This English version is provided for convenience only. In the event of any discrepancy, the official French PDF prevails.
At Nexte, protecting personal data is a top priority. This policy explains what data is collected, why it is processed, which security measures are in place and which rights users may exercise.
1. Data controller
2. Data collected
- Account data such as name, email address and profile photo
- Project data such as clients, milestones, documents and invoices
- Messages exchanged through the client space
- Files uploaded by users and their clients
- Customization data such as logos and colors
No unnecessary or excessive data is collected and Nexte does not carry out commercial profiling.
3. Purposes and legal basis
- Performance of the contract, including operation of the service and management of projects, clients, documents and invoices
- Legitimate interest, including service improvement, platform security and fraud prevention
- Legal obligation, including retention of accounting records
4. Hosting and security
Data is hosted through Supabase. Security measures include encryption in transit and at rest, row level access controls, secure authentication tokens, protected client links, access logging, anomaly monitoring and automatic backups.
If a personal data breach is likely to create a risk to users' rights and freedoms, Nexte undertakes to notify the CNIL within 72 hours and to inform affected users without undue delay.
5. Data sharing and processors
Data is never sold, rented or transferred for commercial purposes. It may only be accessed by the user, the user's clients through secure links, and technical processors acting on Nexte's behalf under GDPR compliant contractual safeguards.
6. Transfers outside the European Union
If data were ever transferred outside the European Economic Area, Nexte would ensure that appropriate safeguards are in place, such as standard contractual clauses approved by the European Commission.
7. Retention period
- Account data is kept for the life of the account and deleted within 30 days after closure
- Documents and invoices are retained for 10 years to comply with accounting obligations
- Security logs are retained for up to 12 months
- Client space data may be deleted at the user's request or when the account is closed
8. Your rights
Users may exercise rights of access, rectification, erasure, restriction, portability, objection and protection against solely automated decisions by contacting contact@getnexte.com. If a dispute remains unresolved, a complaint may be lodged with the CNIL.
9. Cookies and trackers
Nexte uses only technical cookies that are strictly necessary for the operation of the application. No advertising or third party tracking cookies are set and no commercial behavioral analytics tool is used.
10. Changes to this policy
Nexte may amend this policy at any time. In the event of a substantial change, users will be informed by email or through an in app notice at least 15 days before the new provisions take effect. Continued use of the service constitutes acceptance of the updated policy.
This page is an English translation provided for convenience. In case of doubt or discrepancy, the downloadable French PDF prevails.
