Privacy Policy
Last updated: December 30, 2025
Introduction
At NEXFIRE, protecting your personal data is our top priority. This privacy policy explains how we collect, use, store, and protect your information when you use our AI agent orchestration platform.
Collected Data
1. Account Data
- Full name
- Email address
- Password (hashed with bcrypt)
- Role and subscription tier
2. Usage Data
- Agent execution logs
- Performance metrics
- Approval history
- Audit traces (RBAC)
3. Technical Data
- IP address
- User-Agent (browser)
- Connection timestamps
Data Usage
We use your data only to:
- Provide and improve our services
- Authenticate and secure your account
- Generate analytics and performance reports
- Ensure compliance and security audits
- Communicate with you regarding your account
We NEVER sell your data to third parties.
Storage and Security
Encryption
Your sensitive data (secrets, API keys) are encrypted at rest with Fernet (AES-128). Communications use TLS 1.3.
Data Location
On-premise deployment available: You can host NEXFIRE on your own infrastructure. Your data never leaves your servers.
Retention Period
Execution logs are kept for 90 days by default. Account data is deleted 30 days after account closure.
Your Rights (GDPR)
In accordance with the GDPR, you have the following rights:
- Right of access : Request a copy of your data
- Right to rectification : Correct your information via /profile
- Right to erasure : Delete your account and all your data
- Right to data portability : Export your data in JSON format
- Right to object : Refuse certain uses of your data
To exercise these rights, contact us at privacy@nexfire.fr
Cookies
We only use cookies strictly necessary for the platform to function (JWT token). No tracking or advertising cookies are used.
Sharing with Third Parties
Your data may be shared only in the following cases:
- LLM providers : If you use third-party LLM APIs (OpenAI, Anthropic, Google, Mistral...), your prompts are sent to those services in accordance with their own policies.
- Legal obligations : In the event of a valid legal request.
Changes to This Policy
We reserve the right to modify this policy. Major changes will be notified to you by email. The current version is always available on this page.
Contact
If you have any questions regarding this privacy policy:
Email: privacy@nexfire.fr