NexFlow
Privacy policy

How we handle the personal data inside your workspace.

Effective: 2026-06-08 · Owner: security@nexflow.run

What NexFlow is, in data terms

For SOC 2 and GDPR purposes NexFlow operates as a data processor acting on behalf of your workspace (the controller). NexFlow does not sell your data, advertise to your end users, train external models on your data, or share your data with other customers. Anthropic zero-data-retention is enabled on the production API key so prompts and completions are not retained on the model vendor side.

What we collect

  • Account data: workspace owner name, work email, optional phone for SMS notifications, and the engagement scope you set during onboarding.
  • Operational data you connect: meeting transcripts, contracts, ticket and PR metadata pulled via the OAuth integrations you authorize.
  • Outputs produced by NexFlow agents: findings, recommendations, draft PRs, draft emails, and other artifacts the fleet creates on your behalf.
  • Operational logs: agent model used, token counts, cost, latency, error rate. We use these to bill accurately and detect abuse.

We do not collect payment card numbers (Stripe handles billing end to end), government-issued identifiers, biometric data, or health data outside of engagements with a signed BAA.

Why we collect it

Lawful basis under GDPR Article 6: contract performance for every piece of processing needed to deliver the audit or doer work you purchased; legitimate interest for operational metrics, cost tracking, and security monitoring; consent for SMS notifications and any transcript ingestion of meetings you did not originally schedule through NexFlow.

How long we keep it

  • Transcripts: 90 days after the engagement ends, or sooner on written request.
  • Audit deliverables: 365 days.
  • Agent run logs and operational ledger entries: 365 days.
  • Contracts and master agreements: held until you ask us to delete.
  • Security events and SLA alerts: 18 months to satisfy SOC 2 lookback windows.

Your rights

Under GDPR and CCPA you can ask us to access, correct, export, or delete your data. Send the request to security@nexflow.run. We respond within 30 days. Requests from end users referenced inside your data are forwarded to you, since you remain the controller.

How we keep it safe

TLS 1.2 or higher in transit, Postgres at-rest encryption on Supabase, row-level security on every public-schema table, MFA on every operator account, and protected branches with required review and green CI on the production code path. The full security posture lives in our SOC 2 documentation.

Breach notification

If a confirmed security incident affects your data we notify you within 72 hours of detection. Supervisory authorities are notified within the same window where EU data subjects are involved. A post-mortem follows within 14 days of containment.

Sub-processors

The current list of sub-processors lives in the data processing addendum. We notify customers at least 30 days before adding a new sub-processor that touches your data.

Contact

Privacy and DPO designate: Arjun Dixit, security@nexflow.run.