1. Scope
This policy applies to Nexora Teams, Event Execution, invitation and claim links, public project pages and support communications. “Nexora”, “we” and “us” refer to the operator of these services.
2. Data we receive
- Account data: name, email address, profile image, sign-in provider, selected role and account identifiers.
- Team workspace data: team membership, tasks, messages, meeting notes, project records, finance entries, mentor feedback, files and links you choose to add.
- Event data: event details, roster fields, team membership, invitations, milestones, readiness records and limited progress indicators.
- Public content: project information a team deliberately publishes on a public page.
- Technical data: basic device, browser, authentication, security and service logs needed to operate and protect Nexora.
- Support data: messages and files you send when asking for help or reporting a problem.
Some event roster data is supplied by an organiser rather than directly by the participant. The organiser is responsible for using an authorised and relevant roster.
3. Why we use data
We use data to create accounts and workspaces, deliver invitations, save team work, operate event programmes, provide support, prevent abuse, diagnose failures and maintain service records. We may also use aggregated or de-identified information to understand whether features work as intended.
Nexora does not sell personal data. We do not use private team content for third-party advertising.
4. Event progress visibility
Event managers receive a limited progress summary. Depending on the event setting, this summary is either required for participating teams or shared only after a team approves it.
5. When data is shared
Google Firebase and Google Cloud support authentication, application hosting, database storage, server functions and security controls. Mailgun supports transactional invitation email. These providers receive only the data needed to perform the relevant service under their service terms.
Google Analytics 4 is enabled by default to measure aggregate use of customer-facing pages. Nexora excludes invitation, claim and secure file-transfer routes, and does not send names, emails, roster data, messages, uploaded files, tokens or private workspace identifiers. Advertising storage, Google Signals and ad personalisation are disabled.
We also share data when you direct us to, when a team publishes a project, with authorised event personnel as described above, during a lawful business transfer, or when disclosure is required to comply with law or protect users and the service.
6. Storage and retention
We retain account, event, roster and claimed workspace records while they are needed to provide Nexora or until an authorised deletion request is completed. Invitation and claim links expire for security, but expiry of a link does not automatically delete the underlying event record. Claimed workspaces remain separately controlled by their members.
Restricted audit, security and deletion records may be kept where necessary to investigate abuse, establish what action occurred, comply with law or resolve a dispute. We minimise or de-identify those records when their identifying detail is no longer needed.
Deletion from active systems may not remove a record immediately from encrypted backups. Backup copies are isolated and expire through the normal backup cycle.
7. Security
Nexora uses access controls, role separation and restricted progress views to reduce unauthorised access. No online service can guarantee absolute security. Report a suspected account or data issue to akshitsingh@tonexora.com.
8. Your choices and requests
You may ask to access, correct or delete personal data associated with you, withdraw consent where processing depends on consent, or raise a grievance. We may need to verify your identity and may retain information where law or a legitimate security need requires it.
Start a request through the data and account deletion page or email akshitsingh@tonexora.com. Teams can also control whether a project page is public and, for voluntary events, whether their redacted progress is shared.
9. Younger users
A person under 18 must not create an account independently. They may use an institution-managed Nexora programme only where the institution has obtained the parent or guardian authorisation required for that participant and has disclosed the roster and progress-sharing process. Nexora does not use private team content for targeted advertising or behavioural monitoring.
10. International processing
Technology providers may process data in locations outside your state or country. Where this happens, we use providers and contractual arrangements intended to protect the information and follow applicable transfer restrictions.
11. Policy changes
We will revise the effective date when this policy changes. If a change materially affects how account or workspace data is used, we will provide notice in the service or through the account email where reasonably possible.