← Tillbaka till startsidan
Juridiskt

Integritetspolicy

Senast uppdaterad: 2 oktober 2026

Det här dokumentet finns på engelska; den engelska versionen är bindande.

Innehåll
  1. Who is responsible
  2. Scope of this policy
  3. What data we process, why, and on what legal basis
  4. Cookies and local storage
  5. No analytics, advertising or tracking
  6. Who receives your data
  7. International data transfers
  8. How long we keep your data
  9. Your rights
  10. No automated decisions or profiling
  11. How we protect your data
  12. Children
  13. Client project data
  14. United Kingdom, Switzerland and the wider EEA
  15. Visitors from the United States and other countries
  16. Changes to this policy
  17. Contact

This policy explains how Nexera AI handles personal data when you visit this website, send us an enquiry, request our MVP checklist or order a Code Audit. The short version:

  • We use no cookies, no analytics, no advertising and no tracking pixels.
  • We only receive the details you choose to send us through a form or by email, and we use them to respond to your request.
  • We do not sell your data or share it for advertising.

1. Who is responsible

The controller responsible for processing personal data on this website within the meaning of the EU General Data Protection Regulation (GDPR) is:

Company
NEXERA AI LLC
Address
vul. Volodymyra Ivasiuka, Briukhovychi, Lviv district, Lviv region, Ukraine
Represented by
Stanislav Cheslavskyi (Director)
Email
contact@nexeracode.com

Further provider details are in our Legal notice.

We have not appointed a data protection officer, as we are not required to do so under Art. 37 GDPR. Please send any privacy question to contact@nexeracode.com.

2. Scope of this policy

This policy covers this website, the enquiries you send us through it or by email, and the source code you give us access to for a Code Audit. It does not cover personal data we process on behalf of our clients during a project. That is governed by the client contract and a data processing agreement (see Client project data).

3. What data we process, why, and on what legal basis

a) Visiting the website (server logs). When you open a page, your browser automatically sends technical data to our hosting provider: IP address, date and time of the request, the page requested, the referring page, browser type and version, operating system, response status and amount of data transferred. We need this to deliver the website, keep it stable and secure, and detect and prevent abuse (for example attacks or spam). Legal basis: Art. 6(1)(f) GDPR, our legitimate interest in operating a secure and reliable website. The website cannot be delivered without this data.

b) Contact form and email enquiries. When you send an enquiry, we process the details you enter: your email address, your name (optional), the project type you select, your message (which may include a summary from our estimate calculator, if you choose to send it) and the language of the page you used. A hidden anti-spam field is also submitted; it is empty for human visitors. We use this data to answer your enquiry, prepare a proposal if you ask for one, and correspond with you about it. Legal basis: Art. 6(1)(b) GDPR (steps taken at your request before entering into a contract) where your enquiry concerns a possible project; otherwise Art. 6(1)(f) GDPR, our legitimate interest in responding to business enquiries. The same applies when you email us directly.

c) MVP checklist request. If you request our MVP checklist, we process your email address (and any other details you enter, such as your name) and the page language, to send you the checklist and, where useful, one follow-up message about your request. We do not add you to a newsletter or marketing list without your separate consent. Legal basis: Art. 6(1)(b) GDPR (providing what you asked for) and Art. 6(1)(f) GDPR (a brief follow-up about your request). You can object to any follow-up at any time, for example by replying to our email.

d) Code Audit. If you order a Code Audit under our Prototype & Code Audit Terms, you give us temporary read access to your source code, usually by inviting us to a repository on your git hosting service (for example GitHub, GitLab or Bitbucket). We then process the code and its history, which can contain personal data: names, usernames and email addresses of contributors in commit metadata, and any personal data that happens to be in the code, configuration, test fixtures or sample databases. We use this data only to carry out the audit and write your report. We do not use it to train AI models, and we only analyse it with AI services on enterprise or API plans that exclude training on customer data. Legal basis: Art. 6(1)(b) GDPR (performing the audit contract with you) and, for the personal data of contributors and other people contained in the code, Art. 6(1)(f) GDPR, our legitimate interest in performing the audit you ordered. If your code contains personal data of your own users or customers, you are the controller of that data and we act on your behalf (see Client project data); please avoid giving us access to production data where you can.

e) Estimate calculator and demos. The estimate calculator and the interactive demos run entirely in your browser. Nothing you select there is sent to us unless you include it in a form submission.

Providing your details is neither a legal nor a contractual requirement. However, without a valid email address we cannot reply to you.

4. Cookies and local storage

This website does not set any cookies.

If you actively choose a language, or dismiss the suggestion to view the site in your language, we save that choice in your browser's local storage (key nx-locale, for example the value "de"), so the site remembers it on your next visit. To make that suggestion, the page reads your browser's language setting locally; it is not sent to us. The stored value contains no identifier, is never transmitted to our servers and stays on your device until you delete it in your browser settings.

Because this storage only remembers a setting you chose yourself and is strictly necessary to provide that function, it does not require consent under Art. 5(3) of the ePrivacy Directive (2002/58/EC) and the national laws implementing it (for example §25(2) no. 2 of the German TDDDG). For this reason the website does not show a cookie banner.

5. No analytics, advertising or tracking

We do not use web analytics, advertising networks, tracking pixels, social media plugins, embedded third-party content or any form of cross-site tracking. Our fonts are self-hosted and delivered from our own domain, so your browser does not connect to Google Fonts or other font services.

If we ever introduce any of these tools, we will update this policy before they go live and, where the law requires it, ask for your consent first.

6. Who receives your data

We share personal data only as far as needed for the purposes above:

Service providers (processors). They process data on our behalf, only on our instructions, under data processing agreements in line with Art. 28 GDPR:

  • Cloudflare, Inc.: Website hosting, content delivery and DNS. Processes technical request data (including IP addresses) in server logs. Location: United States, with a global edge network. Safeguard: EU Standard Contractual Clauses and, where the provider is certified, the EU–US Data Privacy Framework.
  • Resend (resend.com): Delivers contact and checklist form submissions to our inbox by email. Location: United States. Safeguard: EU Standard Contractual Clauses and, where the provider is certified, the EU–US Data Privacy Framework.
  • Google LLC (Gmail): Business email account in which we receive, answer and keep enquiries. Location: United States and other countries where Google operates data centres. Safeguard: EU Standard Contractual Clauses and, where the provider is certified, the EU–US Data Privacy Framework.
  • Anthropic PBC (Claude): AI coding assistant used, under commercial terms that exclude model training, to build Clickable Prototypes and to analyse code shared with us for a Code Audit. Location: United States. Safeguard: EU Standard Contractual Clauses and, where the provider is certified, the EU–US Data Privacy Framework.

Code Audit. For a Code Audit we access your code through the git hosting service you choose (for example GitHub, GitLab or Bitbucket). That provider works for you under your own agreement with it; we do not transfer your code to it. To analyse the code we may use AI coding services (for example Anthropic or OpenAI) under enterprise or API terms that exclude training on customer data and commit them to process data only on our instructions.

Our team. Our core team in Ukraine and, where your project requires it, the senior engineers in Poland, Albania and Argentina with whom we work. They see your details only when needed to respond to your request and are bound by confidentiality obligations.

Professional advisers and authorities. Lawyers, accountants and auditors who are bound by professional secrecy, and public authorities where we are legally required to disclose data.

We do not sell personal data and do not share it with anyone for advertising purposes.

7. International data transfers

Some of the recipients above are located outside the European Economic Area (EEA). Our core team works from Ukraine, so your enquiry will be accessed and processed there. When personal data is transferred outside the EEA, we make sure it is protected as follows:

  • Ukraine: no EU adequacy decision exists, so we rely on the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914).
  • Poland: an EU member state; no transfer safeguard is needed.
  • Albania: no EU adequacy decision exists, so we rely on the EU Standard Contractual Clauses.
  • Argentina: covered by an EU adequacy decision (Commission Decision 2003/490/EC).
  • United States (hosting and email delivery providers): the EU–US Data Privacy Framework (Commission adequacy decision of 10 July 2023) where the provider is certified under it, and otherwise the EU Standard Contractual Clauses.

In addition, data is encrypted in transit and access is limited to the people who need it. You can request a copy of the safeguards we use by contacting us.

8. How long we keep your data

  • Server logs: kept by our hosting provider for a short period, generally no longer than 30 days, unless a specific security incident requires us to keep certain entries longer to investigate it.
  • Enquiries that do not lead to a contract: deleted 12 months after our last contact with you, unless you ask us to delete them earlier or we need them to establish, exercise or defend legal claims.
  • Enquiries that lead to a contract: kept for the duration of our business relationship. Correspondence and records we are legally required to keep (for example under commercial and tax law) are kept for the statutory retention period, which is typically 6 to 10 years depending on the applicable law, and then deleted.
  • MVP checklist requests: deleted 12 months after we send the checklist, unless our correspondence turns into an enquiry.
  • Source code for a Code Audit: our copies are deleted, and we stop using our access, within 14 days after we deliver the audit report. Please also revoke our access on your side. The report itself and our correspondence about it are kept like other contract records.
  • Language preference (local storage): stays in your browser until you delete it.

9. Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you (Art. 15 GDPR);
  • have inaccurate data corrected (Art. 16 GDPR);
  • have your data erased (Art. 17 GDPR);
  • restrict processing (Art. 18 GDPR);
  • receive your data in a portable format (data portability, Art. 20 GDPR);
  • withdraw consent at any time with effect for the future, where processing is based on consent (Art. 7(3) GDPR). Currently none of the processing described here relies on consent;
  • lodge a complaint with a supervisory authority, in particular in the country where you live, work or where the alleged infringement took place (Art. 77 GDPR). A list of EEA authorities is available from the European Data Protection Board.

Right to object (Art. 21 GDPR). Where we process your data on the basis of legitimate interests (Art. 6(1)(f) GDPR), you can object at any time on grounds relating to your particular situation. We will then stop, unless we can demonstrate compelling legitimate grounds that override your interests, or the processing is needed to establish, exercise or defend legal claims. You can object to any follow-up or direct marketing at any time, without giving reasons.

To exercise your rights, email contact@nexeracode.com. It is free of charge. We will respond within one month (extendable by two further months for complex requests, in which case we will tell you why), and we may ask you to confirm your identity first.

10. No automated decisions or profiling

We do not make decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you (Art. 22 GDPR). Every enquiry is read and answered by a person. We do not use the content of your enquiries to train AI models.

11. How we protect your data

We use technical and organisational measures appropriate to the risk, including:

  • encrypted connections (HTTPS/TLS) for the whole website and the form submission;
  • access to enquiries limited to the people who need it (least privilege), protected by strong authentication;
  • service providers that encrypt stored data (encryption at rest) and are contractually bound to protect it;
  • confidentiality obligations for everyone who works with us, and deletion in line with the retention periods above.

No method of transmission or storage is completely secure. Please do not send us sensitive personal data (for example health data) or confidential business information through the website forms. If you need to share confidential material, we can sign an NDA first and agree a secure channel.

12. Children

This website is aimed at businesses and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has sent us personal data, please contact us and we will delete it.

13. Client project data

When we build software for a client, we may process personal data on the client's behalf (for example user data in the client's application or test environments). In that case the client is the controller and we act as a processor. That processing is governed by our contract with the client and a data processing agreement under Art. 28 GDPR, not by this policy.

We are happy to sign a data processing agreement, either ours or yours. Contact us at contact@nexeracode.com.

14. United Kingdom, Switzerland and the wider EEA

United Kingdom. If you are in the UK, the UK GDPR and the Data Protection Act 2018 apply, and references to the GDPR in this policy mean the UK GDPR. You have the same rights as described above. Transfers from the UK are protected by the UK International Data Transfer Addendum to the EU Standard Contractual Clauses or the UK International Data Transfer Agreement, or by UK adequacy regulations where they exist. You can complain to the Information Commissioner's Office.

Norway, Iceland and Liechtenstein. The GDPR applies in these EEA countries through the EEA Agreement, so this policy applies in full. In Norway you can complain to Datatilsynet.

Switzerland. If you are in Switzerland, the revised Federal Act on Data Protection (FADP) applies. Transfers are protected by the EU Standard Contractual Clauses with the amendments recognised by the Swiss Federal Data Protection and Information Commissioner (FDPIC). You can complain to the FDPIC.

15. Visitors from the United States and other countries

We apply the standards in this policy to all visitors, wherever they are. We do not sell personal information or share it for cross-context behavioural or targeted advertising, as those terms are used in US state privacy laws. If the privacy laws of your country or state (for example US state laws, Ukraine's Law "On Personal Data Protection", or data protection laws in the Gulf states) give you additional rights, contact us and we will respond as those laws require.

16. Changes to this policy

We will update this policy when our website or our processing changes, for example if we add new tools or service providers. The "Last updated" date at the top shows when it last changed. Where a change requires your consent, we will ask for it before the change takes effect.

17. Contact

For any question about this policy or your data, email contact@nexeracode.com or write to NEXERA AI LLC, vul. Volodymyra Ivasiuka, Briukhovychi, Lviv district, Lviv region, Ukraine.

IntegritetspolicyAnvändarvillkorVillkor för prototyp och kodgranskningJuridisk information
© 2026 Nexera AI · Studio för webb-, app- och AI-utveckling