NexaVett Privacy Policy
Last Updated: June 10, 2026
Welcome to NexaVett (“Company”, “we”, “us”, or “our”). We act as an objective, third-party technical governance, escrow administration, and code auditing ecosystem. We are deeply committed to protecting your personal data and your organization’s proprietary engineering assets.
This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website (nexavett.com), use our digital escrow integration pathways, or engage our manual repository auditing and fractional CTO services.
1. Global Regulatory Compliance Statement
To accommodate our cross-border operations, this policy is structured to meet the global data protection requirements of:
- The United States: The California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), and other applicable state-level privacy statutes.
- The European Union & United Kingdom: The General Data Protection Regulation (GDPR) and UK GDPR.
- The Middle East: The United Arab Emirates Federal Decree-Law No. 45 of 2021 on Personal Data Protection (PDPL) and the Saudi Arabian Personal Data Protection Law (PDPL).
2. Information We Collect
We collect information that identifies, relates to, or could reasonably be linked with a specific individual or organization (“Personal Data”).
A. Information You Voluntarily Provide Us:
- Identity and Contact Data: First name, last name, business email address, corporate phone number, and physical office location.
- Professional and Employment Data: Job title, company name, industry sector, and technical stack configurations.
- Project Ecosystem Assets: Software architectural requirements, Business Requirements Documents (BRDs), Functional Specification Documents (FSDs), and requests for proposals (RFPs).
- Financial and Transactional Data: Banking coordinates, corporate KYC documentation (e.g., tax IDs, articles of incorporation), corporate registration numbers, and transactional logs necessary to administer milestone-locked escrow integrations.
B. Information Collected Automatically:
- Technical Logs: IP addresses, browser types, operating systems, geographic location, device identifiers, and website interaction metrics (via cookies and tracking pixels).
C. Information From Third-Party Integrations:
- Source Control Metadata: When you link your version control platforms (e.g., GitHub, GitLab, Bitbucket) to NexaVett for manual code forensics, we fetch metadata, pull request details, and commit logs. Note: We do not store your core codebase permanently unless explicitly requested for deep offline analysis; we access it live to conduct structural audits.
3. Legal Basis for Processing (GDPR & Middle East PDPL)
If you reside within the European Economic Area (EEA), UK, or the Middle East (UAE/KSA), we process your personal data under the following valid legal bases:
- Performance of a Contract: To manage your account, process escrow deposits, and execute architectural scoping or repository forensics.
- Legitimate Interests: To optimize our website performance, secure our tech ecosystem against malicious code or fraudulent payouts, and manage our partner referral network.
- Legal Obligation: To satisfy global Anti-Money Laundering (AML) and Know Your Customer (KYC) requirements dictated by banking escrow partners.
4. How We Use Your Information
We use your data strictly to execute our operational governance model:
- To draft, verify, and validate technical software requirements (BRD/FSD).
- To facilitate milestone authorization and administer split-payout triggers within our regulated tripartite escrow infrastructure.
- To coordinate manual repository code auditing and assign Fractional CTO advisory resources.
- To calculate and settle referral disbursements under our Channel Partner program.
- To comply with statutory legal, accounting, and anti-fraud mandates.
5. Data Sharing and Cross-Border Transfers
NexaVett will never sell, rent, or lease your personal or corporate data to third-party data brokers. We share your information only under strict operational conditions:
- With Your Chosen IT Partner/Client: We share technical specifications, milestone parameters, and validation verdicts with the explicit counterparty involved in your tripartite contract.
- With Regulated Banking/Escrow Infrastructure Providers: Financial data and corporate KYC metadata are shared directly with certified banking escrow portals (e.g., Castler, Tazapay, or regional banking APIs) to authorize frozen capital allocations.
- Cross-Border Transfers: Because NexaVett operates globally, your data may be transferred to and processed in countries outside your home jurisdiction (including the US, EU, and Middle East). We utilize Standard Contractual Clauses (SCCs) approved by the European Commission, alongside equivalent localization protocols under UAE and Saudi PDPL, to ensure your data retains maximum security during transit.
6. Data Retention and Code Security Protocols
- Administrative Data: We retain your identity and account details for as long as your service subscription or channel partnership remains active, or as required by global financial recording laws (typically 5 to 7 years).
- Proprietary Code Auditing Data: Source code pulled during manual Git forensics is reviewed within volatile sandbox environments. Once a milestone is cleared and authorized for payout release, structural metadata reports are retained for your client dashboard record, but temporary code caches are securely purged from our staging environments.
7. Your Global Privacy Rights
Depending on your geographic location, you hold comprehensive rights regarding your Personal Data:
🇪🇺 EU / UK (GDPR) Rights:
- Right of Access & Portability: Request a copy of your personal data in a machine-readable format.
- Right to Rectification or Erasure: Correct inaccurate data or demand the complete deletion of your records (“Right to be Forgotten”).
- Right to Object/Restrict: Halt automated backend processing under certain operational conditions.
🇺🇸 United States (CCPA/CPRA) Rights:
- Right to Know: Discover what personal data elements we have collected, used, and disclosed.
- Right to Delete: Request the deletion of personal information collected from you.
- Right to Non-Discrimination: NexaVett will never deny services or alter pricing if you exercise your statutory privacy rights.
- Opt-Out: Since NexaVett does not sell personal data, there is no requirement to opt out of the sale of your records.
🇦🇪 🇸🇦 Middle East (UAE & Saudi PDPL) Rights:
- Right to Erasure and Cessation of Processing: You can withdraw your operational consent for storage at any time, subject to active transactional escrow pipelines which must be legally settled before account closure.
- Right to Information: Access clear descriptions of the security controls shielding your financial and identity files.
To exercise any of these rights, please submit an official verification request to privacy@nexavett.com.
8. Security Measures
NexaVett employs top-tier organizational and technological safeguards. All financial transaction channels operate via bank-grade TLS/SSL encryption protocols. Access to code repositories and financial escrow configurations is restricted strictly to verified technical architects bound by comprehensive, legally enforceable corporate Non-Disclosure Agreements (NDAs).
9. Contact Information
If you have any questions, compliance concerns, or data requests regarding this global Privacy Policy, please contact our Data Protection Office at:
NexaVett Compliance Team
Email: privacy@nexavett.com
Corporate Portal: nexavett.com/contact


