your organization: user provisioning, directory integration
- From third parties: authentication providers; payment processors ( if you add payments later)
We do not sell your personal information as that term is commonly defined under the CCPA/CPRA.
5. Legal bases (GDPR / UK GDPR)
Where GDPR applies, we rely on one or more of:
| Basis | Typical use |
|---|---|
| Contract | Providing the Service, user accounts, support |
| Legitimate interests | Security, abuse prevention, improving reliability (balanced against your rights) |
| Legal obligation | Tax, regulatory compliance, responding to lawful requests |
| Consent | Non-essential cookies/marketing, where required |
Special categories of data: If Customer Data includes health or other sensitive data, processing is generally based on Article 9 grounds that apply to the controller (e.g., scientific research, healthcare, employment), or on explicit consent where that is the correct basis. Your organization must ensure a valid basis exists.
6. How we use personal data
We use personal data to:
- Provide, operate, and improve the Service
- Authenticate users and enforce access controls
- Communicate about the Service (security notices, updates, support)
- Comply with law and enforce our terms
- Protect the security and integrity of our systems
We do not use personal data for automated decision-making that produces legal or similarly significant effects unless we describe that processing separately and provide required safeguards.
7. Sharing and subprocessors
We may share personal data with:
| Recipient | Purpose |
|---|---|
| Service providers (hosting, email delivery, monitoring) | Operating the Service under contract and confidentiality |
| Professional advisers | Legal, audit, compliance |
| Authorities | When required by law or to protect rights and safety |
| Business transfers | Merger, acquisition, or asset sale (with required notices where applicable) |
We maintain a list of subprocessors (available on request from privacy@nexaqore.ai or in your admin console when we provide it there). We require subprocessors to protect personal data appropriately.
International transfers: If we transfer personal data outside the EEA, UK, or India (as applicable), we use appropriate safeguards such as Standard Contractual Clauses or other mechanisms permitted by law.
8. Retention
We retain personal data only as long as necessary for the purposes above:
- Account data: For the life of the subscription plus a reasonable period for backups, disputes, and legal obligations
- Logs: Typically days to months unless longer retention is needed for security or legal holds
- Customer Data: As set by the customer (e.g., retention in the app) and our contract, unless law requires otherwise
After retention periods end, we delete or irreversibly anonymize data where feasible.
9. Security
We implement technical and organizational measures appropriate to the risk, which may include encryption in transit, access controls, logging, and secure development practices. No method of transmission or storage is 100% secure. We encourage customers to use strong passwords and SSO where available.
10. Your rights
Rights vary by jurisdiction. Depending on applicable law, you may have the right to:
GDPR / UK GDPR (individuals in the EEA/UK):
- Access a copy of your personal data
- Rectify inaccurate data
- Erase (“right to be forgotten”) in certain cases
- Restrict processing
- Object to processing based on legitimate interests
- Data portability where processing is based on contract or consent and is automated
- Withdraw consent where processing is consent-based
- Lodge a complaint with a supervisory authority
CCPA / CPRA (California residents):
- Know what personal information we collect, use, disclose, and retain
- Delete personal information (subject to exceptions)
- Correct inaccurate personal information
- Opt out of “sale” or sharing for cross-context behavioral advertising (we do not sell; update if practices change)
- Limit use of sensitive personal information (where applicable)
- Non-discrimination for exercising these rights
India (DPDPA, where applicable):
You may have rights to access, correction, erasure, grievance redressal, and nomination as provided under Indian law and our Data Protection Board / rules obligations.
How to exercise rights
Email privacy@nexaqore.ai with your request. We may need to verify your identity. If we act as a processor, we may direct you to your organization’s administrator.
Authorized agents (California): We will honor requests from authorized agents where permitted by law and after verification.
11. Controller vs. processor
- If you are an employee or contractor of a NexaQore customer, your employer is usually the controller of your work-related personal data in the Service.
- NexaQore is typically the controller for website visitors, account metadata we determine, and our own marketing (if any).
- A Data Processing Agreement (DPA) governs our processing of Customer Data on behalf of customers.
12. Children
The Service is not directed at children under 16 (or the age required in your jurisdiction). We do not knowingly collect personal information from children. Contact us if you believe we have done so.
13. Changes to this policy
We may update this Privacy Policy. We will post the updated version with a new “Last updated” date and, where required, provide additional notice (e.g., email or in-app banner). Continued use after the effective date may constitute acceptance where permitted by law.
14. Contact
Privacy inquiries: privacy@nexaqore.ai
General: support@nexaqore.ai
EU/UK representative (if required): Add name and address if you appoint a representative under Articles 27 GDPR / UK GDPR.