Your data, your rules.
Native GDPR compliance, sovereign EU hosting, clear legal basis, documented access / erasure / portability rights. No ads, no tracking, no resale.
100% EU
Frankfurt + Paris hosting. No US sub-processor on the data plane. Schrems II compliant.
Zero ads
No tracking cookies, no third-party analytics on the management app. Session cookie only.
Your rights, actually
Signed JSON export, tombstone erasure preserving chain integrity, self-service rectification.
DPA included
Standard EU DPA available on Unlimited and Enterprise. Up-to-date sub-processor list.
What we collect.
Breakdown per user profile and purpose. No hidden collection.
Operators (your team)
- Name, work email
- Hashed password or SSO identity
- RBAC role, organization
- Login IP, login timestamp
Field users
- Name (if provided in invite)
- Email/phone for access link
- Camera, audio, GPS — with on-screen consent
- Hash of IP/user-agent (not raw)
Inspection data
- Photos, annotations, whiteboard exports
- Video recordings (if enabled)
- EU S3 storage with org-prefixed keys
- Audit chain: hashes only
6 rights, all self-service.
Access
Per-user export endpoint. Signed + zipped JSON bundle of all data referencing you.
Erasure
Tombstone pattern: PII fields nulled, audit chain hash preserved to keep legal integrity verifiable.
Rectification
Modify your data via the SPA admin. Members, KYB, identity, preferences.
Portability
Structured JSON export in standard ingest format, importable elsewhere.
Objection
Email privacy@nexbasira.com. Response within 30 days per GDPR article 12.
DPA complaint
Right to file a complaint with your local DPA (CNIL in France, AEPD in Spain, etc.).
Legal basis & retention.
Legal basis (GDPR art. 6)
Retention periods
All sub-processors are EU-based.
Monthly updates. Changes are notified to account admins 30 days in advance.
Data Protection Officer (DPO)
For any question about your personal data, rights or our practices, contact our DPO directly. Reply guaranteed within 30 days.