Who we are
NEXVRA provides software engineering services. For the EU and UK GDPR we act as data controller for information collected through this website and our own operations.
Where we build or operate systems for a client and process personal data belonging to that client's users, we act as a processor on their instructions under a separate data processing agreement. That processing is governed by our agreement with that client and by their privacy notice, not this one.
| entity | NEXVRA |
|---|---|
| registered | State of Wyoming, United States |
| address | 30 N Gould St, Ste R, Sheridan, WY 82801, United States |
| privacy | privacy@nexvraw.com |
What we collect
Given directly by you
- Enquiries — name, email, company, optional phone, the service and budget range selected, timeline, and your free-text description. If you send an estimator result, the selections that produced it.
- Engagement records — billing contacts, business address, tax identifiers where legally required, purchase order references, and project correspondence.
- Applications — CV, portfolio links, and anything else you choose to send.
Collected automatically
- Server logs — requesting IP, timestamp, URL, status code, referrer and user-agent, recorded by our host for security and diagnostics.
- No profiling technologies. No advertising trackers, no social pixels, no cross-site analytics. See our Cookie Policy.
What we ask you not to send
Do not send payment card numbers, government identifiers, health data, or production credentials through the contact form or by email. We do not buy marketing lists and we do not build behavioural profiles of visitors.
Why, and on what legal basis
| purpose | data | basis |
|---|---|---|
| Replying to an enquiry, preparing a scope | Enquiry details | Pre-contractual steps at your request — Art. 6(1)(b) |
| Delivering an engagement | Engagement records | Performance of a contract — Art. 6(1)(b) |
| Invoicing and accounting | Billing details | Legal obligation — Art. 6(1)(c) |
| Securing the site, preventing abuse | Server logs, form metadata | Legitimate interests — Art. 6(1)(f) |
| Establishing or defending claims | Relevant records | Legitimate interests — Art. 6(1)(f) |
We do not carry out automated decision-making producing legal or similarly significant effects, and we do not profile.
Who we share it with
We do not sell personal information and do not share it for cross-context behavioural advertising. Sharing is limited to providers needed to run the business, each contractually bound to process only on our instructions:
| category | purpose | data |
|---|---|---|
| Web hosting | Serving this site, receiving form submissions | Server logs, enquiry content |
| Sending and receiving correspondence | Correspondence content | |
| Cloud infrastructure | Development, staging and production environments | Project data as agreed per engagement |
| Accounting | Invoicing, bookkeeping, tax filing | Billing contacts, transactions |
| Payment processors | Card collection where used | Handled by the processor; we never see full card numbers |
| Collaboration tools | Shared channels, issue tracking, code hosting | Names, work emails, project content |
We also disclose where legally compelled — a valid court order, subpoena, or lawful authority request — and where necessary to protect our rights or safety. Where the law permits, we will tell you first.
International transfers
We operate remotely and our providers may process data in the United States and elsewhere. If you are in the EEA, the UK or Switzerland, contacting us involves transferring information outside your jurisdiction.
Where that happens we rely on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable), with supplementary measures including encryption in transit and at rest and least-privilege access. A copy of the relevant mechanism is available at privacy@nexvraw.com.
How long we keep it
| record | retention |
|---|---|
| Enquiries that do not become engagements | 24 months from last contact |
| Client project records and correspondence | Engagement duration + 6 years |
| Invoices and accounting records | 7 years (tax) |
| Web server logs | Up to 12 months |
| Applications | 12 months unless you ask us to keep them longer |
Client-owned data in systems we build is returned or deleted per the engagement terms, normally within 30 days of a written request after handover.
How we protect it
- TLS for all traffic to and from this site
- Encryption at rest for stored project data
- Multi-factor authentication on every account that can reach client systems
- Least-privilege access, reviewed at each milestone and revoked at handover
- Secrets in a managed vault — never in code, config files or chat
- Dependency and vulnerability scanning on everything we ship
No system is perfectly secure and we do not claim otherwise. If a breach occurs that is likely to risk your rights and freedoms, we notify the competent supervisory authority within 72 hours of becoming aware, and affected individuals without undue delay where the risk is high.
Your rights
EEA, UK and Switzerland
You may access the data we hold, have inaccuracies rectified, request erasure where we no longer have grounds to keep it, restrict processing during a dispute, receive your data in a portable format, object to processing based on legitimate interests, and withdraw consent where consent is the basis relied on. You may also complain to your local supervisory authority — though we would appreciate the chance to resolve it first.
California
Under the CCPA as amended by the CPRA you may know what we collect and how it is used and disclosed, request deletion, request correction, and not be discriminated against for exercising these rights. We do not sell or share personal information as the CPRA defines those terms, and have not in the preceding twelve months.
Other US states
Residents of Virginia, Colorado, Connecticut, Utah, Texas and other states with comprehensive privacy laws hold comparable rights, and may appeal a refused request by writing to privacy@nexvraw.com with "Privacy appeal" in the subject.
Making a request
Email privacy@nexvraw.com from the address you contacted us on. We respond within 30 days for GDPR requests and 45 days for US state requests, and will say if we need an extension. No charge unless a request is manifestly unfounded or excessive. We may ask for information to verify identity, used only for that purpose.
Children
Our services are directed at businesses and this site is not intended for anyone under 16. We do not knowingly collect personal information from children. If you believe a child has provided us with data, contact privacy@nexvraw.com and we will delete it promptly.
Changes
We update this policy when practices change or the law requires it. The effective date at the top reflects the current version. Material changes are notified to active clients by email at least 30 days before taking effect.
Contact
Privacy questions, requests and complaints: privacy@nexvraw.com
NEXVRA, 30 N Gould St, Ste R, Sheridan, WY 82801, United States
We acknowledge every privacy enquiry within one business day.
Last updated September 10, 2026. NEXVRA may revise this document; the version at nexvraw.com/privacy/ is always the one in force. Material changes affecting active engagements are notified by email at least 30 days before taking effect.
Questions: legal@nexvraw.com