Data protection
Privacy Policy
Last updated: September 25, 2026
Introduction
This policy sets out what data Nexfire processes, why, who it is shared with, and the rights you have. It describes how the platform actually works, with no promise the product does not keep.
Our two roles
Data controller
For your Nexfire account data (identity, sign-in, billing, security logs), we decide the purposes and the means: we act as data controller.
Data processor
For the data you entrust to your agents (documents, emails, processed content), you remain the data controller and we act as a processor, on your instructions.
Collected Data
1. Account Data
- Full name
- Email address
- Password (hashed with bcrypt)
- Role and subscription tier
2. Usage Data
- Agent execution logs
- Performance metrics
- Approval history
- Audit traces (RBAC)
3. Technical Data
- IP address
- User-Agent (browser)
- Connection timestamps
Legal bases
Every processing activity rests on a legal basis:
Service delivery, account management, agent execution
- Legal basis
- Performance of the contract
Billing and accounting obligations
- Legal basis
- Legal obligation
Security, audit logs, abuse prevention
- Legal basis
- Legitimate interest
Choosing an AI provider outside the EU, enabling media capabilities
- Legal basis
- Your explicit choice
Transactional emails related to the service
- Legal basis
- Performance of the contract
Reading the new emails received in your workspace's mailbox, for the "email received" automations, only after the mailbox owner allowed it (the content is sent to the chosen AI provider)
- Legal basis
- Your instructions (we act as a processor); for the authors of the emails, your company's legitimate interest or pre-contractual measures, to record in your own register
Receiving the requests sent through the contact form Nexfire hosts for your company (shared link or form placed on your website): the visitor's contact details and message, the proof of their agreement, a non-reversible fingerprint of their IP address (never the address itself), passed to your automation
- Legal basis
- Your instructions (we act as a processor); for the visitors, the consent given by ticking the form's box, whose proof is kept
| Processing | Legal basis |
|---|---|
| Service delivery, account management, agent execution | Performance of the contract |
| Billing and accounting obligations | Legal obligation |
| Security, audit logs, abuse prevention | Legitimate interest |
| Choosing an AI provider outside the EU, enabling media capabilities | Your explicit choice |
| Transactional emails related to the service | Performance of the contract |
| Reading the new emails received in your workspace's mailbox, for the "email received" automations, only after the mailbox owner allowed it (the content is sent to the chosen AI provider) | Your instructions (we act as a processor); for the authors of the emails, your company's legitimate interest or pre-contractual measures, to record in your own register |
| Receiving the requests sent through the contact form Nexfire hosts for your company (shared link or form placed on your website): the visitor's contact details and message, the proof of their agreement, a non-reversible fingerprint of their IP address (never the address itself), passed to your automation | Your instructions (we act as a processor); for the visitors, the consent given by ticking the form's box, whose proof is kept |
Data Usage
We use your data only to:
- Provide and improve our services (Forge, Studio, connectors, and knowledge bases)
- Authenticate and secure your account
- Generate analytics and performance reports
- Ensure compliance and security audits (RBAC, budgets, approvals)
- Communicate with you regarding your account
We never sell your data to third parties.
Storage and Security
Encryption
Your sensitive data (secrets, API keys) are encrypted at rest with Fernet (AES-128). Communications use TLS 1.3.
Data location
The platform is hosted in the European Union (Germany and Finland). A version installed on your own servers is available on quotation: in that case only, your data stays on your infrastructure.
Retention periods
Execution logs: 90 days by default, adjustable from 1 to 3650 days by an administrator of your workspace. Execution snapshots are encrypted at rest and purged automatically when the period expires. The content of a received email read by an automation is removed from the run after 30 days (only the references remain: sender, subject, date). A request received through the hosted contact form is deleted after the period the company chose (90 days by default, from 30 to 365 days), and together with the contact's record if that record is deleted; its copy in the run it started is erased at the same time. Replies already prepared by the automation follow the execution log period. Account: anonymized 30 days after closure. Runs dissociated from your identity are kept until the retention period configured for the workspace expires.
Subprocessors and recipients
Depending on the features you enable, the following third parties may process data on our behalf:
Hetzner Online GmbH
- Role
- Platform hosting
- Region
- European Union (Germany, Finland)
Mistral AI
- Role
- AI provider
- Region
- European Union (France)
Ollama
- Role
- Models run locally
- Region
- No transfer
data.gouv.fr
- Role
- Public company data
- Region
- European Union (France)
Recall.ai
- Role
- Meeting notetaker bot
- Region
- Processing in the European Union (Frankfurt) by default, vendor based in the United States
Resend
- Role
- Delivery of service emails
- Region
- United States
Composio
- Role
- Connection to your tools and document retrieval
- Region
- United States
Cloudflare R2
- Role
- Temporary transfer of connector files
- Region
- United States
Lemon Squeezy
- Role
- Subscription payments
- Region
- United States
Stripe
- Role
- Payment mandates delegated to agents
- Region
- United States
Twilio
- Role
- Phone channel, if you enable it with your own credentials
- Region
- United States
OpenAI, Anthropic, Google, xAI, Perplexity, OpenRouter, Together, Groq
- Role
- AI providers, depending on your choice
- Region
- United States
DeepSeek, Moonshot (Kimi), Alibaba (Qwen), MiniMax, Z.ai
- Role
- AI providers, depending on your choice
- Region
- China
fal.ai, Runway, Luma, ElevenLabs, Ideogram, Stability AI
- Role
- Image, video, voice, and music generation, if enabled
- Region
- United States and United Kingdom
Black Forest Labs
- Role
- Image generation, if enabled
- Region
- European Union (Germany)
Kling (Kuaishou), MiniMax
- Role
- Video and music generation, if enabled
- Region
- China
| Recipient | Role | Region |
|---|---|---|
| Hetzner Online GmbH | Platform hosting | European Union (Germany, Finland) |
| Mistral AI | AI provider | European Union (France) |
| Ollama | Models run locally | No transfer |
| data.gouv.fr | Public company data | European Union (France) |
| Recall.ai | Meeting notetaker bot | Processing in the European Union (Frankfurt) by default, vendor based in the United States |
| Resend | Delivery of service emails | United States |
| Composio | Connection to your tools and document retrieval | United States |
| Cloudflare R2 | Temporary transfer of connector files | United States |
| Lemon Squeezy | Subscription payments | United States |
| Stripe | Payment mandates delegated to agents | United States |
| Twilio | Phone channel, if you enable it with your own credentials | United States |
| OpenAI, Anthropic, Google, xAI, Perplexity, OpenRouter, Together, Groq | AI providers, depending on your choice | United States |
| DeepSeek, Moonshot (Kimi), Alibaba (Qwen), MiniMax, Z.ai | AI providers, depending on your choice | China |
| fal.ai, Runway, Luma, ElevenLabs, Ideogram, Stability AI | Image, video, voice, and music generation, if enabled | United States and United Kingdom |
| Black Forest Labs | Image generation, if enabled | European Union (Germany) |
| Kling (Kuaishou), MiniMax | Video and music generation, if enabled | China |
Transfers outside the European Union
When you choose an AI provider or a media capability located outside the European Union, the data processed is sent to it and leaves the European Union. That choice is yours, agent by agent.
You can stay entirely within the European Union: by selecting Mistral as your AI provider and leaving media generation capabilities disabled, your execution data does not leave the European Union.
We are progressively formalizing contractual safeguards with our subprocessors. This section is updated as that work advances.
Your rights
Under the GDPR, you have the following rights:
- Access and portability
- From your profile, export your data as an archive of reusable JSON files: profile, workspaces, executions, conversations, and the metadata of your secrets, knowledge bases, and API keys. Audit logs, meeting transcripts, and generated media are not part of this automatic export: ask us for them.
- Rectification
- Correct your account information from your profile.
- Erasure
- From your profile, deleting your account erases your secrets, credentials, API keys, knowledge bases, and conversations. Your account is then anonymized and your past executions are dissociated from your identity; their content is kept until the workspace retention period expires, then purged.
- Objection and restriction
- Write to us: we handle these requests manually.
To exercise these rights or ask a question: privacy@nexfire.fr
Complaint
If you believe that the processing of your data is not compliant, you may lodge a complaint with the French data protection authority (CNIL), 3 place de Fontenoy, 75007 Paris, cnil.fr.
Changes to This Policy
We reserve the right to modify this policy. Major changes will be notified to you by email. The current version is always available on this page.
Contact
If you have any questions regarding this privacy policy:
Email: privacy@nexfire.fr