LEGAL

Privacy Policy

Last updated: 6 September 2026  ·  Effective: 6 September 2026  ·  Controller: Ne-xio  ·  Contact: [email protected]

1. Who we are

Ne-xio ("we", "our", "us") operates the website at ne-xio.net, which presents Ne-xio's orchestration layer and the systems built on it — MPS, ServiceTracker 2, BakePix, Mail Platform, and Ne-xio AI — and provides a contact form for inquiries about those systems.

For the purposes of EU data protection law (GDPR), Ne-xio is the data controller for personal data collected through this website.

2. What data we collect

Data you give us directly:

  • Name and email address submitted through our contact form
  • Message content you submit via the contact form
  • Meeting date and time preferences, if you request a call

Data collected automatically:

  • Basic request metadata (such as IP address and request path), processed only to rate-limit and prevent abuse of the contact form — held in memory and not written to persistent storage
  • Standard technical logs that our hosting and network infrastructure (see Section 4) may generate for security and operational purposes
  • No tracking pixels, no third-party analytics scripts, no cookies (see Section 8)

3. How we use your data

  • Contact form submissions — to respond to your inquiry and, where relevant, scope a system or project with you. Legal basis: legitimate interest / steps taken at your request prior to entering into a contract.
  • Request metadata — to keep the contact form available and secure, and to diagnose errors or abuse. Legal basis: legitimate interest.

We do not use your data for advertising. We do not sell your data to third parties. We do not use your message content to train AI models.

4. Third parties and infrastructure providers

We use a small number of infrastructure providers to operate this website:

  • Hetzner Cloud — the website runs on a server hosted with Hetzner Cloud (Germany, EU); your requests are processed there.
  • Cloudflare — public traffic reaches the website through Cloudflare's tunnel and network, which processes IP addresses and request headers in transit.
  • Internal email delivery — when you submit the contact form, its content is relayed through our internal email system to reach our team's mailbox. It is not shared with any other third party.

5. Data retention

  • Contact form submissions — kept in our contact mailbox for as long as reasonably necessary to respond to and resolve your inquiry, then retained in line with normal email-retention practice.
  • Rate-limiting counters — held only in memory; they are cleared automatically whenever the server restarts and are never written to persistent storage.

We do not currently commit to a fixed retention period beyond the above. If you'd like your data deleted sooner, contact us (Section 11) and we will act on that request.

6. Your rights (GDPR)

If you are located in the EU or EEA, you have the following rights regarding your personal data:

  • Access — request a copy of the personal data we hold about you
  • Rectification — request correction of inaccurate data
  • Erasure — request deletion of your personal data (subject to legal retention obligations)
  • Portability — receive your data in a structured, machine-readable format
  • Restriction — request that we limit processing of your data
  • Objection — object to processing based on legitimate interest
  • Complaint — lodge a complaint with your national data protection authority

To exercise any of these rights, email [email protected]. We will respond within 30 days.

7. Security

We apply reasonable technical and organisational measures to protect the data we process. All traffic to this website is encrypted in transit via TLS/HTTPS, with HTTP Strict Transport Security enforced. Administrative access to the underlying infrastructure is restricted.

No system is perfectly secure. If you discover a security vulnerability, please report it to [email protected].

8. Cookies

This website does not use cookies. We do not set session cookies, advertising cookies, tracking pixels, or third-party analytics cookies.

9. Children

Ne-xio's website and systems are intended for business use. We do not knowingly collect personal data from individuals under 18 years of age. If you believe we have collected such data, contact us immediately.

10. Changes to this policy

We may update this policy as this website and our systems evolve. Changes will be posted on this page with an updated "Last updated" date.

11. Contact

For any privacy-related questions or requests: [email protected]