1. Overview & Privacy Commitment
At NexCore Technologies Inc. ("NexCore", "we", "us", or "our"), privacy and data security are foundational principles embedded directly into our cloud architecture, machine learning algorithms, and software design.
This Privacy Policy explains how we collect, process, secure, store, and disclose information when you interact with the NexCore Platform, including our web applications, artificial intelligence APIs, enterprise automation pipelines, cloud services, and developer portals.
2. Information We Collect
We collect data across three main categories to provide, optimize, and protect our platform:
A. Information You Directly Provide Us
- Account Credentials: Name, work email address, company name, job title, encrypted password hash, and two-factor authentication metadata.
- Billing Information: Payment card tokens, corporate billing address, tax identification numbers, and transaction logs processed via PCI-DSS Level 1 payment providers.
- Support & Communications: Messages, feedback, ticket contents, and phone records submitted to our customer success or engineering teams.
B. Information Collected Automatically
- Telemetry & Diagnostics: IP address, user agent, browser fingerprinting parameters, operating system, network latency, system status, error logs, and API invocation rates.
- Usage Analytics: Feature utilization, clickstream pathways, session duration, and page view metrics collected via privacy-first aggregated tracking.
C. Customer Payload & API Inputs
Data, code snippets, prompts, datasets, or files transmitted to NexCore AI APIs or Cloud compute clusters for real-time inference or processing.
3. How We Use Your Data
We process personal data solely based on legitimate legal grounds (GDPR Article 6), including contractual necessity, legal compliance, and valid consent.
| Processing Purpose | Categories of Data | Legal Basis (GDPR / CCPA) |
|---|---|---|
| Platform Provision & Service Delivery | Account info, Billing, API Payloads | Performance of Contract |
| Security, Threat Prevention & Fraud Detection | IP addresses, Telemetry, Access logs | Legitimate Interest & Legal Obligation |
| Product Optimization & Reliability | De-identified system telemetry | Legitimate Interest |
| Customer Support & Account Communications | Account metadata, Support tickets | Performance of Contract |
| Marketing & Product Announcement Newsletters | Name, Work Email | Consent (Opt-in) |
4. Artificial Intelligence & Model Data Privacy Notice
NexCore powers next-generation Machine Learning and Large AI Models. We maintain strict safeguards regarding customer inputs and outputs:
Zero Foundation Model Training
Enterprise payloads, proprietary code, prompts, and API outputs are NEVER used to train, fine-tune, or weight foundation AI models without explicit, opt-in consent.
In-Memory Processing
Real-time inference inputs are processed in-memory (RAM) and immediately discarded upon completion, unless zero-retention logging is configured by your administrator.
5. Data Security & Encryption Standards
NexCore employs defense-in-depth security architectures certified against international standards:
-
Encryption in Transit: All data transmitted to or from NexCore endpoints is encrypted using mandatory TLS 1.3 with Perfect Forward Secrecy (PFS) and HSTS.
-
Encryption at Rest: Persistent datastores, object storage buckets, and database backups are encrypted with AES-256 with customer-managed encryption key (CMEK) options.
-
Access Controls & RBAC: Internal access to production environments follows Zero-Trust principles, requiring Hardware Security Keys (FIDO2), Multi-Factor Authentication, and just-in-time privilege authorization.
-
Continuous Auditing: Independent 3rd-party penetration testing and SOC 2 Type II audits are performed bi-annually.
6. Third-Party Sub-processors & Sharing
We do not sell personal data. We only share information with verified sub-processors necessary to operate our infrastructure, subject to Data Processing Agreements (DPAs):
- Cloud Infrastructure Providers: AWS, Google Cloud Platform, Microsoft Azure (for data hosting and GPU compute clusters).
- Payment Processors: Stripe Inc. (for secure PCI-compliant transactions).
- Communication Platforms: Twilio, SendGrid (for transaction emails and 2FA SMS verification).
- Legal Compliance: We may disclose data if required by a binding court order, valid subpoena, or lawful request by public authorities.
7. Cookies & Tracking Technologies
NexCore uses cookies and local storage tokens to deliver a smooth user experience and authenticate web sessions. You can adjust your cookie settings at any time:
8. Your Privacy Rights (GDPR & CCPA / CPRA)
Depending on your geographical jurisdiction, you possess specific statutory rights regarding your personal data:
Right to Access
Request a copy of your personal data processed by NexCore in machine-readable JSON format.
Right to Rectification
Correct inaccurate or incomplete account and profile records at any time.
Right to Erasure ("To Be Forgotten")
Request permanent deletion of your account and associated personal data logs.
Right to Object & Opt-Out
Opt-out of promotional communications, analytics profiling, or data processing.
Ready to exercise one of your statutory privacy rights?
9. Data Retention & Deletion Schedule
We retain personal data only as long as necessary to fulfill the operational purposes described in this policy:
- Active Account Data: Retained for the duration of your active subscription.
- Closed Accounts: Purged from active production databases within 30 days of account termination.
- System Audit & Security Logs: Retained for 90 days before automatic cryptographic shredding.
- Financial & Tax Records: Retained for 7 years to satisfy statutory tax obligations.
10. International Data Transfers
NexCore operates globally with primary cloud data centers located in North America, Europe (Frankfurt, Dublin), and Asia-Pacific (Tokyo, Singapore).
Cross-border data transfers from the EEA, UK, or Switzerland to third countries rely on approved legal transfer mechanisms, including the EU-U.S. Data Privacy Framework (DPF), UK Extension, and standard EU Standard Contractual Clauses (SCCs).
11. Contact Our Data Protection Officer (DPO)
If you have any questions, privacy complaints, or data protection inquiries, please reach out directly to our DPO team:
Data Protection Officer
Email: pokarkiran@gmail.com
DPO Desk: pokarkiran@gmail.com
Response Time: Within 24-48 business hours
Global Headquarters
KC App Tech
Attn: Legal & Privacy Department
100 Cybernetic Way, Suite 800
San Francisco, CA 94105, USA