NEXORA
Legal

Privacy Policy

Draft — Effective date: [NOT YET PUBLISHED] · Version 0.1

Draft — not reviewed by a lawyer.

This document is a starting draft, not a finished legal document. It has not been reviewed by a lawyer, references a legal entity and jurisdiction that don’t exist yet, and must not be treated as binding until reviewed and approved for the jurisdictions NEXORA actually operates in. Questions: legal@onenexora.com.

This Privacy Policy describes how [LEGAL ENTITY NAME — NOT YET INCORPORATED] (“NEXORA,” “we,” “us”) collects, uses and shares information in connection with the NEXORA platform. It describes our actual architecture, not generic boilerplate — each section below reflects what the system genuinely does.

1. Information we collect

Account and identity information. Sign-up and sign-in are handled by our identity provider, Clerk — your name, email address, password (hashed by Clerk, never seen by us), and organisation memberships are stored there, not in NEXORA’s own database. We never store a copy of your password.

Payment information. Subscription payments are processed by Stripe. We do not collect or store your card number, expiry date, or CVC — Stripe handles and stores that directly. We store only the subscription status, plan, and Stripe’s own customer/subscription identifiers needed to know what your organisation is entitled to.

API keys. When your organisation creates an API key, we store a one-way hash of it and a short, non-secret prefix for identification — the plaintext key is shown to you once, at creation, and is never stored or retrievable again.

Usage and audit events. We log events describing what your organisation does within the Service — for example, that a scan completed, or an API key was created — including a timestamp, the organisation and actor involved, and an outcome. This powers billing/usage limits, the Usage and Analytics views in Console, and security auditing. We do not log the content of what you submit to a product (for example, the log sample you paste into Sentinel) as part of this audit trail — only that the action occurred.

Content you submit to a product. Some products (for example, Sentinel and CSPM) accept data you paste in directly — log samples, resource descriptions — to analyse on request. Handling of that content is described on each product’s own page; [TODO(launch): confirm and state each product’s retention period for submitted content here once decided].

2. How we use information

We do not sell your personal information, and we do not use content you submit to a product to train any model.

3. Who we share information with

We share information with the following categories of service providers ( “subprocessors”), each acting under its own terms, solely to operate the Service:

We do not share your information with third parties for their own marketing purposes.

4. Data retention

We retain account and audit data for as long as your organisation’s account is active, and for a limited period afterward as needed for legal, tax, or dispute-resolution purposes. [TODO(launch): specific retention periods per data category not yet decided.]

5. Cookies

We use cookies required for authentication (set by Clerk) and, where used, essential session state. We do not currently use third-party advertising or cross-site tracking cookies. [TODO(launch): update this section if analytics/marketing cookies are added.]

6. Your rights

Depending on your location, you may have rights to access, correct, delete, or export your personal information, and to object to or restrict certain processing. To exercise any of these rights, contact legal@onenexora.com. [TODO(launch): this section needs jurisdiction-specific detail — e.g. GDPR/UK GDPR and CCPA/CPRA rights and response timelines — once NEXORA’s operating jurisdictions and user base are known.]

7. Security

See our Security Statement for the concrete practices in place. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

8. Children’s privacy

The Service is not directed at children and is not intended for use by anyone under the age of 16. We do not knowingly collect personal information from children.

9. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be notified through the Service or by email before taking effect.

10. Contact

Questions about this policy can be sent to legal@onenexora.com. Registered address: [REGISTERED BUSINESS ADDRESS — TBD].