Privacy notice
This notice explains what personal data Nexiel collects when you use this site (in particular when you join the waiting list through Get started): why we collect it, who it is shared with, how long it is kept, and the rights you have over it.
Who is responsible (the data controller)
The controller for personal data processed through this site is NEXIEL LTD (“Nexiel”), an Irish company that hosts its infrastructure in the EU. Nexiel has not appointed a formal Data Protection Officer. For any privacy question, or to exercise the rights described below, contact privacy@nexiel.io.
What personal data we collect, and why
The one place on this site that collects personal data directly from you is the Get started waiting list form. When you join the list, we process:
- Your email address, so we can contact you when onboarding opens for your account.
- Your name and company name, if you choose to provide them, to personalize that contact.
This is the only personal data the form collects. Nexiel Verify's end-user identity flows (EUDI wallet) are a separate matter covered under “Retention” below.
What happens if you are invited to onboard
Joining the waiting list does not by itself start an application. If we invite you to onboard, we will separately ask for company details (legal entity name, registry country and number) and beneficial owner/director details (name, and where relevant date of birth, nationality, ownership percentage, and basis of control), as part of the customer due diligence EU anti-money-laundering law requires us to perform. We will give you a further notice at that point covering that specific processing.
Purposes and legal bases
- Legitimate interest (GDPR Art. 6(1)(f)): maintaining a waiting list and contacting you about it, since you asked to join it.
- Contract, or steps prior to a contract (GDPR Art. 6(1)(b)): if you are later invited to onboard, handling that submission so you can become a Nexiel client.
Who your data is shared with (recipients and sub-processors)
Nexiel does not sell personal data or share it for advertising. To operate the waiting list, the personal data above may be processed by the following sub-processors, each only for the purpose stated:
- ZeptoMail (Zoho): transactional email delivery, for any confirmation or follow-up email we send you.
- Hetzner: the hosting provider for Nexiel's servers (EU infrastructure).
If you are later invited to onboard, additional sub-processors apply to that separate processing: OpenSanctions for sanctions/PEP screening data, Stripe for billing, and Anthropic, which helps prepare parts of your application for a human reviewer to assess and never decides the outcome. We will name these in the further notice referenced above.
International transfers
Nexiel's own infrastructure is EU-hosted. Some sub-processors named above (for example Anthropic and Stripe) are US-headquartered, so certain processing may involve a transfer outside the EEA. Where that is the case, it is intended to rely on an appropriate GDPR transfer mechanism (such as the EU Standard Contractual Clauses or an adequacy decision). Nexiel is formalizing sub-processor data-processing agreements. This notice will be updated once that work is complete.
How long we keep it (retention)
- Waiting list details are kept until we invite you to onboard, or until you ask to be removed, whichever comes first. You can ask to be removed at any time by emailing privacy@nexiel.io.
- Nexiel Verify transaction PII is deleted immediately. Raw personal data from an end-user identity or age check (name, DOB, address, document number, nationality) is never persisted beyond the single verification transaction. Deletion is enforced by TTL/cron, not a manual step. What remains afterward is only non-identifying records (session id, timestamps, boolean proofs, a SHA-256 hash of the presented token, and the screening result).
- If you are onboarded as a client, KYB/UBO customer due-diligence records are retained for the statutory AML period. EU AML law requires an obliged entity to retain beneficial-ownership/CDD records for the life of the business relationship plus a statutory period after it ends. Deleting them on a short timer would breach that legal obligation rather than satisfy data minimisation. Nexiel retains this data for five years after the end of the business relationship (the floor set by Article 40 of Directive (EU) 2015/849, carried into Article 77 of the incoming AML Regulation (EU) 2024/1624, and matched by the national transpositions in the jurisdictions Nexiel operates registry checks against: Ireland, France, Finland, Norway). An automated purge job deletes this data once the retention period lapses.
Your rights
Under the GDPR you have the right to request access to your personal data and its rectification or erasure, to object to or restrict certain processing, and to data portability. These rights are not absolute: where Nexiel is under a legal obligation to retain CDD records (see “Retention” above), an erasure request may be limited for the duration of that statutory retention period. To exercise any of these rights, contact privacy@nexiel.io.
Complaints
If you believe Nexiel has handled your personal data unlawfully, you have the right to lodge a complaint with a supervisory authority. Nexiel is established in Ireland, so the relevant authority is the Irish Data Protection Commission (dataprotection.ie). You may also complain to the supervisory authority in your own EU/EEA country of residence.
Nexiel has not appointed a Data Protection Officer. See also the legal disclaimer.