Back to Home

GDPR Compliance

Nelix's GDPR compliance and data protection measures for EU users

Effective: January 1, 2025
Last Updated: January 27, 2025

GDPR Compliance & Data Protection

Last Updated: January 27, 2025

Overview

Nelix is fully committed to compliance with the General Data Protection Regulation (GDPR) and protecting the privacy rights of individuals in the European Union (EU) and European Economic Area (EEA).

Our Role Under GDPR

Data Controller

When you use Nelix directly, we act as the Data Controller for your personal data, determining the purposes and means of processing.

Data Processor

For enterprise customers who use our services to analyze documents on behalf of their users, we act as a Data Processor, processing data according to their instructions.

Legal Basis for Processing

We process personal data based on the following legal grounds:

1. Contract Performance

  • Providing our document analysis services
  • Managing your account and subscription
  • Processing payments and billing

2. Legitimate Interests

  • Improving and securing our services
  • Preventing fraud and abuse
  • Analyzing usage patterns for service enhancement

3. Consent

  • Marketing communications
  • Optional features and services
  • Cookie usage for non-essential purposes

4. Legal Obligations

  • Compliance with legal requirements
  • Tax and accounting obligations
  • Responding to lawful requests

Your Rights Under GDPR

As a data subject, you have the following rights:

1. Right to Access (Article 15)

You can request a copy of your personal data we hold, including:

  • Categories of personal data
  • Processing purposes
  • Recipients of your data
  • Retention periods
  • Your rights

How to exercise: Submit a request through your account settings or email privacy@nelix.ai

2. Right to Rectification (Article 16)

You can correct inaccurate or incomplete personal data.

How to exercise: Update information in your account settings or contact support

3. Right to Erasure / "Right to be Forgotten" (Article 17)

You can request deletion of your personal data when:

  • Data is no longer necessary
  • You withdraw consent
  • You object to processing
  • Data was unlawfully processed

How to exercise: Use the "Delete Account" option or email privacy@nelix.ai

4. Right to Restrict Processing (Article 18)

You can limit how we process your data in certain circumstances.

How to exercise: Contact privacy@nelix.ai with your specific request

5. Right to Data Portability (Article 20)

You can receive your data in a structured, commonly used, machine-readable format.

How to exercise: Use the export feature in account settings

6. Right to Object (Article 21)

You can object to processing based on legitimate interests or direct marketing.

How to exercise: Update preferences in account settings or email privacy@nelix.ai

7. Rights Related to Automated Decision-Making (Article 22)

You have rights regarding decisions based solely on automated processing.

Note: Our document analysis involves automated processing, but critical decisions always involve human review.

Data Protection Measures

Technical Measures

  • Encryption: Encryption in transit (TLS) and at rest
  • Pseudonymization: Where possible, data is pseudonymized
  • Access Controls: Strict access control and authentication

Organizational Measures

  • Privacy by Design: Privacy considerations in all new features

Data Processing Details

Categories of Personal Data

Basic Personal Data

  • Name and email address
  • Account credentials
  • Contact information
  • Payment details (tokenized)

Usage Data

  • Service usage patterns
  • Feature preferences
  • Analysis history
  • IP addresses and device information

Document Data

  • Uploaded PDFs (temporary processing only)
  • Analysis results and reports
  • Security findings

Purpose Limitation

We only process data for specified, explicit, and legitimate purposes:

  • Service provision
  • Security and fraud prevention
  • Legal compliance
  • Service improvement (with consent)

Data Minimization

We collect only the minimum data necessary:

  • No unnecessary personal information
  • Automatic data deletion policies

Storage Limitation

  • Personal Data: Retained while account is active
  • Documents: Deleted immediately after analysis
  • Logs: 90-day retention period
  • Backups: 30-day retention with encryption

International Transfers

Data Transfer Mechanisms

When transferring data outside the EEA, we use:

  • Standard Contractual Clauses (SCCs): EU Commission approved clauses
  • Adequacy Decisions: Transfers to countries with adequate protection
  • Supplementary Measures: Additional technical and organizational safeguards

Transfer Safeguards

  • Encryption during transfer
  • Access restrictions
  • Contractual obligations for recipients

Sub-Processors

We use carefully selected sub-processors for specific services:

| Sub-Processor | Service | Location | | ------------------- | --------------------------------------------------------- | ------------------ | | Supabase | Authentication and database | West EU (London) | | Amazon Web Services | Document analysis pipeline (S3, Lambda, SQS, API Gateway) | eu-west-2 (London) | | Cloudflare | Website and application hosting | — | | Paddle.com | Payment processing (Merchant of Record) | — | | Sentry | Error and performance monitoring | — | | Google Analytics | Website analytics | — |

Where a region is listed, our configuration pins that service to it.

Our sub-processors provide data-processing terms as part of their standard service agreements; their documentation is linked from each provider's site.

Data Breach Procedures

Breach Response

In case of a personal data breach:

  1. Detection: Continuous monitoring for breach detection
  2. Assessment: Immediate assessment of impact and risk
  3. Containment: Swift action to contain and remediate
  4. Notification:
    • Supervisory authority: Within 72 hours
    • Affected individuals: Without undue delay (if high risk)
  5. Documentation: Detailed breach documentation
  6. Review: Post-incident review and improvements

Breach Prevention

  • Access controls
  • Encryption

Consent Management

Obtaining Consent

When we rely on consent, we ensure it is:

  • Freely given: No coercion or negative consequences
  • Specific: Clear about what you're consenting to
  • Informed: Full information provided
  • Unambiguous: Clear affirmative action required

Withdrawing Consent

You can withdraw consent at any time:

  • Marketing emails: Unsubscribe link in every email
  • Cookies: Cookie settings in your browser
  • Optional features: Account settings
  • Data processing: Contact privacy@nelix.ai

Children's Privacy

  • Our services are not directed to children under 16
  • We do not knowingly collect data from children
  • If we discover child data, we delete it immediately
  • Parents can contact us about their children's data

Data Protection Officer

Contact DPO: Email: dpo@nelix.ai Post: Data Protection Officer Clouxart LTD (trading as Nelix) 20 Station Road, Cambridge, England, CB1 2JD

Supervisory Authority

EU users have the right to lodge complaints with their local supervisory authority:

Lead Supervisory Authority:
[Relevant EU Country Data Protection Authority]
[Address]
[Contact Information]

You may also contact your local supervisory authority in your country of residence.

Data Processing Agreement (DPA)

For Enterprise Customers

We offer a comprehensive DPA that includes:

  • Detailed processing instructions
  • Security obligations
  • Sub-processor management
  • Audit rights
  • Liability and indemnification

Request DPA: legal@nelix.ai

Key DPA Terms

  • Processing only on documented instructions
  • Confidentiality obligations
  • Security measures implementation
  • Assistance with data subject rights
  • Deletion or return of data

Record of Processing Activities

We maintain detailed records as required by Article 30:

  • Processing purposes
  • Data categories
  • Recipients
  • Transfers
  • Retention periods
  • Security measures

Contact Us

For GDPR-related inquiries:

General Privacy Inquiries:
privacy@nelix.ai

Data Protection Officer:
dpo@nelix.ai

Legal Department:
legal@nelix.ai

Postal Address: Clouxart LTD (trading as Nelix) Attn: Privacy Team 20 Station Road, Cambridge, England, CB1 2JD


This document describes how Nelix handles personal data under the General Data Protection Regulation (EU) 2016/679.