Client Portal Privacy Policy.
This policy covers the NexDam Client Portal app, used by clients to follow their own projects. The main NexDam Privacy Policy covers the website and the services in general; this one explains what the app does on your device.
The short version. The app shows you the data of the projects you commissioned: progress, messages, files, invoices. It is the same data you see on the website, on a device instead of a browser. No advertising, no analytics, nothing sold or shared for marketing.
1. Who is responsible
NexDam is a personal software project and technical service operated under the NexDam name — not a company. For the data described here I am the data controller under the EU General Data Protection Regulation (Regulation 2016/679).
Email: contact@nexdam.it
Website: www.nexdam.it
Where the material you send me in a project contains personal data of your users or customers, you remain the data controller for that data and I act as processor under Art. 28 GDPR, on the basis of our written agreement.
2. What the app collects
The app has no data of its own: it reads and writes the same account and the same projects as the website. There is no separate portal account.
2.1 Account
- Name, email address, company, phone number — as entered at registration.
- Password — stored only as a secure hash, never in readable form.
- Two-factor codes, if you enabled the second factor. The app never stores the secret in clear text.
2.2 Project data
- Projects: title, description, status, phase, progress, next step, dates.
- Messages exchanged with me about a project, and their timestamps.
- Files uploaded by either side, and their names and sizes.
- Invoices: amount, currency, status, due date, payment date, description.
Invoices record what is owed and whether it was paid. They contain no card numbers and no banking credentials: the app processes no payments.
2.3 Technical data
- Session tokens, kept on the device so you are not asked to sign in at every launch.
- Notification token — see the next section.
- Server logs kept by the providers listed below, for security purposes.
3. Push notifications
So that a new message reaches you even with the app closed, the device registers a notification token issued by Firebase Cloud Messaging, stored alongside your account identifier.
The token identifies the installation, not you: it changes when you reinstall the app and is used only to deliver notifications about your own projects. Denying the notification permission — or signing out — stops it being used; the app keeps working, you simply learn about new messages when you open it.
4. What the app does not collect
- No advertising identifiers, and no advertising.
- No analytics or behavioural-tracking SDK.
- No location.
- No access to contacts, photos, microphone or camera. Files are only those you choose to attach.
- No card details or banking credentials.
- No special-category data under Art. 9 GDPR.
5. Why, and on what legal basis
- Providing the service you commissioned — project tracking, messaging, file exchange, invoice consultation: performance of a contract, Art. 6(1)(b) GDPR.
- Notifying you of news on your projects — performance of a contract, Art. 6(1)(b), limited to the projects that are yours.
- Keeping accounts and data secure — legitimate interest, Art. 6(1)(f).
- Meeting accounting and tax obligations for invoices — legal obligation, Art. 6(1)(c).
6. Who else processes the data
- Supabase — database, authentication and file storage, on EU servers.
- Google Firebase Cloud Messaging — delivery of push notifications, Android and iOS only.
- Vercel and Cloudflare — hosting and protection of the website and its interfaces.
Each acts as processor on documented instructions. Nothing is passed to advertising networks or data brokers, for any reason.
7. How long it is kept
- Account — for as long as it exists.
- Projects, messages, files — for the duration of the working relationship and for the time needed afterwards to defend a legal claim.
- Invoices and accounting records — for the period Italian tax law requires, currently ten years. These cannot be deleted on request before then: a legal obligation prevails over erasure.
- Notification token — until you sign out, uninstall the app, or the token is replaced.
8. Security
Data travels encrypted in transit. Access is protected at database level so each account can read only its own projects, and a second authentication factor is available and recommended.
No system is immune. If a breach occurs that puts your rights at risk, I will notify the supervisory authority within 72 hours and inform you directly, as Articles 33 and 34 GDPR require.
9. Your rights
Access, rectification, erasure, restriction, portability, and objection to processing based on legitimate interest. You may also complain to the Italian Data Protection Authority (Garante per la protezione dei dati personali).
Write to contact@nexdam.it: I reply within one month. Bear in mind the limit above — invoices remain for as long as tax law requires, even after an account is closed.
10. Changes
Changes appear here with a new date, and are announced in the app when they materially affect how your data is handled.
11. Contact
See also: Client Portal Terms of Service · NexDam Privacy Policy · NexDam Terms of Service