Privacy Policy

Protection of your personal data

NexDash Privacy Policy

Last Updated: June 16, 2025

1. Controller and Data Protection Officer

1.1 Data Controller

The data controller responsible for your personal data is:

NexDash Autonomy GmbHKantstr. 3010623 Berlin, GermanyHandelsregister: HRB 277084 B, Amtsgericht CharlottenburgGeschäftsführer: Michael CassauEmail: privacy@nexdash.com

This Privacy Policy explains how we collect, use, disclose, and safeguard personal information when you visit nexdash.com and any sub‑pages (the "Site") in accordance with the EU General Data Protection Regulation (GDPR) and German Federal Data Protection Act (BDSG).

2. Quick‑Read Summary

Topic

What You Need to Know

Data Collected

Minimal: server logs, basic analytics, cookies, and any info you choose to send via email/contact forms.

Legitimate interests (security & analytics); consent (cookies); compliance with law.

Sharing

Only with trusted processors (hosting, analytics, security) under strict contracts.

International Transfers

Protected via Standard Contractual Clauses (SCCs) or adequacy decisions.

Your Rights

GDPR: access, rectify, erase, restrict, object, data portability. CCPA/CPRA: know, delete, correct, opt‑out of "sale/share."

Retention

Logs ≤ 12 months; contact emails ≤ 24 months; analytics data ≤ 26 months.

Security

Industry‑standard encryption in transit & at rest; AWS ISO/IEC 27001 hosting.

Children

Site not directed at <16; we don't knowingly collect their data.

Changes

We'll post any material changes here with a new "Last Updated" date.

3. Information We Collect

3.1 Information You Provide Voluntarily

Email & Correspondence Data – When you email us, request a white‑paper, or otherwise contact NexDash.

3.2 Information Collected Automatically

Server Log Data – IP address, user‑agent string, date/time, referring URL, pages visited, and basic error diagnostics.

Analytics Data – We currently use Plausible Analytics (EU‑hosted) to gather aggregated, non‑personally‑identifiable traffic insights. No profiling or cross‑site tracking.

Cookies & Local Storage – A single, first‑party cookie (_plausible) used for analytics opt‑out/opt‑in, plus a banner consent cookie (nexdash_cookie_consent). No advertising or third‑party cookies.

We do not collect sensitive categories of personal data (e.g., health, biometric, precise geo‑location) or track your activity across other sites.

4. Why We Process Your Information

Purpose

Legal Basis (GDPR art. 6)

Typical Data

Site security, fraud detection

Legitimate interest (recital 49)

IP, user‑agent, log timestamps

Basic aggregated analytics

Consent (ePrivacy/GDPR)

Page‑view events, referrer

Responding to inquiries

Legitimate interest / pre‑contractual steps

Email address, name, content of message

Legal & regulatory compliance

Legal obligation

Any data required under law

5. How We Share Information

We share personal information only as necessary with:

Service Providers / "Processors" – e.g., AWS (hosting), Plausible Analytics, Cloudflare (CDN & security). Contracts include confidentiality, purpose limitation, and SCCs where required.

Professional Advisers – Lawyers, auditors, insurers under duty of confidentiality.

Authorities – When legally compelled (court order, subpoena) or to protect rights, safety, or property.

We never sell or rent personal data.

5.1 Google Analytics 4

This website uses Google Analytics 4, a web analytics service provided by Google Ireland Limited ("Google"). Google Analytics 4 uses cookies, which are text files placed on your computer, to help the website analyze how users use the site. The information generated by the cookie about your use of this website (including your anonymized IP address) will be transmitted to and stored by Google on servers in the United States.

We have configured Google Analytics 4 to ensure a GDPR-compliant operation, specifically by:

IP Anonymization: Your IP address is anonymized by Google Analytics 4 upon collection. This means your full IP address is never stored.

Data Processing Agreement: We have concluded a data processing agreement with Google regarding the use of Google Analytics.

Data Retention: We have set the data retention period for user and event data in Google Analytics to a maximum of 14 months. After this period, the data is automatically deleted.

Purpose of Data Processing:

The purpose of using Google Analytics 4 is to analyze user behavior on our landing page. This allows us to improve the structure and content of our website, making it more user-friendly and effective. We gain insights into, for example, which pages are visited most frequently, how long users stay on a page, and from which regions our visitors come. This data helps us understand the effectiveness of our marketing efforts.

The legal basis for the processing of data using Google Analytics 4 is your explicit consent in accordance with Art. 6 para. 1 lit. a GDPR. We only activate Google Analytics after you have given your consent via our cookie banner.

You can withdraw your consent for Google Analytics tracking at any time by clicking on the "Cookie Settings" button in our privacy section. This will allow you to change your preferences or opt-out of Google Analytics.

Data Transfer to Third Countries (USA):

Please note that Google may process data, including your anonymized IP address, in the United States. The European Court of Justice has determined that the USA does not currently offer an adequate level of data protection comparable to the GDPR. In particular, there is a risk that your data may be subject to access by US authorities for control and monitoring purposes, without effective legal remedies being available to you. By consenting to Google Analytics, you also explicitly consent to this data transfer.

6. International Transfers

Where data moves outside your jurisdiction (e.g., EU→US), we rely on:

EU Standard Contractual Clauses (SCCs) incorporating the 2021 European Commission templates;

Supplementary measures such as at‑rest encryption, strict access controls, and data‑minimization; or

Adequacy decisions where applicable.

7. Data Retention

Data Type

Retention Period

Server logs

12 months (rolled daily)

Analytics events

26 months (Plausible default)

Contact emails

24 months after final correspondence

Legal records

As required by law (typically 7 years for corporate records)

After the retention window, data is deleted or anonymized.

8. Your Privacy Rights

8.1 EU / EEA / UK Residents

Under GDPR, you have the following rights:

  • Right of access (Art. 15 GDPR) - obtain confirmation and information about processing
  • Right to rectification (Art. 16 GDPR) - correct inaccurate personal data
  • Right to erasure (Art. 17 GDPR) - request deletion under certain conditions
  • Right to restriction (Art. 18 GDPR) - limit processing under certain circumstances
  • Right to data portability (Art. 20 GDPR) - receive data in structured format
  • Right to object (Art. 21 GDPR) - object to processing based on legitimate interests
  • Right to withdraw consent (Art. 7(3) GDPR) - where processing is based on consent

To exercise these rights, contact us at privacy@nexdash.com.

Right to Lodge a Complaint

You have the right to lodge a complaint with the competent supervisory authority:

Berlin Commissioner for Data Protection and Freedom of InformationFriedrichstr. 21910969 Berlin, GermanyPhone: +49 30 13889-0Email: mailbox@datenschutz-berlin.deWebsite: www.datenschutz-berlin.de

8.2 California Residents (CCPA/CPRA)

You may request (i) disclosure of personal info categories collected, (ii) deletion, (iii) correction, and (iv) to opt‑out of any "sale" or "sharing." We do not sell personal data in the CCPA sense. Submit requests at privacy@nexdash.com or 1‑844‑NEX‑DASH.

8.3 Other Jurisdictions

Where local law grants additional rights (e.g., Brazil's LGPD, Canada's PIPEDA), we will honor those rights upon request.

9. Security Measures

We implement technical and organizational measures including:

  • TLS 1.3 encryption in transit
  • AES‑256 encryption at rest
  • Principle of least privilege via IAM roles
  • Continuous vulnerability scanning and monthly patch cycles

No system is 100% secure, but we strive to mitigate risk to a commercially reasonable level.

10. Cookies and Tracking Technologies

We use the following types of cookies and similar technologies:

Cookie Type

Purpose

Legal Basis

Duration

Necessary

Cookie consent management, security

Legitimate interest

Session / 1 year

Analytics

Website usage statistics (privacy-focused analytics)

Consent

26 months

Functional

Theme preferences, language settings

Consent

1 year

Marketing

Currently not used

Consent

N/A

You can manage your cookie preferences through our cookie banner or by adjusting your browser settings. Blocking necessary cookies may impact site functionality.

11. Children's Privacy

The Site is not directed to children under 16 years of age. We do not knowingly collect personal information from children under 16. If we become aware that we have collected personal data from a child under 16, we will delete such information promptly. Parents or guardians who believe we may have collected information from a child under 16 should contact us immediately at privacy@nexdash.com.

The Site may link to external websites. We are not responsible for their privacy practices; review their policies separately.

13. Changes to This Policy

We may revise this Privacy Policy from time to time. Material changes will be signaled via banner or updated "Last Updated" date. Continued use of the Site after such changes constitutes acceptance of the revised policy.

14. Contact Information

Data Protection Inquiries

Email: privacy@nexdash.com

Postal Address:

NexDash Autonomy GmbHPrivacy TeamKantstr. 3010623 BerlinGermany

You can change your cookie preferences at any time:

We will respond to privacy-related inquiries within 30 days as required by GDPR Article 12(3).

NEXDASH
© 2026 NexDash. All rights reserved.