Privacy Policy
What personal data Nexiv Labs collects, why we collect it, how long we keep it, who else sees it, and the rights you have over it.
In short: we collect what we need to run the service you asked for, we keep health data in your region and never sell it, we use a small set of vetted sub-processors, and you can ask us for a copy of your data or its deletion at support@nexivlabs.com at any time. We do not sell personal data to anyone.
1. Who is responsible for your data
Nexiv Labs, trading as A-SERVICE-A, is the data controller for personal data described in this policy, except where section 14 says we act as a processor on someone else's behalf.
- Business address: Lees Street, Address line 2, Pendlebury, M27 6BU, United Kingdom
- Support address: Lees Street, Pendlebury, M27 6BU, GB
- Privacy contact: support@nexivlabs.com
- Phone: +1 (323) 289-0039
2. Scope
This policy covers our websites and all Nexiv Labs divisions: Nexiv Health, Nexiv Vet, Nexiv Pets, Nexiv Technology, Nexiv Chain and Nexiv Cloud. Where a division handles data differently — most significantly the clinical divisions — that is called out below.
3. Personal data we collect
| Category | Examples | Source |
|---|---|---|
| Identity & contact | Name, email, phone, postal address, organisation, job title | You |
| Account | Username, hashed credentials, MFA settings, preferences, role | You / generated |
| Verification | Identity documents, professional registration numbers, business licences | You / verification providers |
| Transaction | Orders, invoices, payment tokens, payout details, refunds, disputes | You / payment providers |
| Clinical | Consultation records, symptoms, prescriptions, monitoring readings, uploaded media | You / clinicians / devices |
| Animal & owner | Species, breed, age, microchip ID, vaccination and treatment history | You / practices |
| Communications | Emails, support tickets, in-app messages, call notes | You / us |
| Technical | IP address, device and browser type, timestamps, referring pages, error logs | Automatic |
| Usage | Features used, session duration, navigation paths, aggregate performance data | Automatic |
| Marketing | Subscription status, communication preferences, engagement with our emails | You / automatic |
We do not require you to provide personal data to browse our public website, beyond the strictly necessary technical data any web server receives.
4. Health and special category data
Health data receives the strongest protection we apply. It is pinned to your region, encrypted with tenant-specific keys, accessible only to named clinical roles, and every single read is written to an append-only audit log.
Where we process health data through Nexiv Health, we rely on:
- Article 9(2)(h) — provision of health or social care and the management of health care systems, where care is delivered by or under the responsibility of a professional bound by an obligation of professional secrecy; and/or
- Article 9(2)(a) — your explicit consent, where that is the appropriate basis in the context.
Health data is never used for advertising, never sold, and never used to train general-purpose AI models. Access by our engineering staff requires just-in-time elevation against a named ticket, expires automatically, and generates an entry in the operating organisation's audit log.
Animal health data processed by Nexiv Vet is not "special category" personal data under GDPR, but it is bound to an identifiable owner and we protect it to the same technical standard.
5. Why we process, and our lawful basis
| Purpose | Data used | Lawful basis |
|---|---|---|
| Providing the service you requested | Identity, account, transaction, clinical | Contract; Art. 9(2)(h) for health data |
| Taking payment and preventing payment fraud | Transaction, technical | Contract; legal obligation; legitimate interests |
| Verifying sellers and clinicians | Verification, identity | Legal obligation; legitimate interests (platform safety) |
| Support and communications | Contact, communications, account | Contract; legitimate interests |
| Security, abuse prevention and audit | Technical, usage, account | Legitimate interests; legal obligation |
| Service improvement and diagnostics | Usage, technical (aggregated or pseudonymised) | Legitimate interests |
| Marketing to businesses | Contact, marketing | Legitimate interests; consent where required |
| Legal, tax and regulatory compliance | Transaction, identity, clinical | Legal obligation |
| Establishing or defending legal claims | Any relevant category | Legitimate interests; Art. 9(2)(f) |
Where we rely on legitimate interests, we have carried out a balancing assessment and will provide a summary on request. You may object to processing based on legitimate interests — see section 11.
6. Cookies and similar technologies
We use a small number of cookies and equivalent technologies. Strictly necessary cookies (session, security, load balancing) are set without consent because the service cannot function without them. Any analytics or preference cookies are set only where you have consented. Full detail, categories and durations are in the Cookie Policy.
7. Who we share personal data with
We share personal data only in these circumstances:
- Service providers (sub-processors) — cloud infrastructure, CDN, payment processing, communications, identity verification, real-time media and observability. Each is assessed before onboarding and bound by a data processing agreement.
- Within the group — between Nexiv divisions where you use more than one service and the sharing is necessary or you have asked for it (for example, a pet's record moving from Nexiv Pets to Nexiv Vet).
- Clinical and veterinary organisations — the practice, clinic or employer responsible for your care, where that is the point of the service.
- Marketplace counterparties — the information a seller needs to fulfil your order, and the information a buyer needs to complete a purchase.
- Professional advisers — lawyers, accountants, insurers and auditors, under duties of confidentiality.
- Authorities — where required by law, court order or a competent regulator. We check that any request is valid and disclose only what is required.
- Corporate transactions — a prospective buyer or investor under confidentiality, in connection with a reorganisation, merger or sale.
We do not sell personal data, and we do not share it with third parties for their own marketing.
A current named sub-processor list is provided with our data processing agreement — request it at support@nexivlabs.com. Customers under a DPA receive 30 days' notice before a new sub-processor is added.
8. International transfers
Clinical data is pinned to your tenant's region (UK or EU) and is not replicated outside it. For other categories, where data is transferred outside the UK or EEA we rely on one of:
- an adequacy decision covering the destination country;
- the UK International Data Transfer Addendum or EU Standard Contractual Clauses, with a transfer risk assessment; or
- another lawful transfer mechanism recognised under applicable law.
Details of the safeguards applying to a specific transfer are available on request.
9. How long we keep personal data
| Data | Retention | Why |
|---|---|---|
| Account & contact | Life of the account + 12 months | Service delivery, reactivation, dispute window |
| Clinical records | As set by the responsible healthcare organisation | Clinical and legal retention obligations |
| Veterinary consult records | Typically 7 years, or as the practice directs | Professional record-keeping standards |
| Transaction & invoices | 6 years from end of the relevant tax year | Tax and accounting law |
| Verification documents | Duration of the relationship + 5 years | Anti-fraud and regulatory obligations |
| Support communications | 3 years from last contact | Service quality and dispute handling |
| Security & access logs | 12 months (clinical audit logs longer) | Security investigation and audit |
| Operational logs & traces | 30–90 days | Diagnostics; personal data minimised at ingestion |
| Marketing preferences | Until you withdraw, then a suppression record indefinitely | To honour your opt-out |
| Job applications | 12 months from decision | Future opportunities; consent-based |
When a retention period ends we delete or irreversibly anonymise the data. Backups age out on their own cycle (typically within 35 days) rather than being edited individually.
10. How we protect personal data
TLS 1.3 in transit, AES-256 at rest with per-tenant envelope keys, enforced MFA, no standing production access, default-deny network policy, signed build artefacts, append-only audit logging and quarterly disaster recovery testing. The full description is in the Trust Centre.
If a personal data breach occurs and it is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware, and notify you without undue delay where the risk is high.
11. Your rights
Under UK and EU GDPR you have the right to:
- Access — obtain a copy of the personal data we hold about you;
- Rectification — have inaccurate data corrected or incomplete data completed;
- Erasure — have data deleted, where no overriding basis to retain it applies;
- Restriction — limit how we use your data while a concern is resolved;
- Portability — receive data you gave us in a structured, machine-readable format, or have it sent to another controller where technically feasible;
- Object — object to processing based on legitimate interests, and to direct marketing at any time;
- Withdraw consent — where we rely on consent, withdraw it at any time without affecting prior processing.
To exercise any right, email support@nexivlabs.com. We respond within one month, extendable by two further months for complex requests (we will tell you if that applies). We may ask for information to verify your identity — particularly for health data, where releasing records to the wrong person is the greater harm.
Where we hold clinical data on behalf of a healthcare organisation, we will direct your request to that organisation as controller and support them in responding.
12. Automated decision-making and AI
We do not make decisions producing legal or similarly significant effects based solely on automated processing without human involvement.
Where automated systems assist, a person remains responsible for the outcome:
- Triage scoring orders a queue and flags red flags; a registered professional makes every clinical decision.
- Fraud and welfare heuristics hold a listing or transaction for review; a human reviewer decides.
- AI-assisted drafting may prepare a summary or note; the clinician edits and approves it before it enters the record.
- Search ranking orders results; paid placement is always labelled.
We do not use your personal data, and never use health data, to train general-purpose AI models. Where AI features process your content, model, prompt and dataset versions are recorded so a decision can be reconstructed. You can ask for human review of any automated flag that affected you.
13. Children
Our services are not directed at children and accounts require an adult holder. Where a service is provided to a child through a parent or guardian — for example a paediatric consultation — the adult account holder provides the information and exercises rights on the child's behalf, subject to the clinician's judgement about the child's own capacity.
If you believe a child has given us personal data without appropriate adult involvement, contact us and we will investigate and delete where appropriate.
14. When we act as a processor
For Nexiv Cloud managed services, Nexiv Technology engagements and clinical deployments operated by a healthcare organisation, that organisation is the controller and we act as processor. In those cases:
- we process only on documented instructions from the controller;
- a data processing agreement governs the relationship, including our security measures and sub-processor list;
- data subject requests should be directed to the controller, and we will assist them;
- we notify the controller without undue delay of any personal data breach affecting their data;
- on termination we delete or return the data as instructed, subject to legal retention.
15. Changes to this policy
We may update this policy. The "last updated" date will change and, for material changes, we will notify account holders by email or in-app notification at least 30 days before the change takes effect. Previous versions are available on request for 24 months.
16. Questions and complaints
Please raise any concern with us first at support@nexivlabs.com — we take privacy complaints seriously and most are resolved quickly.
You also have the right to complain to a supervisory authority. In the UK that is the Information Commissioner's Office (ICO). If you are in the EU, you may complain to the supervisory authority in your country of residence, place of work, or where the alleged infringement occurred.