Privacy Policy
Last updated:
1. Who this policy is for
NexaOS is a desktop app that companies (our customers) use to manage remote staff (reps): attendance, scheduling, activity, payroll and client invoicing. This policy explains what NexaOS collects about reps and other users of the app, why, who can see it, and how long it is kept. It also covers visitors to nexaosdesk.com.
When a customer uses NexaOS to monitor its reps, the customer decides what is monitored and why, and is responsible for that data (the "controller"). NexaOS processes it on the customer's behalf (as a "processor"). Customers are responsible for telling their reps that NexaOS is in use and for having a lawful basis to use it. If you are a rep and have a question about your data, your employer is usually the right first contact, but you are always welcome to write to us.
2. What NexaOS collects
The app collects data only while a rep is clocked in.
- Account details. Name, email, role, department, assigned clients and shifts, as entered by the customer.
- Attendance times. Clock-in and clock-out times, breaks, late reasons a rep enters, and missed or upcoming shifts.
- Activity levels. Whether the computer received any keyboard or mouse input each second, summarised into ten-minute blocks, plus mouse-pointer movement patterns used to spot automated input (for example, a mouse jiggler or auto-clicker). NexaOS does not log keystrokes and never records what is typed.
- Apps and website domains. The name of the program in front of the rep (for example, "Microsoft Excel") and, for a web browser, the website's domain only (for example, "youtube.com"), with how long each was used. App & website tracking never records page titles, page addresses (URLs), paths or search queries.
- Periodic screenshots. Screenshots taken at intervals during a shift. Each one is blurred on the rep's computer before it is uploaded, so the unblurred image never leaves the device. Each screenshot is stored with the name of the active app and the titles of the windows open at that moment, which can include the titles of open browser tabs. This text is used to flag non-work activity and is deleted along with the screenshot (see section 5).
- IP address at clock-in. The network address a rep clocks in from, so a customer can confirm that reps who must work from an approved office network are doing so.
- Payroll and invoicing records. Salaries, bonuses, fines, overtime, time off, warnings and client invoices, as entered by the customer or calculated from tracked hours.
- Telegram link (optional). If a user connects the NexaOS Telegram bot, we store their Telegram account ID so we can send them alerts and reports.
3. Why we collect it
- To record hours worked, so customers can pay reps correctly and bill their own clients accurately.
- To help managers run shifts across time zones: late check-ins, missed shifts, clock-out reminders.
- To give customers an honest picture of working time, including catching automated input that would otherwise inflate activity.
- To enforce office-network rules where a customer has set them.
- To send the alerts and reports a user asks for in Telegram.
- To keep the service secure, fix problems and support customers.
We do not sell personal data, use it for advertising, or use it for any purpose other than providing NexaOS to the customer.
4. Who can see it
- The customer's admins and managers, according to the roles and departments the customer sets up. Access to screenshots can be limited per department.
- NexaOS staff, only when needed to operate the service, to fix a problem, or to answer a support request, and only to the extent necessary.
- Service providers that run parts of NexaOS for us (listed in section 6), only to provide their service.
- Authorities, if we are legally required to disclose data. Where we lawfully can, we will tell the customer first.
5. How long we keep it
- Screenshots, together with the window titles stored with them, are deleted automatically after 7 days.
- App & website usage is deleted automatically after 60 days.
- Attendance times, activity levels, clock-in IP addresses, payroll and invoicing records are kept for as long as the customer's account is active, because customers need them for payroll, billing and records. A customer can delete a rep's records, or ask us to.
- When a customer's account is closed, we delete its data unless the law requires us to keep part of it.
6. Where data is stored and who processes it
NexaOS data (including screenshots) is stored with Supabase, our database and file-storage provider, which runs on cloud infrastructure. Data is encrypted in transit, and access inside the app is controlled by role and department.
We also use these service providers:
- Vercel, which hosts this website and provides cookieless visit statistics.
- Web3Forms, which delivers demo requests sent from the form on this website to us.
- Cal.com, which handles demo bookings. Its booking window loads only when you choose to book, and it receives the details you enter there.
- Telegram, which delivers bot messages to users who choose to connect it.
- Google Fonts, which serves the fonts on this website. Your browser requests them from Google, which receives your IP address.
These providers may process data in countries other than your own. Where the law requires it, we rely on appropriate safeguards for those transfers.
7. Visitors to this website
This website does not use advertising or analytics cookies. We use Vercel Web Analytics to count page views; it works without cookies and does not identify individual visitors. If you request a demo, we receive the name, company, email, team size and message you enter and use them only to reply to you. Our hosting provider keeps standard server logs, such as IP addresses, for security.
8. Your rights
Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal data, and to object to or restrict how it is used. Because customers control the data about their reps, we will usually pass a rep's request to the customer and help them answer it. You can also complain to your local data-protection authority.
9. Security
We protect data with encryption in transit, role- and department-based permissions, and automatic deletion of screenshots and app usage. No system is perfectly secure. If a breach affects personal data, we will notify affected customers without undue delay.
10. Changes to this policy
If we change this policy, we will update the date at the top. If a change materially affects how data is handled, we will tell customers before it takes effect.
11. Contact
Questions or requests about privacy: info@nexaosdesk.com.
