Nexara

Privacy Policy

Effective date: 7 July 2026 · Last updated: 7 July 2026

1. Who we are

Nexara Private Limited, which operates nexaragroups.com (“Nexara”, “we”, “our”, or “us”), is a talent and technology company based in Visakhapatnam, Andhra Pradesh, India. We build AI-powered software, communication and automation platforms, CRM integrations, and digital-marketing tools for businesses, and we operate this website. For personal data we determine the purposes and means of processing, we act as the Data Fiduciary under India’s Digital Personal Data Protection Act, 2023 (“DPDP Act”) and as the Data Controller under the EU/UK General Data Protection Regulation (“GDPR”). Where we process data on behalf of a business client under their instructions, we act as a Data Processor and that client is the fiduciary/controller.

2. Scope

This policy covers personal data processed through (a) this website, (b) our products and platforms, and (c) integrations you or our clients authorise, including Meta products such as the WhatsApp Business Platform, Facebook Login, and Instagram APIs. It does not cover third parties’ own products, which are governed by their own policies.

3. Data we collect

You provide to us

Collected automatically

From Meta products (when authorised)

4. How we use data

We do not sell personal data or Platform Data, and we do not use Platform Data for advertising.

5. Lawful basis

PurposeDPDP ActGDPR Art. 6
Analytics cookiesConsentConsent (6(1)(a))
Responding to enquiriesConsent / voluntary provisionLegitimate interests / pre-contract (6(1)(b),(f))
Providing the servicePerformance of contract / legitimate useContract (6(1)(b))
Security & fraud preventionLegitimate useLegitimate interests (6(1)(f))
Legal complianceCompliance with lawLegal obligation (6(1)(c))

You may withdraw consent at any time; this does not affect processing already carried out.

6. Meta Platform Data

When a client authorises a Meta integration, Nexara accesses and processes Platform Data solely to provide messaging, automation, customer support, analytics, and related business services on the client’s instructions. We use Platform Data only for these permitted purposes, keep it only as long as needed to provide the service, and protect it under §14. We do not sell Platform Data, transfer it to a data broker, or use it to build user profiles for advertising. Deletion of Platform Data is described in §11 and on our Data Deletion page. Our use of information received from Meta APIs adheres to the Meta Platform Terms and Developer Policies.

7. Sharing & processors

We share the minimum data necessary with vetted service providers who act on our instructions under contract:

ProviderRole
Google (Google Analytics)Consent-based website usage measurement
CloudflareWebsite hosting, delivery, and security
Amazon Web Services (AWS)Cloud infrastructure and storage
Auth0 / identity providerUser authentication
Meta PlatformsMessaging via WhatsApp Business Platform, Facebook Login, Instagram APIs

We may also disclose data where required by law, to enforce our agreements, or to protect the rights, safety, and security of Nexara, our users, or the public. We do not sell personal information.

8. International transfers

Some providers may store or process data outside India or the EEA. Where they do, transfers are protected by appropriate safeguards — such as Standard Contractual Clauses or an adequacy decision — and by the provider’s contractual and technical protections.

9. Retention

We keep personal data only as long as necessary for the purpose collected, to comply with legal obligations, resolve disputes, and enforce agreements. Enquiry data is kept for the duration of our engagement plus a reasonable follow-up period; Platform Data is kept only while the client’s integration is active or as instructed by the client; Google Analytics data is retained per our GA4 data-retention setting. When a purpose is served or consent is withdrawn, we delete or anonymise the data.

10. Your rights

Under the DPDP Act 2023, you may: access your personal data; correct or complete it; erase it; withdraw consent; nominate another person to exercise your rights; and seek grievance redressal (§15). As a Data Principal you also have duties, including not raising false or frivolous complaints and furnishing authentic information.

Under the GDPR (if you are in the EU/UK), you may request access, rectification, erasure, restriction, and portability, object to processing, and withdraw consent. You may also lodge a complaint with your supervisory authority.

To exercise any right, contact us (§15). We verify identity before acting and respond within the timelines required by applicable law (and in any case without undue delay).

11. Data deletion

You can request deletion of your personal information or authorised Platform Data at any time. Full instructions, including what to include and our processing timeline, are on our Data Deletion page, or email info@nexaragroups.com. We action verified requests in accordance with applicable law and our contractual obligations to clients.

12. Cookies

We use essential storage to run the site and, only with your consent, Google Analytics cookies. Until you accept, analytics runs in a consent-denied state and sets no _ga cookies (Google Consent Mode v2). You can change or withdraw your choice anytime via Cookie Preferences in the footer. Full details and the cookie table are in our Cookie Policy.

13. Children

Our services are not directed to children. Under the DPDP Act we do not knowingly process the personal data of anyone under 18 in India without verifiable consent of a parent or lawful guardian; in other jurisdictions we apply the minimum digital-consent age (for example, 13 where applicable). We do not carry out tracking or targeted advertising directed at children. If you believe a child has provided us data, contact us and we will delete it.

14. Security

We apply reasonable administrative, technical, and organisational safeguards — including encryption in transit, access controls, and least-privilege practices — to protect data from unauthorised access, disclosure, alteration, or destruction. No method of transmission or storage is perfectly secure. In the event of a personal-data breach, we will notify affected individuals and the Data Protection Board of India (and other regulators where required) as mandated by law.

15. Grievance Officer & contact

For any privacy request, question, or complaint, contact our Grievance Officer:

G Pala Raju, Grievance Officer
Nexara, Visakhapatnam, Andhra Pradesh, India
Email: info@nexaragroups.com

We acknowledge grievances promptly and resolve them within the period prescribed by applicable law.

16. Changes

We may update this policy from time to time. Material changes will be reflected in the “Last updated” date above, and continued use of our services after an update indicates acceptance of the revised policy.

Framework: DPDP Act 2023, read with the Information Technology Act 2000 and the SPDI Rules 2011; GDPR for EU/UK visitors; Meta Platform Terms and Developer Policies for Platform Data.