Privacy Policy
1. Data Controller and Contact Details
The Data Controller for the processing of personal data is Zbigniew Jaryst, conducting business under the name Zbigniew Jaryst – Nexir Systems.
For matters concerning the processing of personal data, the Data Controller can be contacted at contact@nexir.ai.
2. Definitions
The following terms mean:
- Data Controller – Zbigniew Jaryst, conducting business under the name Zbigniew Jaryst – Nexir Systems,
- GDPR – Regulation (EU) 2016/679 concerning the protection of personal data,
- Nexir – the service provided at nexir.ai,
- Policy – the Privacy Policy,
- User – a natural person using Nexir,
- Account – the User's account enabling access to Nexir functions,
- Organization – the entity within which the User uses Nexir,
- Local Component – software operating locally in the User's IDE environment,
- Verification Session – a controlled verification stage preceding the implementation of Nexir in the Organization.
3. Scope of the Privacy Policy
The Policy sets out the rules for processing personal data related to the use of Nexir.
It covers two distinct areas of data processing.
Public Layer
Covers data processed within the Nexir infrastructure.
It includes:
- using the Nexir website,
- contacting the Data Controller,
- creating and operating the Account,
- using the organization panel,
- preparing and conducting the Verification Session,
- organizing access to the service.
In this area, data is processed to the extent necessary to provide the service and manage relations with the User and the Organization.
Organization Environment
Covers the area where Nexir operates in the User's development environment and the Organization's infrastructure.
In this area:
- operations using AI models are executed outside the Nexir infrastructure,
- source code and file context are transmitted to AI models to the extent determined by the Organization and its configuration,
- Nexir does not process or store the content of operations, including code, prompts, and model responses.
On the Nexir side, operational metadata and system events described in the Policy are processed.
Separation of Scopes
The public layer and the Organization environment are logically and technically separated from each other.
The Policy covers data processed within the Data Controller's infrastructure and systems.
Operations performed in the Organization environment, including the processing of source code, remain outside the scope of data processing within Nexir.
4. Verification Session
The Verification Session constitutes a separate stage preceding the implementation of the service.
The session does not require integration with the Organization's systems or access to its internal environment. It is not conducted on the Organization's private repositories or using its internal source code.
For the purposes of the session, a copy of the repository indicated by the Organization, prepared for the needs of the Verification Session, is used.
As part of the session, the Data Controller processes data necessary for its organization, execution, and documentation of the result.
5. What Data We Process
The Data Controller processes data necessary to provide the service, organize access, and ensure the security and proper operation of Nexir.
Depending on the scope of using the service, this may include:
- identification and contact data – used to create the Account, contact the User, and manage relations with the Organization,
- Account and access-related data – used for authentication, access management, assignment to the Organization, and use of service functions,
- operational and technical data – including metadata of system events, technical identifiers, and information necessary to ensure the security, integrity, and stable operation of the service.
The detailed scope of data has been described further in the Policy.
6. Data Processing Architecture
The data processing architecture in Nexir is based on data minimization and the separation of system layers.
AI Operations Processing Model
Operations using AI models are executed from the level of the User's environment – directly to the infrastructure of the AI model provider indicated by the Organization using the Organization's key, or through the Organization's internal intermediary layer connected to the Local Component.
The content of these operations, including the prompt, model response, code context, and file fragments, is not transmitted through the Nexir infrastructure.
No Access to Source Code
The Nexir infrastructure does not have access to the Organization's repositories, source code, file structure, or change history.
Repository analysis for the purposes of the rollout report is performed locally in the Organization's environment by the Nexir Impact Service, and only aggregated metrics results are transmitted to the Nexir infrastructure, without repository source data.
Operational Telemetry
On the Nexir side, operational metadata related to the system's operation is processed, in particular the type of operation, its status, duration, and technical events related to its operation.
This data does not include source code, prompts, model responses, or file context. It is used to analyze system operation and aggregate metrics for the Organization.
Connection Model with AI Model Provider
The Organization can use Nexir in two models: using its own access key to the AI model entered in the Nexir panel, or using its own internal intermediary layer connected to the Local Component.
In the API key-based model, the key is stored in an encrypted form, is not revealed in the user interface, and is used solely for the time necessary to execute the request to the model, exclusively in the operational memory of the Local Component.
In the model based on the internal intermediary layer, the model call takes place within the Organization's infrastructure, in accordance with the method adopted by the Organization for managing access and traffic to the API.
Separation of System Layers
The Nexir architecture separates three areas: operational metadata, operation control mechanisms, and rollout results analysis.
Telemetry does not include data from the repository, and the rollout results analysis performed by the Nexir Impact Service remains separate from telemetry and the processing of AI operations.
Processing Model Summary
Nexir processes operational data necessary for the system's operation.
The content of operations performed using AI models, including source code, remains outside the Nexir infrastructure and is neither processed nor stored within it.
7. Purposes and Legal Bases for Processing
Personal data is processed for the following purposes and on the following legal bases:
-
contact and correspondence handling
basis: Art. 6(1)(f) GDPR – the Data Controller's legitimate interest in conducting communication related to the service, -
creation and maintenance of the Account and providing access to service functions
basis: Art. 6(1)(b) GDPR – processing is necessary for the performance of a contract or to take steps prior to entering into a contract, -
organization and execution of the Verification Session and handling access to the service
basis: Art. 6(1)(f) GDPR – the Data Controller's legitimate interest in enabling the verification of Nexir's operation and organizing access to the service, -
ensuring the security, integrity, and continuity of the service's operation, including detecting and mitigating abuse
basis: Art. 6(1)(f) GDPR – the Data Controller's legitimate interest, -
maintaining the quality of the service's operation and analyzing operational and technical events
basis: Art. 6(1)(f) GDPR – the Data Controller's legitimate interest in maintaining the quality, stability, and accountability of the service's operation.
8. Data Recipients and Data Transfer Outside the EU/EEA
Personal data may be transferred to entities supporting the Data Controller in maintaining, securing, and providing Nexir, to the extent necessary for the service's operation.
Data recipients include providers of hosting, email, technical infrastructure, payment processing, service maintenance and development, and – within the scope resulting from the processing model – AI model providers indicated by the Organization.
If, in connection with providing the service, personal data is transferred outside the EU or the EEA, the Data Controller applies the mechanisms required by the GDPR, appropriate to the nature of the given transfer, in particular an adequacy decision or standard contractual clauses approved by the European Commission.
9. Data Retention Period
Personal data is stored for the period necessary to fulfill the purposes of its processing.
The following retention rules apply:
-
Account data and data related to the Organization
are stored for the period of Account activity; after its deletion, they are subject to deletion or anonymization within up to 30 days, -
Verification Session results and data necessary to document its result
are stored for the duration of the Account's existence; after its deletion, they are subject to anonymization within up to 30 days, -
copy of the repository indicated by the Organization, prepared for the needs of the Verification Session
is subject to deletion within up to 3 months from the sharing of the session results, -
detailed operational metadata and system events
are stored for a period of up to 14 days; after this period, they are subject to aggregation, and after the termination of service provision – anonymization or deletion, -
aggregated and anonymized data
may be used for comparative analyses and creating aggregate reference indicators presented in Nexir and stored for up to 3 years to analyze trends and maintain service quality, without the possibility of identifying the User or the Organization.
In the event of termination of access to Nexir on the Data Controller's initiative, data may be stored for the period necessary to ensure security, accountability of the system's operation, and analysis of events, not longer than 90 days, and are then deleted or anonymized.
10. Data Security
The Data Controller applies technical and organizational measures appropriate to the nature of the service, the scope of processing, and the level of risk.
The Nexir security model is based on data minimization, local operation control, and the separation of system layers.
Within the Nexir infrastructure, operational metadata necessary for the system's operation is processed. Nexir does not process source code, prompts, model responses, or file context.
Operation control takes place in the User's environment. Operations are evaluated locally against applicable rules, and violations are blocked before their execution in a fail-closed model.
The Organization may limit the scope of data used in operations, in particular to selected directories, files, or repository areas. These restrictions are enforced locally.
Communication with the service is secured using HTTPS/TLS. Access keys to AI models are stored in an encrypted form.
The system logs event metadata to the extent necessary to ensure security and operational accountability.
The Nexir security model is based on controlling operations before their execution, limiting the scope of data available to the system, and separating processing layers, rather than monitoring the content of the user's work.
11. Rights of Data Subjects
The data subject has the rights set out in the GDPR, in particular:
- the right of access to data,
- the right to rectify data,
- the right to erase data,
- the right to data portability,
- the right to restrict processing,
- the right to object to processing, in cases provided for by law,
- the right to lodge a complaint with the President of the Personal Data Protection Office.
Requests regarding the exercise of rights can be sent to the address: contact@nexir.ai.
The Data Controller provides a response without undue delay, no later than within the time limit provided for in the GDPR.
12. Cookies, Similar Technologies, and Product Analytics
Nexir does not use marketing or advertising cookies and does not use external analytical tools for User profiling.
Data on how the service is used, including interactions with its functions, is processed within internal product analytics for the needs of the service's operation, maintaining its quality, and ensuring security, without being used for marketing purposes or User profiling.
13. Changes to the Privacy Policy
The Data Controller may update the Policy in the event of legal, organizational, technical changes or changes regarding the method of providing the service.
The current version of the Policy is published in Nexir along with its effective date.
In the case of changes significantly affecting the rules of personal data processing, Users with an Account are informed electronically.
Changes apply from the day indicated in the updated version of the Policy.
If you have questions about this document, please contact us at contact@nexir.ai