Data protection

Privacy Policy

Last updated: September 25, 2026

Introduction

This policy sets out what data Nexfire processes, why, who it is shared with, and the rights you have. It describes how the platform actually works, with no promise the product does not keep.

Our two roles

Data controller

For your Nexfire account data (identity, sign-in, billing, security logs), we decide the purposes and the means: we act as data controller.

Data processor

For the data you entrust to your agents (documents, emails, processed content), you remain the data controller and we act as a processor, on your instructions.

Collected Data

1. Account Data

  • Full name
  • Email address
  • Password (hashed with bcrypt)
  • Role and subscription tier

2. Usage Data

  • Agent execution logs
  • Performance metrics
  • Approval history
  • Audit traces (RBAC)

3. Technical Data

  • IP address
  • User-Agent (browser)
  • Connection timestamps

Data Usage

We use your data only to:

  • Provide and improve our services (Forge, Studio, connectors, and knowledge bases)
  • Authenticate and secure your account
  • Generate analytics and performance reports
  • Ensure compliance and security audits (RBAC, budgets, approvals)
  • Communicate with you regarding your account

We never sell your data to third parties.

Storage and Security

Encryption

Your sensitive data (secrets, API keys) are encrypted at rest with Fernet (AES-128). Communications use TLS 1.3.

Data location

The platform is hosted in the European Union (Germany and Finland). A version installed on your own servers is available on quotation: in that case only, your data stays on your infrastructure.

Retention periods

Execution logs: 90 days by default, adjustable from 1 to 3650 days by an administrator of your workspace. Execution snapshots are encrypted at rest and purged automatically when the period expires. The content of a received email read by an automation is removed from the run after 30 days (only the references remain: sender, subject, date). A request received through the hosted contact form is deleted after the period the company chose (90 days by default, from 30 to 365 days), and together with the contact's record if that record is deleted; its copy in the run it started is erased at the same time. Replies already prepared by the automation follow the execution log period. Account: anonymized 30 days after closure. Runs dissociated from your identity are kept until the retention period configured for the workspace expires.

Subprocessors and recipients

Depending on the features you enable, the following third parties may process data on our behalf:

  • Hetzner Online GmbH

    Role
    Platform hosting
    Region
    European Union (Germany, Finland)
  • Mistral AI

    Role
    AI provider
    Region
    European Union (France)
  • Ollama

    Role
    Models run locally
    Region
    No transfer
  • data.gouv.fr

    Role
    Public company data
    Region
    European Union (France)
  • Recall.ai

    Role
    Meeting notetaker bot
    Region
    Processing in the European Union (Frankfurt) by default, vendor based in the United States
  • Resend

    Role
    Delivery of service emails
    Region
    United States
  • Composio

    Role
    Connection to your tools and document retrieval
    Region
    United States
  • Cloudflare R2

    Role
    Temporary transfer of connector files
    Region
    United States
  • Lemon Squeezy

    Role
    Subscription payments
    Region
    United States
  • Stripe

    Role
    Payment mandates delegated to agents
    Region
    United States
  • Twilio

    Role
    Phone channel, if you enable it with your own credentials
    Region
    United States
  • OpenAI, Anthropic, Google, xAI, Perplexity, OpenRouter, Together, Groq

    Role
    AI providers, depending on your choice
    Region
    United States
  • DeepSeek, Moonshot (Kimi), Alibaba (Qwen), MiniMax, Z.ai

    Role
    AI providers, depending on your choice
    Region
    China
  • fal.ai, Runway, Luma, ElevenLabs, Ideogram, Stability AI

    Role
    Image, video, voice, and music generation, if enabled
    Region
    United States and United Kingdom
  • Black Forest Labs

    Role
    Image generation, if enabled
    Region
    European Union (Germany)
  • Kling (Kuaishou), MiniMax

    Role
    Video and music generation, if enabled
    Region
    China

Transfers outside the European Union

When you choose an AI provider or a media capability located outside the European Union, the data processed is sent to it and leaves the European Union. That choice is yours, agent by agent.

You can stay entirely within the European Union: by selecting Mistral as your AI provider and leaving media generation capabilities disabled, your execution data does not leave the European Union.

We are progressively formalizing contractual safeguards with our subprocessors. This section is updated as that work advances.

Your rights

Under the GDPR, you have the following rights:

Access and portability
From your profile, export your data as an archive of reusable JSON files: profile, workspaces, executions, conversations, and the metadata of your secrets, knowledge bases, and API keys. Audit logs, meeting transcripts, and generated media are not part of this automatic export: ask us for them.
Rectification
Correct your account information from your profile.
Erasure
From your profile, deleting your account erases your secrets, credentials, API keys, knowledge bases, and conversations. Your account is then anonymized and your past executions are dissociated from your identity; their content is kept until the workspace retention period expires, then purged.
Objection and restriction
Write to us: we handle these requests manually.

To exercise these rights or ask a question: privacy@nexfire.fr

Cookies

We only use cookies strictly necessary for the platform to function (JWT token). No tracking or advertising cookies are used.

Sharing with Third Parties

Your data may be shared only in the following cases:

LLM providers
If you use third-party LLM APIs (OpenAI, Anthropic, Google, Mistral...), your prompts are sent to those services in accordance with their own policies.
Legal obligations
In the event of a valid legal request.

Complaint

If you believe that the processing of your data is not compliant, you may lodge a complaint with the French data protection authority (CNIL), 3 place de Fontenoy, 75007 Paris, cnil.fr.

Changes to This Policy

We reserve the right to modify this policy. Major changes will be notified to you by email. The current version is always available on this page.

Contact

If you have any questions regarding this privacy policy:

Email: privacy@nexfire.fr

Back to home