Skip to content

Privacy Policy

What we collect, and why.

Plain answers about the data this website and our team workspace handle: what we ask for, where it goes, how long we keep it, and how to have it removed.

Last updated
Controller
[Legal entity name - owner to confirm]

In short

  • We collect what you type into our forms, and how you found us.
  • No advertising or tracking cookies, and analytics without cookies.
  • We never sell your data or use it for anyone else’s ads.
  • Unused enquiries lose their personal details after 24 months; spam goes after 30 days.

Who we are

NixGen Solutions (“NixGen”, “we”, “us”) is a trading name of [Legal entity name - owner to confirm], registered at [Registered address - owner to confirm]. We are the controller of the personal data described in this policy.

This policy covers the website at nixgensolutions.com, its contact and newsletter forms, and the team workspace at workspace.nixgensolutions.com, which our team and invited clients sign in to. When we build or run systems for a client, the data inside those systems is handled under our agreement with that client, not under this policy.

Questions about your data go to nixgensolutions@gmail.com.

What we collect

When you send an enquiry

  • What you type: your name, email address, company, phone number (optional), the services you are interested in, budget range, timeline and your message.
  • Your consent: the time you ticked the box agreeing to this policy.
  • How you found us: the campaign tags in the link you arrived from (for example utm_source or a Google Ads click id), the website that referred you (its address without the query string) and the page you landed on.
  • Anti-spam signals: a one-way, salted fingerprint of your IP address (we never store the address itself), the result of the Turnstile check, how long the form took to fill in, and whether the hidden trap field was filled.

We use these details to work out how quickly to reply and who on the team should handle it. That internal ranking never decides anything about you on its own: a person reads every genuine enquiry.

When you join the newsletter

Your email address, where on the site you signed up, the time you gave consent and the same salted IP fingerprint. We have not sent a newsletter yet; when we do, every email will include a way to unsubscribe.

When you visit

  • Analytics: we use Cloudflare Web Analytics, which counts page views and performance without cookies and without building a profile of you across sites.
  • Delivery and security: like any website, our hosting provider processes your IP address, browser type and the pages requested to serve the site and block attacks.
  • Error reports: if the site breaks in your browser, it may send us a technical report of the error. Email addresses, tokens and the query strings of links are scrubbed out before the reports are logged.

When you email or work with us

Your messages and anything you choose to share with us, and, for clients and team members, the account details needed to sign in to the workspace.

Cookies and browser storage

We do not use advertising or cross-site tracking cookies, so this site has no cookie banner. What it does store in your browser:

  • nx_attribution in sessionStorage: the first and latest source of your visit (campaign tags, referring site, landing page and time), read by the contact form so we know which channels bring enquiries. Your browser deletes it when you close the tab, and it is only ever sent to us if you submit the form.
  • nixgen-theme as a cookie and in localStorage: whether you chose the light or dark theme. It holds nothing else.
  • Cloudflare Turnstile runs a short check in your browser when you use a form, to tell people from bots. It does not use cookies to follow you across sites.
  • Workspace sign-in (team members and invited clients only): a session kept in your browser’s storage so you stay signed in.

You can clear any of these in your browser settings; the site keeps working without them.

How we use it, and why we are allowed to

  • Answering your enquiry and preparing a proposal: at your request, before any contract, and because you agreed to this policy when you sent the form.
  • Keeping the forms free of spam and abuse: our legitimate interest in running a safe service. Suspected spam is set aside without alerting anyone, and deleted after 30 days unless we find it was genuine.
  • Understanding which channels bring enquiries: our legitimate interest in running our business, using only the source details listed above and aggregate analytics.
  • Sending the newsletter: your consent, which you can withdraw at any time.
  • Delivering a project: our contract with you or your company.
  • Keeping records the law requires: our legal obligations.

We do not sell your personal data, and we do not share it with anyone for their own advertising.

If our system cannot take your enquiry

Enquiries go straight into our own database. If that step fails or cannot be confirmed, the form sends the same enquiry through FormSubmit (formsubmit.co), an email-forwarding service, to our company inbox at nixgensolutions@gmail.com, so your message is not lost. FormSubmit handles the contents only to deliver that email.

This is a temporary safety net. We intend to remove it once our own system has run reliably for several weeks, and we will update this section when we do.

Who we share it with

We use the providers below to run the site and our business. They process personal data only on our instructions and under contracts that require them to protect it.

CloudflareHosting & security
Serves this website and runs its server code, protects the forms with Turnstile, and provides our cookieless Web Analytics. Processes your IP address and request details to deliver and secure the site.
SupabaseDatabase
Stores enquiries, newsletter sign-ups and the team workspace (database, sign-in and file storage). This is where your enquiry is kept.
GoogleEmail & workspace
Our company email runs on Gmail, so the replies we send you and the messages you send us pass through Google. Workspace users who connect a Google account also use Google Calendar and Drive, as described in section 08.
FormSubmit (formsubmit.co)Fallback only
Used only when our own system cannot confirm it received your enquiry. It forwards the form to our company inbox so nothing is lost (section 05).
Workflow automation (n8n)Run by us
A workflow tool we operate ourselves. It can send the confirmation email for a new enquiry and alerts the team member responsible for it.
Web push servicesTeam devices
Deliver notifications about new enquiries to our own team members’ browsers and phones (for example Apple, Google or Mozilla push services). Nothing is pushed to visitors.

We will also disclose personal data where the law requires it, to protect our rights or someone’s safety, or to a buyer if our business is ever sold, in which case this policy continues to apply.

International transfers

Our providers run data centres in several countries, so your data may be processed outside the country you live in. Where data protection law requires it, transfers rely on safeguards such as the European Commission’s Standard Contractual Clauses or an adequacy decision, as offered in each provider’s data processing terms.

Google user data in the workspace

This section applies only to team members and invited clients who connect a Google account in the workspace. The workspace asks Google for the narrowest access each feature needs, and nothing more:

Sign-in identityopenid
Confirms which Google account is being connected.
Email addressemail
Shows which account is connected, so you can tell it apart from others and disconnect it.
Google Drive: files this app usesdrive.file
Saves the exports and attachments you ask for into your Drive. The app can see only files it created or that you chose to open with it, never the rest of your Drive.
Google Calendar: calendars this app createscalendar.app.created
Keeps the shared team calendar the app created up to date, with events, invitations and meeting links. The app cannot read the events in your other calendars.
Google Calendar: busy and free timescalendar.freebusy
Lets the booking page offer only times when the connected company account is free. The app sees when that account is busy, never the events themselves: no titles, details or guests. Optional: without it, booking checks only the team calendar.

The workspace never asks for access to your Gmail, your contacts or your whole Drive. The connection’s access tokens are stored encrypted on our servers and used only when you, or the shared team calendar, need them. You can disconnect at any time in the workspace settings or from your Google Account permissions; when a team member leaves, we revoke their connection.

NixGen Solutions’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular, we:

  • use Google user data only to provide and improve the workspace features you can see;
  • never sell it, or use or transfer it for advertising, including retargeting or personalised ads;
  • never use it to develop, improve or train generalised artificial intelligence or machine learning models;
  • transfer it to others only as needed to provide those features, to comply with the law, or as part of a merger or sale with notice to you;
  • do not let people read it unless you ask us to (for example for support), it is needed for security or the law, or it has been aggregated and anonymised for internal operations.

How long we keep it

We keep personal data only as long as we need it. Most of the periods below are enforced automatically by a scheduled job in our database, not left to someone remembering.

Enquiries we decide not to pursue24 months
Counted from your last message or our last update, whichever is later. We then remove your name, email, phone, company, message, our notes about you, your IP fingerprint, and the referring page, landing page and click id. What remains (the service asked about, budget band, timeline, campaign name, dates and outcome) no longer identifies you and is kept for our own reporting.
Submissions marked as spam30 days
Deleted entirely once 30 days have passed since the submission was last received or changed, so a genuine message caught by mistake can still be recovered in that time.
Enquiries that become a projectEngagement + legal period
Kept for the length of our work together and afterwards for as long as accounting, tax and contract law require, then deleted or anonymised.
Internal team notifications90 days
All in-app team notifications, including those that quote an enquiry, are deleted after 90 days, and sooner if the enquiry itself is deleted or anonymised.
Newsletter sign-upsUntil you unsubscribe
When you unsubscribe we keep your address, the date you left and the record of your original sign-up as a do-not-contact entry, so you are never added back by mistake. Ask us and we will delete it entirely.
Form abuse checks1 day
The short-lived records we use to slow down repeated sign-up attempts are cleared after one day.
Visit source in your browserUntil the tab closes
The nx_attribution entry lives in sessionStorage, which your browser clears when you close the tab.
Server and error logsUp to 7 days
Technical logs from our server code, including error reports from the site, have email addresses, tokens and link query strings scrubbed out, and expire with our hosting provider’s log retention.

Enquiries that reached us by the fallback email are kept in our company inbox and follow the same periods. Backups roll over on their own schedule, so a deleted record can survive in a backup for a short time before it is overwritten.

How we protect it

Everything travels over encrypted connections. Our database only lets each team member see what their role allows, form endpoints check where a request came from and how big it is before anything is stored, and secrets and passwords live in encrypted storage rather than in code. IP addresses are reduced to a salted fingerprint before they reach the database.

No system is perfectly secure. If a breach puts your data at risk, we will tell you and the relevant authorities as the law requires.

Your rights and data requests

Depending on where you live, you can ask us to:

  • tell you what personal data we hold about you and give you a copy;
  • correct it, or delete it;
  • stop or limit how we use it, including for our own reporting;
  • give it to you in a portable format;
  • withdraw a consent you gave, such as for the newsletter, without affecting what came before.

Email nixgensolutions@gmail.com with the subject “Privacy request” and the email address you used with us. To protect you, we confirm the request from that address before acting on it. We reply within 30 days, and there is no charge.

If you are in California: we do not sell or share personal information for cross-context behavioural advertising, and we will not treat you differently for using these rights. If you are unhappy with our answer, you can complain to the data protection authority where you live.

Children

This site and our services are for businesses. They are not directed at children under 16, and we do not knowingly collect their personal data. If you think a child has sent us their details, write to us and we will delete them.

Changes to this policy

When we change how we handle personal data, we update this page and the date at the top. If a change matters to how we use data you already gave us, we will tell you before it applies.

Contact

[Legal entity name - owner to confirm]
[Registered address - owner to confirm]
nixgensolutions@gmail.com