1. Roles: Data Controller vs. Data Processor
Under the European Union General Data Protection Regulation (EU GDPR), UK GDPR, and Swiss FADP:
- The Subscriber / Business (You): Acts as the Data Controller for all information entered regarding your customers, patients, clients, staff appointments, service pricing, and inventory records. You determine the lawful basis and purposes for processing your customer records.
- Servexa (Nexxel Digital): Acts strictly as the Data Processor. We process your tenant operational data only on your documented instructions and exclusively to deliver the Servexa SaaS services.
- Account & Billing Data: Servexa acts as a Data Controller solely for direct account registration credentials (business owner/staff email addresses, subscription tier, and platform operational logs).
2. Categories of Personal Data We Collect & Process
We process the following categories of data in connection with the platform:
3. Lawful Basis for Processing (GDPR Article 6)
We process personal data only when an authorized legal basis exists:
- Performance of a Contract (Art. 6(1)(b)): Providing core booking scheduling, point-of-sale calculation, inventory movement tracking, and customer management.
- Compliance with Legal Obligations (Art. 6(1)(c)): Retaining transaction and tax receipts for mandatory financial accounting periods.
- Legitimate Business Interests (Art. 6(1)(f)): Maintaining multi-tenant security, preventing malicious cross-tenant penetration, and diagnosing server health.
- Explicit Consent (Art. 6(1)(a)): For optional communication channels where explicit consent has been granted.
4. Cryptographic Multi-Tenancy & Security Measures
Servexa employs a defense-in-depth architectural model engineered to prevent unauthorized access:
- PostgreSQL Row-Level Security (RLS): Every database entity is partitioned by an immutable
tenant_id. Database queries execute with active session tenant constraints, ensuring zero accidental cross-tenant data leak. - Passwordless Zero-Trust Access: All authentication occurs via Google Single Sign-On (OAuth2 OIDC) or cryptographically hashed, rate-limited email one-time passcodes (OTP). Reversible passwords do not exist in our systems.
- Encryption in Transit & at Rest: All traffic is enforced over TLS 1.3 with strict HSTS headers. Persistent database disks and S3-compatible asset buckets use AES-256 encryption at rest.
- Audit Immutability: Hibernate Envers and business activity logs track all sensitive actions (stock adjustments, staff transfers, invoice voids) for non-repudiation.
5. Your Rights as a Data Subject (GDPR Chapter III)
Under GDPR and applicable international data privacy frameworks, you have the right to:
To exercise any of these rights, contact your workspace administrator or email our compliance desk at [email protected]. We respond to all verified requests within thirty (30) calendar days.
6. Sub-processors & Infrastructure Providers
To deliver high-availability cloud services, we partner with vetted infrastructure sub-processors bound by GDPR Data Processing Agreements (DPAs):
| Sub-processor | Role / Service | Data Location |
|---|---|---|
| Google Cloud Platform (GCP) | Container execution & secure backend hosting | United States / EU Regions |
| Cloudflare Inc. | Edge CDN, DDoS mitigation & DNS routing | Global Edge Network |
| PostgreSQL Managed Cloud | Relational multi-tenant database & automated backups | Encrypted SOC 2 Tier-4 Facilities |
7. International Data Transfers
When data is transferred outside the European Economic Area (EEA), we ensure adequate safeguards are in place pursuant to GDPR Chapter V, including the European Commission's Standard Contractual Clauses (SCCs) and supplementary technical encryption standards.
8. Security Breach Notification (GDPR Article 33/34)
In the unlikely event of a confirmed security incident impacting customer personal data, Servexa will notify affected tenant administrators without undue delay and, where feasible, within 72 hours of becoming aware of the breach, providing comprehensive remediation documentation.
9. Contact & Data Protection Officer
For inquiries regarding this Privacy Policy, GDPR compliance, or data subject requests, please contact: