Legal
1
AMXNexus Technologies L.L.C. ([registered address]) is the data controller for the personal data described in this policy. For questions about it, or to exercise any of the rights below, contact [privacy@amxnexus.com].
2
We collect only what a specific function needs. Each item below names the reason it exists; where there is no reason, we do not collect it.
Account details
Your email address, your name if you provide one, and a hashed form of your password. Required to create an account, sign you in, and contact you about your orders. Passwords are stored as scrypt hashes and are never recoverable, by us or anyone else.
Organisation and role
The organisation your account belongs to and your role in it. Required to decide what you may see and do.
Orders, invoices and licences
What you bought, when, for how much, and the licence keys issued to you. Required to deliver what you paid for and to meet tax and accounting obligations.
Payment details
We do not store card numbers. Payments are processed by Stripe or PayPal, who receive your payment details directly; we store only the provider's reference, the amount and the outcome.
Sessions and devices
For each sign-in: a hashed session token, the IP address and the browser's user-agent string. Required to keep you signed in and to let you see and revoke sessions you do not recognise.
Audit records
Administrative actions taken in the platform — who changed what, and when. Required for security and accountability. These records are append-only and are not deleted on request, because a log an administrator can edit is not a record of anything.
Support messages
The content of tickets and contact forms you send us, so we can answer them.
3
Stated plainly, because a policy that only lists what is permitted tells you very little.
We do not sell personal data
Not to advertisers, data brokers, or anyone else.
We do not use advertising or tracking cookies
The site sets cookies for signing in, your language and your light/dark preference. Nothing follows you to other websites.
We do not profile you for advertising
There is no behavioural profiling and no automated decision-making that produces legal effects concerning you.
4
Where the GDPR or a comparable law applies, we rely on the following bases.
Performance of a contract
Account details, orders, invoices, licences and support — we cannot supply the service without them.
Legal obligation
Invoices and financial records, retained for the period tax law requires.
Legitimate interests
Security logging, rate limiting and fraud prevention. We have assessed these as proportionate: they are limited to what security requires and are not used for any other purpose.
Consent
Optional cookies and any marketing email. You may withdraw consent at any time, and withdrawing it is as easy as giving it.
6
Specific periods, because 'as long as necessary' tells you nothing.
Account data — until you delete the account
Deleting an account disables sign-in immediately. Orders, invoices and licences are retained, because they are financial records with their own retention obligation.
Invoices and financial records — [7] years
The period required by applicable tax law.
Sessions — 30 days, or until revoked
Expired and revoked sessions are removed.
Password reset and verification links — 1 to 24 hours
Single-use, and expired records are pruned.
Audit records — [2] years
Retained for security and accountability.
7
Contact [privacy@amxnexus.com] to exercise any of these. We respond within 30 days and do not charge for a reasonable request.
Access and portability
A copy of your personal data in a machine-readable format.
Correction
You can change your name, email and password from your account at any time.
Deletion
Subject to the retention obligations above — we cannot delete an invoice we are legally required to keep.
Objection and restriction
You may object to processing based on legitimate interests, and ask us to restrict processing while a dispute is resolved.
Complaint
You may complain to your local data protection authority. We would prefer you tell us first, but you are not required to.
8
Specific measures, so you can judge them rather than take our word for it.
Passwords are hashed with scrypt
They are never stored in a readable form and cannot be recovered — only reset.
Licence keys and provider secrets are encrypted
AES-256-GCM, with the key held outside the database, so a database copy alone does not expose them.
Two-factor authentication is available
On every account, with single-use recovery codes.
Sessions are server-side and revocable
You can see every signed-in device and end all other sessions at once.
Access is role-based and logged
Staff see only what their role requires, and administrative actions are recorded.
9
Our infrastructure and processors may be located outside your country. Where data leaves the EEA or the UK, transfers rely on Standard Contractual Clauses or an adequacy decision. Contact us for a copy of the safeguards in place.
10
AMXNexus is a business platform and is not directed at children under 16. We do not knowingly collect their data. If you believe a child has given us personal data, contact us and we will delete it.
11
If we make a material change we will tell account holders by email before it takes effect, not only by updating the date at the top of this page.
Write to [privacy@amxnexus.com]. A person reads it, and you will get an answer.

