Privacy Policy

    How NexArt handles personal data and execution evidence

    Effective date: 28 June 2026

    This notice describes how NexArt handles personal data. It is provided for transparency and is not a substitute for the contractual terms in your applicable agreement. Specific points marked below may require legal review for use in particular jurisdictions.

    1. Who operates NexArt

    NexArt is operated by Artnames Ltd ("NexArt", "we", "us", "our"). Contact: security@nexart.io.

    2. What NexArt provides

    NexArt is verifiable execution infrastructure for AI and software systems. NexArt helps teams produce tamper-evident, independently verifiable execution records (including Certified Execution Records and project bundles), with a confidential mode designed to minimise raw data exposure in proof records.

    3. Roles: controller and processor

    For account management, billing, security, support, marketing, and website operations, NexArt acts as a controller of the relevant personal data.

    For customer-submitted execution content processed to produce Certified Execution Records, NexArt generally acts as a processor acting on customer instructions, subject to the applicable agreement and the customer's configuration of NexArt features. The specific allocation of roles may require legal review for particular use cases.

    4. Data we collect

    • Account and authentication data: email address and authentication identifiers (including Google OAuth, if used).
    • API key metadata: key identifiers, scopes, creation time, and revocation state. Raw API keys are hashed at rest and are not recoverable.
    • Usage and security logs: request counts, timestamps, success and error codes, request duration, and pseudonymised IP and security logs (see Security).
    • Certified Execution Record metadata: certificate hashes, execution identifiers, bundle types, attestation timestamps, lifecycle and visibility state, protocol version, runtime hash, and customer-scoped metadata fields.
    • Support and contact data: information you submit when you contact us.

    5. Execution records and confidential mode

    In confidential mode, NexArt is designed to avoid storing raw AI inputs and outputs in permanent proof records by default. Records instead use hash-bound commitments and the metadata needed for verification. Raw input and output are rejected in confidential attestation paths by default, and failed ingest paths apply redaction before persistence.

    If a customer explicitly uses a mode or integration that submits raw content (for example, a full-content mode), that content may be processed and retained according to the applicable configuration, agreement, and retention policy. Full-content mode carries a higher data-exposure profile than confidential mode and should be assessed separately.

    Retention windows for proof records are enforced by the Canonical Node and described in the CER retention policy. Legal-hold flags suspend deletion where required.

    6. Public verification records

    Public verification is based on exact-hash lookup at verify.nexart.io. The public verifier is designed not to expose raw prompts, raw inputs, raw outputs, API keys, account emails, or internal operational metadata by default. Hidden or deleted project bundles are suppressed from public lookup.

    Customers and integrating applications are responsible for the content of identifier and metadata fields they submit. Using opaque, non-personal identifiers is strongly recommended; see Privacy & data handling.

    7. Cookies and marketing tags

    NexArt uses strictly necessary cookies and storage for authentication, security, and preferences. Marketing and analytics tags, including Google Ads / Google Tag, do not load before you accept marketing cookies. You can change your preferences at any time from the Cookies page or the cookie preferences link in the footer.

    8. Sub-processors and international transfers

    NexArt uses a limited set of sub-processors to operate the service, including authentication, database hosting, email delivery, and payment processing. NexArt maintains an internal sub-processor and international-transfer register. A summary of sub-processors is available to customers under NDA via security@nexart.io. The specific legal basis for international transfers may require legal review for particular jurisdictions.

    Payments

    Payment processing is handled by Stripe. Stripe processes personal and transactional data in accordance with its own privacy policy. NexArt does not store full payment card details.

    9. Retention

    • Account and usage data are retained for the life of the account and for a reasonable period afterward for security, billing, and dispute resolution.
    • Proof-record retention follows the CER retention policy.
    • Pseudonymised security logs are retained for a limited period for incident investigation.
    • Legal-hold flags suspend deletion where required.

    10. Data subject rights

    Subject to applicable law, you may have rights of access, correction, deletion, restriction, and portability over personal data NexArt holds about you, and the right to object to certain processing. To exercise these rights, contact security@nexart.io. NexArt operates an internal DSAR register to track requests. Where NexArt acts as a processor on customer instructions, requests relating to customer-controlled data are routed via the relevant customer.

    11. Security

    See the Security architecture page for current technical controls, including confidential mode, public verifier minimisation, IP minimisation, retention enforcement, hashed API keys, and internal access governance. No method of transmission or storage is fully secure, and NexArt does not currently hold SOC 2, ISO 27001, or ISO 42001 certification.

    12. Changes to this notice

    We may update this notice as the service evolves. Material changes will be reflected on this page with an updated effective date.

    13. Contact

    Privacy, security, and data-subject requests: security@nexart.io.