Legal · Privacy

Privacy policy

What is collected, why, for how long, and the rights you can exercise yourself — for this website, your account, the live demo, and Naxis Assistant deployments.

This is one policy in two halves, because Naxis wears two hats. For this website and your Naxis account (including the live demo), Naxis Technologies is the controller: we decide what is collected and answer for it. For Naxis Assistant deployments, the client company is the controller and Naxis acts, at most, as a processor under a signed Data Processing Agreement. Both halves are written to be checked, not skimmed.

The website

Cookies and third parties. This website loads no third-party scripts and calls no analytics service; fonts and all other assets are served from this domain. It sets two first-party cookies as a rule: the strictly-necessary session cookie that keeps you signed in to your account, and a visit-measurement cookie (nx_v) holding a random identifier, valid for 13 months, used only so that the visit log below counts a returning browser as one visitor. It contains nothing about you, is never shared, and never follows you to any other site. One more exists only if you arrive through a customer's referral link: a cookie (nx_ref) holding that referral code for 90 days, used solely to credit the referrer if you create an account in that window.

Visit measurement. The site keeps its own visit log, on its own server, written by the page itself as it renders: the page address, the referring address, the IP address together with the country and network operator it points to (derived from a local database, no lookup service is called), the browser's identifying string with the device type read from it, the browser's language and the other technical headers the browser sends with the request (cookie contents are never stored), the time, how long the page stayed open in view and how far down it was read. We use this to understand which pages are read, where visitors arrive from and how the site is crawled, and for security (legal basis: legitimate interest, art. 6(1)(f); you may object at info@naxistechnologies.com). Returning visits are recognised through the first-party nx_v cookie described above; the log follows nobody across sites and is shared with nobody. While you are signed in, page views are additionally linked to your account, part of the agreement made when the account is created (views made in the same browser shortly before signing in are linked too). They are included in your account export, and deleting the account detaches them. After 13 months each entry loses its IP address, browser string, stored headers, visitor identifier and account link; the anonymous counts remain.

Server logs. The hosting provider additionally keeps standard web-server access logs (IP address, requested page, time) for security and operations. We read them when something breaks or someone attacks, not to profile visitors.

Writing to us. The contact form is an account action: your message, name and company travel with your account email to our mailbox at info@naxistechnologies.com and are used only to answer you (legal basis: taking steps at your request before a contract, GDPR art. 6(1)(b), or our legitimate interest in answering correspondence, art. 6(1)(f)). Enquiry mail is kept as ordinary business correspondence and is not added to marketing lists.

Your Naxis account

What it holds. Email, name, company, a password hash and/or your Google identity (see below), your newsletter choice, subscriptions, support threads, document requests and, if you join one, your team workspace membership. We use this to run the service you asked for and to reach you about it (art. 6(1)(b)).

Sign-in with Google. "Continue with Google" sends us exactly three things from Google, over a direct server-to-server exchange: your verified email address, your name and Google's stable account identifier. No Google scripts run on our pages, and we receive no contacts, files or anything else from your Google account.

Newsletter. Product news goes only to accounts that keep the switch on (consent, art. 6(1)(a)); every email carries an unsubscribe, and the switch lives under Settings.

Team workspaces. If you invite colleagues (or accept an invitation), the members of the workspace see each other's names, emails, support threads and document requests. That visibility is the feature; leaving the workspace ends it forward-looking.

Billing. Payments run through Stripe, our payment processor. Your card number never touches our servers; Stripe tells us who paid for what, and we keep the subscription record and invoices (retained as accounting records for as long as tax law requires, art. 6(1)(c)).

Your rights, self-service. Under Settings → Privacy & data you can export everything your account is as one JSON file (arts. 15 and 20) and delete the account (art. 17), both immediate and automatic, no request form and no waiting. Deletion removes the account, its sessions and its demo records; support threads you wrote to our mailbox may survive as our business correspondence. Rectification is Settings too: name, company, email (with confirmation to the new address). For anything the buttons do not cover, write to info@naxistechnologies.com.

The interactive demo

The demo at demo.naxistechnologies.com is entered through this website with your account. You agree to this recording when you create the account (this policy is part of that agreement), and the date of your first entry is recorded. While you use the demo we record, linked to your account: your IP address and country, how you move through the guided tour (steps and time on each), which demo documents you open and for how long, and the exact questions you ask with the answers you receive. Legal basis: your consent, given at account creation (GDPR art. 6(1)(a)).

We use this solely to understand how prospective customers explore the product, never for advertising, never shared with anyone. Chat logs and detailed timings are erased after 90 days, the visit record after 12 months; deleting your account erases all of it immediately. Withdraw consent any time by emailing info@naxistechnologies.com, recording stops with your next visit and past records are erased on request. The demo's documents are fictional; nothing you upload or connect is involved (the demo accepts neither).

Naxis Assistant deployments (the product)

Who answers for what. A deployment processes the client company's documents and its people's questions. For all of that, the client is the controller. Naxis is a processor only where we actually touch something: operating managed hosting, running the Naxis AI service where a deployment uses it, and support access when it is granted. Every deployment is covered by a Data Processing Agreement; each one also generates its own GDPR Article 30 record of processing from its live configuration, so the paperwork cannot drift from reality.

Where the data lives. Each client runs a single-tenant deployment: own instance, own database, own document store, on the client's servers or in an EU data centre under our management. Documents, the search index, conversations and the audit log never leave the deployment. Nobody at Naxis reads inside a client's instance without a consent the client grants per support ticket, and that consent is recorded.

The AI boundary. Indexing runs entirely inside every deployment. The fullest configuration keeps answering home too: a self-hosted deployment that answers entirely on its own hardware, where nothing leaves the client's boundary at all. Deployments that use the Naxis AI service instead send only the question and the permission-filtered excerpts needed to answer it, under zero-retention terms: nothing is stored after the answer returns, nothing trains any model, and no personal identity of the asker accompanies the request.

What reaches Naxis from a running deployment. Operational signals only: version, health, and aggregate counters (documents indexed, questions answered, seats in use) so that plans, updates and support work. No document content, no question text, no personal data of the client's people rides a heartbeat.

Rights inside a deployment. The product implements them as mechanisms for the client: self-service data export for every signed-in person, hard-delete erasure that removes records from store and search index alike, and a tamper-evident audit log. If you are an employee of a Naxis client, your controller is your employer; exercise your rights with them, the product gives them the buttons.

The record-keeping

Sub-processors. For the website and accounts: our hosting provider (site and database) and Stripe (payments), plus Google only if you choose to sign in with it. For deployments: at most the Naxis AI service and, for managed hosting, an EU data-centre provider; a self-hosted deployment with self-hosted AI has none. Changes follow the DPA's written notice procedure.

Retention, in one place. Account data lives while the account does. Sessions expire on their own. Demo chat logs: 90 days; demo visit records: 12 months. Site visit log: IP address and browser string 13 months, anonymous counts indefinitely. Invoices: statutory accounting periods. Support threads: while the account or the deployment they belong to lives. Server logs: the hosting provider's standard short window.

Security. The controls are described, in the open, on the Security & Compliance page: single-tenant isolation, permission checks inside every query, a hash-chained audit log, signed releases, throttled sign-in surfaces. This policy inherits all of it.

Complaints. If you believe we handle your data wrongly, tell us first and we will fix it. You also have the right to complain to a supervisory authority; for Greece that is the Hellenic Data Protection Authority (dpa.gr).

Changes. When this policy changes materially, the change is dated here and account holders are notified by email.

Contact. Privacy questions: info@naxistechnologies.com.