Legal

Privacy Policy

We respect your privacy and are committed to protecting your personal data. This policy explains how NexaCore collects, uses, and safeguards your information.

Summary: NexaCore Industrial AI & Robotics Pvt. Ltd. ("NexaCore", "we", "us", "our") is committed to protecting your personal data. We collect only what is necessary, use it only for stated purposes, do not sell it to third parties, and give you full control over your information. This policy applies to our website nexacore.aisehi.site and all related services.

1. Who We Are

NexaCore Industrial AI & Robotics Pvt. Ltd. is a company incorporated under the Companies Act, 2013, with its registered office at Tech Innovation Park, Tower 3, Bandra Kurla Complex, Mumbai 400 051, Maharashtra, India.

For the purposes of the General Data Protection Regulation (GDPR), the UK GDPR, the India Digital Personal Data Protection Act 2023 (DPDP Act), and other applicable privacy laws, NexaCore is the Data Controller of your personal data collected through this website and our services.

Our Data Protection Officer (DPO) can be contacted at dpo@nexacore.ai.

2. Personal Data We Collect

We collect personal data only when you actively provide it or when it is automatically generated by your use of our website. The categories of data we may collect include:

Identity Data
First name, last name, job title, company name, professional role and seniority level.
Contact Data
Business email address, telephone number, company postal address, country/region.
Enquiry & Project Data
Details you provide in our contact form about your automation challenges, project scope, industry, company size, and budget range.
Technical Data
IP address, browser type and version, operating system, device type, time zone, referring URL, pages visited, session duration, and other standard web server log data.
Usage Data
Information about how you use our website — which pages you visit, which links you click, and how you navigate our content.
Cookie Data
Data collected through cookies and similar tracking technologies as described in Section 9 and our Cookie Policy.
Communications Data
Records of correspondence when you contact us by email, phone, or our contact form.
Marketing Preferences
Your preferences regarding receiving marketing communications from us and your consent records.

We do not collect or process any Special Category Data (sensitive personal data such as health, racial or ethnic origin, religious beliefs, biometric data, etc.) through this website. We do not knowingly collect personal data from children under 18.

3. How We Use Your Personal Data

We use the personal data we collect for the following specific purposes:

Purpose Data Used Legal Basis
Responding to consultation requests & enquiries Identity, Contact, Enquiry Data Legitimate Interests / Contract
Providing consulting & professional services Identity, Contact, Project Data Contract Performance
Sending requested information & resources Identity, Contact Data Consent
Marketing communications (with consent) Identity, Contact, Preferences Consent
Website analytics & performance monitoring Technical, Usage, Cookie Data Legitimate Interests
Security, fraud prevention & legal compliance Technical, Identity Data Legal Obligation
Improving our website & services Usage, Technical Data Legitimate Interests
Managing business relationships Identity, Contact, Comms Data Legitimate Interests / Contract

5. Data Sharing & Disclosure

We do not sell, rent, or trade your personal data to any third party for commercial purposes.

We may share your data in the following limited circumstances:

  • Service Providers & Data Processors: Trusted third-party vendors who process data on our behalf under strict Data Processing Agreements — including cloud hosting (AWS/Azure), CRM software, email service providers, and analytics platforms.
  • Professional Advisers: Lawyers, auditors, and insurers who require access to data to provide their professional services to NexaCore, bound by confidentiality obligations.
  • Regulatory & Legal Authorities: Where required by applicable law, court order, or governmental authority — including tax authorities, regulators, and law enforcement agencies.
  • Business Transfers: In the event of a merger, acquisition, or sale of assets, your data may be transferred to the relevant party — subject to the same privacy protections described in this policy.
  • With Your Consent: Any other sharing not described above will only occur with your explicit, prior consent.

6. International Data Transfers

NexaCore operates globally with offices in India, Germany, Singapore, USA, and UAE. Your personal data may be transferred to and processed in countries other than your country of residence, including countries outside the European Economic Area (EEA).

Whenever we transfer personal data internationally, we ensure appropriate safeguards are in place including:

  • EU Standard Contractual Clauses (SCCs) approved by the European Commission
  • UK International Data Transfer Agreements (IDTAs) where applicable
  • Adequacy decisions by the European Commission for transfers to recognised adequate countries
  • Binding Corporate Rules (BCRs) within the NexaCore group

You may request a copy of the transfer mechanism used for any specific transfer by contacting dpo@nexacore.ai.

7. Data Retention

We retain personal data only for as long as necessary for the purposes for which it was collected, or as required by law. Our standard retention periods are:

Contact form & enquiry data
3 years from last contact (or duration of business relationship + 3 years)
Client project data & correspondence
7 years from project completion (for audit and legal purposes)
Marketing consent records
Until consent is withdrawn + 1 year
Website analytics data
26 months (anonymised after 13 months)
Cookie data
Per cookie type — see Cookie Policy
Financial & invoice records
7 years (statutory requirement under Companies Act / GST)
Job applicant data (unsolicited)
6 months

When data is no longer required, we ensure it is securely deleted or anonymised in accordance with our Data Destruction Policy.

8. Your Data Protection Rights

Depending on your jurisdiction and the legal basis for processing, you may have the following rights regarding your personal data:

Right to Access
Request a copy of the personal data we hold about you (Subject Access Request / SAR).
Right to Rectification
Request correction of inaccurate or incomplete personal data we hold about you.
Right to Erasure
Request deletion of your personal data where there is no compelling reason to continue processing ("Right to be Forgotten").
Right to Restrict Processing
Request that we restrict or suspend processing of your personal data in certain circumstances.
Right to Data Portability
Receive your personal data in a structured, machine-readable format and transfer it to another controller.
Right to Object
Object to processing based on legitimate interests or for direct marketing purposes at any time.
Right to Withdraw Consent
Withdraw consent at any time where processing is based on consent — without affecting the lawfulness of prior processing.
Right to Complain
Lodge a complaint with your local supervisory authority (e.g. ICO in UK, CNIL in France, MeitY / DPBI in India).

To exercise any of the above rights, please contact us at privacy@nexacore.ai or write to our DPO at the address in Section 14. We will respond within 30 days (or within the timeframe required by applicable law). We may need to verify your identity before processing your request.

9. Cookies & Tracking Technologies

Our website uses cookies and similar tracking technologies to enhance your experience, analyse site usage, and support our marketing activities. Please refer to our Cookie Policy for full details of the cookies we use, their purposes, durations, and how to manage your preferences.

You can manage or withdraw your cookie consent at any time by clicking "Cookie Settings" in the footer or adjusting your browser settings.

10. Data Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, accidental loss, destruction, or damage. These include:

  • TLS/SSL encryption for all data in transit
  • AES-256 encryption for sensitive data at rest
  • Role-based access controls and least-privilege principles
  • Regular security assessments and penetration testing
  • Staff training on data protection and security awareness
  • Data breach response plan with 72-hour notification protocol (GDPR Article 33)

If you believe your data has been compromised, please contact us immediately at security@nexacore.ai.

11. Children's Privacy

Our website and services are directed exclusively to business professionals and are not intended for individuals under the age of 18. We do not knowingly collect personal data from anyone under 18. If you believe we have inadvertently collected data from a minor, please contact us at privacy@nexacore.ai and we will promptly delete it.

12. Third-Party Links

Our website may contain links to third-party websites, partner organisations, and external resources. This Privacy Policy applies only to NexaCore's website and services. We have no control over third-party sites and are not responsible for their privacy practices. We encourage you to review the privacy policy of every website you visit before submitting personal data.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:

  • Update the "Last Updated" date at the top of this policy
  • Post a prominent notice on our website homepage
  • Where required by law, notify you directly by email

Your continued use of our website after any changes constitutes your acceptance of the updated policy. If you do not agree with the revised policy, please discontinue use of our website and contact us to exercise your data rights.

14. Contact Us & Data Protection Officer

For any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact:

Data Protection Officer
NexaCore Industrial AI & Robotics Pvt. Ltd.
Attn: Data Protection Officer
Tech Innovation Park, Tower 3
Bandra Kurla Complex
Mumbai 400 051, India

dpo@nexacore.ai
privacy@nexacore.ai
EU / UK Representative
NexaCore GmbH
Industriepark Höchst, Building G830
65926 Frankfurt am Main
Germany

eu-privacy@nexacore.ai
+49 69 1234 5678

You also have the right to lodge a complaint with a supervisory authority. In India: the Data Protection Board of India (DPBI). In the EU: your national Data Protection Authority. In the UK: the Information Commissioner's Office (ICO) at ico.org.uk.

NexaCore Industrial AI & Robotics Pvt. Ltd. © 2026