This page explains, in plain words, what happens to personal data when you use this website and when you run your own NEXAENVISION app. No dark patterns, and nothing sold to anyone.
The short version
- We are REDOC Sp. z o.o. and you can reach us at contact@nexaenvision.com.
- On this website we collect what you type into a form and, once you agree, events from our own measurement - with no cookies and no identifier. Nothing else.
- Inside your app the data stays yours: we process it only on your instructions, and you can export all of it in one click.
- Customer data and content processed in NEXAENVISION is never used to train any AI model - ours or anyone else's.
01Who is responsible for your data
NEXAENVISION is a product of REDOC Sp. z o.o., ul. Kasprzaka 31/119, 01-234 Warsaw, Poland. For everything described on this page we are the data controller within the meaning of the GDPR - except for the data inside your own app, which point 2 covers. Write to contact@nexaenvision.com or call +48 500 240 912 and a person, not a bot, will answer.
Company details: KRS 0000709354, NIP 9522173543, REGON 369348579.
02Two roles: this website and your app
We handle two very different kinds of data, and the law treats them differently. It is worth knowing which one you are reading about.
This website - we are the controller
What you send through the contact form or the trial form, and the cookies you agree to. We decide how that data is used, and this page describes it.
Your NEXAENVISION app - we are the processor
Your customers, documents, invoices and everything else you put inside your app. You stay the controller. We process it only on your instructions, under a data processing agreement signed before your app goes live.
03What we collect on this website
Only what we need to answer you and to keep the site working.
- Contact and trial forms: your name and e-mail - without them we cannot handle the request - and the message you write, plus company and phone if you choose to give them.
- Technical logs: IP address, browser and time of the request, recorded by our hosting so the site stays available and secure.
- Cookies: the necessary ones only. The analytics you agree to uses no cookies - see point 5.
- E-mail: what you write to us and what we reply.
We do not collect special categories of data, we do not build profiles, and no decision about you is made automatically.
04Why we are allowed to use it
Every use of data needs a legal basis under the GDPR. Ours are:
- Answering your enquiry and running your free trial - art. 6(1)(b), steps taken at your request before a contract when you act on your own behalf, or art. 6(1)(f), our legitimate interest in handling enquiries and B2B relationships when you write on behalf of an organisation.
- Providing, billing and supporting your app - art. 6(1)(b), performance of a contract.
- Keeping the site secure and defending claims - art. 6(1)(f), our legitimate interest.
- Keeping accounting records - art. 6(1)(c), a legal obligation we cannot opt out of.
- Website analytics - your consent: art. 399(1) of the Polish Electronic Communications Law and, for personal data, art. 6(1)(a) GDPR. You can withdraw it at any time.
05Cookies and analytics
The only cookies we use are the necessary ones: your session, security, your language and the record of your analytics choice itself. Analytics is our own measurement system and starts only after you agree. The website script then sends events to our own endpoint: a page view, an element click, starting and submitting a form, selecting a tier, opening an FAQ question, clicking a contact element, scroll depth and a language switch. We record a server-generated timestamp, the event name, the page path without query parameters or fragments, the language code and limited event parameters.
This system does not store or read cookies, localStorage, sessionStorage or IndexedDB, does not create a user or device identifier, does not use fingerprinting and does not count unique users or sessions. We keep the data in our database in the European Union for 400 days and do not pass it to an external analytics provider.
The legal basis for accessing information on your device for analytics is your consent - art. 399(1) in conjunction with art. 400 of the Polish Electronic Communications Law of 12 July 2024. To the extent that this information is personal data, the basis is art. 6(1)(a) GDPR.
You can change or withdraw your consent at any time in the privacy settings in the site footer. Withdrawal stops further measurement and does not undo what happened while consent was given.
Independently of analytics, our server temporarily processes technical connection data: the IP address in memory only, to limit excessive request rates, and the User-Agent, to recognise automated traffic. Neither is written to our analytics database. To the extent that they are personal data, the basis is art. 6(1)(f) GDPR - our legitimate interest in the security, availability and integrity of the site.
06How long we keep it
We delete data once it stops being useful for the purpose we collected it for.
- Contact form enquiry
- For as long as we handle the matter and then, where that is needed to continue the relationship or for legal claims, no longer than 24 months from our last message.
- Free trial app
- The trial app and its backups are deleted within 30 days after the trial ends.
- Your app and its backups
- For as long as the contract runs. After it ends you get 30 days to export everything, then the app and its backups are deleted.
- Invoices and accounting
- 5 years from the end of the tax year, as Polish law requires.
- Server logs
- Up to 12 months.
- Record of a trial signup
- Once the app is deleted only a technical record remains: service type, instance name, status, dates and the versions of the terms accepted. Contact details are stripped from it after 30 days. The record itself is deleted after 365 days - we keep it to be able to show what was consented to, and to enforce the limit of one free trial per company per year.
07Who else can see the data
We do not sell data, and we do not share customer data processed in the NEXAENVISION application with anyone for their own advertising or marketing purposes. A small number of suppliers process it on our behalf, each under a written agreement:
- Our hosting and backup provider, in the region agreed for your app - by default the European Union.
- Our e-mail and helpdesk provider, for the correspondence we have with you.
- Our accountants and public authorities, where the law requires it.
We give you notice before a subprocessor changes. The full list of parties processing data from your application is published at a separate address and forms part of the data processing agreement:
See the subprocessor list
08AI and your data
A human reads your request. Our administrator writes down, in their own words, what needs to be built, and only that description reaches the AI tools we write code with. What that means in practice:
- The AI tools receive neither the text of your request nor any data from your application - they work on the task description written by our administrator and on source code.
- Customer data and content processed in NEXAENVISION is never used to train any AI model - ours or anyone else's.
- When a change needs test data we use anonymised or invented data, never your live records.
- Every change is logged, so you can always see what changed, who approved it and when.
09Where your data is stored
Your app, its database and its backups are hosted in a single region, agreed with you before the app goes live; by default that is the European Union. If your app runs outside the European Economic Area, or a supplier has to process data outside it, we do that only under the European Commission's standard contractual clauses or another mechanism allowed by chapter V of the GDPR, and we tell you before it happens.
10How we protect it
Security here is a design decision, not a feature bolted on later:
- Each company gets its own app with its own separate storage - customers never share one database.
- Data is encrypted in transit and at rest, and access is limited to the people who need it for their work.
- Backups run daily and are tested by restoring them.
- Every change to your app is logged and can be rolled back.
- You can export everything you have, in one click, at any time.
11Your rights
Under the GDPR you can ask us to:
- give you a copy of your data (art. 15),
- correct anything that is wrong (art. 16),
- delete it (art. 17),
- limit what we do with it (art. 18),
- hand it over in a portable format (art. 20),
- stop processing based on our legitimate interest (art. 21),
- accept the withdrawal of a consent you gave us (art. 7(3)).
Write to contact@nexaenvision.com. We answer within one month, free of charge. If the data sits inside an app run by another company, we pass your request on to them, because they are the controller there.
If you think we mishandled your data, you can complain to the President of the Personal Data Protection Office (Urzad Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warsaw.
12Changes to this policy, and how to reach us
If we change this policy, the new version appears here with a new date. When a change actually matters for you - a new subprocessor, a shorter retention period - we tell you by e-mail before it takes effect. Questions about privacy, a data processing agreement or an export of your data all go to the same address.