Privacy Policy

Privacy Policy

This Privacy Policy describes how Nexvala processes the personal data of users who visit the website, create an account, use the Nexvala platform or interact with our services. This notice is provided pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR) and applicable data protection legislation.

Information pursuant to Regulation (EU) 2016/679
Last updated: August 14, 2026

Data Controller

The data controller for personal data processed in connection with the website, management of Nexvala accounts, business relationships, support and Nexvala's own activities is the entity that determines the purposes and means of the relevant processing.

Controller:

Nexvala

Registered office:

-

Privacy email:

hello@nexvala.com

Support email:

support@nexvala.com

Data Protection Officer (DPO)

Nexvala has not appointed a Data Protection Officer (DPO), as the legal requirements for such appointment are not met. If appointment becomes necessary in the future or is made voluntarily, the relevant contact details will be indicated in this section.

Scope of application

This Privacy Policy applies to personal data processed through the Nexvala website, pages and online forms, registration and account management, the trial period, the Nexvala SaaS platform, assistance and support services, service-related communications, business relationships and administrative and contractual activities.

For personal data independently entered by customers into the Nexvala platform for their own business purposes, the provisions of the section concerning processing of data on behalf of the customer apply.

Categories of personal data processed

Nexvala processes only the personal data necessary for the purposes described in this Privacy Policy. The categories of data may vary depending on the relationship with the user and the functionalities used.

Identification and professional data

First name, surname, professional role, company affiliation and other professional information that may be provided by the user.

Contact details

Email address, telephone number and other professional contact details provided during registration, the business relationship or support requests.

Account data

Information relating to the Nexvala account, credentials and technical identifiers necessary to authenticate and manage access to the platform.

Organisation-related data

Information relating to the company or organisation associated with the account, including information necessary to configure and administer the relevant company workspace.

Administrative and billing data

Information necessary to manage subscriptions, payments, invoicing and administrative and tax obligations.

Technical and security data

Technical information relating to access to and use of the services, such as IP address, technical identifiers, device information, browser, operating system, security logs and information relating to authentication and access events.

Data contained in support requests

Information that the user chooses to provide when contacting Nexvala for assistance, technical support, commercial information or other communications.

Data entered into the platform

Customers may enter information relating to suppliers, representatives, business contacts, parts, non-conformities, quality activities, documents and other content necessary to manage their business processes.

Special categories of personal data

Nexvala does not require users to enter special categories of personal data within the meaning of Article 9 GDPR as part of the normal functionality of the service. Users and customers must not enter unnecessary personal data into the platform, including special categories of data, unless such processing is lawful and necessary for their own purposes and is carried out in compliance with applicable law.

Purposes of processing

Account creation and management

To create, activate, administer and manage Nexvala accounts, verify user identity and authorisation, and provide access to platform functionalities.

Performance of a contract or taking pre-contractual measures at the request of the data subject.

Provision of the platform

To provide the Nexvala functionalities requested by the user or customer organisation, ensure service availability and manage the functionalities included in the subscribed plan.

Performance of the contract.

Trial period

To allow the user to use the service during the trial period, provide the requested functionalities and manage communications strictly related to the trial.

Performance of pre-contractual measures or the contract, depending on the relationship established.

Assistance and support

To respond to user requests, provide technical assistance, resolve issues and manage service-related communications.

Performance of the contract and, where applicable, the legitimate interest of the controller in managing and improving the service.

Security and abuse prevention

To protect the platform, accounts and infrastructure, prevent unauthorised access, fraud, abuse, harmful activities and security incidents, and ensure system integrity.

Legitimate interest of the controller in the security of its systems and services and, where applicable, compliance with legal obligations.

Administrative and contractual management

To manage subscriptions, orders, payments, invoices, contractual communications and other administrative requirements related to the provision of the service.

Performance of the contract and compliance with legal obligations.

Compliance with legal obligations

To comply with applicable legal obligations, including tax, accounting and administrative requirements and obligations arising from legitimate requests by competent authorities.

Compliance with a legal obligation.

Service improvement

To analyse service performance and reliability, identify technical issues and improve functionality, security and quality of the user experience, in compliance with the principles of data minimisation and purpose limitation.

Legitimate interest of the controller, where applicable.

Commercial communications

To send communications relating to Nexvala products, functionalities, services, initiatives and offers only where an appropriate legal basis exists for such communications. Where required, processing is based on the consent of the data subject.

Consent of the data subject or another legal basis provided by applicable law.

Legal bases for processing

Every processing activity carried out by Nexvala is linked to a specific legal basis provided by Article 6 GDPR. The applicable legal basis depends on the purpose of the processing.

Performance of a contract or taking pre-contractual measures.
Compliance with a legal obligation to which the controller is subject.
Pursuit of a legitimate interest of the controller or a third party, following an assessment balancing such interest against the rights and freedoms of the data subject.
Consent of the data subject, where required by law.
Where processing is based on consent, the data subject may withdraw consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

Provision of data

The provision of data may be necessary to create an account, enter into or perform a contract, provide certain functionalities, process payments or comply with legal obligations. Strictly necessary data are normally indicated in registration forms or the relevant procedures.

Failure to provide necessary data may prevent the creation of an account, conclusion of a contract, use of certain functionalities or provision of the relevant service.

The provision of data used exclusively for optional purposes, such as certain commercial communications, is voluntary and failure to provide such data does not prevent use of the main services.

Data processed on behalf of Nexvala customers

As part of the SaaS platform, a customer organisation may enter and manage personal data relating to its employees, contractors, representatives, suppliers, customers or other persons involved in its business processes.

Where Nexvala processes such data exclusively on behalf of and according to the documented instructions of the customer, the customer acts as the data controller and Nexvala acts as the data processor pursuant to Article 28 GDPR.

The customer determines the purposes and means of processing data entered into its Nexvala environment and remains responsible for verifying the lawfulness of processing, data accuracy, applicable legal bases and compliance with information obligations towards data subjects.

The relationship between Nexvala and the customer as data processor is governed, where applicable, by a Data Processing Agreement (DPA) or provisions concerning the processing of personal data.

Nexvala processes such data exclusively to provide, maintain, protect and support the service in accordance with the contract and the customer's instructions, subject to obligations arising from applicable law.

Recipients of personal data

Personal data may be processed by authorised persons and providers that assist Nexvala in delivering its services. Access to data is limited to the information necessary to perform the respective functions.

Providers of hosting, cloud infrastructure, databases, security and technological services necessary to provide the platform.

Providers of payment services and subscription management where necessary to process transactions and subscriptions.

Providers of email services and transactional communications.

Providers of tools necessary to manage assistance and support requests.

Consultants, professionals and providers of administrative, accounting, legal or technical services where necessary.

Public, judicial or administrative authorities or other parties where disclosure is required by law or by a legitimate order.

Data processors

Nexvala may use external providers that process personal data on behalf of the controller. Such providers are selected taking into account the guarantees they offer regarding data protection and are, where applicable, bound by a contract or other legal act compliant with Article 28 GDPR.

Transfers of personal data outside the European Economic Area

Nexvala favours providers and infrastructures that allow data to be processed within the European Economic Area where compatible with the service requirements. If processing involves the transfer of personal data to a country outside the European Economic Area, the transfer will be carried out in accordance with Chapter V GDPR.

Depending on the specific case, the transfer may be based on an adequacy decision by the European Commission, Standard Contractual Clauses adopted by the European Commission, other safeguards provided by Articles 46 et seq. GDPR or another lawful basis provided by applicable law.

Information concerning the main providers, data locations and safeguards applied to transfers must be kept up to date according to the actual configuration of Nexvala services.

Data retention period

Nexvala retains personal data for no longer than necessary for the purposes for which they were collected, also taking into account applicable contractual, administrative, tax and legal obligations.

Account data are retained for the duration of the contractual relationship and thereafter for the period necessary to manage any legal, accounting or tax obligations or disputes.

Communications and support requests are retained for the time necessary to manage the request and, where necessary, to document the relationship and protect the rights of the controller.

Billing and payment data are retained for the periods required by applicable tax, accounting and civil law requirements.

Security logs and technical information are retained for the period necessary to prevent, detect and manage incidents, abuse and unauthorised access, according to criteria proportionate to the purpose.

Data used for commercial communications are retained until consent is withdrawn or until there is no longer a valid legal basis for the relevant processing, subject to any additional periods necessary for legal obligations or the protection of rights.

Data security

Nexvala adopts technical and organisational measures appropriate to the risk to protect personal data from unauthorised access, loss, destruction, alteration, disclosure or other unlawful processing.

Depending on the service and risk, measures may include:

Access controls and authorisation management.
Authentication mechanisms and account protection.
Encryption of data in transit and, where applicable, at rest.
Monitoring and logging of security-relevant events.
Backup, recovery and business continuity procedures.
Logical separation of customer environments and resources according to the service architecture.
Procedures for managing security incidents and potential personal data breaches.

Personal data breaches

In the event of a personal data breach, Nexvala will apply the procedures required by applicable law and contractual agreements. Where Nexvala acts as a data processor, it will inform the relevant customer without undue delay in accordance with the DPA and applicable law, so that the customer can fulfil its obligations as data controller.

Rights of data subjects

Data subjects may, in the cases provided for by the GDPR, exercise the rights recognised by Articles 15 to 22 of the Regulation.

Right to obtain confirmation as to whether processing is taking place and access to personal data.
Right to obtain rectification of inaccurate personal data and completion of incomplete data.
Right to erasure of personal data in the cases provided for by law.
Right to obtain restriction of processing in the cases provided for by law.
Right to object to processing in the cases provided for by law.
Right to data portability where processing is based on consent or contract and carried out by automated means.
Right to withdraw consent at any time where processing is based on consent.
Right not to be subject to a decision based solely on automated processing, including profiling, where provided for by Article 22 GDPR.

How to exercise your rights

To exercise your rights, you may send a request to privacy@nexvala.com. Where necessary to protect personal data, the request must enable Nexvala to reasonably verify the identity of the requester.

Nexvala will respond to the request without undue delay and, in any event, normally within one month of receipt. This period may be extended by a further two months in the cases provided for by the GDPR, taking into account the complexity and number of requests. In such circumstances, the data subject will be informed of the extension and the reasons for it.

hello@nexvala.com

Right to lodge a complaint

Without prejudice to any other administrative or judicial remedy, a data subject who considers that the processing of their personal data infringes the GDPR has the right to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, place of work or the place where the alleged infringement occurred.

For Italy, the competent supervisory authority is the Garante per la protezione dei dati personali.

Automated decision-making and profiling

Nexvala does not make decisions based solely on automated processing that produce legal effects or similarly significantly affect the data subject within the meaning of Article 22 GDPR.

Any statistical analyses or functions supporting business activities should not be interpreted as automated decision-making processes concerning natural persons, unless specifically indicated otherwise.

Commercial communications

Nexvala may send communications relating to its products and services where it has a valid legal basis to do so. Where processing is based on consent, the user may withdraw consent at any time.

Each direct commercial email, where applicable, will allow the user to easily stop receiving commercial communications.

Where permitted by applicable law, Nexvala may communicate information about similar services or products to its customers on the basis of legitimate interest, in compliance with the applicable conditions and the data subject's right to object.

Cookies and tracking technologies

For specific information about the cookies and other tracking technologies used by the website, their purposes and consent management, please consult Nexvala's Cookie Policy.

Read the Cookie Policy

Children

Nexvala services are primarily intended for professional and business users. Nexvala does not knowingly intend to collect personal data of children for purposes incompatible with the nature of the service. If a parent or guardian believes that a child has provided personal data to Nexvala, they may contact the controller at privacy@nexvala.com.

Source of personal data

Personal data may be collected directly from the data subject, for example during registration, use of the service or a support request, or may be received from the customer organisation as part of the management of its Nexvala environment.

Where data are not collected directly from the data subject, Nexvala processes such data in accordance with the applicable legal basis and the role assumed in the relevant processing. For data processed on behalf of a customer, the customer remains the data controller unless otherwise qualified by applicable law.

Changes to the Privacy Policy

Nexvala may periodically update this Privacy Policy to reflect regulatory, technological, organisational or service-related changes. In the event of significant changes, appropriate measures will be taken to inform data subjects as required by applicable law.

The date of the latest update is indicated at the beginning of this Privacy Policy.

Contact

For questions regarding this Privacy Policy, the processing of personal data or the exercise of GDPR rights, you may contact Nexvala using the contact details below.

Related documents