Platform

Integrations

Solutions

Company

Book a demo

Privacy Policy

NEXERA PXM, a trade name of DEED B.V.

Boven de Wolfskuil 20, 6049 LZ Herten, The Netherlands

KVK 73419583

Version 1.6 · Effective 1 August 2026

The short version

We are a Dutch company running a product information platform. We hold two different kinds of personal data, and we hold them in two different capacities.

Data about you as a visitor or customer: your name, work email, phone number, company, billing details, support messages. Here we are the controller. This policy tells you what we do with it.

Data inside your catalog: anything personal that you or your suppliers put into product records, assets or the supplier portal. Here we are the processor. You decide what happens to it; our Data Processing Agreement governs it, not this policy.

We do not sell personal data. We do not run advertising networks on our site. We do not build a marketing profile from your product data.

Most of the platform runs on European infrastructure. The AI features are the exception, and section 8 says exactly where that data goes.

1. Who to contact

DEED B.V., Boven de Wolfskuil 20, 6049 LZ Herten, The Netherlands. KVK 73419583. NEXERA PXM is a registered trade name of DEED B.V.

Privacy questions: privacy@nexerapxm.com

We have not appointed a Data Protection Officer. Our core activities do not consist of large-scale systematic monitoring of data subjects, nor of large-scale processing of special categories of data, so Article 37 GDPR does not require one.

2. What we collect, and why

2.1 When you visit nexerapxm.com

What

Why

Lawful basis

Pages viewed, referrer, approximate country from IP, device and browser type

To understand which pages work and to keep the site up

Legitimate interest in operating and improving our website

Anything you type into a form

To answer you

Legitimate interest, or steps taken at your request before entering a contract

Our website analytics run on software we host ourselves. See section 7.

2.2 When you book a demo

Booking runs through Cal.com. We receive your name, email, the time you chose, and whatever you write in the booking form. The call itself runs on Google Meet. We record calls only when you agree, and we share recordings on request.

Lawful basis: taking steps at your request before entering a contract. For recordings: your consent, which you can withdraw at any time.

2.3 When you hold an account

What

Why

Lawful basis

Name, work email, role, company

To give you an account and apply permissions

Performance of a contract

Phone number

To send one-time codes for two-factor authentication

Performance of a contract; legitimate interest in account security

Authentication data, including hashed tokens and session records

To keep the account secure

Performance of a contract; legitimate interest in security

Billing name, address, VAT number, payment status

To invoice you

Performance of a contract; legal obligation for tax records

Audit log entries recording who did what and when

Security, accountability and dispute resolution

Legitimate interest; often also your own compliance requirement

Support conversations

To help you

Performance of a contract

Usage and AI spend telemetry

To enforce plan limits and bill AI usage correctly

Performance of a contract

Providing the data in the first two rows is a contractual requirement. Without it we cannot give you a working account.

2.4 Where we got your details, if you did not give them to us yourself

Two situations:

  • An administrator at your company created your account. We received your name, work email and role from them, not from you.

  • A customer invited you into their supplier or reseller portal. We received your contact details from that customer. They are the controller for that data and they decide why you are there. We process it to run the portal.

In both cases you have the same rights as anyone else, set out in section 11.

2.5 What we do not collect

We do not collect special categories of personal data about you, and the platform is not designed to hold them. We do not profile you for advertising.

3. Payment data

Payments run through Stripe. Card details go to Stripe directly and never reach our servers. We hold the billing identity, the invoice history and the payment status. We do not hold card numbers.

4. Your catalog content

Product records, assets, brand profiles and supplier submissions are yours. We process them on your instructions, to run the features you use.

That processing includes sending content to AI providers where you use AI features, and to sales channels where you publish. Our Data Processing Agreement sets out the detail: purposes, sub-processors, retention, deletion and the audit clause. Where this policy and the DPA differ on catalog content, the DPA governs.

If your catalog, supplier portal or reseller portal contains personal data, for example a supplier contact name, a photographer credit, or a model’s likeness in an image, you are the controller for it and you decide the lawful basis. We will not use it for anything except providing the service.

5. Who else sees the data

Our sub-processors, and only for what they do:

Sub-processor

What they do

Where

Railway

Application and database hosting

EU region. Railway is a US company; support staff may access infrastructure from outside the EEA under contractual safeguards.

Cloudflare

Object storage (R2) and edge delivery

EU jurisdictional restriction. Cloudflare is a US company; same caveat as above.

Clerk

Authentication and session management

EU region. Clerk is a US company; same caveat as above.

Zavu.dev

Transactional email and SMS delivery, including one-time codes

EU

BetterStack

Application logging and uptime monitoring

EU

Gleap

In-app support chat

EU

Anthropic

AI text generation and enrichment

United States

fal.ai

Background removal and 3D model generation

United States

Shopify

Product sync to your connected stores

Per your store’s region

Stripe

Billing and payments

EU, with global processing by Stripe

Cal.com

Demo booking

EU

Google

Meet, for demo calls

Global

We keep this list versioned and dated at nexerapxm.com/company/security. We give thirty days’ notice before adding a sub-processor that handles personal data.

Transfers outside the EEA. For Anthropic, fal.ai, Google and the US-incorporated infrastructure providers above, we rely on the European Commission’s Standard Contractual Clauses, supplemented where the provider holds a current EU-US Data Privacy Framework certification. We have carried out transfer impact assessments for the AI providers and will share a summary on request.

We also disclose data where the law requires it, and to professional advisers under confidentiality.

6. Marketing and product emails

If you create an account, we send onboarding and product emails about the service you are using. Lawful basis: performance of a contract, and our legitimate interest in helping you get value out of the platform.

If you sign up for our mailing list without becoming a customer, we send it only after you have opted in. Lawful basis: your consent.

Every message has an unsubscribe link, and unsubscribing works immediately. You can also object at any time by writing to privacy@nexerapxm.com. We keep a record of when and how you gave consent, because we have to be able to show it.

We do not buy contact lists and we do not send unsolicited cold outreach.

7. Cookies and analytics

The site sets cookies that are strictly necessary to make it work, including your session and security cookies. Those need no consent, and you cannot turn them off without breaking the site.

For website statistics we run Umami on our own European infrastructure. It sets no cookies, does not track you across sites, does not build a profile, and sends nothing to a third party. We use it to count page views and see which pages work.

We do not run advertising pixels, session recording, or third-party analytics.

If that changes, we will ask for your consent through a banner before anything non-essential loads, and you will be able to withdraw it at any time.

8. Where your data lives

Everything except AI stays in Europe. The application, the database, your assets in object storage, authentication, logs, email and SMS delivery, and support conversations all run in EU regions and are not replicated outside the EU, not for analytics, not for backups, not for support.

AI features are the exception, and we want to be plain about it. When you use text enrichment or translation, the content you send is processed by Anthropic in the United States. When you use background removal or 3D generation, the asset is processed by fal.ai in the United States. Neither provider trains its models on your content, and both transfers run under Standard Contractual Clauses.

If your organisation cannot accept US processing of catalog content, do not enable the AI features, and talk to us. We can discuss EU-resident inference for enterprise agreements.

Several of our EU-hosted providers are US-incorporated companies. Your data is stored and processed in Europe, but their staff may access systems from outside the EEA for support and maintenance under contractual restrictions. That is a smaller exposure than a transfer, but it is not zero, and we would rather say so than imply otherwise.

9. How we protect it

Tenant data is isolated at the database row level. Authentication tokens are hashed and never stored in plaintext, with refresh-token rotation and reuse detection. Shopify access tokens are encrypted at rest. Webhook payloads are verified by HMAC. Every destructive action is written to an audit log, role-based access is enforced at the API layer, and impersonation is always logged.

Our full security posture, including the current sub-processor list, is at nexerapxm.com/company/security.

If something goes wrong, we notify affected tenants without undue delay, and in any event within 72 hours of confirming a material incident, followed by a post-mortem. Where the law requires it, we also notify the Autoriteit Persoonsgegevens.

10. How long we keep things

Data

Retention

Website statistics

12 months

Application and access logs

30 days

Demo booking records

24 months, then deleted

Demo call recordings

12 months, or sooner on request

Account and profile data

For the life of the account

Catalog content after account closure

30 days to export, then a 30-day soft-delete window, then permanent removal. Backups rotate out within a further 30 days.

Audit logs

For the life of the tenant, then deleted with the tenant

Invoices and tax records

7 years, as Dutch law requires

Support conversations

24 months

Marketing consent and unsubscribe records

For as long as we hold the contact, and after that for as long as we need to prove we handled it correctly

You can ask us to delete your content sooner and we will.

11. Automated decision-making

We do not make decisions about you by automated means that produce legal effects or similarly significantly affect you. AI features generate suggested content for your review; a person decides what to publish.

12. Your rights

Under the GDPR you can ask us to:

  • give you a copy of the personal data we hold about you;

  • correct it if it is wrong;

  • delete it;

  • restrict or object to how we use it, including objecting to any processing we base on legitimate interest;

  • give it to you, or to another provider, in a portable format;

  • withdraw consent, where consent is what we relied on. Withdrawing does not affect the lawfulness of what we did before you withdrew.

Write to privacy@nexerapxm.com. We answer within one month. If a request is complex or you have made several, we may extend that by up to two further months, and we will tell you why within the first month. We may ask you to confirm your identity before we act, so that we do not hand your data to someone else. We do not charge for any of this.

If you are unhappy with how we handle it, you can complain to the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl).

If your request is about data inside a customer’s catalog or portal, we will pass it to that customer, because they are the controller and the decision is theirs.

13. Children

NEXERA PXM is a business tool. It is not directed at children and we do not knowingly collect data about them.

14. Changes

We will post any new version here with a new effective date. For material changes affecting account holders we will also email you.