GDPR Compliance
Nelix's GDPR compliance and data protection measures for EU users
GDPR Compliance & Data Protection
Last Updated: January 27, 2025
Overview
Nelix is fully committed to compliance with the General Data Protection Regulation (GDPR) and protecting the privacy rights of individuals in the European Union (EU) and European Economic Area (EEA).
Our Role Under GDPR
Data Controller
When you use Nelix directly, we act as the Data Controller for your personal data, determining the purposes and means of processing.
Data Processor
For enterprise customers who use our services to analyze documents on behalf of their users, we act as a Data Processor, processing data according to their instructions.
Legal Basis for Processing
We process personal data based on the following legal grounds:
1. Contract Performance
- Providing our document analysis services
- Managing your account and subscription
- Processing payments and billing
2. Legitimate Interests
- Improving and securing our services
- Preventing fraud and abuse
- Analyzing usage patterns for service enhancement
3. Consent
- Marketing communications
- Optional features and services
- Cookie usage for non-essential purposes
4. Legal Obligations
- Compliance with legal requirements
- Tax and accounting obligations
- Responding to lawful requests
Your Rights Under GDPR
As a data subject, you have the following rights:
1. Right to Access (Article 15)
You can request a copy of your personal data we hold, including:
- Categories of personal data
- Processing purposes
- Recipients of your data
- Retention periods
- Your rights
How to exercise: Submit a request through your account settings or email privacy@nelix.ai
2. Right to Rectification (Article 16)
You can correct inaccurate or incomplete personal data.
How to exercise: Update information in your account settings or contact support
3. Right to Erasure / "Right to be Forgotten" (Article 17)
You can request deletion of your personal data when:
- Data is no longer necessary
- You withdraw consent
- You object to processing
- Data was unlawfully processed
How to exercise: Use the "Delete Account" option or email privacy@nelix.ai
4. Right to Restrict Processing (Article 18)
You can limit how we process your data in certain circumstances.
How to exercise: Contact privacy@nelix.ai with your specific request
5. Right to Data Portability (Article 20)
You can receive your data in a structured, commonly used, machine-readable format.
How to exercise: Use the export feature in account settings
6. Right to Object (Article 21)
You can object to processing based on legitimate interests or direct marketing.
How to exercise: Update preferences in account settings or email privacy@nelix.ai
7. Rights Related to Automated Decision-Making (Article 22)
You have rights regarding decisions based solely on automated processing.
Note: Our document analysis involves automated processing, but critical decisions always involve human review.
Data Protection Measures
Technical Measures
- Encryption: Encryption in transit (TLS) and at rest
- Pseudonymization: Where possible, data is pseudonymized
- Access Controls: Strict access control and authentication
Organizational Measures
- Privacy by Design: Privacy considerations in all new features
Data Processing Details
Categories of Personal Data
Basic Personal Data
- Name and email address
- Account credentials
- Contact information
- Payment details (tokenized)
Usage Data
- Service usage patterns
- Feature preferences
- Analysis history
- IP addresses and device information
Document Data
- Uploaded PDFs (temporary processing only)
- Analysis results and reports
- Security findings
Purpose Limitation
We only process data for specified, explicit, and legitimate purposes:
- Service provision
- Security and fraud prevention
- Legal compliance
- Service improvement (with consent)
Data Minimization
We collect only the minimum data necessary:
- No unnecessary personal information
- Automatic data deletion policies
Storage Limitation
- Personal Data: Retained while account is active
- Documents: Deleted immediately after analysis
- Logs: 90-day retention period
- Backups: 30-day retention with encryption
International Transfers
Data Transfer Mechanisms
When transferring data outside the EEA, we use:
- Standard Contractual Clauses (SCCs): EU Commission approved clauses
- Adequacy Decisions: Transfers to countries with adequate protection
- Supplementary Measures: Additional technical and organizational safeguards
Transfer Safeguards
- Encryption during transfer
- Access restrictions
- Contractual obligations for recipients
Sub-Processors
We use carefully selected sub-processors for specific services:
| Sub-Processor | Service | Location | | ------------------- | --------------------------------------------------------- | ------------------ | | Supabase | Authentication and database | West EU (London) | | Amazon Web Services | Document analysis pipeline (S3, Lambda, SQS, API Gateway) | eu-west-2 (London) | | Cloudflare | Website and application hosting | — | | Paddle.com | Payment processing (Merchant of Record) | — | | Sentry | Error and performance monitoring | — | | Google Analytics | Website analytics | — |
Where a region is listed, our configuration pins that service to it.
Our sub-processors provide data-processing terms as part of their standard service agreements; their documentation is linked from each provider's site.
Data Breach Procedures
Breach Response
In case of a personal data breach:
- Detection: Continuous monitoring for breach detection
- Assessment: Immediate assessment of impact and risk
- Containment: Swift action to contain and remediate
- Notification:
- Supervisory authority: Within 72 hours
- Affected individuals: Without undue delay (if high risk)
- Documentation: Detailed breach documentation
- Review: Post-incident review and improvements
Breach Prevention
- Access controls
- Encryption
Consent Management
Obtaining Consent
When we rely on consent, we ensure it is:
- Freely given: No coercion or negative consequences
- Specific: Clear about what you're consenting to
- Informed: Full information provided
- Unambiguous: Clear affirmative action required
Withdrawing Consent
You can withdraw consent at any time:
- Marketing emails: Unsubscribe link in every email
- Cookies: Cookie settings in your browser
- Optional features: Account settings
- Data processing: Contact privacy@nelix.ai
Children's Privacy
- Our services are not directed to children under 16
- We do not knowingly collect data from children
- If we discover child data, we delete it immediately
- Parents can contact us about their children's data
Data Protection Officer
Contact DPO: Email: dpo@nelix.ai Post: Data Protection Officer Clouxart LTD (trading as Nelix) 20 Station Road, Cambridge, England, CB1 2JD
Supervisory Authority
EU users have the right to lodge complaints with their local supervisory authority:
Lead Supervisory Authority:
[Relevant EU Country Data Protection Authority]
[Address]
[Contact Information]
You may also contact your local supervisory authority in your country of residence.
Data Processing Agreement (DPA)
For Enterprise Customers
We offer a comprehensive DPA that includes:
- Detailed processing instructions
- Security obligations
- Sub-processor management
- Audit rights
- Liability and indemnification
Request DPA: legal@nelix.ai
Key DPA Terms
- Processing only on documented instructions
- Confidentiality obligations
- Security measures implementation
- Assistance with data subject rights
- Deletion or return of data
Record of Processing Activities
We maintain detailed records as required by Article 30:
- Processing purposes
- Data categories
- Recipients
- Transfers
- Retention periods
- Security measures
Contact Us
For GDPR-related inquiries:
General Privacy Inquiries:
privacy@nelix.ai
Data Protection Officer:
dpo@nelix.ai
Legal Department:
legal@nelix.ai
Postal Address: Clouxart LTD (trading as Nelix) Attn: Privacy Team 20 Station Road, Cambridge, England, CB1 2JD
This document describes how Nelix handles personal data under the General Data Protection Regulation (EU) 2016/679.