1. Introduction
Welcome to Nexana (hereafter "Nexana", "we", "us", or "our"), a full-stack project management platform designed to help teams organize, track, and streamline their development, management, marketing, sales, and support projects.
We are committed to protecting your privacy and ensuring a secure user experience. This Privacy Policy describes how we collect, use, store, share, and protect your information when you access or use our platform, including our website and any connected third-party integrations (such as Google, Microsoft, and Zoom).
The party responsible for the processing of personal data (the "controller") on this platform is:
NexPatch AI UG
Represented by: Fabian Franz
Neumarkt 31
04109 Leipzig
Germany
Phone: +49 341-97856921
Email: info@nexpatch.ai
The controller's appointed Data Protection Officer is:
Philip Foitzik
Phone: +49 341-97856922
Email: phil@nexpatch.ai
By accessing or using Nexana, you agree to the collection and use of information in accordance with this policy. If you do not agree with the terms outlined here, please do not use our services.
2. Information We Collect
To provide our project management features, Nexana collects data from different sources:
- Account Registration Information: When you sign up, we collect your email address, full name, and hashed passwords.
- User Content: We store the information you create within Nexana, including spaces, portfolios, projects, tasks, Kanban boards, list items, files, comments, documents, and chat records.
- Connected Account Integrations: If you link third-party services like Google, Microsoft (M365), Zoom, or GitHub to your profile, we collect and store authorization credentials (OAuth tokens) required to interact with their APIs on your behalf.
- System and Diagnostic Logs: We collect request IP addresses, error logs, and system analytics to optimize performance, prevent server abuse, and troubleshoot technical bugs.
3. Google API Data Usage & Scopes
Nexana offers integrations with Google services to consolidate your workflow. By authorizing Google OAuth, you grant Nexana permission to interact with your Google Account for the specific features listed below:
Requested Scopes & Functionality:
Google Drive API
Allows you to select files from your Google Drive and attach them directly to tasks, comments, and project documents. The app reads file metadata (names, paths, sizes) and creates/updates attachments within your workspace. We only access specific files you explicitly select or upload; we never index your entire Drive.
Google Calendar API
Syncs your Nexana task deadlines and meeting bookings with your Google Calendar. This scope enables Nexana to view, create, edit, or delete events on your behalf. Nexana only modifies calendar events related to bookings and tasks that you manage inside our application.
Google User Profile Info
Reads your primary email address to authenticate the integration and ensure that Google tokens are tied correctly and securely to your Nexana user profile.
Nexana only retrieves and transmits data from these scopes to provide the specific services you have initiated. We do not use these permissions to gather general diagnostic or advertising information.
4. Google API Limited Use Compliance
"Nexana's use and transfer of information received from Google APIs to any other app will adhere to Google API Services User Data Policy, including the Limited Use requirements."
To clarify how we respect and safeguard the data received under the Google API Scopes, we enforce the following rules:
- We do not use your Google User Data to show you advertisements.
- We do not sell, transfer, or share your Google User Data with third parties (such as data brokers, ad networks, or third-party marketing services) under any circumstances.
- We do not use or transfer your Google User Data for the purpose of training generalized artificial intelligence (AI) or machine learning models. If you explicitly use our built-in AI Chat companion to ask questions about your tasks or calendar, the specific context is processed securely and is never stored, retained, or utilized by external AI models to train their base weights.
- Human employees of Nexana are strictly prohibited from viewing your Google User Data. We may access user content only if you request specific support and provide explicit, time-limited permission to troubleshoot your individual account.
5. Data Sharing & Third-Party Services
We only share your information with trusted service providers (subprocessors) that are required to run Nexana:
- Database and Infrastructure Providers: Our cloud hosting providers secure our databases and file systems.
- SMTP Email Delivery Services: Outbound emails (like invite notifications, sign-up confirmations, and password resets) are routed through secure SMTP channels.
- Web Real-Time Communication Services: Real-time operations (such as multi-user task updates and meetings) use secure webhooks and signaling tunnels.
All our subprocessors are legally and contractually bound to process your data only in accordance with our instructions and in compliance with general data protection standards (such as GDPR where applicable).
6. Data Security & Retention
We implement robust technical and organizational security measures to protect your information:
- Data Encryption: All information is encrypted during transit using standard Transport Layer Security (TLS/SSL). Sensitive credentials, API keys, and third-party OAuth access tokens are encrypted at-rest using secure cryptographic algorithms.
- Access Control: System administrative access is restricted to authorized personnel who need the information to perform support operations.
- Data Retention: We store your personal information and user content for as long as your account remains active. If you close your account, we delete or anonymize your personal data and project records within 30 days, unless legally required to retain it.
7. Your Rights & Data Deletion
You retain full control over your data. Depending on your jurisdiction, you may have the right to access, correct, export, or delete the personal data we hold about you.
You can exercise control over your connected accounts directly through the application:
- Disconnecting Integrations: You can navigate to your Account Settings panel and disconnect Google, Microsoft, or Zoom integrations. This action immediately deletes all corresponding OAuth tokens and access profiles from our database and prevents any further API requests.
- Account Deletion: You can initiate a complete account deletion request. Upon confirmation, all your profile data, project structures, and connected credentials will be permanently erased.
For any help regarding data export, deletion, or privacy inquiries, contact us at: info@nexpatch.ai.