Privacy Policy
NEXERA PXM, a trade name of DEED B.V.
Boven de Wolfskuil 20, 6049 LZ Herten, The Netherlands
KVK 73419583
Version 1.6 · Effective 1 August 2026
The short version
We are a Dutch company running a product information platform. We hold two different kinds of personal data, and we hold them in two different capacities.
Data about you as a visitor or customer: your name, work email, phone number, company, billing details, support messages. Here we are the controller. This policy tells you what we do with it.
Data inside your catalog: anything personal that you or your suppliers put into product records, assets or the supplier portal. Here we are the processor. You decide what happens to it; our Data Processing Agreement governs it, not this policy.
We do not sell personal data. We do not run advertising networks on our site. We do not build a marketing profile from your product data.
Most of the platform runs on European infrastructure. The AI features are the exception, and section 8 says exactly where that data goes.
1. Who to contact
DEED B.V., Boven de Wolfskuil 20, 6049 LZ Herten, The Netherlands. KVK 73419583. NEXERA PXM is a registered trade name of DEED B.V.
Privacy questions: privacy@nexerapxm.com
We have not appointed a Data Protection Officer. Our core activities do not consist of large-scale systematic monitoring of data subjects, nor of large-scale processing of special categories of data, so Article 37 GDPR does not require one.
2. What we collect, and why
2.1 When you visit nexerapxm.com
What
Why
Lawful basis
Pages viewed, referrer, approximate country from IP, device and browser type
To understand which pages work and to keep the site up
Legitimate interest in operating and improving our website
Anything you type into a form
To answer you
Legitimate interest, or steps taken at your request before entering a contract
Our website analytics run on software we host ourselves. See section 7.
2.2 When you book a demo
Booking runs through Cal.com. We receive your name, email, the time you chose, and whatever you write in the booking form. The call itself runs on Google Meet. We record calls only when you agree, and we share recordings on request.
Lawful basis: taking steps at your request before entering a contract. For recordings: your consent, which you can withdraw at any time.
2.3 When you hold an account
What
Why
Lawful basis
Name, work email, role, company
To give you an account and apply permissions
Performance of a contract
Phone number
To send one-time codes for two-factor authentication
Performance of a contract; legitimate interest in account security
Authentication data, including hashed tokens and session records
To keep the account secure
Performance of a contract; legitimate interest in security
Billing name, address, VAT number, payment status
To invoice you
Performance of a contract; legal obligation for tax records
Audit log entries recording who did what and when
Security, accountability and dispute resolution
Legitimate interest; often also your own compliance requirement
Support conversations
To help you
Performance of a contract
Usage and AI spend telemetry
To enforce plan limits and bill AI usage correctly
Performance of a contract
Providing the data in the first two rows is a contractual requirement. Without it we cannot give you a working account.
2.4 Where we got your details, if you did not give them to us yourself
Two situations:
An administrator at your company created your account. We received your name, work email and role from them, not from you.
A customer invited you into their supplier or reseller portal. We received your contact details from that customer. They are the controller for that data and they decide why you are there. We process it to run the portal.
In both cases you have the same rights as anyone else, set out in section 11.
2.5 What we do not collect
We do not collect special categories of personal data about you, and the platform is not designed to hold them. We do not profile you for advertising.
3. Payment data
Payments run through Stripe. Card details go to Stripe directly and never reach our servers. We hold the billing identity, the invoice history and the payment status. We do not hold card numbers.
4. Your catalog content
Product records, assets, brand profiles and supplier submissions are yours. We process them on your instructions, to run the features you use.
That processing includes sending content to AI providers where you use AI features, and to sales channels where you publish. Our Data Processing Agreement sets out the detail: purposes, sub-processors, retention, deletion and the audit clause. Where this policy and the DPA differ on catalog content, the DPA governs.
If your catalog, supplier portal or reseller portal contains personal data, for example a supplier contact name, a photographer credit, or a model’s likeness in an image, you are the controller for it and you decide the lawful basis. We will not use it for anything except providing the service.
5. Who else sees the data
Our sub-processors, and only for what they do:
Sub-processor
What they do
Where
Railway
Application and database hosting
EU region. Railway is a US company; support staff may access infrastructure from outside the EEA under contractual safeguards.
Cloudflare
Object storage (R2) and edge delivery
EU jurisdictional restriction. Cloudflare is a US company; same caveat as above.
Clerk
Authentication and session management
EU region. Clerk is a US company; same caveat as above.
Zavu.dev
Transactional email and SMS delivery, including one-time codes
EU
BetterStack
Application logging and uptime monitoring
EU
Gleap
In-app support chat
EU
Anthropic
AI text generation and enrichment
United States
fal.ai
Background removal and 3D model generation
United States
Shopify
Product sync to your connected stores
Per your store’s region
Stripe
Billing and payments
EU, with global processing by Stripe
Cal.com
Demo booking
EU
Meet, for demo calls
Global
We keep this list versioned and dated at nexerapxm.com/company/security. We give thirty days’ notice before adding a sub-processor that handles personal data.
Transfers outside the EEA. For Anthropic, fal.ai, Google and the US-incorporated infrastructure providers above, we rely on the European Commission’s Standard Contractual Clauses, supplemented where the provider holds a current EU-US Data Privacy Framework certification. We have carried out transfer impact assessments for the AI providers and will share a summary on request.
We also disclose data where the law requires it, and to professional advisers under confidentiality.
6. Marketing and product emails
If you create an account, we send onboarding and product emails about the service you are using. Lawful basis: performance of a contract, and our legitimate interest in helping you get value out of the platform.
If you sign up for our mailing list without becoming a customer, we send it only after you have opted in. Lawful basis: your consent.
Every message has an unsubscribe link, and unsubscribing works immediately. You can also object at any time by writing to privacy@nexerapxm.com. We keep a record of when and how you gave consent, because we have to be able to show it.
We do not buy contact lists and we do not send unsolicited cold outreach.
7. Cookies and analytics
The site sets cookies that are strictly necessary to make it work, including your session and security cookies. Those need no consent, and you cannot turn them off without breaking the site.
For website statistics we run Umami on our own European infrastructure. It sets no cookies, does not track you across sites, does not build a profile, and sends nothing to a third party. We use it to count page views and see which pages work.
We do not run advertising pixels, session recording, or third-party analytics.
If that changes, we will ask for your consent through a banner before anything non-essential loads, and you will be able to withdraw it at any time.
8. Where your data lives
Everything except AI stays in Europe. The application, the database, your assets in object storage, authentication, logs, email and SMS delivery, and support conversations all run in EU regions and are not replicated outside the EU, not for analytics, not for backups, not for support.
AI features are the exception, and we want to be plain about it. When you use text enrichment or translation, the content you send is processed by Anthropic in the United States. When you use background removal or 3D generation, the asset is processed by fal.ai in the United States. Neither provider trains its models on your content, and both transfers run under Standard Contractual Clauses.
If your organisation cannot accept US processing of catalog content, do not enable the AI features, and talk to us. We can discuss EU-resident inference for enterprise agreements.
Several of our EU-hosted providers are US-incorporated companies. Your data is stored and processed in Europe, but their staff may access systems from outside the EEA for support and maintenance under contractual restrictions. That is a smaller exposure than a transfer, but it is not zero, and we would rather say so than imply otherwise.
9. How we protect it
Tenant data is isolated at the database row level. Authentication tokens are hashed and never stored in plaintext, with refresh-token rotation and reuse detection. Shopify access tokens are encrypted at rest. Webhook payloads are verified by HMAC. Every destructive action is written to an audit log, role-based access is enforced at the API layer, and impersonation is always logged.
Our full security posture, including the current sub-processor list, is at nexerapxm.com/company/security.
If something goes wrong, we notify affected tenants without undue delay, and in any event within 72 hours of confirming a material incident, followed by a post-mortem. Where the law requires it, we also notify the Autoriteit Persoonsgegevens.
10. How long we keep things
Data
Retention
Website statistics
12 months
Application and access logs
30 days
Demo booking records
24 months, then deleted
Demo call recordings
12 months, or sooner on request
Account and profile data
For the life of the account
Catalog content after account closure
30 days to export, then a 30-day soft-delete window, then permanent removal. Backups rotate out within a further 30 days.
Audit logs
For the life of the tenant, then deleted with the tenant
Invoices and tax records
7 years, as Dutch law requires
Support conversations
24 months
Marketing consent and unsubscribe records
For as long as we hold the contact, and after that for as long as we need to prove we handled it correctly
You can ask us to delete your content sooner and we will.
11. Automated decision-making
We do not make decisions about you by automated means that produce legal effects or similarly significantly affect you. AI features generate suggested content for your review; a person decides what to publish.
12. Your rights
Under the GDPR you can ask us to:
give you a copy of the personal data we hold about you;
correct it if it is wrong;
delete it;
restrict or object to how we use it, including objecting to any processing we base on legitimate interest;
give it to you, or to another provider, in a portable format;
withdraw consent, where consent is what we relied on. Withdrawing does not affect the lawfulness of what we did before you withdrew.
Write to privacy@nexerapxm.com. We answer within one month. If a request is complex or you have made several, we may extend that by up to two further months, and we will tell you why within the first month. We may ask you to confirm your identity before we act, so that we do not hand your data to someone else. We do not charge for any of this.
If you are unhappy with how we handle it, you can complain to the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl).
If your request is about data inside a customer’s catalog or portal, we will pass it to that customer, because they are the controller and the decision is theirs.
13. Children
NEXERA PXM is a business tool. It is not directed at children and we do not knowingly collect data about them.
14. Changes
We will post any new version here with a new effective date. For material changes affecting account holders we will also email you.