This Privacy Policy explains what personal data Nexso collects, why we collect it, how we use it, and the choices you have. It applies to the Nexso web dashboard at nexso.net, the Nexso Android launcher installed on your screens, and the APIs that connect them.
1. Who we are
Nexso (“we”, “us”) is the operator of the Nexso remote digital signage platform. For the purposes of the EU General Data Protection Regulation (GDPR) and the UK GDPR, Nexso acts as the data controller of information you provide to your Nexso account, and as a data processor for content you display to your end viewers.
Data-protection questions can be sent to privacy@nexso.net.
2. What we collect
We only collect what we need to operate the service. Specifically:
a. Account & profile data
- Email address, password (stored as a bcrypt hash — never plaintext)
- Display name and business name (optional)
- Plan status, trial dates, promo redemptions, AI credit balance
b. Payment data
- Stripe Customer ID + Subscription ID
- Invoice records, payment transactions, refund status
- We do NOT store your credit card number. Card details are handled entirely by Stripe.
c. Content you create
- Design configurations (text, colours, layout, prices, images you upload)
- Media library files (images, videos, documents you upload)
- Playlists, screen assignments, schedules, brand kit palette
- Support-ticket messages you send us via the help form
d. Screen & device telemetry
Each paired screen periodically reports the following so we can keep it online and help you troubleshoot:
- Anonymous device id (a random UUID stored in the screen’s local storage — not tied to any government identifier)
- OS version, hardware manufacturer & model, screen resolution, user-agent string
- Nexso launcher app version
- Local (LAN) IP address, Wi-Fi SSID, Wi-Fi signal strength — used for support & ADB access diagnostics
- Public (WAN) IP address — derived from HTTP proxy headers, used for geo-triage and abuse prevention
- “Last seen” timestamp for online/offline indicators
We do NOT collect: IMEI, MAC address, GPS coordinates, camera feeds, microphone input, ambient audio, or content displayed to end viewers.
e. Usage & log data
- Server access logs (IP, timestamp, endpoint, response code)
- Feature usage counters (e.g. AI image generations, template clones) — aggregate only
- Error/crash reports triggered by the dashboard or the launcher
f. Cookies
Nexso uses strictly necessary httpOnly cookies to keep you logged in (`access_token`, `refresh_token`) and to remember your session. We do not use tracking cookies, third-party ad cookies, or Google Analytics. If we add analytics in the future we will update this policy and offer an opt-out.
3. How we use your data
We use the data described above to:
- Provide, maintain, and improve the service
- Authenticate you and keep your account secure
- Bill you correctly and issue receipts
- Deliver content to your paired screens in real time
- Respond to your support requests
- Detect abuse, fraud, and violations of our Terms of Service
- Comply with applicable legal obligations
Legal basis under GDPR: performance of the contract with you (Art 6(1)(b)), our legitimate interests in running a secure service (Art 6(1)(f)), and your consent where required (Art 6(1)(a)).
5. How long we keep data
- Account data: for the life of the account, plus 30 days after cancellation to allow reactivation
- Content (designs, media): until you delete it or your account is deleted
- Payment records: up to 7 years, as required by tax and accounting law
- Server logs: up to 90 days rolling
- Support tickets: up to 24 months for continuity of care
6. Your rights
Depending on your country you have the right to:
- Access a copy of the personal data we hold about you
- Correct inaccurate or outdated data
- Delete your account and associated data (right to erasure)
- Restrict or object to certain processing
- Portability — export your data in a machine-readable format
- Withdraw consent at any time where processing is based on consent
- Lodge a complaint with a data-protection authority
To exercise any of these rights email privacy@nexso.net from the address associated with your account. We’ll respond within 30 days as required by law.
California residents (CCPA/CPRA): you have equivalent rights to know, delete, and opt out of “sale” or “sharing” of personal information. Nexso does not sell or share personal information as those terms are defined in the CCPA.
7. Security
We protect your data with industry-standard measures: HTTPS/TLS in transit, encryption at rest for backups, bcrypt password hashing, httpOnly cookies for session tokens, principle-of-least-privilege access for our staff, and regular dependency updates. No system is 100% secure — if we ever suffer a breach affecting your data we’ll notify you within 72 hours as required by GDPR Art 34.
8. Children
Nexso is intended for business use. We do not knowingly collect personal data from children under 16. If you believe a child has provided us data, email privacy@nexso.net and we’ll delete it promptly.
9. International transfers
Nexso is a global service. Your data may be processed in countries outside your home jurisdiction, including the United States. When we transfer personal data out of the EU/UK we rely on the European Commission’sStandard Contractual Clauses or an equivalent lawful transfer mechanism.
10. Changes to this policy
If we make material changes to this Privacy Policy we will notify you by email or via an in-app banner at least 14 days before they take effect. The “Last updated” date at the top of this page reflects the current version.
11. Contact
For any privacy question, request to exercise your rights, or data-breach notification, contact us at:
Nexso — Data Protection
Email: privacy@nexso.net
General: hello@nexso.net