GDPR & Global Privacy Compliance

Privacy Policy

Effective Date: September 5, 2026. This Privacy Policy governs how Servexa (engineered and operated by Nexxel Digital) processes, protects, and respects personal data across our multi-tenant software-as-a-service platform.

Zero Marketing Abuse

We never sell, rent, monetize, or profile your customers' emails, phones, or addresses for advertising.

PostgreSQL RLS Protected

Defense-in-depth database Row-Level Security ensures tenant records remain strictly isolated.

Guaranteed Right to Erasure

Permanent tenant footprint deletion on demand with zero residual data retention.

1. Roles: Data Controller vs. Data Processor

Under the European Union General Data Protection Regulation (EU GDPR), UK GDPR, and Swiss FADP:

  • The Subscriber / Business (You): Acts as the Data Controller for all information entered regarding your customers, patients, clients, staff appointments, service pricing, and inventory records. You determine the lawful basis and purposes for processing your customer records.
  • Servexa (Nexxel Digital): Acts strictly as the Data Processor. We process your tenant operational data only on your documented instructions and exclusively to deliver the Servexa SaaS services.
  • Account & Billing Data: Servexa acts as a Data Controller solely for direct account registration credentials (business owner/staff email addresses, subscription tier, and platform operational logs).

2. Categories of Personal Data We Collect & Process

We process the following categories of data in connection with the platform:

A. Authentication & User ProfileEmail addresses, display names, OAuth Google identity tokens, one-time login verifications, and assigned tenant roles (Owner, Manager, Staff Specialist). No cleartext passwords are ever collected or stored.
B. Business & Branch ProfilesBusiness names, industry/service verticals, branch physical addresses, business timezones, operating currencies, and branch operational hours.
C. Customer & Booking RecordsCustomer full names, phone numbers, email addresses, booked appointment schedules, practitioner assignments, session notes, and attendance statuses.
D. Financial & Audit LogsInvoices, payment method tokens (cash/card POS tags), immutable stock ledger movements, expense records, IP addresses, and user-agent technical request logs.

3. Lawful Basis for Processing (GDPR Article 6)

We process personal data only when an authorized legal basis exists:

  • Performance of a Contract (Art. 6(1)(b)): Providing core booking scheduling, point-of-sale calculation, inventory movement tracking, and customer management.
  • Compliance with Legal Obligations (Art. 6(1)(c)): Retaining transaction and tax receipts for mandatory financial accounting periods.
  • Legitimate Business Interests (Art. 6(1)(f)): Maintaining multi-tenant security, preventing malicious cross-tenant penetration, and diagnosing server health.
  • Explicit Consent (Art. 6(1)(a)): For optional communication channels where explicit consent has been granted.

4. Cryptographic Multi-Tenancy & Security Measures

Servexa employs a defense-in-depth architectural model engineered to prevent unauthorized access:

  • PostgreSQL Row-Level Security (RLS): Every database entity is partitioned by an immutable tenant_id. Database queries execute with active session tenant constraints, ensuring zero accidental cross-tenant data leak.
  • Passwordless Zero-Trust Access: All authentication occurs via Google Single Sign-On (OAuth2 OIDC) or cryptographically hashed, rate-limited email one-time passcodes (OTP). Reversible passwords do not exist in our systems.
  • Encryption in Transit & at Rest: All traffic is enforced over TLS 1.3 with strict HSTS headers. Persistent database disks and S3-compatible asset buckets use AES-256 encryption at rest.
  • Audit Immutability: Hibernate Envers and business activity logs track all sensitive actions (stock adjustments, staff transfers, invoice voids) for non-repudiation.

5. Your Rights as a Data Subject (GDPR Chapter III)

Under GDPR and applicable international data privacy frameworks, you have the right to:

Right of Access (Art. 15): Request full copies of your personal data processed by our platform.
Right to Rectification (Art. 16): Correct inaccurate or incomplete profile and business settings instantly via your dashboard.
Right to Erasure / "Forgotten" (Art. 17): Request total eradication of your tenant account, client profiles, and historical records.
Right to Data Portability (Art. 20): Export your client directory, appointments, and inventory ledgers in structured formats (CSV/JSON).

To exercise any of these rights, contact your workspace administrator or email our compliance desk at [email protected]. We respond to all verified requests within thirty (30) calendar days.

6. Sub-processors & Infrastructure Providers

To deliver high-availability cloud services, we partner with vetted infrastructure sub-processors bound by GDPR Data Processing Agreements (DPAs):

Sub-processorRole / ServiceData Location
Google Cloud Platform (GCP)Container execution & secure backend hostingUnited States / EU Regions
Cloudflare Inc.Edge CDN, DDoS mitigation & DNS routingGlobal Edge Network
PostgreSQL Managed CloudRelational multi-tenant database & automated backupsEncrypted SOC 2 Tier-4 Facilities

7. International Data Transfers

When data is transferred outside the European Economic Area (EEA), we ensure adequate safeguards are in place pursuant to GDPR Chapter V, including the European Commission's Standard Contractual Clauses (SCCs) and supplementary technical encryption standards.

8. Security Breach Notification (GDPR Article 33/34)

In the unlikely event of a confirmed security incident impacting customer personal data, Servexa will notify affected tenant administrators without undue delay and, where feasible, within 72 hours of becoming aware of the breach, providing comprehensive remediation documentation.

9. Contact & Data Protection Officer

For inquiries regarding this Privacy Policy, GDPR compliance, or data subject requests, please contact:

Servexa Privacy & Data Protection Office
Nexxel Digital Software Engineering Group
© 2026 Servexa by Nexxel Digital. All rights reserved.