PRIVACY POLICY FOR NEX SOFTWARE (GENERAL)
Reference is made to NEX Team Inc. (“NEX Team”, “us”, “our”, and “we”) and our products and services including but not limited to motion entertainment apps published by us, our websites and other related products and services with the exception of those specifically governed by another set of privacy policy (collectively, the “Services”).
This Privacy Policy (this “Policy”), which is incorporated into and is subject to our Terms of Use, describes the information that we gather from you, how we use and disclose such information, the legal basis on which we process it, and the steps we take to protect such information. For information on Children’s Privacy, click here. A simplified, child-friendly version of this Policy for younger users of Nex Playground is available at .
If you are located in the European Economic Area or the United Kingdom, certain GDPR-specific provisions apply to you in addition to, and where applicable take precedence over, the rest of this Policy. We adopt these provisions to comply with the European Union’s General Data Protection Regulation (EU 2016/679), the UK General Data Protection Regulation, and the UK Data Protection Act (collectively, the “GDPR”).
Who We Are
Data Controller: NEX Team Inc., 333 W San Carlos St, Suite 600, San Jose, CA 95110, USA
Email: support@nex.inc
Phone: (408) 357-4989
EU / UK Representative: info@edpo.com
Data Protection Officer (DPO): dpo@nex.inc
Information We Collect on the Services
User-provided Information
When you use the Services, we may collect information about you, including name, email address, performance statistics, user name, photos/videos or preferences and we may link this information with other information about you. You may provide us with information in various ways on the Services. For example, you provide us with information when you register for an account, authenticate your account using a third-party service, create your profile, record videos using the Services, or send us customer service-related requests. Payment and subscription details are processed via our payment provider; we do not store full card details.
Special Categories of Information. We do not ask you to provide, and we do not knowingly collect, any special categories of Personal Data (as defined in Article 9 of the GDPR) from you through our Services.
Automatically Collected Information
When you use the Services, we may automatically record certain information from your device by using various types of technology, including “cookies”, “clear gifs” or “web beacons”. This automatically collected information may include your IP address or other device address or ID, information about your web browser or device (including its model, version and/or operating system), the web pages or sites that you visit just before or just after you use the Services, the pages or other content you view or otherwise interact with on the Services, and information about how you visit, access, use or interact with the Services (including dates, times, duration, progress and other activities). We also may use these technologies to collect information regarding your interaction with email messages, such as whether you opened, clicked on, or forwarded a message. Automatically collected information is gathered from all users, and may be connected with other information about you.
Data from Third-Party Sources
We may receive data about you from, inter alia, the following sources:
- Google, if you choose to sign in with Google for authentication
- Our payment processing partners, for subscription verification
- Our analytics providers, solely for internal operations purposes
Examples of Required vs. Optional Data
Required: Email address and device identifier are required to create an account and use core Services. Without these, we cannot provide login, Play Pass management, or device functionality.
Optional: Marketing communications consent, profile photos, and analytics preferences are optional. Declining them does not affect your access to core Services.
How We Use the Information We Collect
We use information we collect on the Services in a variety of ways in providing the Services and operating our business, including the following:
- We use the information that we collect on the Services to operate, maintain, enhance and provide all features of the Services, to provide services and information that you request, to respond to comments and questions and otherwise to provide support to users, and to process and deliver entries and rewards in connection with promotions that may be offered from time to time on the Services.
- We use the information that we collect on the Services to identify our users, understand and analyze the usage trends and preferences of our users, to improve the Services, and to develop new products, services, features, and functionality.
- We may use your email address or other information we collect to contact you for administrative purposes such as customer service or to send communications, including updates on promotions and events, relating to products and services offered by us (but not third parties), where you have provided consent or we have a legitimate basis to do so under applicable ePrivacy rules.
- We may use automatically collected information to: (i) personalize our Services, such as remembering information about you so that you will not have to re-enter it during your visit or the next time you visit the Services; (ii) monitor and analyze the effectiveness of the Services; (iii) monitor aggregate site usage metrics such as total number of visitors and pages viewed; and (iv) track your entries, submissions, and status in any promotions or other activities on the Services.
Legal Basis for Processing (GDPR)
Where GDPR or UK GDPR applies, we process your personal data only where we have a lawful basis to do so under Article 6. The legal bases we rely on are:
- Performance of a contract (Art. 6(1)(b)): Account creation, authentication, login, Play Pass subscription management, billing, and customer support.
- Legitimate interests (Art. 6(1)(f)): Device stability diagnostics, fraud prevention, and security. We have carried out a balancing test and are satisfied our interests do not override your rights. You have the right to object to processing on this basis; see Your Data Protection Rights below.
- Consent (Art. 6(1)(a)): Analytics, marketing communications, and cookies beyond those that are strictly necessary. Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.
- Legal obligation (Art. 6(1)(c)): Fraud prevention, law enforcement cooperation, and regulatory compliance.
For children’s data, we additionally apply the COPPA internal operations exception (16 C.F.R. §312.5(c)(7)) and, for EU users, GDPR Art. 6(1)(f) for pre-consent device data, and parental consent (Art. 6(1)(a)) for post-consent analytics.
When We Disclose Information
Except as described in this Policy, we will not disclose information about you that we collect on the Services to third parties without your consent. We do not sell your personal data. We may disclose information to third parties if you consent to us doing so, as well as in the following circumstances:
- Service Providers. We work with third party service providers to provide application development, hosting, maintenance, analytics, marketing, communication, and other services for us. These include, amongst others, Amazon Web Services (AWS), Mixpanel Inc., Memfault Inc, Rebrandly, payment processor, and Google reCAPTCHA. We may transfer data to these providers, and we require them to agree to maintain confidentiality of such information and to process it only on our behalf under Data Processing Agreements (DPAs). We limit the information provided to that which is reasonably necessary for them to perform their functions.
- Legal Disclosures. We may disclose information about you if required to do so by law or in the good-faith belief that such action is necessary to comply with state, federal, or international laws, in response to a court order, judicial or other government subpoena or warrant, or to otherwise cooperate with law enforcement or other governmental agencies.
- Protection of Rights. We also reserve the right to disclose information about you that we believe, in good faith, is appropriate or necessary to: (i) take precautions against liability; (ii) protect ourselves or others from fraudulent, abusive, or unlawful uses or activity; (iii) investigate and defend ourselves against any third-party claims or allegations; (iv) protect the security or integrity of the Services and any facilities or equipment used to make the Services available; or (v) protect our property or other legal rights (including, but not limited to, enforcement of our agreements), or the rights, property, or safety of others.
- Business Transfers. Information about our users may be disclosed and otherwise transferred to an acquirer, successor, or assignee as part of any merger, acquisition, debt financing, sale of assets, or similar transaction, or in the event of an insolvency, bankruptcy, or receivership in which information is transferred to one or more third parties as one of our business assets.
- Aggregated Data. We may make certain aggregated, automatically-collected, or otherwise non-personal information available to third parties for various purposes, including: (i) compliance with various reporting obligations; (ii) for business purposes; or (iii) to assist such parties in understanding our users’ interests, habits, and usage patterns for certain programs, content, services, and functionality available through the Services.
Analytics data from the Nex Playground device is not linked to or combined with data collected through our website, e-commerce platform, or Play Pass subscription system.
International Transfer
In order to provide our Services to you, we may transfer and store information that we collect about you to affiliated entities, or to other third parties across borders and from your country or jurisdiction to other countries or jurisdictions around the world, including to the United States. If you are located in the European Union, the United Kingdom, or other regions with laws governing data collection and use that may differ from U.S. law, please note that your information may be transferred to the United States or other countries. Where required by applicable law, such transfers are carried out on the basis of appropriate safeguards, including Standard Contractual Clauses (SCCs) adopted by the European Commission, UK International Data Transfer Agreements (IDTAs), or other lawful transfer mechanisms under GDPR Art. 46 or UK GDPR. Where required, we supplement these clauses with additional technical and organizational measures based on a transfer impact assessment to ensure an essentially equivalent level of protection. Under these Standard Contractual Clauses, you have the same rights as if your personal data was not transferred to such a third country. By using the Services, you acknowledge that your information may be processed in countries where data protection laws may differ from those in your home jurisdiction. For more information about our international transfer mechanisms or to request a copy of the Standard Contractual Clauses or other transfer mechanism documentation, please contact us at dpo@nex.inc.
Data Retention
We retain personal information only for as long as is necessary to fulfil the purpose for which it was collected, taking into account our legal obligations and the need to resolve disputes or enforce agreements. The criteria we use to determine retention periods are: (a) the purpose for which data was collected; (b) any legal or regulatory obligation to retain it; and (c) our legitimate interest in maintaining business records.
In summary:
- Device analytics data: retained for no more than 13 months on a rolling basis, then permanently deleted or de-identified.
- Device vitals and firmware telemetry: retained for no more than 60 months on a rolling basis.
- Customer support records involving children: retained for 3 years from ticket closure.
- Consent records (accept or decline): retained for the life of the device registration plus 3 years.
- Account data (general): retained for the duration of the account plus 3 years after a deletion request, then permanently deleted.
- Marketing consent records: retained until consent is withdrawn plus 3 years for audit purposes.
- Financial / billing records: retained for 7 years to satisfy tax and legal obligations.
Parents and users may request deletion of their data at any time by contacting support@nex.inc. Deletion requests are processed within 30 days, subject to legal retention requirements.
Cookies and Tracking Technologies
Cookies are small text files placed on your device to collect standard internet log information and visitor behaviour data. Our web client uses cookies and similar technologies. We categorise these as follows:
- Strictly Necessary: Required to deliver core Services — authentication, session management, and security tokens. These fire unconditionally and do not require your consent.
- Statistics / Analytics: Used to understand how you interact with our Services (e.g. Mixpanel, Google Analytics). These only activate if you provide consent.
- Marketing / Personalisation: Used for A/B testing and experimentation (e.g. Optimizely). These only activate if you provide consent.
On your first visit to our web client, we present a Cookie Consent Banner. You may accept all, reject all, or choose granular preferences by category. You may change your preferences at any time via the cookie settings link in the footer. For users in the EEA, UK, and Switzerland, we only place non-essential cookies on your device with your affirmative consent. You may withdraw or change your consent at any time through the cookie preferences link on our website or by adjusting your device or browser settings. If you decline non-essential cookies, all core Services, including login, Play Pass management, and parental controls, remain fully functional. Withholding core Services access pending cookie consent is not permitted under GDPR Art. 7(4).
Your Data Protection Rights
If you are in the EU or UK, you are entitled to the following rights under GDPR / UK GDPR. We have one calendar month to respond to any request. To exercise any of these rights, please contact us at support@nex.inc or dpo@nex.inc.
- The right to access. You have the right to request copies of your personal data, how we use it, who we share it with, and how long we keep it.
- The right to rectification. You have the right to request that we correct any information you believe is inaccurate or incomplete.
- The right to erasure. You have the right to request that we erase your personal data, under certain conditions — including where it is no longer necessary for the purpose it was collected, or where you withdraw consent and no other lawful basis applies.
- The right to restrict processing. You have the right to request that we restrict processing of your personal data, under certain conditions — for example while a dispute about accuracy is being resolved. Where processing is restricted, we will store but not actively process your data.
- The right to object. You have the right to object at any time to processing where we rely on legitimate interests (Art. 6(1)(f)). We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests. You have an absolute right to object to direct marketing at any time and we will stop immediately.
- The right to data portability. You have the right to request that we transfer your personal data to another organisation, or directly to you, in a structured, commonly used, machine-readable format, under certain conditions.
- The right to withdraw consent. Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal. You can withdraw marketing consent via any marketing email’s unsubscribe link or via Account Settings. You can withdraw analytics/cookie consent via your Cookie Settings in the web client footer.
- The right to lodge a complaint. You have the right to lodge a complaint with a supervisory authority at any time. See “How to Contact the Appropriate Authority” below.
If you make a request, we have one month to respond to you. There is no charge for exercising your rights unless requests are manifestly unfounded or excessive.
Automated Decisions and Player Profiling
Nex Playground uses on-device AI for motion-capture gameplay. This processing occurs entirely locally on the device — no images or video are uploaded to the cloud or processed remotely. This does not constitute profiling for GDPR purposes.
Where you have given consent, we use aggregated gameplay data to improve the Services at a population level only. This does not produce decisions that have a legal or similarly significant effect on individual users.
We do not currently use algorithmic recommendations, personalised content feeds, or automated decision-making that produces legal effects for individual users (GDPR Art. 22). If we introduce such features in the future, we will update this Policy and, where required, obtain your explicit consent. If you believe automated processing has affected you in a significant way, please contact dpo@nex.inc.
Marketing
NEX Team would like to send you information about our products and Services that we think you might like. We will only send you marketing communications where:
- You have given us your explicit consent (opt-in) at registration or login, OR
- You are an existing customer and we are marketing similar products or Services, and you have not opted out (soft opt-in under ePrivacy Directive Art. 13(2) / PECR Reg. 22)
Every marketing email includes an unsubscribe link. If you have agreed to receive marketing, you may always opt out at a later date. You have the right at any time to stop NEX Team from contacting you for marketing purposes. To opt out, follow the unsubscribe instructions in any marketing email, update your preferences in Account Settings, or email support@nex.inc.
Please be aware that if you opt out of receiving commercial email from us, it may take up to five business days to process your request and you may receive one further communication during that period. Even after you opt out of commercial messages, you will continue to receive administrative messages regarding the Services.
We do not share your personal data with third-party companies for their own marketing purposes.
Your Choices
You may, of course, decline to share certain information with us, in which case we may not be able to provide to you some of the features and functionality of the Services. If you wish to access, amend or delete any other personal information we hold about you, you may contact us at support@nex.inc. Please note that while any changes you make will be reflected in active user databases within a reasonable period of time, we may retain all information you submit for backups, archiving, prevention of fraud and abuse, analytics, satisfaction of legal obligations, or where we otherwise reasonably believe that we have a legitimate reason to do so.
Under California law, California Residents who have an established business relationship with us may choose to opt out of the disclosure of personal information about them to third parties for such third parties’ direct marketing purposes. Our policy is not to disclose personal information collected online to a third party for direct marketing purposes without your approval. If you choose to opt-out at any time after granting approval, email support@nex.inc.
Third-Party Services
The Services may contain features or links to websites and services provided by third parties, and the Services may be made available via third party platforms/marketplaces, such as Apple’s App Store. Any information you provide on third-party sites, services or platforms/marketplaces is provided directly to the operators of such services and is subject to those operators’ policies, if any, governing privacy and security, even if accessed through the Services. We are not responsible for the content or privacy and security practices and policies of such third parties. We encourage you to learn about third parties’ privacy and security policies before providing them with information.
Our web client uses Google reCAPTCHA to prevent fraud. reCAPTCHA processes data under Google’s Privacy Policy and Terms of Service.
Children’s Privacy
We are committed to protecting the privacy of children. The following provisions apply specifically to Nex Playground and any other child-directed portions of our Services. We comply with the Children’s Online Privacy Protection Act (“COPPA”) and applicable regulations, including 16 C.F.R. Part 312.
Age Rules and Parental Consent
Nex Playground is designed for family use. For COPPA compliance, users under 13 in the United States require verifiable parental consent before we collect personal information beyond what is permitted under the internal operations exception. For EU and UK users:
- In the EU, children under 16 require parental consent for processing based on consent (some member states set the threshold at 13).
- In the UK, children under 13 require parental consent (UK GDPR Art. 8 / Age Appropriate Design Code).
Our platform requires parental account set-up and consent before a child’s account is activated. If we discover that a child’s data has been collected without appropriate consent, we will delete it promptly.
Parental Consent
We do not knowingly collect personal information from children under the age of 13 on child-directed portions of our Services without a lawful basis under applicable law. On Nex Playground, a limited set of technical data (device identifier and device vitals) is collected from first boot solely under the COPPA internal operations exception (16 C.F.R. §312.5(c)(7)) and, for EU users, under a documented Legitimate Interests basis (GDPR Art. 6(1)(f)). Following device setup and account sign-in, we present a data collection consent prompt. (For more information, please see Persistent Identifier – Internal Operations Exception below). Where a parent or user consents, analytics collection continues under GDPR Art. 6(1)(a). Where consent is declined, no further analytics events are transmitted and any pre-consent data associated with that device is deleted. Parents or guardians may review the personal information collected from their child, request deletion of that information, and withdraw consent at any time by contacting us at support@nex.inc.
How Consent Works and How to Withdraw
Consent is recorded with a timestamp, the version of the consent prompt shown, and the parental account ID. To withdraw consent at any time, parents may contact support@nex.inc. Withdrawal does not affect the lawfulness of processing carried out before withdrawal. Upon withdrawal, analytics collection will cease and any pre-consent data associated with that device will be deleted.
Information We Do Not Collect from Children
Even though Nex Playground is equipped with a camera, it is used solely for local motion-capture games. No images or video of any user’s interaction with Nex Playground, regardless of age, are uploaded to the cloud or otherwise collected by us via Nex Playground. We do not collect names or contact information on Nex Playground. No information from Nex Playground that could be used to directly identify a child is shared with independent third parties for commercial or advertising purposes.
Persistent Identifiers — Internal Operations Exception
On Nex Playground, we collect certain persistent identifiers and technical telemetry data from first boot to support internal operations of the Services. Specifically: (a) a persistent device identifier is transmitted to Mixpanel for internal analytics and product support, as permitted under COPPA (16 C.F.R. §312.5(c)(7)); and (b) device vitals and firmware error telemetry are transmitted to Memfault for device stability and crash diagnostics, as permitted under COPPA and, for EU users, under GDPR Art. 6(1)(f) Legitimate Interests documented in our Legitimate Interests Assessment (LIA). “Internal operations” means activities necessary to maintain or analyze the functioning of the Services, perform network communications, authenticate users or devices, ensure legal or industry compliance, and fulfil a request made by a child that is consistent with our parental consent obligations. Following sign-in, users are presented with a data collection consent prompt; where consent is given, analytics collection continues under GDPR Art. 6(1)(a); where consent is declined, pre-consent analytics data is deleted. We maintain Legitimate Interests Assessments for our pre-consent processing activities on Nex Playground, which are available upon request by contacting us at support@nex.inc.
Persistent identifiers collected from children on Nex Playground are:
- Not used to build profiles of children or to track children across third-party websites or online services;
- Not disclosed to third parties for commercial, advertising, or marketing purposes;
- Not used for behavioral advertising or interest-based advertising directed at children; and
- Retained only for as long as reasonably necessary to support the internal operations for which they were collected, after which they are deleted or de-identified.
Means to Prevent Prohibited Use
To enforce the above restrictions, NEX Team Inc. takes the following measures:
- Analytics data from the Nex Playground device is not linked to or combined with data collected through our website, ecommerce platform, or Play Pass subscription system.
- Access to analytics data is restricted internally to personnel with a legitimate operational need, in accordance with our Written Information Security Program.
No Conditioning of Participation
We do not condition a child’s participation in any activity on the disclosure of more personal information than is reasonably necessary to participate in that activity, as required by 16 C.F.R. §312.7.
Parental Rights
Parents and guardians have the right to: (i) review the personal information we have collected from their child; (ii) request that we delete their child’s personal information; (iii) refuse to permit further collection or use of their child’s personal information; and (iv) agree to the collection and use of their child’s personal information without consenting to disclosure to third parties, where applicable. To exercise any of these rights, please contact us at support@nex.inc. If you believe that personal information has been collected from your child without proper consent, please contact us immediately so that we may take corrective action.
Third-Party Operators and Service Providers on Child-Directed Services
We do not permit third-party operators to collect personal information from children on child-directed portions of our Services through integrated plug-ins, APIs, or SDKs for their own purposes. Any third-party service providers that access data on the child-directed portions of our Services are contractually restricted to processing that data only to provide services to us, are prohibited from using children’s data for independent commercial purposes, and are required to maintain confidentiality and appropriate security safeguards consistent with COPPA.
Data Security
We use certain physical, managerial, and technical safeguards that are designed to improve the integrity and security of information that we collect and maintain, including encryption in transit (TLS) and at rest, access controls restricting data access to personnel with a legitimate operational need, Data Processing Agreements with all third-party processors, and regular security assessments. Please be aware that no security measures are perfect or impenetrable. We cannot and do not guarantee that information about you will not be accessed, viewed, disclosed, altered, or destroyed by breach of any of our physical, technical, or managerial safeguards.
Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority (ICO / EU DPA) within 72 hours of becoming aware, as required by GDPR Art. 33. Where the breach is likely to result in a high risk to you, we will also notify you directly without undue delay (GDPR Art. 34). To report a security concern or potential breach, please contact: security@nex.inc.
Changes and Updates to this Policy
Please revisit this Policy periodically to stay aware of any changes to this Policy, which we may update from time to time. If we make material changes, we will notify you via email or a prominent notice on our Services before the change takes effect, and we will indicate the date of the latest revision at the top of this Policy. For significant changes affecting how we process children’s data, or changes to our legal basis for processing, we will seek fresh consent where required. Your continued use of the Services after the revised Policy has become effective indicates that you have read, understood and agreed to the current version of this Policy.
How to Contact Us
Please contact us with any questions or comments about this Policy, information we have collected or otherwise obtained about you, our use and disclosure practices, our service providers, or your consent choices:
NEX Team Inc.
333 W San Carlos St, Suite 600
San Jose, CA 95110
Email: support@nex.inc
DPO / Data Rights: dpo@nex.inc
Security / Breach: security@nex.inc
Phone: (408) 357-4989
EU / UK Representative: info@edpo.com
How to Contact the Appropriate Authority
Should you wish to report a complaint or if you feel that NEX Team has not addressed your concern in a satisfactory manner, you have the right to lodge a complaint with a data protection supervisory authority. You do not need to contact us first, though we encourage you to reach out so we can try to resolve your concern directly.
United Kingdom — Information Commissioner’s Office (ICO)
Website: ico.org.uk
Helpline: 0303 123 1113
Address: Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
European Union — Your National Data Protection Authority (DPA)
If you are in the EU, you may contact your national DPA. A full list of EU DPAs is available at: edpb.europa.eu/about-edpb/board/members_en
United States — Federal Trade Commission (FTC)
For COPPA-related concerns:
Website: ftc.gov
Address: 600 Pennsylvania Avenue NW, Washington, DC 20580





