Legal
Privacy Policy
Effective date: 25 August 2026
Operated by Nexpher Limited (“Nexpher”, “we”, “us”, or “our”).
This Privacy Policy explains how Nexpher Limited (“Nexpher”, “we”, “us” or “our”) collects, uses, discloses and protects personal data when you use Nexpher AI (the website, applications, APIs, agents, marketplace and related services, collectively the “Service”).
Nexpher AI is a product operated by Nexpher Limited. By using the Service, you acknowledge the practices described here. If you do not agree, please do not use the Service.
1. Data controller
The data controller responsible for personal data processed in connection with the Service is Nexpher Limited. For privacy requests, contact [email protected].
Where we process personal data on behalf of an organisation customer under a separate written agreement, that organisation is the controller and we act as a processor for the scoped processing described in that agreement.
2. Information we collect
We collect information in the following categories:
- Account and identity data: name, email address, password (stored as a salted hash), organisation or team affiliation, and authentication metadata.
- Billing data: subscription plan, token usage, invoices, and payment status. Card details are processed by our payment provider and are not stored in full on our servers.
- Content you provide: conversations, prompts, agent names and descriptions, system instructions, training or fine-tuning materials, files you upload, marketplace listing details, and messages sent through agent APIs you enable.
- Technical and usage data: IP address, device and browser type, approximate location derived from IP, timestamps, request latency, model identifiers, token counts, feature usage, referrer URLs, and diagnostic logs.
- Custom endpoint credentials: if you connect a bring-your-own-model, we store the base URL, model identifier and API credentials you provide in order to route your requests.
- Communications: support tickets, feedback, email correspondence and survey responses.
- Cookies and similar technologies: as described in our Cookie Policy.
3. Sources of information
We collect information directly from you, automatically from your devices when you use the Service, from team administrators who invite you, and from service providers that help us operate the Service (for example payment and analytics providers), where permitted by law.
4. How we use information
We use personal data to:
- Provide, operate, maintain and improve the Service, including generating model responses and persisting your agents and conversations.
- Authenticate users, issue and validate API keys, and secure accounts.
- Enforce plan quotas, process payments, prevent fraud and abuse, and collect debts.
- Provide customer support and respond to enquiries.
- Send transactional notices (security alerts, billing receipts, material policy changes). Marketing emails are sent only where permitted, and you may opt out.
- Monitor performance, debug errors, and develop new features using aggregated or de-identified metrics where practicable.
- Comply with legal obligations, enforce our Terms, and protect the rights, safety and property of Nexpher Limited, our users and the public.
5. Legal bases (EEA/UK and similar regimes)
Where required, we process personal data on the following bases: performance of a contract with you; our legitimate interests in operating a secure, efficient SaaS platform (balanced against your rights); compliance with legal obligations; and consent where we rely on it (for example certain cookies or marketing), which you may withdraw at any time.
6. Model training and your Content
We do not use your Content to train foundation models for unrelated third parties without your instruction or another lawful basis clearly disclosed to you.
When you explicitly initiate training or fine-tuning of an agent, we process the materials you supply for that purpose. Content you submit to third-party or bring-your-own-model endpoints is processed by those providers under their terms.
We may use aggregated, de-identified or anonymised statistics about Service usage to improve reliability and product design.
8. International transfers
We and our processors may process data in jurisdictions outside your country of residence. Where required, we use appropriate safeguards such as standard contractual clauses or equivalent mechanisms recognised by applicable law.
9. Retention
We retain personal data for as long as your account is active and as needed to provide the Service, resolve disputes, enforce agreements, and meet legal, tax and accounting requirements.
You may delete conversations, agents or your account through the product where available, or by contacting [email protected]. Residual copies may persist in encrypted backups for a limited period before deletion in the ordinary course of operations. Inactive anonymous sessions may be purged after prolonged inactivity.
10. Security
We implement technical and organisational measures designed to protect personal data, including encryption in transit (HTTPS/TLS), hashed storage of passwords and API keys where applicable, access controls and monitoring. No method of transmission or storage is completely secure. You are responsible for safeguarding your credentials and for configuring agents and public endpoints appropriately.
Report suspected vulnerabilities to [email protected]. Please do not publicly disclose a vulnerability until we have had a reasonable opportunity to investigate and remediate.
11. Your rights
Depending on your jurisdiction (including under GDPR, UK GDPR, CCPA/CPRA and similar laws), you may have rights to access, correct, delete, restrict or object to certain processing, to data portability, to withdraw consent, and to lodge a complaint with a supervisory authority.
California residents may have rights to know, delete, correct and opt out of certain sharing. We do not sell personal information as “sale” is commonly defined under CCPA. We do not knowingly sell or share the personal information of consumers under 16.
To exercise rights, email [email protected] from the address associated with your account. We may need to verify your identity before fulfilling a request. We will not discriminate against you for exercising privacy rights.
12. Children
The Service is not directed to individuals under 18 (or the higher age of majority where applicable). We do not knowingly collect personal data from children. If you believe a child has provided us data, contact [email protected] and we will take appropriate steps to delete it.
13. Automated decision-making
The Service generates Output using automated systems. We do not use solely automated decision-making that produces legal or similarly significant effects about you without human involvement, except as necessary to enforce quotas, security controls or fraud prevention. You may contact us for more information about such controls.
14. Changes to this Policy
We may update this Privacy Policy from time to time. The effective date at the top of this page will be revised, and material changes will be communicated by reasonable means where required. Continued use of the Service after the effective date constitutes acknowledgement of the updated Policy.
15. Contact
Nexpher Limited — Privacy: [email protected]. Legal: [email protected]. Support: [email protected].
Related policies
These documents are provided for informational and contractual purposes. They do not constitute legal advice. For advice specific to your situation, consult qualified counsel.
