Privacy Policy.
This Privacy Policy explains how NexDam ("I", "me", "my") collects, uses, stores and protects personal data when you visit www.nexdam.it, create an account, use the NexDam platform, request technical services, or contact me. NexDam is a software project and technical service operated under the NexDam name. I comply with the EU General Data Protection Regulation (GDPR — Regulation 2016/679) and applicable Italian data protection law.
1. Data Controller
NexDam
Email: contact@nexdam.it
Website: www.nexdam.it
For any privacy-related request you may contact me directly at the address above.
For data relating to NexDam accounts, contact requests, platform usage, monitoring configuration, website analytics strictly necessary for security, and direct communication with NexDam, I act as data controller.
When NexDam processes personal data on behalf of a client as part of technical services, monitoring, maintenance, hosting configuration, project support, or similar activities, the client remains the data controller and NexDam acts as data processor under Art. 28 GDPR, based on a separate agreement, written proposal, or documented instructions.
2. Data I Collect
2.1 Data you provide directly
- Account registration: name, email address, company name, phone number, password (stored as a secure hash).
- Contact form: name, email address, selected service, free-text message.
- Project requests: service type, description, budget range, timeline.
- Reviews: name, company (optional), star rating, review text.
- Client project information: domain names, website URLs, technical requirements, project notes, access details provided by the client, and communication needed to deliver the requested service.
2.2 Data collected automatically
- Authentication tokens: session JWTs issued by Supabase Auth, stored only in your browser's local storage.
- Server logs: IP address, browser type, pages visited, timestamp — retained for security purposes by Vercel and Cloudflare infrastructure.
- Monitoring and health-check data: domain name, URL, public IP address, SSL/TLS status, DNS records, HTTP headers, response time, uptime and downtime events, technical errors, non-invasive scan results, status reports, and generated health reports.
2.3 Data I do NOT collect
- Payment card details (I do not process payments directly).
- Biometric data or sensitive special-category data under Art. 9 GDPR.
- Precise geolocation.
3. Purposes and Legal Basis
- Providing my services (account management, client dashboard, project communication, monitoring, health checks, reports, and technical support) — legal basis: performance of a contract (Art. 6(1)(b) GDPR).
- Responding to enquiries sent via the contact form or other communication channels — legal basis: pre-contractual measures requested by the data subject (Art. 6(1)(b) GDPR) and/or legitimate interest (Art. 6(1)(f) GDPR).
- Sending transactional emails (password reset, project updates, review requests) — legal basis: performance of a contract (Art. 6(1)(b) GDPR).
- Security and fraud prevention (including abuse prevention, account protection, service reliability, and non-invasive technical checks) — legal basis: legitimate interest (Art. 6(1)(f) GDPR).
- Publishing reviews (only after your explicit approval) — legal basis: consent (Art. 6(1)(a) GDPR).
4. Data Retention
- Account data: retained for the duration of your account. Deleted within 30 days of a confirmed account deletion request.
- Contact messages: retained for up to 2 years for business correspondence purposes.
- Project data and files: retained for the duration of the contractual relationship and then for as long as needed to manage support, legal, contractual, administrative, or tax obligations.
- Commercial, contractual, accounting, and tax documentation: retained for the period required by applicable law, generally up to 10 years where necessary.
- Monitoring and health-check data: retained according to the active plan, account settings, or project agreement, unless earlier deletion is requested and legally possible.
- Session tokens: expire automatically as configured in Supabase Auth (default: 1 hour access token, 7 days refresh token).
- Server logs: retained by Vercel/Cloudflare for up to 30 days.
In the event of a personal data breach, NexDam will take reasonable steps to contain and assess the event and, where required by applicable law, notify the relevant controller, affected users, or competent authorities within the deadlines required by the GDPR.
5. Third-Party Processors
I use the following third-party providers and sub-processors where necessary to operate the website, platform, dashboard, authentication, hosting, email delivery, security, and monitoring services. Each provider is subject to its own privacy policy and contractual terms, including data protection terms where applicable:
- Supabase Inc. (USA) — database and authentication. Privacy policy →
- Vercel Inc. (USA) — hosting and serverless functions. Privacy policy →
- Cloudflare Inc. (USA) — CDN, DNS and security. Privacy policy →
- Resend Inc. (USA) — transactional email delivery. Privacy policy →
I do not sell, rent or share your personal data with any third party for marketing purposes.
6. International Data Transfers
Some providers may process data outside the European Economic Area, including in the United States. Where applicable, international transfers are carried out on the basis of adequacy decisions, the EU–US Data Privacy Framework, Standard Contractual Clauses (SCCs), or other safeguards provided by Articles 44 and following of the GDPR.
7. Your Rights Under GDPR
As a data subject you have the following rights, exercisable free of charge by contacting me at contact@nexdam.it:
- Right of access (Art. 15) — obtain a copy of your personal data.
- Right to rectification (Art. 16) — correct inaccurate data.
- Right to erasure (Art. 17) — request deletion ("right to be forgotten").
- Right to restriction (Art. 18) — limit how I process your data.
- Right to data portability (Art. 20) — receive your data in a machine-readable format.
- Right to object (Art. 21) — object to processing based on legitimate interest.
- Right to withdraw consent — at any time, without affecting prior processing.
I will respond within 30 days. You also have the right to lodge a complaint with the Italian supervisory authority: Garante per la protezione dei dati personali — www.garanteprivacy.it.
8. Cookies and Tracking
I use only strictly necessary cookies and browser storage:
- Supabase Auth tokens — stored in
localStorageto maintain your login session. These are not advertising cookies. - Cloudflare — may set a
__cf_bmcookie for bot management. This is a security-essential cookie exempt from consent requirements under ePrivacy rules.
I do not use Google Analytics, Facebook Pixel, or any other third-party tracking or advertising cookies. No cookie banner is shown because no consent-requiring cookies are intentionally set. If this changes in the future, this Policy will be updated and, where required, a consent mechanism will be displayed.
9. Minors
My services are not directed to individuals under the age of 16. I do not knowingly collect personal data from minors. If you believe a minor has provided me with personal data, please contact me and I will delete it promptly.
10. Changes to This Policy
I may update this Privacy Policy to reflect changes in my practices or applicable law. When I do, I will update the "Last updated" date at the top of this page. For material changes I will notify registered users by email.
11. Contact
For any privacy-related question, request or complaint:
NexDam
contact@nexdam.it
www.nexdam.it