Nexos Privacy Policy
This Privacy Policy explains how LUKA BJELICA PR FIDERAIT ZRENJANIN, Pariske komune 28, 23000 Zrenjanin, Republic of Serbia, PIB 115208742 ("Nexos", "we", "us") processes personal data when you use the Nexos platform, websites, dashboard, APIs, CLI tools, and node agent (the "Service"). We are the data controller for the processing described here, and we process personal data in accordance with the EU General Data Protection Regulation ("GDPR") and Serbia's Law on Personal Data Protection ("ZZPL").
Contact for all privacy matters: legal@nexos.rs.
1. Data we collect
Account data
- Username/password sign-up: username, email address, and a bcrypt hash of your password (we never store the password itself).
- GitHub sign-in: your GitHub ID, GitHub username, email address, and avatar URL, as authorized by you on GitHub's consent screen. We also store the GitHub OAuth access token — encrypted with AES-256-GCM — so the Service can clone your repositories, read commit metadata, and post deployment status or PR comments on your behalf.
- Email verification status, team memberships and roles, and your recorded acceptance of our Terms (version and timestamp).
Content you deploy
- Repository contents are fetched from GitHub to build and run your preview environments. Source checkouts and build caches are kept on the nodes that build your projects to speed up subsequent builds.
- Environment variables and secrets you configure are encrypted at rest with AES-256-GCM and decrypted only to inject them into your builds and containers.
- Databases and files inside your preview environments, including any database seeds or backups you upload (stored encrypted).
- You control what personal data, if any, is contained in your repositories and environments; for that data you (or your organization) act as controller and we process it on your instructions.
Usage, billing, and technical data
- Deployment and build history, resource consumption (CPU, memory, build minutes), and quota usage.
- Subscription and payment status. Payments are handled by Paddle as merchant of record — we never receive or store your full card details.
- Server logs (IP address, user agent, timestamps, requested endpoints) and, if you connect your own nodes, node telemetry (hardware capacity, resource usage, agent version).
- Cookies: we use strictly necessary cookies only — an authentication cookie to keep you signed in and a short-lived state cookie during GitHub sign-in. We do not use advertising or third-party analytics cookies, so no cookie consent banner is required.
2. Why we process it (purposes and legal bases)
| Purpose | Legal basis (GDPR Art. 6 / ZZPL) |
|---|---|
| Creating and operating your account; building, deploying, and running your environments; providing support | Performance of a contract (Art. 6(1)(b)) |
| Billing and subscription management | Performance of a contract; legal obligation (Art. 6(1)(b), (c)) |
| Securing the Service: abuse prevention, quota enforcement, incident investigation, logging | Legitimate interests (Art. 6(1)(f)) — keeping the platform and its users safe |
| Service emails (verification, security notices, material changes to terms) | Performance of a contract; legitimate interests |
| Complying with accounting, tax, and other legal duties | Legal obligation (Art. 6(1)(c)) |
| Optional communications, if any | Consent (Art. 6(1)(a)), withdrawable at any time |
3. Distributed infrastructure — where your workloads run
Nexos schedules workloads onto a network of nodes. Shared nodes are operated by Nexos as a global pool. If your project uses the shared pool, your built images, source checkouts, running containers, and environment data are processed on that Nexos-operated infrastructure. Traffic between the control plane and nodes, and between nodes, is encrypted (TLS and WireGuard tunnels); secrets are encrypted at rest and only decrypted for injection into your workloads. If you need workloads to stay on hardware you control, configure your projects to use private nodes that you connect yourself.
Private nodes — reduced processing scope
When a project runs exclusively on private nodes (hardware you own and operate), your source-code checkouts, build caches, built images, running containers, and application databases — including any personal data inside them — are processed and stored on your hardware, not on Nexos infrastructure. In that configuration, the Nexos control plane still processes:
- Account and workspace data — users, emails, team membership, audit logs (Section 1).
- Configuration, including secrets — environment variables and repository access tokens, AES-256-GCM encrypted at rest and decrypted transiently when a deployment is dispatched to your node.
- Deployment metadata — repository and branch names, commit identifiers and messages, changed-file paths, and platform configuration files.
- Build logs — the output of your builds, stored to power the dashboard; you control what your build tooling prints.
- Traffic in transit — preview-URL HTTPS traffic terminates at the Nexos-operated edge before being forwarded to your node over an encrypted tunnel (this includes custom domains routed through the platform).
- Optional uploads and endpoints — database seeds/backups are stored encrypted on the control plane only if you upload them, and external TCP endpoints (
*.tcp.nexos.rs) relay database traffic through Nexos infrastructure only if you create them. Avoid both features if database contents must never reach Nexos infrastructure.
For business customers, our Data Processing Addendum documents this shared-responsibility split, our processor obligations (including notification of personal-data breaches without undue delay and within 72 hours of becoming aware), and the current subprocessor list. Where we process personal data contained in Customer Content on your behalf, we act as your processor and on your instructions.
4. Who we share data with
- GitHub, Inc. — when you sign in with GitHub or connect repositories; GitHub also processes webhook and API traffic about your repositories.
- Paddle.com Market Ltd — our payment provider and merchant of record for subscriptions.
- Contabo GmbH (Germany, EU) — hosts our control plane, database, and edge infrastructure, under a data-processing agreement.
- Zoho Corporation (ZeptoMail) — delivers transactional email (verification, security notices), under a data-processing agreement.
- Authorities — where required by law or to protect rights, safety, or the integrity of the Service.
- In connection with a business transfer (merger, acquisition), with notice to you.
We do not sell personal data and we do not use it for third-party advertising.
5. International transfers
We are based in Serbia, and nodes, subprocessors, and users are located in multiple countries, so personal data may be transferred internationally — including between Serbia, the EU/EEA, and other jurisdictions. Where a transfer requires safeguards under the GDPR or ZZPL, we rely on adequacy decisions where available or on appropriate safeguards such as the European Commission's Standard Contractual Clauses (Serbia's government has likewise adopted standard contractual clauses under the ZZPL).
6. How long we keep data
- Account data: for as long as your account exists, then deleted or anonymized within a reasonable period after account deletion.
- Preview environments, checkouts, build caches: ephemeral by design — removed when environments are destroyed (for example when a branch is deleted), when caches are evicted, or shortly after account closure.
- Billing records: retained for the period required by Serbian accounting and tax law.
- Logs: retained for a limited period for security and troubleshooting, then deleted or aggregated.
- Terms-acceptance records: retained as evidence of the agreement for as long as legally relevant.
7. Security
We apply technical and organizational measures appropriate to the risk, including: TLS for data in transit and WireGuard tunnels between nodes; AES-256-GCM encryption at rest for secrets, OAuth tokens, and uploaded database seeds; bcrypt password hashing; hashed API keys with granular scopes; container isolation with resource limits; role-based access control; and audit logging of administrative actions. No system is perfectly secure; if we learn of a personal-data breach that requires notification, we will notify the competent authority and affected users as required by the GDPR and ZZPL.
8. Your rights
Under the GDPR and the ZZPL you have the right to:
- access the personal data we hold about you, and receive a copy;
- rectify inaccurate data;
- erasure ("right to be forgotten"), where applicable;
- restrict or object to processing, including any processing based on legitimate interests;
- data portability for data you provided to us;
- withdraw consent at any time, where processing is based on consent, without affecting prior processing.
To exercise any right, email legal@nexos.rs. We respond within the statutory deadline (one month under the GDPR, extendable as permitted). You also have the right to lodge a complaint with a supervisory authority — in Serbia, the Commissioner for Information of Public Importance and Personal Data Protection (poverenik.rs); in the EU/EEA, the data protection authority of your country of residence.
9. Children
The Service is not directed to children under 16, and our Terms require users to be at least 16 years old. We do not knowingly collect personal data from children under 16; if you believe a child has created an account, contact us and we will delete it.
10. Changes to this policy
We may update this Privacy Policy from time to time. The version date at the top identifies the current version, which shares a version identifier with our Terms; material changes will be presented for your review in the dashboard and, where appropriate, announced by email.
11. Contact
LUKA BJELICA PR FIDERAIT ZRENJANIN
Pariske komune 28, 23000 Zrenjanin, Republic of Serbia
PIB: 115208742
legal@nexos.rs