Summary: NexaCore Industrial AI & Robotics Pvt. Ltd. ("NexaCore", "we", "us", "our") is committed to protecting your personal data. We collect only what is necessary, use it only for stated purposes, do not sell it to third parties, and give you full control over your information. This policy applies to our website nexacore.aisehi.site and all related services.
1. Who We Are
NexaCore Industrial AI & Robotics Pvt. Ltd. is a company incorporated under the Companies Act, 2013, with its registered office at Tech Innovation Park, Tower 3, Bandra Kurla Complex, Mumbai 400 051, Maharashtra, India.
For the purposes of the General Data Protection Regulation (GDPR), the UK GDPR, the India Digital Personal Data Protection Act 2023 (DPDP Act), and other applicable privacy laws, NexaCore is the Data Controller of your personal data collected through this website and our services.
Our Data Protection Officer (DPO) can be contacted at dpo@nexacore.ai.
2. Personal Data We Collect
We collect personal data only when you actively provide it or when it is automatically generated by your use of our website. The categories of data we may collect include:
We do not collect or process any Special Category Data (sensitive personal data such as health, racial or ethnic origin, religious beliefs, biometric data, etc.) through this website. We do not knowingly collect personal data from children under 18.
3. How We Use Your Personal Data
We use the personal data we collect for the following specific purposes:
| Purpose | Data Used | Legal Basis |
|---|---|---|
| Responding to consultation requests & enquiries | Identity, Contact, Enquiry Data | Legitimate Interests / Contract |
| Providing consulting & professional services | Identity, Contact, Project Data | Contract Performance |
| Sending requested information & resources | Identity, Contact Data | Consent |
| Marketing communications (with consent) | Identity, Contact, Preferences | Consent |
| Website analytics & performance monitoring | Technical, Usage, Cookie Data | Legitimate Interests |
| Security, fraud prevention & legal compliance | Technical, Identity Data | Legal Obligation |
| Improving our website & services | Usage, Technical Data | Legitimate Interests |
| Managing business relationships | Identity, Contact, Comms Data | Legitimate Interests / Contract |
4. Legal Basis for Processing
Under GDPR and applicable data protection laws, we rely on the following legal bases for processing your personal data:
-
ConsentWhere you have given clear, informed consent — for example, subscribing to our newsletter or agreeing to non-essential cookies. You may withdraw consent at any time.
-
Contract PerformanceWhere processing is necessary to fulfil a contract with you or to take steps at your request before entering a contract — such as processing a consulting engagement.
-
Legal ObligationWhere we are required to process your data to comply with applicable law, court orders, or regulatory requirements.
-
Legitimate InterestsWhere processing is necessary for our legitimate business interests (such as improving our services, website security, and business development) — provided these interests are not overridden by your rights.
5. Data Sharing & Disclosure
We do not sell, rent, or trade your personal data to any third party for commercial purposes.
We may share your data in the following limited circumstances:
- Service Providers & Data Processors: Trusted third-party vendors who process data on our behalf under strict Data Processing Agreements — including cloud hosting (AWS/Azure), CRM software, email service providers, and analytics platforms.
- Professional Advisers: Lawyers, auditors, and insurers who require access to data to provide their professional services to NexaCore, bound by confidentiality obligations.
- Regulatory & Legal Authorities: Where required by applicable law, court order, or governmental authority — including tax authorities, regulators, and law enforcement agencies.
- Business Transfers: In the event of a merger, acquisition, or sale of assets, your data may be transferred to the relevant party — subject to the same privacy protections described in this policy.
- With Your Consent: Any other sharing not described above will only occur with your explicit, prior consent.
6. International Data Transfers
NexaCore operates globally with offices in India, Germany, Singapore, USA, and UAE. Your personal data may be transferred to and processed in countries other than your country of residence, including countries outside the European Economic Area (EEA).
Whenever we transfer personal data internationally, we ensure appropriate safeguards are in place including:
- → EU Standard Contractual Clauses (SCCs) approved by the European Commission
- → UK International Data Transfer Agreements (IDTAs) where applicable
- → Adequacy decisions by the European Commission for transfers to recognised adequate countries
- → Binding Corporate Rules (BCRs) within the NexaCore group
You may request a copy of the transfer mechanism used for any specific transfer by contacting dpo@nexacore.ai.
7. Data Retention
We retain personal data only for as long as necessary for the purposes for which it was collected, or as required by law. Our standard retention periods are:
When data is no longer required, we ensure it is securely deleted or anonymised in accordance with our Data Destruction Policy.
8. Your Data Protection Rights
Depending on your jurisdiction and the legal basis for processing, you may have the following rights regarding your personal data:
To exercise any of the above rights, please contact us at privacy@nexacore.ai or write to our DPO at the address in Section 14. We will respond within 30 days (or within the timeframe required by applicable law). We may need to verify your identity before processing your request.
10. Data Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, accidental loss, destruction, or damage. These include:
- ✓ TLS/SSL encryption for all data in transit
- ✓ AES-256 encryption for sensitive data at rest
- ✓ Role-based access controls and least-privilege principles
- ✓ Regular security assessments and penetration testing
- ✓ Staff training on data protection and security awareness
- ✓ Data breach response plan with 72-hour notification protocol (GDPR Article 33)
If you believe your data has been compromised, please contact us immediately at security@nexacore.ai.
11. Children's Privacy
Our website and services are directed exclusively to business professionals and are not intended for individuals under the age of 18. We do not knowingly collect personal data from anyone under 18. If you believe we have inadvertently collected data from a minor, please contact us at privacy@nexacore.ai and we will promptly delete it.
12. Third-Party Links
Our website may contain links to third-party websites, partner organisations, and external resources. This Privacy Policy applies only to NexaCore's website and services. We have no control over third-party sites and are not responsible for their privacy practices. We encourage you to review the privacy policy of every website you visit before submitting personal data.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:
- → Update the "Last Updated" date at the top of this policy
- → Post a prominent notice on our website homepage
- → Where required by law, notify you directly by email
Your continued use of our website after any changes constitutes your acceptance of the updated policy. If you do not agree with the revised policy, please discontinue use of our website and contact us to exercise your data rights.
14. Contact Us & Data Protection Officer
For any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact:
Attn: Data Protection Officer
Tech Innovation Park, Tower 3
Bandra Kurla Complex
Mumbai 400 051, India
dpo@nexacore.ai
privacy@nexacore.ai
Industriepark Höchst, Building G830
65926 Frankfurt am Main
Germany
eu-privacy@nexacore.ai
+49 69 1234 5678
You also have the right to lodge a complaint with a supervisory authority. In India: the Data Protection Board of India (DPBI). In the EU: your national Data Protection Authority. In the UK: the Information Commissioner's Office (ICO) at ico.org.uk.