Cyber Security Vulnerability Disclosure Policy

At a glance

  • Most requests (get a copy of your data, ask us to delete it, fix errors, and similar): use our secure online request form (preferred) or email privacy@nex.inc. This is also the address for regulatory correspondence
  • Formal privacy or Data Protection Officer (DPO) matters: email dpo@nex.inc
  • We usually reply within a calendar month. We may need to confirm who you are before we act.

Rights you may have

Not every right applies in every situation, but when the law applies you may be able to:

  • See your data (access) — Find out if we process your information and get a copy. (GDPR Article 15)
  • Fix mistakes (rectification) — Ask us to correct information that is wrong or incomplete. (Article 16)
  • Ask us to delete data (erasure) — Request deletion when the law allows (“right to be forgotten” in everyday terms). (Article 17)
  • Limit how we use data (restriction) — In some cases, ask us to pause or narrow certain processing. (Article 18)
  • Take your data elsewhere (portability) — Receive certain information you gave us in a structured, machine-readable form, where the law allows. (Article 20)
  • Object — Object to some types of processing, including direct marketing. (Article 21)
  • Withdraw consent — If we rely on your consent, you can withdraw it at any time. That does not affect processing that was lawful before you withdrew.
  • Complaint to a regulator — Contact the data protection authority where you live, work, or where you think the issue happened. In the EEA, see the European Data Protection Board list of authorities. In the UK, contact the Information Commissioner’s Office (ICO).
  • Automated decisions — In limited cases, the law gives you rights when decisions with legal or similar effects are made about you using solely automated means (including profiling). (Article 22) For questions of that kind, contact dpo@nex.inc.

What happens when you contact us

We usually do not charge a fee for helping you exercise your rights. If a request is clearly unfounded or excessive (for example, repeated or abusive requests), we may charge a reasonable fee or refuse, as the law allows.

We aim to respond within one calendar month of receiving your request. If your request is unusually complex or you send several at once, we may need up to two extra months. If that happens, we will tell you within the first month and explain why.

We may ask you to confirm your identity first—for example, if the email you use does not match our records or the request is sensitive. You will not be treated worse simply because you used these rights.

Get a copy of your data

To ask for a copy of your personal information, or a digital export when portability applies, email privacy@nex.inc. If you can, send the message from the same email you use with our services—that makes it easier for us to confirm it is you and find your data.

Email privacy@nex.inc

Subject line (Optional): GDPR — Request for copy of personal data / data portability

Please include: Your name, the email tied to your account or service (if any), and which product or service the request is about.

Ask us to delete your data

To ask us to delete personal information we hold about you, email privacy@nex.inc when the law allows. We may need to confirm your identity. Sometimes we must keep certain data (for example for security, fraud prevention, backups, or legal requirements). If so, we will explain why, as described in our Privacy Policy.

Email privacy@nex.inc

Subject line (Optional): GDPR — Request for erasure of personal data

Please include: Your name, the email tied to your account or service, and which product or service the request is about.

Other requests

If you need something other than a copy of your data or deletion, email privacy@nex.inc and explain what you want in plain language. We handle timing, identity checks, and any extensions the same way as in What happens when you contact us.

Examples:

  • Correct wrong or incomplete information.
  • Restrict processing—ask us to limit how we use your data when the law allows.
  • Object to certain processing (including direct marketing).
  • Withdraw consent where we relied on your consent.
  • Any other GDPR request that does not fit the sections above.

For automated decisions with legal or similar effects, contact dpo@nex.inc (see Rights you may have).

Email privacy@nex.inc

Subject line (Optional): GDPR — Data subject request

Please include: What you want us to do, your name, the email tied to your account or service (if any), and which product or service it concerns.

Requests on behalf of a child

If you are a parent or guardian and wish to submit a request on behalf of a child under 13, you may do so using the secure online request form or by emailing privacy@nex.inc. Please state clearly that you are acting as a parent or guardian and include your relationship to the child.

Children aged 13 to 17 may exercise their rights directly, without requiring parental intermediation. We will verify the identity of the requester before responding. We may ask for confirmation of your relationship to the child and will only act on requests we can verify.

EU and UK Representatives

Because NEX Team Inc. is established outside the EU and UK, we are required by Article 27 of the EU GDPR and UK GDPR to appoint a representative in each jurisdiction. Our EU and UK representatives are authorised to receive regulatory correspondence and data subject requests on our behalf. Their contact details will be listed here once the appointments are confirmed. In the meantime, please contact us directly at privacy@nex.inc or dpo@nex.inc.

Postal mail

You can write to us at the address below. Formal GDPR requests are best sent by email so we can log and reply within the usual timelines.

Postal address

NEX Team Inc.

333 W San Carlos St, Suite 600

San Jose, CA 95110

United States

Data outside your country. Information you send us may be stored or processed in the United States and other countries, as explained in our Privacy Policy. Where the law requires it, we use safeguards for data transferred from the EEA or UK.

Organisation responsible for your data (controller): NEX Team Inc.
Most requests (access, deletion, regulatory): privacy@nex.inc
Formal privacy / DPO: dpo@nex.inc
Full privacy policy: nex.inc/content/legal/privacy