Nexiv Labs is now operating six divisions across healthcare, veterinary, commerce and infrastructure. See the group →
Legal

Privacy Policy

What personal data Nexiv Labs collects, why we collect it, how long we keep it, who else sees it, and the rights you have over it.

Last updated: 13 August 2026 Version 3.0 UK GDPR & EU GDPR

In short: we collect what we need to run the service you asked for, we keep health data in your region and never sell it, we use a small set of vetted sub-processors, and you can ask us for a copy of your data or its deletion at support@nexivlabs.com at any time. We do not sell personal data to anyone.

1. Who is responsible for your data

Nexiv Labs, trading as A-SERVICE-A, is the data controller for personal data described in this policy, except where section 14 says we act as a processor on someone else's behalf.

  • Business address: Lees Street, Address line 2, Pendlebury, M27 6BU, United Kingdom
  • Support address: Lees Street, Pendlebury, M27 6BU, GB
  • Privacy contact: support@nexivlabs.com
  • Phone: +1 (323) 289-0039

2. Scope

This policy covers our websites and all Nexiv Labs divisions: Nexiv Health, Nexiv Vet, Nexiv Pets, Nexiv Technology, Nexiv Chain and Nexiv Cloud. Where a division handles data differently — most significantly the clinical divisions — that is called out below.

3. Personal data we collect

CategoryExamplesSource
Identity & contactName, email, phone, postal address, organisation, job titleYou
AccountUsername, hashed credentials, MFA settings, preferences, roleYou / generated
VerificationIdentity documents, professional registration numbers, business licencesYou / verification providers
TransactionOrders, invoices, payment tokens, payout details, refunds, disputesYou / payment providers
ClinicalConsultation records, symptoms, prescriptions, monitoring readings, uploaded mediaYou / clinicians / devices
Animal & ownerSpecies, breed, age, microchip ID, vaccination and treatment historyYou / practices
CommunicationsEmails, support tickets, in-app messages, call notesYou / us
TechnicalIP address, device and browser type, timestamps, referring pages, error logsAutomatic
UsageFeatures used, session duration, navigation paths, aggregate performance dataAutomatic
MarketingSubscription status, communication preferences, engagement with our emailsYou / automatic

We do not require you to provide personal data to browse our public website, beyond the strictly necessary technical data any web server receives.

4. Health and special category data

Health data receives the strongest protection we apply. It is pinned to your region, encrypted with tenant-specific keys, accessible only to named clinical roles, and every single read is written to an append-only audit log.

Where we process health data through Nexiv Health, we rely on:

  • Article 9(2)(h) — provision of health or social care and the management of health care systems, where care is delivered by or under the responsibility of a professional bound by an obligation of professional secrecy; and/or
  • Article 9(2)(a) — your explicit consent, where that is the appropriate basis in the context.

Health data is never used for advertising, never sold, and never used to train general-purpose AI models. Access by our engineering staff requires just-in-time elevation against a named ticket, expires automatically, and generates an entry in the operating organisation's audit log.

Animal health data processed by Nexiv Vet is not "special category" personal data under GDPR, but it is bound to an identifiable owner and we protect it to the same technical standard.

5. Why we process, and our lawful basis

PurposeData usedLawful basis
Providing the service you requestedIdentity, account, transaction, clinicalContract; Art. 9(2)(h) for health data
Taking payment and preventing payment fraudTransaction, technicalContract; legal obligation; legitimate interests
Verifying sellers and cliniciansVerification, identityLegal obligation; legitimate interests (platform safety)
Support and communicationsContact, communications, accountContract; legitimate interests
Security, abuse prevention and auditTechnical, usage, accountLegitimate interests; legal obligation
Service improvement and diagnosticsUsage, technical (aggregated or pseudonymised)Legitimate interests
Marketing to businessesContact, marketingLegitimate interests; consent where required
Legal, tax and regulatory complianceTransaction, identity, clinicalLegal obligation
Establishing or defending legal claimsAny relevant categoryLegitimate interests; Art. 9(2)(f)

Where we rely on legitimate interests, we have carried out a balancing assessment and will provide a summary on request. You may object to processing based on legitimate interests — see section 11.

6. Cookies and similar technologies

We use a small number of cookies and equivalent technologies. Strictly necessary cookies (session, security, load balancing) are set without consent because the service cannot function without them. Any analytics or preference cookies are set only where you have consented. Full detail, categories and durations are in the Cookie Policy.

7. Who we share personal data with

We share personal data only in these circumstances:

  • Service providers (sub-processors) — cloud infrastructure, CDN, payment processing, communications, identity verification, real-time media and observability. Each is assessed before onboarding and bound by a data processing agreement.
  • Within the group — between Nexiv divisions where you use more than one service and the sharing is necessary or you have asked for it (for example, a pet's record moving from Nexiv Pets to Nexiv Vet).
  • Clinical and veterinary organisations — the practice, clinic or employer responsible for your care, where that is the point of the service.
  • Marketplace counterparties — the information a seller needs to fulfil your order, and the information a buyer needs to complete a purchase.
  • Professional advisers — lawyers, accountants, insurers and auditors, under duties of confidentiality.
  • Authorities — where required by law, court order or a competent regulator. We check that any request is valid and disclose only what is required.
  • Corporate transactions — a prospective buyer or investor under confidentiality, in connection with a reorganisation, merger or sale.

We do not sell personal data, and we do not share it with third parties for their own marketing.

A current named sub-processor list is provided with our data processing agreement — request it at support@nexivlabs.com. Customers under a DPA receive 30 days' notice before a new sub-processor is added.

8. International transfers

Clinical data is pinned to your tenant's region (UK or EU) and is not replicated outside it. For other categories, where data is transferred outside the UK or EEA we rely on one of:

  • an adequacy decision covering the destination country;
  • the UK International Data Transfer Addendum or EU Standard Contractual Clauses, with a transfer risk assessment; or
  • another lawful transfer mechanism recognised under applicable law.

Details of the safeguards applying to a specific transfer are available on request.

9. How long we keep personal data

DataRetentionWhy
Account & contactLife of the account + 12 monthsService delivery, reactivation, dispute window
Clinical recordsAs set by the responsible healthcare organisationClinical and legal retention obligations
Veterinary consult recordsTypically 7 years, or as the practice directsProfessional record-keeping standards
Transaction & invoices6 years from end of the relevant tax yearTax and accounting law
Verification documentsDuration of the relationship + 5 yearsAnti-fraud and regulatory obligations
Support communications3 years from last contactService quality and dispute handling
Security & access logs12 months (clinical audit logs longer)Security investigation and audit
Operational logs & traces30–90 daysDiagnostics; personal data minimised at ingestion
Marketing preferencesUntil you withdraw, then a suppression record indefinitelyTo honour your opt-out
Job applications12 months from decisionFuture opportunities; consent-based

When a retention period ends we delete or irreversibly anonymise the data. Backups age out on their own cycle (typically within 35 days) rather than being edited individually.

10. How we protect personal data

TLS 1.3 in transit, AES-256 at rest with per-tenant envelope keys, enforced MFA, no standing production access, default-deny network policy, signed build artefacts, append-only audit logging and quarterly disaster recovery testing. The full description is in the Trust Centre.

If a personal data breach occurs and it is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware, and notify you without undue delay where the risk is high.

11. Your rights

Under UK and EU GDPR you have the right to:

  • Access — obtain a copy of the personal data we hold about you;
  • Rectification — have inaccurate data corrected or incomplete data completed;
  • Erasure — have data deleted, where no overriding basis to retain it applies;
  • Restriction — limit how we use your data while a concern is resolved;
  • Portability — receive data you gave us in a structured, machine-readable format, or have it sent to another controller where technically feasible;
  • Object — object to processing based on legitimate interests, and to direct marketing at any time;
  • Withdraw consent — where we rely on consent, withdraw it at any time without affecting prior processing.

To exercise any right, email support@nexivlabs.com. We respond within one month, extendable by two further months for complex requests (we will tell you if that applies). We may ask for information to verify your identity — particularly for health data, where releasing records to the wrong person is the greater harm.

Where we hold clinical data on behalf of a healthcare organisation, we will direct your request to that organisation as controller and support them in responding.

12. Automated decision-making and AI

We do not make decisions producing legal or similarly significant effects based solely on automated processing without human involvement.

Where automated systems assist, a person remains responsible for the outcome:

  • Triage scoring orders a queue and flags red flags; a registered professional makes every clinical decision.
  • Fraud and welfare heuristics hold a listing or transaction for review; a human reviewer decides.
  • AI-assisted drafting may prepare a summary or note; the clinician edits and approves it before it enters the record.
  • Search ranking orders results; paid placement is always labelled.

We do not use your personal data, and never use health data, to train general-purpose AI models. Where AI features process your content, model, prompt and dataset versions are recorded so a decision can be reconstructed. You can ask for human review of any automated flag that affected you.

13. Children

Our services are not directed at children and accounts require an adult holder. Where a service is provided to a child through a parent or guardian — for example a paediatric consultation — the adult account holder provides the information and exercises rights on the child's behalf, subject to the clinician's judgement about the child's own capacity.

If you believe a child has given us personal data without appropriate adult involvement, contact us and we will investigate and delete where appropriate.

14. When we act as a processor

For Nexiv Cloud managed services, Nexiv Technology engagements and clinical deployments operated by a healthcare organisation, that organisation is the controller and we act as processor. In those cases:

  • we process only on documented instructions from the controller;
  • a data processing agreement governs the relationship, including our security measures and sub-processor list;
  • data subject requests should be directed to the controller, and we will assist them;
  • we notify the controller without undue delay of any personal data breach affecting their data;
  • on termination we delete or return the data as instructed, subject to legal retention.

15. Changes to this policy

We may update this policy. The "last updated" date will change and, for material changes, we will notify account holders by email or in-app notification at least 30 days before the change takes effect. Previous versions are available on request for 24 months.

16. Questions and complaints

Please raise any concern with us first at support@nexivlabs.com — we take privacy complaints seriously and most are resolved quickly.

You also have the right to complain to a supervisory authority. In the UK that is the Information Commissioner's Office (ICO). If you are in the EU, you may complain to the supervisory authority in your country of residence, place of work, or where the alleged infringement occurred.