— PRIVACY POLICY —

How we handle your data.

What Nexes collects, why we collect it, how long we keep it, and your rights under the Australian Privacy Act 1988 and the Privacy Act 2026 amendments.

01 · Who we are

Nexes is a trading name of Ninth Gate Holdings Pty Ltd, ABN 41 693 266 465, registered in NSW, Australia (the “Data Controller”). Contact for privacy matters: privacy@nexes.com.au.

02 · What we collect

Customer-supplied documents

When you submit a Cover Audit intake, we receive the documents you upload (insurance policy schedules, certificates of currency, WorkCover notices, payroll records, contractor agreements, intake form answers).

Identity & contact data

Name, business name, email, phone, business address, ABN/ACN where provided.

Technical data

IP address, browser type, device fingerprint hash, and standard server logs for fraud, security, and abuse monitoring. Cookies used only for session and rate-limit enforcement — no third-party advertising trackers.

Payment data

Stripe processes all payments on our behalf. We receive only the billing summary (last 4 digits of card, brand, country) — we never see or store full card numbers.

03 · How we use it

We do not sell, rent, or share your data with insurers, brokers, marketing companies, or any third party for their own commercial purposes.

04 · Where we store it

DataStorageRegion
Intake answers, contact detailsSupabase (Postgres)AU / Sydney
Uploaded documentsCloudflare R2 object storageAU / APAC
Audit reports (generated)Supabase + R2 (mirrored)AU / Sydney
Payment recordsStripe (PCI-DSS Level 1)US / EU (Stripe global)
Email delivery logsResendUS
AI processing (transient)Anthropic Claude APIUS / EU (no training data retention)

Anthropic processes documents under their commercial API terms — no data is used for model training, all transit is TLS-encrypted, all rest is AES-256-encrypted.

05 · How long we keep it

DataRetention
Uploaded source documents90 days from audit completion, then auto-deleted
Generated audit reports7 years (compliance & refund-window obligations)
Identity & contact records7 years (ATO & Corporations Act)
Payment records7 years (Stripe + our records)
Server / security logs180 days, then auto-rotated
Marketing email subscribersUntil you unsubscribe + 30 days

06 · Your rights

Under the Australian Privacy Principles you have the right to:

To exercise any of these rights, email privacy@nexes.com.au. We respond within 30 days.

07 · Privacy Act 2026 & automated decisions

The Privacy Act 2026 amendments introduce new obligations around automated decision-making. Nexes Sentinel is an AI-assisted diagnostic — every audit finding is generated by a Claude model and reviewed by a human operator before delivery. No fully-automated decisions are made about you without human oversight.

If you would like to understand how a specific finding was produced, request a methodology explanation at privacy@nexes.com.au or read our public /methodology page.

08 · Data breach notification

If we become aware of a notifiable data breach affecting your personal information, we will notify you and the OAIC within 72 hours of confirmation, as required by the Notifiable Data Breaches scheme.

09 · Children

Nexes services are intended for Australian businesses. We do not knowingly collect personal information from children under 18. If you believe we have, contact us and we will delete it.

10 · Changes to this policy

We may update this policy from time to time. Material changes will be emailed to customers whose data we hold. The latest version is always at nexes.com.au/privacy.

Quick reference: the legal scope, AFSL disclaimer, refund terms, and limitation of liability are at /legal. The methodology behind audit findings is at /methodology.

Last updated 3 June 2026 · v1.0