Nexyfab · Privacy Policy
Privacy Policy
Nexyfab protects user's personal information and
manages it safely in compliance with relevant laws.
Effective Date: August 28, 2026
1. Personal Information Collected
The Company may collect the following information to provide services.
① Customer (Project Client)
- Name
- Contact (Phone, Email)
- Company Name
- Project requirements, drawings, files
- Consultation and communication records
② Partner (Developer/Manufacturer)
- Name
- Contact
- Company name and business information
- Technology, equipment info, portfolio
- Project history and related materials
③ Account and Pilot Users
- Email address
- Name (optional)
- Pilot participation and project usage records
- Plan and billing records only if payments are enabled and the user initiates payment (card numbers are handled by the processor and not stored by us)
- Service usage records
④ Automatically Collected
- Access logs
- IP address
- Cookies
- Service usage records
- Browser and device info
2. Purpose of Collection and Use
- Service provision and project intake
- Partner matching and recommendation
- Account registration, identity verification
- Payment processing and invoicing only when payments are enabled and requested (not applicable to the current no-payment pilot)
- Customer inquiry and support
- NDA procedures and collaboration support
- Service improvement and internal management
- Legal compliance
3. Retention and Use Period
Personal information is destroyed without delay once the purpose is achieved. The following are retained after account deletion per applicable law:
- Contract and billing records: 5 years (E-Commerce Act)
- Consumer complaints and disputes: 3 years (E-Commerce Act)
- Access log records: 1 year (Communications Secrecy Act)
- Payment and supply records: 5 years (E-Commerce Act)
- Files uploaded without a quote request: 30 days; RFQ-only files without a contract: 90 days; completed-contract files: 180 days after completion
- Private drawings, prompts, and outputs are not used to train public/shared AI models by default; training use requires separate explicit opt-in or a written agreement
4. Provision to Third Parties
The Company does not provide personal information to third parties in principle. Exceptions:
- Customer → Matched Partner (for project, with user consent)
- Partner → Relevant Customer (for collaboration, with user consent)
- If payments are enabled and the user initiates payment: the applicable payment processor (payment purpose only; card data not retained by us)
- When the user separately consents
- When required by law (e.g. law enforcement)
The Company does not provide personal information beyond the scope of the intended use.
5. Entrustment of Personal Information Processing
The Company entrusts personal information processing to the following vendors. We supervise to ensure data security per applicable law.
| Vendor | Entrusted Task | Location |
|---|---|---|
| Stripe / Toss Payments / Airwallex | Payment processing and billing only after payments are enabled and initiated | United States / South Korea / Hong Kong·Australia |
| Cloudflare, Inc. | File storage (R2), CDN, DNS | United States |
| Railway Corp. | Service infrastructure hosting | United States |
| OpenAI / Alibaba Cloud (Qwen) / DeepSeek | Requirements and drawing analysis or generation with the selected/configured AI model | United States / Singapore·China / China |
| Resend or configured SMTP provider | Account verification and customer-support email delivery | Varies by provider |
| Sentry | Error and performance diagnostics when configured, with sensitive-data minimization | United States |
| Google reCAPTCHA / Google Analytics / PostHog | Abuse prevention and consent-based analytics | United States |
6. User Rights
Users may exercise the following rights at any time:
- Request to access personal information
- Request to correct or delete personal information
- Request to suspend processing
- Withdraw consent (mandatory info may limit service access)
To exercise rights, email nexyfab@nexysys.com. The Company will act within 10 business days.
7. Destruction Procedure and Method
When retention periods expire or purposes are met, electronic files are deleted irrecoverably, and paper documents are shredded or incinerated.
8. Data Protection Officer
9. Policy Changes
This policy may change according to law or company policy, and notice will be provided on the service screen. For significant changes, prior email notice will be sent.