Privacy Policy
What we collect, and why.
Plain answers about the data this website and our team workspace handle: what we ask for, where it goes, how long we keep it, and how to have it removed.
- Last updated
- Controller
- [Legal entity name - owner to confirm]
- Questions
- nixgensolutions@gmail.com
In short
- We collect what you type into our forms, and how you found us.
- No advertising or tracking cookies, and analytics without cookies.
- We never sell your data or use it for anyone else’s ads.
- Unused enquiries lose their personal details after 24 months; spam goes after 30 days.
Who we are
NixGen Solutions (“NixGen”, “we”, “us”) is a trading name of [Legal entity name - owner to confirm], registered at [Registered address - owner to confirm]. We are the controller of the personal data described in this policy.
This policy covers the website at nixgensolutions.com, its contact and newsletter forms, and the team workspace at workspace.nixgensolutions.com, which our team and invited clients sign in to. When we build or run systems for a client, the data inside those systems is handled under our agreement with that client, not under this policy.
Questions about your data go to nixgensolutions@gmail.com.
What we collect
When you send an enquiry
- What you type: your name, email address, company, phone number (optional), the services you are interested in, budget range, timeline and your message.
- Your consent: the time you ticked the box agreeing to this policy.
- How you found us: the campaign tags in the link you arrived from (for example
utm_sourceor a Google Ads click id), the website that referred you (its address without the query string) and the page you landed on. - Anti-spam signals: a one-way, salted fingerprint of your IP address (we never store the address itself), the result of the Turnstile check, how long the form took to fill in, and whether the hidden trap field was filled.
We use these details to work out how quickly to reply and who on the team should handle it. That internal ranking never decides anything about you on its own: a person reads every genuine enquiry.
When you join the newsletter
Your email address, where on the site you signed up, the time you gave consent and the same salted IP fingerprint. We have not sent a newsletter yet; when we do, every email will include a way to unsubscribe.
When you visit
- Analytics: we use Cloudflare Web Analytics, which counts page views and performance without cookies and without building a profile of you across sites.
- Delivery and security: like any website, our hosting provider processes your IP address, browser type and the pages requested to serve the site and block attacks.
- Error reports: if the site breaks in your browser, it may send us a technical report of the error. Email addresses, tokens and the query strings of links are scrubbed out before the reports are logged.
When you email or work with us
Your messages and anything you choose to share with us, and, for clients and team members, the account details needed to sign in to the workspace.
Cookies and browser storage
We do not use advertising or cross-site tracking cookies, so this site has no cookie banner. What it does store in your browser:
nx_attributionin sessionStorage: the first and latest source of your visit (campaign tags, referring site, landing page and time), read by the contact form so we know which channels bring enquiries. Your browser deletes it when you close the tab, and it is only ever sent to us if you submit the form.nixgen-themeas a cookie and in localStorage: whether you chose the light or dark theme. It holds nothing else.- Cloudflare Turnstile runs a short check in your browser when you use a form, to tell people from bots. It does not use cookies to follow you across sites.
- Workspace sign-in (team members and invited clients only): a session kept in your browser’s storage so you stay signed in.
You can clear any of these in your browser settings; the site keeps working without them.
How we use it, and why we are allowed to
- Answering your enquiry and preparing a proposal: at your request, before any contract, and because you agreed to this policy when you sent the form.
- Keeping the forms free of spam and abuse: our legitimate interest in running a safe service. Suspected spam is set aside without alerting anyone, and deleted after 30 days unless we find it was genuine.
- Understanding which channels bring enquiries: our legitimate interest in running our business, using only the source details listed above and aggregate analytics.
- Sending the newsletter: your consent, which you can withdraw at any time.
- Delivering a project: our contract with you or your company.
- Keeping records the law requires: our legal obligations.
We do not sell your personal data, and we do not share it with anyone for their own advertising.
If our system cannot take your enquiry
Enquiries go straight into our own database. If that step fails or cannot be confirmed, the form sends the same enquiry through FormSubmit (formsubmit.co), an email-forwarding service, to our company inbox at nixgensolutions@gmail.com, so your message is not lost. FormSubmit handles the contents only to deliver that email.
This is a temporary safety net. We intend to remove it once our own system has run reliably for several weeks, and we will update this section when we do.
International transfers
Our providers run data centres in several countries, so your data may be processed outside the country you live in. Where data protection law requires it, transfers rely on safeguards such as the European Commission’s Standard Contractual Clauses or an adequacy decision, as offered in each provider’s data processing terms.
Google user data in the workspace
This section applies only to team members and invited clients who connect a Google account in the workspace. The workspace asks Google for the narrowest access each feature needs, and nothing more:
- Sign-in identity
openid - Confirms which Google account is being connected.
- Email address
email - Shows which account is connected, so you can tell it apart from others and disconnect it.
- Google Drive: files this app uses
drive.file - Saves the exports and attachments you ask for into your Drive. The app can see only files it created or that you chose to open with it, never the rest of your Drive.
- Google Calendar: calendars this app creates
calendar.app.created - Keeps the shared team calendar the app created up to date, with events, invitations and meeting links. The app cannot read the events in your other calendars.
- Google Calendar: busy and free times
calendar.freebusy - Lets the booking page offer only times when the connected company account is free. The app sees when that account is busy, never the events themselves: no titles, details or guests. Optional: without it, booking checks only the team calendar.
The workspace never asks for access to your Gmail, your contacts or your whole Drive. The connection’s access tokens are stored encrypted on our servers and used only when you, or the shared team calendar, need them. You can disconnect at any time in the workspace settings or from your Google Account permissions; when a team member leaves, we revoke their connection.
NixGen Solutions’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular, we:
- use Google user data only to provide and improve the workspace features you can see;
- never sell it, or use or transfer it for advertising, including retargeting or personalised ads;
- never use it to develop, improve or train generalised artificial intelligence or machine learning models;
- transfer it to others only as needed to provide those features, to comply with the law, or as part of a merger or sale with notice to you;
- do not let people read it unless you ask us to (for example for support), it is needed for security or the law, or it has been aggregated and anonymised for internal operations.
How long we keep it
We keep personal data only as long as we need it. Most of the periods below are enforced automatically by a scheduled job in our database, not left to someone remembering.
- Enquiries we decide not to pursue24 months
- Counted from your last message or our last update, whichever is later. We then remove your name, email, phone, company, message, our notes about you, your IP fingerprint, and the referring page, landing page and click id. What remains (the service asked about, budget band, timeline, campaign name, dates and outcome) no longer identifies you and is kept for our own reporting.
- Submissions marked as spam30 days
- Deleted entirely once 30 days have passed since the submission was last received or changed, so a genuine message caught by mistake can still be recovered in that time.
- Enquiries that become a projectEngagement + legal period
- Kept for the length of our work together and afterwards for as long as accounting, tax and contract law require, then deleted or anonymised.
- Internal team notifications90 days
- All in-app team notifications, including those that quote an enquiry, are deleted after 90 days, and sooner if the enquiry itself is deleted or anonymised.
- Newsletter sign-upsUntil you unsubscribe
- When you unsubscribe we keep your address, the date you left and the record of your original sign-up as a do-not-contact entry, so you are never added back by mistake. Ask us and we will delete it entirely.
- Form abuse checks1 day
- The short-lived records we use to slow down repeated sign-up attempts are cleared after one day.
- Visit source in your browserUntil the tab closes
- The nx_attribution entry lives in sessionStorage, which your browser clears when you close the tab.
- Server and error logsUp to 7 days
- Technical logs from our server code, including error reports from the site, have email addresses, tokens and link query strings scrubbed out, and expire with our hosting provider’s log retention.
Enquiries that reached us by the fallback email are kept in our company inbox and follow the same periods. Backups roll over on their own schedule, so a deleted record can survive in a backup for a short time before it is overwritten.
How we protect it
Everything travels over encrypted connections. Our database only lets each team member see what their role allows, form endpoints check where a request came from and how big it is before anything is stored, and secrets and passwords live in encrypted storage rather than in code. IP addresses are reduced to a salted fingerprint before they reach the database.
No system is perfectly secure. If a breach puts your data at risk, we will tell you and the relevant authorities as the law requires.
Your rights and data requests
Depending on where you live, you can ask us to:
- tell you what personal data we hold about you and give you a copy;
- correct it, or delete it;
- stop or limit how we use it, including for our own reporting;
- give it to you in a portable format;
- withdraw a consent you gave, such as for the newsletter, without affecting what came before.
Email nixgensolutions@gmail.com with the subject “Privacy request” and the email address you used with us. To protect you, we confirm the request from that address before acting on it. We reply within 30 days, and there is no charge.
If you are in California: we do not sell or share personal information for cross-context behavioural advertising, and we will not treat you differently for using these rights. If you are unhappy with our answer, you can complain to the data protection authority where you live.
Children
This site and our services are for businesses. They are not directed at children under 16, and we do not knowingly collect their personal data. If you think a child has sent us their details, write to us and we will delete them.
Changes to this policy
When we change how we handle personal data, we update this page and the date at the top. If a change matters to how we use data you already gave us, we will tell you before it applies.
Contact
[Legal entity name - owner to confirm]
[Registered address - owner to confirm]
nixgensolutions@gmail.com