Nexunova RMS ← Back to sign in

Privacy Policy

How Nexunova collects, uses, shares, and protects personal data in the Nexunova RMS platform.
Last updated: 26 May 2026

This Privacy Policy explains how Nexunova ("we", "us") handles personal data when you use Nexunova RMS (the "Service"). It applies to data about our customers' account users (the people who sign in) and to personal data our customers enter about their own clients ("end-customer data"). For end-customer data, our customer is the data controller and Nexunova acts as a data processor on their behalf.

1.Data we collect

  • Account & company data: name, work email, phone, company name, business type, country/city, address, and the username generated for you.
  • Authentication data: hashed passwords (we never store plaintext passwords), login timestamps, failed-attempt counters, session and device metadata (browser, OS, user-agent), and one-time verification codes.
  • End-customer data you enter: client names, CNIC/identity numbers, contact details, payment and installment records, and related documents. You are responsible for the lawful basis to collect this.
  • Usage & technical data: IP address, audit/activity logs, and diagnostic information needed to operate and secure the Service.

2.How we use data

  • To provide, maintain, secure, and support the Service;
  • To authenticate users, prevent fraud and abuse, and enforce tenant isolation;
  • To process subscriptions and communicate service, security, and billing notices;
  • To comply with legal obligations and to establish, exercise, or defend legal claims.

We do not sell personal data, and we do not use end-customer data for advertising.

3.Legal bases

Where data-protection law applies, we rely on: performance of our contract with you; your consent (which you may withdraw); our legitimate interests in operating and securing the Service; and compliance with legal obligations.

4.Sharing & sub-processors

We share data only with service providers that help us run the Service, under appropriate confidentiality and data-protection terms. These include our cloud and database infrastructure provider (Supabase / hosted PostgreSQL) and our transactional email provider for verification and notification messages. We may also disclose data where required by law or to protect rights and safety.

5.Data retention

We retain account and Customer Data for as long as your account is active. Trial data may be deleted approximately 30 days after trial expiry. After account termination we delete or anonymise Customer Data within a reasonable period, except where retention is required by law (for example, financial records) or for legitimate backup cycles.

6.Security

We apply technical and organisational measures including encryption in transit and at rest, hashed passwords, row-level tenant isolation, role-based access control, audit logging, failed-login lockout, session/idle timeouts, and optional admin two-factor authentication. No system is perfectly secure, but we work to protect your data and to notify affected parties of material breaches as required by law.

7.Your rights

Subject to applicable law, you may request to access, correct, export, or delete your personal data, object to or restrict certain processing, and withdraw consent. Account users can exercise many of these directly in-app; for other requests, contact us using the details below. Where Nexunova acts as a processor, requests about end-customer data should be directed to the customer that controls that data.

8.Cookies & local storage

The Service uses browser storage (cookies, localStorage, sessionStorage) strictly to keep you signed in, remember preferences such as theme and session timeout, and operate the application. We do not use third-party advertising or tracking cookies.

9.International transfers

Your data may be processed in data centres located outside your country. Where this occurs, we take steps to ensure an appropriate level of protection consistent with applicable law.

10.Children

The Service is intended for business use and is not directed to children under 18. We do not knowingly collect personal data from children.

11.Changes to this Policy

We may update this Policy from time to time. We will revise the "Last updated" date and, for material changes, provide additional notice in-app or by email.

12.Contact

For privacy questions or to exercise your rights, contact us at support@nexunova.com.

© 2026 Nexunova. All rights reserved.  ·  Terms of Service  ·  Sign in