← Back to Nekseer

Privacy Policy

Last updated: September 2, 2026

1. Who we are and who is responsible for your data

NEKSEER is a DMS (dealer management system) for used-vehicle dealerships, currently operated by [full name pending] (ID [ID pending]), prior to incorporating a company or registering as a self-employed business. This policy will be updated with a corporate name and tax ID as soon as either exists — it is not a placeholder we intend to leave unresolved.

You can reach us for anything related to this policy or your personal data at soporte@nekseer.com.

2. Scope of this policy

This policy covers: (a) anyone browsing nekseer.com, (b) anyone who contacts us by email, and (c) account holders using the NEKSEER platform (employees of the dealerships that subscribe to our service, including anyone testing the BETA program described in our Terms of Service).

It does NOT cover the personal data a dealership using NEKSEER enters into the platform about its own customers (buyers, leads, sales files). That data is governed by the privacy policy the dealership itself publishes on its own public page, configurable from its own admin panel. For that data, NEKSEER acts as processor on the dealership's behalf — see §9 below.

3. What data we collect and why

Browsing nekseer.com: only what your browser sends by default (no analytics or advertising cookies — see §10). We do not build a browsing profile of visitors.

Contacting us by email: whatever you choose to send us (name, email address, and the content of your message), used only to answer you and, where relevant, follow up on the request.

Creating a platform account: identity data (name, email, profile photo if you sign in with Google), authentication data (via Supabase Auth / Google OAuth), the company/dealership data you register, and a security/usage audit trail needed to operate the service safely.

Billing: subscription and plan-usage data. Card payments are processed entirely by Stripe — NEKSEER never stores or has access to your card details. During the BETA trial described in our Terms, no card is required at all, so there is nothing for Stripe to process until you choose to subscribe.

4. Signing in with Google ("Continue with Google")

When you click "Continue with Google" to create an account or sign in, Google shares with us only your basic profile data: your name, email address, profile photo (if you have one set), and a unique identifier for your Google account. We request only the openid, email, and profile scopes — the minimum Google offers for sign-in.

We never request, and never access, your Gmail, Google Drive, Google Calendar, Contacts, or any other Google data or service beyond that basic identification data. We do not use any sensitive or restricted Google API scope.

We use this data exclusively to create and authenticate your NEKSEER account, and to identify you within the platform (for example, showing your name and photo to your teammates). We do not share it with anyone except Supabase (our authentication provider, which stores it to manage your session), and we never use it for any other purpose — no advertising, no profiling.

You can revoke NEKSEER's access to your Google account at any time from your Google account's permissions page (myaccount.google.com/permissions), and you can ask us to delete this data by writing to soporte@nekseer.com.

Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements, to the extent they apply to the basic scopes described above.

5. Legal basis for processing

Performance of a contract (Art. 6.1.b GDPR): to provide the service to anyone who creates an account, joins the BETA program, or subscribes to a plan.

Consent (Art. 6.1.a GDPR): when you voluntarily write to us by email, or when you choose to sign in with Google.

Legitimate interest (Art. 6.1.f GDPR): to keep the service secure, prevent abuse, and improve it — always balanced against your rights.

Legal obligation (Art. 6.1.c GDPR): tax and accounting obligations, when applicable.

6. Recipients and processors (our providers)

We work with a small, deliberately short list of providers, each acting as our processor under Art. 28 GDPR (or as an independent controller for the specific service they provide, such as Stripe for payment processing itself, or Google for authentication itself):

• Supabase — database hosting, EU region. Stores your account and platform data.

• Vercel — application hosting and content delivery.

• Resend — delivery of transactional emails (confirmations, notifications, password resets).

• Stripe — subscription billing and card payment processing.

• Groq — AI inference for platform features such as the NEKIA assistant and AI-assisted email drafting; this may involve processing content you write inside the platform (e.g. email drafts, lead notes) when you actively use those features.

• Google — authentication only, when you choose to sign in with "Continue with Google" (see §4).

We never sell personal data, and we do not use it for behavioral advertising.

7. International transfers

Our database (Supabase) is hosted in the European Union, so your account and platform data are not transferred outside the EEA on that account.

Some of the providers above (Stripe, Resend, Vercel, Groq, Google) may process data outside the EEA as part of their own infrastructure. Where that happens, it is covered by the Standard Contractual Clauses approved by the European Commission or another safeguard recognized as valid under Arts. 44 et seq. GDPR.

8. Retention periods

Account data: for as long as the contractual relationship is active — including the BETA trial period and, if you continue, your paid subscription.

After account closure (including a BETA trial that is not converted into a subscription): for the period reasonably needed to comply with legal obligations (tax, accounting) and to exercise or defend against legal claims — never longer than necessary.

Contact emails: for the time needed to handle your request and, where relevant, the period reasonably required to manage the relationship that follows from it.

9. If you run a dealership on NEKSEER: our role as your processor

If you use NEKSEER to manage leads, sales, or documentation about your own customers, you are the controller of that data — NEKSEER acts as your processor (Art. 28 GDPR), handling it strictly under your instructions, only to provide you the service.

The privacy policy shown to your own end customers is the one you configure from your admin panel and that is published on your own public dealership page — this NEKSEER-level policy does not replace it, and does not describe the specific data categories, retention periods, or recipients that apply to your customers' data (those depend on your own configuration and business).

10. Cookies and similar technologies

NEKSEER does not use analytics, advertising, or third-party tracking cookies of any kind.

We only use strictly necessary technical cookies: an authentication session cookie (set by Supabase once you sign in) and an interface-preference cookie (remembers whether the workspace sidebar is collapsed). Both are exempt from consent requirements under Spanish law (Art. 22.2 LSSI-CE) and the ePrivacy Directive, because they are either essential to the service or set as a direct result of an action you take.

That is why you don't see a cookie consent banner: there is nothing non-essential to ask your consent for. If we ever add analytics or advertising cookies, we will ask for your consent before activating them, and we will update this section first.

11. Your rights

You can exercise, at any time, your rights of access, rectification, erasure, objection, restriction of processing, and data portability, by writing to soporte@nekseer.com. We will respond within the legal timeframes and, where relevant, request the identification we reasonably need to verify it's really you.

You may also withdraw consent at any time, without affecting the lawfulness of processing carried out before the withdrawal.

12. Right to complain to the supervisory authority

If you believe your rights have not been properly addressed, you can file a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos) at www.aepd.es.

13. Minors

NEKSEER's website and platform are not directed at minors under 16. If we become aware that we hold data from a minor without valid parental consent, we will delete it.

14. Changes to this policy

We may update this policy to reflect changes in the service, our providers, or the law. Material changes will be highlighted, and the date at the top of this page always reflects the last update.