← Back to NexaFI Analytics
DRAFT: review with your CA/lawyer before publishing. This is a generic template and not legal advice. Items marked TODO must be completed.

Privacy Policy

NexaFI Analytics LLP · Last updated: TODO date

1. Who we are

NexaFI Analytics LLP ("NexaFI", "we", "us") is a limited liability partnership registered in India (LLPIN: TODO), with its registered office at TODO address, Bengaluru, Karnataka, India. We design and build AI-assisted workflow automations for businesses. Contact: info@nexafi.io.

2. Scope

This policy explains how we handle personal data when you visit leads.nexafi.io, contact us, book a call, or become a client. When we build or operate automations for a client, we process the client's end-customer data on the client's behalf (as a "data processor" in GDPR terms, or equivalent under India's Digital Personal Data Protection Act, 2023). In that case the client's own privacy notice applies, and our obligations are set out in our agreement with the client.

3. Data we collect

4. Why we use it (purposes and legal bases)

We don't sell personal data, and we don't use client project data to train AI models.

5. Service providers we share data with

We use trusted providers who process data for us under contract, for example: email and document hosting (TODO: Google Workspace / Zoho), website hosting (TODO: Netlify / Vercel / Cloudflare), scheduling, payments, and, for client builds, AI model providers (e.g. OpenAI, Anthropic), automation platforms (e.g. n8n, Make), messaging (e.g. WhatsApp Business Platform, Twilio), and CRMs chosen by the client. Some of these providers are located outside India, including in the US and EU. Where required, we rely on appropriate safeguards for cross-border transfers.

6. Retention

Enquiry data is kept for up to TODO: 24 months after our last contact. Client and billing records are kept for as long as required by Indian tax and company law. Client project credentials are deleted or handed back at the end of the engagement.

7. Your rights

Depending on where you live (for example under India's DPDP Act 2023, the EU/UK GDPR, or UAE PDPL), you may have rights to access, correct, delete, or restrict the use of your personal data, to withdraw consent, and to complain to a data-protection authority. To exercise these rights, email info@nexafi.io. We'll respond within the time required by applicable law.

8. Security

We use reasonable technical and organisational measures, including access controls, least-privilege credentials, encrypted connections, and client-owned accounts where possible. No method of transmission or storage is 100% secure.

9. Children

Our services are for businesses and aren't directed at children.

10. Grievance officer / contact

Grievance officer: TODO name, NexaFI Analytics LLP, TODO address. Email: info@nexafi.io.

11. Changes

We may update this policy from time to time. The "last updated" date above shows the latest version.