NexusNest

Legal

Privacy Policy

Last updated: October 3, 2026

1. Introduction

NexusNest Technologies Private Limited (“NexusNest”, “we”, “us”, or “our”) operates the NexusNest platform, including the PromptWall and NetLens products (collectively, the “Service”). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.

We are committed to protecting your privacy and handling your data in an open and transparent manner. This policy is written with the Indian Digital Personal Data Protection Act, 2023 (DPDP Act) in mind. NexusNest is certified to ISO/IEC 27001:2022 and ISO 9001:2015.

Our role depends on the data. For customer content processed by the Service, such as employee prompts, files and usage data, the customer is the Data Fiduciary and NexusNest acts as its Data Processor, processing only on the customer's instructions. For administrators' account and billing data and for visitors to our marketing site, NexusNest is the Data Fiduciary. If your prompts are processed by the Service, send rights requests to your employer first. NexusNest assists the customer in responding.

2. Information We Collect

2.1 Account Information

When you create an account, we collect:

  • Name, email address, and organization name
  • Billing information (processed securely by Razorpay, we do not store card details)
  • Account credentials (passwords are hashed, not kept in plaintext)

2.2 PromptWall: AI Redaction Data

When the PromptWall agent processes AI requests under normal conditions:

  • Original prompts are redacted in-line by the redaction pipeline before storage. The version retained on our servers has sensitive fields replaced by labelled placeholders (e.g., [EMAIL_1], [CREDENTIAL_1]). See Section 2.2.1 for the exceptions that apply when the redaction pipeline is unavailable or redaction is turned off.
  • Redacted prompts may be logged for tenant administrator review
  • Redaction is one-way and irreversible. There is no mechanism to recover original data from a redacted output
  • Detection metadata: category of data detected, number of fields redacted, AI tool involved, timestamp

2.2.1 Degraded-Mode and Redaction-Off Capture (important exceptions)

The redaction pipeline can be temporarily unavailable for a number of reasons. These include, but are not limited to: your tenant's monthly redaction quota being exhausted, a license becoming inactive or revoked, a machine being de-registered or revoked, network connectivity loss between the agent and our redaction endpoint, transient server-side errors or maintenance windows, malformed responses caused by version skew, or any other condition that prevents the in-line redaction pipeline from completing for a given request. By default, in any of these situations the agent does not block your AI request and your work continues. The request is forwarded to the AI provider unredacted. Administrators can configure a stricter mode in the Privacy panel.

When the agent forwards an unredacted prompt because redaction was unavailable, the original prompt text is captured and stored in the tenant's audit trail. This is a deliberate transparency feature: administrators need to see precisely what content left employee devices unprotected so they can assess exposure and take corrective action. The captured row is clearly flagged with the reason redaction was skipped (quota exhausted, license inactive, server unreachable, etc.) and is visible only to administrators of the tenant whose machine produced it.

Specifically, in degraded mode:

  • The full unredacted prompt text is stored in the tenant's network and redaction audit logs
  • The row carries a redaction skip reason indicating why redaction was bypassed
  • Tenant administrators see a sticky banner across the dashboard explaining that AI traffic is currently being forwarded unredacted
  • The same retention windows in Section 7 apply. Degraded-mode captures are not retained longer than redacted captures
  • Degraded-mode captures are never used to train or improve any model, never sold, and never shared outside the tenant

Turning redaction off does not stop capture. When redaction is off for a category, or entirely, prompts are forwarded as typed and, if prompt monitoring is on, stored as typed in that tenant's logs. If prompt monitoring is off, the prompt text is not captured or stored. The controlling administrator manages both settings in the Privacy panel of your dashboard. Disabling redaction removes the protective layer of the product.

2.3 NetLens: AI Usage Analytics Data

When the NetLens agent records activity on AI tool traffic:

  • Request metadata: URL, domain, HTTP method, status code, response time
  • Device and agent details: machine ID and device fingerprint, hostname, operating system and version, agent version, the licence the agent is registered under, and the IP address and user agent our servers observe
  • Agent health reported on each heartbeat: protection status (proxy and certificate trust state, and whether protection needed repair), AI hostnames the agent could not redact or discovered, applications from the administrator-configured catalog found on the device (name, version, whether running), and per-host request and prompt counts
  • By default NetLens stores redacted prompt and response text alongside each request's metadata. A tenant can switch to metadata-only mode, which keeps counts, categories, tool and timing and never stores prompt or response text
  • Retention periods are set out in Section 7

2.4 Usage and Analytics Data

  • Dashboard usage patterns (pages visited, features used)
  • Device and browser information
  • IP address and approximate location

2.5 AI Control Panel

When you use the AI Control Panel to manage seats for ChatGPT, Claude and Claude Code, we process:

  • Seat and account records: employee email, which employee holds which seat, and usage samples
  • Encrypted session material used to sign employees in to those accounts. It is encrypted with AES-256-GCM before storage, and employees never see passwords
  • One-time passcodes, read from a designated mailbox through a delegated Google Workspace service account that your administrator authorises, solely to complete sign-in
  • Workspace directory data, read to sync your employees into seats

2.6 File Uploads

Files uploaded to supported AI tools are processed by our document-redaction service (text extraction and image and face redaction) before being forwarded. We do not store the original file bytes. The redacted text of a document may be stored in the tenant's activity records under the retention periods in Section 7. When an administrator allow-lists a file, we store its SHA-256 hash, filename and size so that later copies skip redaction.

2.7 MCP Server

If your administrator enables the tenant MCP server, authorised MCP clients can access your tenant's NexusNest data using OAuth or API keys. Connections and the creation and revocation of keys are recorded in the audit log.

3. How We Use Your Information

We use collected information to:

  • Provide, maintain, and improve the Service
  • Process AI requests through the redaction pipeline and deliver redacted outputs
  • Generate audit logs and analytics for your tenant administrators
  • Process payments via Razorpay
  • Send transactional communications (account verification, billing, security alerts)
  • Detect and prevent fraud, abuse, and security incidents
  • Comply with legal obligations

We do not: sell your data, use your data to train AI models, or use your data for advertising purposes. We do not share your prompts or network logs with anyone other than the sub-processors listed in Section 5.1.

The redacted prompt is forwarded to the AI tool your employee chose, and that provider handles it under its own terms. Our commitment not to use your data for training applies to NexusNest only.

4. Data Processing and Detection

PromptWall uses a proprietary multi-layered detection engine to identify sensitive data. Key privacy guarantees:

  • Detection runs on infrastructure NexusNest operates. Analytics and reports are generated from already-redacted text by models hosted on Microsoft Azure AI Foundry, a sub-processor, and may be processed outside India on Azure's global tier. Prompts are not used to train these models
  • NexusNest never uses your data to train, fine-tune, or improve any models
  • Detection results are not shared across tenants. Each organization's data is strictly isolated
  • Under normal operation, the detection pipeline redacts sensitive content before any storage. The exceptions are described in Section 2.2.1, where unredacted content is retained inside the tenant's logs when the pipeline was unavailable to redact it or redaction was turned off

5. Data Sharing and Disclosure

We share your information only in the following circumstances:

5.1 Service Providers

  • Razorpay: Payment processing. Razorpay processes your payment information in accordance with their Privacy Policy and is PCI DSS Level 1 compliant. We do not store your full card number, CVV, or bank account details.
  • Microsoft Azure: Cloud infrastructure hosting. Data is stored in Microsoft Azure Central India. Azure AI Foundry hosts the models used for analytics and reports, which process redacted text and may run outside India. Microsoft processes data under their data processing agreement.
  • Google: Workspace directory sync and one-time passcodes for AI Control Panel accounts, and Google Analytics on our marketing site.
  • Microsoft Clarity: Session analytics on our marketing site.
  • Calendly: Scheduling of demos through the booking widget on our marketing site.
  • Resend: Delivery of transactional email.

5.2 Legal Requirements

We may disclose your information if required by law, court order, or government request, or if we believe disclosure is necessary to protect the rights, property, or safety of NexusNest, our users, or the public.

5.3 Business Transfers

In the event of a merger, acquisition, or sale of assets, your data may be transferred. We will provide notice before your personal data is transferred and becomes subject to a different privacy policy.

6. Data Security

We implement industry-standard security measures:

  • Encryption in transit: All data is encrypted using TLS 1.2+ for data in transit
  • Encryption at rest: Data is encrypted at rest with Azure-managed AES-256
  • Access controls: Role-based access control (RBAC) with least-privilege principles
  • Multi-tenant isolation: Each organization's data is logically isolated by tenant-scoped access controls enforced in the data layer
  • Secrets management: All credentials and API keys are stored in Azure Key Vault
  • Audit logging: All administrative actions are recorded in a hash-chained, tamper-evident audit log with an integrity check, and the log can be exported to your SIEM
  • Network security: The database is not reachable from the public internet
  • Incident response: We maintain a documented incident response plan with defined escalation procedures
  • Password security: Passwords are hashed using scrypt with unique salts

7. Data Retention

  • Account data and tenant content: Retained for the duration of your subscription and deleted within 30 days after termination, except payment records kept as required by law and the audit log for its configured period
  • Request metadata and redacted prompt, response and document text: Retained for 90 days by default, configurable per tenant from 1 to 365 days, then automatically deleted
  • Audit logs: Retained for 365 days by default, configurable per tenant up to 10 years
  • AI Control Panel usage samples: Retained for 180 days by default, configurable per tenant
  • Payment records: Retained as required by Indian tax law (typically 8 years)

Enterprise customers may negotiate custom retention periods. You can request early deletion of your data at any time.

8. Your Rights

8.1 Under the DPDP Act (India)

As a Data Principal, you have the right to:

  • Access a summary of your personal data and processing activities
  • Correct inaccurate or incomplete personal data
  • Erase your personal data (subject to legal retention obligations)
  • Nominate another person to exercise your rights in case of death or incapacity
  • Grievance redressal: contact our Grievance Officer (Section 13)

8.2 Other jurisdictions

We are an Indian company subject to Indian law. Customers based outside India may have additional statutory rights under their local privacy regulations; reach out to [email protected] and we will honour any reasonable request to the extent the law requires.

8.3 EU and UK visitors

The Service is directed to businesses. Residents of the EU or UK may contact [email protected] to exercise their rights under the GDPR and may complain to their local supervisory authority.

To exercise any of these rights, contact us at [email protected]. We will respond within 30 days. Employees should contact their employer first, as described in Section 1.

9. International Data Transfers

Our primary data storage is in India (Microsoft Azure Central India). AI model inference for analytics may run outside India. Where personal data is processed outside India by a sub-processor, we rely on contractual safeguards with that sub-processor and on the cross-border transfer rules under the DPDP Act and Rules.

10. Cookies and Tracking

  • Dashboard: The dashboard uses essential session cookies only, for session management and authentication
  • Marketing site: Google Analytics, Microsoft Clarity session analytics and the Calendly booking widget set cookies and send usage data to Google, Microsoft and Calendly respectively

11. Children's Privacy

The Service is for business use by adults. Employee accounts are provisioned by the employer.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes at least 30 days in advance by posting the new policy on this page and updating the “Last updated” date, with additional notice for significant changes (e.g., email notification or in-dashboard banner).

13. Contact Us

If you have questions about this Privacy Policy or our data practices:

  • Email: [email protected]
  • Grievance Officer (DPDP Act): Puru Sharma, Co-founder
  • Grievance email: [email protected]
  • Registered office: NexusNest Technologies Private Limited, New Delhi, India

We acknowledge grievances within 7 days and resolve them within the period prescribed under the DPDP Rules.