Data Protection & IP Governance

Client Code Ownership & Privacy Framework

Built for technical leaders who demand clear IP assignment, zero data selling, and direct senior engineer accountability. No ambiguous disclaimers.

100% IP Transfer
Zero AI Code Ingestion
14-Day Log Expiry
Updated: July 23, 2026
Signature Commitment

Client IP & Zero-Data-Minimization Matrix

Interactive breakdown of Nexacos's engineering rules, legal guarantees, and technical boundary commitments.

Live Policy Enforcement

Client Code & IP Ownership

Metric: 100% Code Handover

Technical Implementation

  • Git repository ownership transferred completely upon final milestone payment.
  • No hidden proprietary runtime dependencies, locked SDKs, or recurring agency licensing fees.
  • All architecture diagrams, database schemas, and documentation delivered in open formats.

Legal & Client Rights

  • You retain full commercial and intellectual property rights to all custom code written for your application.
  • Zero retainage of derivative works or reusable client logic in agency repositories.
  • Written custom IP Assignment Agreement included with every scoping engagement.
SECTION 01Core Guarantee

Scope & Corporate Identity

Nexacos Private Limited ("Nexacos", "we", "our", or "us") operates as a boutique, senior-only engineering consultancy incorporated in West Bengal, India. This policy governs how we collect, handle, protect, and minimize data across our website and engineering engagements.

  • Applies to all visitors of nexacos.com and clients engaging in software scoping or development contracts.
  • Operated directly by senior technical leadership with zero third-party data broker involvement.
  • Governed under the laws of India and applicable international data protection standards (including GDPR compliance principles).
SECTION 02

Data Collection & Minimal Footprint

We practice strict data minimization. We only request information essential to evaluate software scoping requests or deliver engineered systems.

  • Voluntary Form Data: Name, business email, phone number, company name, and project scope details provided during contact submissions.
  • Automated Technical Metadata: Anonymized IP addresses, browser headers, operating system types, and page access timestamps logged purely for security and performance optimization.
  • Zero Sensitive Data Solicitations: We never ask for personal financial credentials, national identifiers, or non-essential personal attributes.
SECTION 03Core Guarantee

Client Code & Intellectual Property Isolation

Client IP protection is our core operational foundation. We enforce strict multi-tenant codebase isolation and zero public model exposure.

  • Zero AI Telemetry Exposure: Code written or audited for clients is NEVER used to train public or proprietary AI foundation models.
  • 100% Client Code Ownership: All repository deliverables, custom scripts, database schemas, and documentation transfer fully to the client upon milestone settlement.
  • Isolated Build Environments: Dedicated, encrypted repositories and containerized build pipelines accessible only by assigned senior engineers under NDA.
SECTION 04Core Guarantee

14-Day Log Expiry & Telemetry Purging

We do not hoard historical access logs. Operational server logs are auto-purged on a rolling 14-day schedule.

Diagnostic Log Lifecycle

Server request logs, error tracebacks, and edge routing metrics automatically expire and overwrite every 14 days.

Scoping Note Cleanup

Unexecuted software proposal notes and preliminary scoping documents are deleted 30 days after proposal expiration unless converted into an active SOW.

SECTION 05

Zero Data Brokerage & Sharing Policy

We do not sell, rent, monetize, or trade client information under any circumstances. Data sharing occurs exclusively under explicit legal or infrastructure mandates.

  • Zero Advertising Networks: We do not share data with ad exchanges, remarketing networks, or lead generation brokers.
  • Certified Service Providers: Cloud infrastructure partners (Vercel, AWS, Google Cloud) handle data under strict SOC2 Type II confidentiality terms.
  • Statutory Legal Compliance: Disclosure occurs only if legally compelled by valid court orders or statutory government authorities.
SECTION 06

Security Architecture & Encryption Standards

We employ defense-in-depth technical and organizational controls to safeguard client data in transit and at rest.

  • Encryption in Transit: Mandatory TLS 1.3 encryption across all web traffic and API endpoints.
  • Encryption at Rest: AES-256 bit encryption applied to encrypted database volumes and repository backups.
  • Role-Based Access Control (RBAC): Principle of least privilege enforced across internal engineering tools.
SECTION 07

Cookies & Preference Management

We utilize essential operational cookies for site navigation and optional anonymized analytics. You maintain total control over your cookie preferences.

  • Essential Cookies: Required for core site navigation, security token verification, and theme preference retention (light/dark mode).
  • Analytics Cookies: Optional Google Analytics cookies used to understand page performance with IP masking enabled.
  • Zero Retargeting Pixels: No Facebook pixels, LinkedIn ad tracking tags, or cross-site behavioral tracking cookies are deployed on this site.
SECTION 08

Sub-processors & Service Partners

We work only with reputable, enterprise-certified infrastructure providers under strict confidentiality agreements.

  • Vercel / Edge Network: Web hosting and edge serverless deployment infrastructure.
  • Google Workspace / SMTP: Encrypted transactional communication and direct email delivery.
  • Google Analytics: Anonymized web traffic metrics (with IP anonymization active).
SECTION 09

Your Data Protection Rights

Regardless of location, we respect fundamental privacy rights and provide transparent mechanisms to control your data.

  • Right to Access & Export: Request a complete copy of any personal data held in our systems.
  • Right to Erasure (Right to be Forgotten): Request immediate deletion of non-contractual personal records.
  • Right to Restriction & Object: Withdraw consent for analytics tracking at any time.
  • Right to Rectification: Correct inaccurate or outdated business contact records.
SECTION 10

Policy Updates & Direct DPO Contact

This Privacy Policy is updated periodically to reflect evolving legal standards. Material changes will be noted with a revised execution date.

  • Direct DPO Channel: Questions regarding data protection or custom NDA execution can be sent directly to info@nexacos.com.
  • 24-Hour Business SLA: Compliance and security inquiries receive a response within 24 business hours.
  • Registered Office: Nexacos Private Limited, Rabindranagar, Paschim Para, Chinsurah R S, Chinsurah, West Bengal 712103, India.
Direct Compliance Line

Have a Security Questionnaire or Custom NDA?

Speak directly with our senior engineering architects and Data Protection Officer. We review vendor onboarding questionnaires within 24 business hours.

Chinsurah, Hooghly, West Bengal 712103
+91 6291441225
Nexacos Private Limited