NEXA
How it works Architecture Modules Why NEXA Who it is for Pricing Questions Contact
Start free trial→

Privacy

Privacy and GDPR

Last updated 29 July 2026

On this page

  1. Who is responsible for your data
  2. Two roles: this website and your app
  3. What we collect on this website
  4. Why we are allowed to use it
  5. Cookies
  6. How long we keep it
  7. Who else can see the data
  8. AI and your data
  9. Where your data is stored
  10. How we protect it
  11. Your rights
  12. Changes to this policy, and how to reach us

This page explains, in plain words, what happens to personal data when you use this website and when you run your own NEXA app. No dark patterns, and nothing sold to anyone.

The short version

  • We are REDOC Sp. z o.o. and you can reach us at contact@nexaenvision.com.
  • On this website we collect what you type into a form, plus the cookies you agree to. Nothing else.
  • Inside your app the data stays yours: we process it only on your instructions, and you can export all of it in one click.
  • Your data is never used to train any AI model - ours or anyone else's.

01Who is responsible for your data

NEXA is a product of REDOC Sp. z o.o., ul. Kasprzaka 31/119, 01-234 Warsaw, Poland. For everything described on this page we are the data controller within the meaning of the GDPR - except for the data inside your own app, which point 2 covers. Write to contact@nexaenvision.com or call +48 500 240 912 and a person, not a bot, will answer.

Company details: KRS 0000709354, NIP 9522173543, REGON 369348579.

02Two roles: this website and your app

We handle two very different kinds of data, and the law treats them differently. It is worth knowing which one you are reading about.

This website - we are the controller

What you send through the contact form or the trial form, and the cookies you agree to. We decide how that data is used, and this page describes it.

Your NEXA app - we are the processor

Your customers, documents, invoices and everything else you put inside your app. You stay the controller. We process it only on your instructions, under a data processing agreement signed before your app goes live.

03What we collect on this website

Only what we need to answer you and to keep the site working.

  • Contact and trial forms: your name and e-mail, optionally company and phone, and the message you write.
  • Technical logs: IP address, browser and time of the request, recorded by our hosting so the site stays available and secure.
  • Cookies: the necessary ones, plus analytics if you accept them.
  • E-mail: what you write to us and what we reply.

We do not collect special categories of data, we do not build profiles, and no decision about you is made automatically.

04Why we are allowed to use it

Every use of data needs a legal basis under the GDPR. Ours are:

  • Answering your enquiry and running your free trial - art. 6(1)(b), steps taken at your request before a contract.
  • Providing, billing and supporting your app - art. 6(1)(b), performance of a contract.
  • Keeping the site secure, measuring how it is used and defending claims - art. 6(1)(f), our legitimate interest.
  • Keeping accounting records - art. 6(1)(c), a legal obligation we cannot opt out of.
  • Analytics cookies - art. 6(1)(a), your consent, which you can withdraw at any time.

05Cookies

We use two groups. Necessary cookies keep the site working - your session, security, your language and the record of your cookie choice itself. Analytics cookies tell us which pages people actually read. Analytics stay off until you accept them, and the site works fine if you never do.

You can change your mind at any time from the cookie banner, or clear cookies in your browser settings. Withdrawing consent does not undo what happened while it was given.

06How long we keep it

We delete data once it stops being useful for the purpose we collected it for.

Contact form enquiry
Up to 24 months from our last message, then deleted.
Free trial app
Deleted within 30 days after the trial ends, unless you continue on a paid plan.
Your app and its backups
For as long as the contract runs. After it ends you get 30 days to export everything, then the app and its backups are deleted.
Invoices and accounting
5 years from the end of the tax year, as Polish law requires.
Server logs
Up to 12 months.

07Who else can see the data

We do not sell data and we do not hand it to anyone for their own marketing. A small number of suppliers process it on our behalf, each under a written agreement:

  • Our hosting and backup provider, in the region agreed for your app - by default the European Union.
  • Our e-mail and helpdesk provider, for the correspondence we have with you.
  • AI providers, used to draft the code of a change you asked for - see point 8.
  • Our accounting office, and public authorities where the law obliges us.

The current list of subprocessors for your app is part of your data processing agreement, and we tell you before it changes.

08AI and your data

When you send a request, AI writes the code of the change and a developer reviews it before it reaches your app. What that means in practice:

  • The AI works on your description of the request and on the app's source code - not on your business records.
  • Your data is never used to train any AI model, ours or anyone else's.
  • When a change needs test data we use anonymised or invented data, never your live records.
  • Every change is logged, so you can always see what changed, who approved it and when.

09Where your data is stored

Your app, its database and its backups are hosted in a single region, agreed with you before the app goes live; by default that is the European Union. If your app runs outside the European Economic Area, or a supplier has to process data outside it, we do that only under the European Commission's standard contractual clauses or another mechanism allowed by chapter V of the GDPR, and we tell you before it happens.

10How we protect it

Security here is a design decision, not a feature bolted on later:

  • Each company gets its own app with its own separate storage - customers never share one database.
  • Data is encrypted in transit and at rest, and access is limited to the people who need it for their work.
  • Backups run daily and are tested by restoring them.
  • Every change to your app is logged and can be rolled back.
  • You can export everything you have, in one click, at any time.

11Your rights

Under the GDPR you can ask us to:

  • give you a copy of your data (art. 15),
  • correct anything that is wrong (art. 16),
  • delete it (art. 17),
  • limit what we do with it (art. 18),
  • hand it over in a portable format (art. 20),
  • stop processing based on our legitimate interest (art. 21),
  • accept the withdrawal of a consent you gave us (art. 7(3)).

Write to contact@nexaenvision.com. We answer within one month, free of charge. If the data sits inside an app run by another company, we pass your request on to them, because they are the controller there.

If you think we mishandled your data, you can complain to the President of the Personal Data Protection Office (Urzad Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warsaw.

12Changes to this policy, and how to reach us

If we change this policy, the new version appears here with a new date. When a change actually matters for you - a new subprocessor, a shorter retention period - we tell you by e-mail before it takes effect. Questions about privacy, a data processing agreement or an export of your data all go to the same address.

Write to us→ Back to home

NEXA

NEXA is a custom business-management app you own and grow by request.

Site

  • How it works
  • Pricing
  • Questions

Contact

  • contact@nexaenvision.com
  • REDOC Sp. z o.o.
    01-234 Warsaw, ul. Kasprzaka 31/119

© 2026 REDOC. All rights reserved. REDOC Sp. z o.o., KRS 0000709354, NIP 9522173543, REGON 369348579

Privacy and GDPR

We use only what is needed to run the site, plus optional analytics. You choose.