Privacy Policy
Last Updated: August 18, 2026
Effective Date: July 12, 2026
Scope of this policy
NexaSocial is currently in a pre-launch phase. This site collects only waitlist signups and one-time purchases (Lifetime Deal, Founding Member, and Supporter Program) — it does not yet offer accounts, social media account connections, AI content generation, or any dashboard features. This policy describes exactly what we collect and do today. When the full NexaSocial platform launches with those additional features, this policy will be updated to reflect the new data types collected, and you will be notified of the material changes per Section 13 below. For a description of the full platform's planned security architecture, see our Security page.
1. Data Controller / Data Fiduciary Identity
This Privacy Policy is published by RAMSIO CLOUDSERVE INFOTECH PRIVATE LIMITED ("NexaSocial," "we," "our," or "us"), a company incorporated under the Companies Act, 2013 (India) (CIN: U62091KA2025PTC210162), with its registered office at #36, WeWork Prestige Central, Infantry Road, MG Road, Bengaluru, Karnataka 560001, India, operating the NexaSocial pre-launch marketing site.
For the purposes of the EU General Data Protection Regulation (GDPR), RAMSIO CLOUDSERVE INFOTECH PRIVATE LIMITED is the data controller. For the purposes of the Digital Personal Data Protection Act, 2023 (India DPDP Act), RAMSIO CLOUDSERVE INFOTECH PRIVATE LIMITED is the Data Fiduciary.
This Privacy Policy explains how we collect, use, disclose, and protect information when you join our waitlist, make a purchase, or contact us through this site.
By using NexaSocial, you agree to the collection and use of information in accordance with this policy. If you do not agree, please discontinue use of the service.
2. Information We Collect
2.1 Waitlist Signup
When you join the waitlist, we collect your email address and, optionally, your first name. We do not require or collect a password — there is no account or login on this site.
2.2 Purchases & Supporter Contributions
When you buy the Lifetime Deal, Founding Member offer, or make a Supporter Program contribution, we collect your email address, the display name you provide, the amount and currency paid, and — for Indian billing — your billing state and, optionally, a GSTIN for your own input-tax-credit purposes. Card and payment details are never collected or stored by us; they are handled entirely by Razorpay (see Section 2.4).
2.3 Usage and Log Data
We collect standard server logs including IP address, browser type, pages visited, timestamps, and error reports. This data is used for security monitoring and service improvement.
2.4 Payment Information
Payment card details are processed exclusively by our PCI-DSS compliant payment processor, Razorpay. We do not store raw card numbers on our systems.
3. Purposes and Legal Basis for Processing
We process your personal data for the following purposes, each supported by a specific legal basis under GDPR Art. 6 and the India DPDP Act 2023:
| Purpose | GDPR Legal Basis | DPDP Legal Basis |
|---|---|---|
| Operate the waitlist and notify you of your queue position | Art. 6(1)(b) — performance of a contract | Consent |
| Process one-time purchases and Supporter Program contributions, and issue receipts | Art. 6(1)(b) — performance of a contract | Consent / legal obligation |
| Detect fraud, abuse, and security incidents (bot protection on forms) | Art. 6(1)(f) — legitimate interests (security) | Legitimate use / legal obligation |
| Comply with legal obligations (tax, audit, court orders) | Art. 6(1)(c) — legal obligation | Legal obligation |
| Improve the site using aggregated, anonymised analytics data (only with your cookie consent) | Art. 6(1)(a) — consent | Consent (opt-in) |
We do not sell your personal data to third parties, and we do not currently send marketing newsletters — the only emails we send are the waitlist confirmation and purchase/contribution receipts described in Section 2.
Contractual necessity: Providing your email address is required to join the waitlist or complete a purchase. Without it, we cannot notify you of your queue position or send a receipt.
4. Data Security
The measures actually in place today, protecting the data described in Section 2, include:
- AES-256-GCM field-level encryption for stored email addresses, with a separate one-way hash used for duplicate-signup lookups so your plaintext email is never queried directly
- TLS in transit for all traffic to this site, with HTTP Strict Transport Security (HSTS) enforced
- Cloudflare Turnstile bot verification on the waitlist and purchase forms
- Card and payment details are never collected or stored by us — Razorpay's hosted, PCI-DSS-compliant checkout handles all payment data
Despite these measures, no method of transmission over the Internet or electronic storage is 100% secure. For the security architecture planned for the full NexaSocial platform (account authentication, role-based access control, and more), see our Security page.
5. Data Retention
We retain each category of personal data only for as long as necessary for the stated purpose, and no longer than required by applicable law:
| Data Category | Retention Period |
|---|---|
| Waitlist entry (email, first name) | Until public launch or deletion request, whichever is sooner; deleted within 30 days of a deletion request |
| Server logs and IP addresses | 90 days for security monitoring |
| Purchase / Supporter Program contribution records | 7 years (statutory tax and accounting obligations under Indian Income Tax Act / applicable law) |
Upon a deletion request, your personal data is scheduled for permanent deletion within 30 days, including removal from backup systems, except where we are legally required to retain purchase/financial records (Section 5, above). Anonymized, aggregated data that cannot identify you individually may be retained for product improvement.
6. Data Deletion
You have the right to request deletion of all personal data we hold about you. To do so:
- Send an email to [email protected] with the subject line "Data Deletion Request" and include the email address you used to join the waitlist or make a purchase.
- Full instructions and what gets deleted: see our Data Deletion page.
We will confirm receipt of your request within 3 business days and complete deletion within 30 days.
7. Your Rights
7.1 Rights under GDPR (EEA / UK residents)
If you are located in the European Economic Area or United Kingdom, you have the following rights under the GDPR:
- Right to Access (Art. 15): Request a copy of all personal data we hold about you and information on how it is processed.
- Right to Rectification (Art. 16): Request correction of inaccurate or incomplete personal data.
- Right to Erasure / Right to be Forgotten (Art. 17): Request deletion of your personal data where there is no compelling reason for continued processing.
- Right to Data Portability (Art. 20): Receive a copy of your data in a structured, machine-readable format by emailing our DPO — we currently fulfil this request manually rather than via self-service export.
- Right to Restrict Processing (Art. 18): Request that we restrict how we use your data in certain circumstances.
- Right to Object (Art. 21): Object to processing based on legitimate interests. We will cease processing unless we can demonstrate compelling legitimate grounds.
- Right to Withdraw Consent (Art. 7(3)): Where processing is based on your consent, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing prior to withdrawal.
- Right to Lodge a Complaint (Art. 77): You have the right to lodge a complaint with the data protection supervisory authority in your EU member state or the UK ICO (for UK residents) if you believe we have processed your personal data unlawfully. Exercising this right does not affect any other legal remedy available to you.
- Rights related to automated decision-making (Art. 22): We do not currently perform any automated decision-making or profiling that produces legal or similarly significant effects.
7.2 Rights under India DPDP Act 2023 (Data Principals in India)
If you are a Data Principal under the Digital Personal Data Protection Act, 2023 (India), you have the following rights:
- Right to Access Information (S.11): Request a summary of the personal data we hold about you and the processing activities carried out with that data.
- Right to Correction and Erasure (S.12): Request correction of inaccurate or misleading personal data, and request erasure of personal data that is no longer necessary for the purpose for which it was processed.
- Right to Grievance Redressal (S.13): Register a grievance with us regarding any act or omission by us in relation to your personal data. See Section 12 below for our Grievance Officer details and resolution timelines.
- Right to Nominate (S.14): You may nominate any other individual to exercise your rights under the DPDP Act in the event of your death or incapacity. To register a nominee, contact [email protected] with the subject "DPDP Nominee Registration".
- Right to Withdraw Consent: You may withdraw consent at any time by contacting us. Withdrawal does not affect the lawfulness of processing prior to withdrawal.
7.3 Rights under CCPA (California residents)
- Right to Opt-Out of Sale/Sharing: We do not sell or share personal information, and we honor the Global Privacy Control (GPC) browser signal automatically. See our Do Not Sell or Share My Personal Information page for the full CCPA/CPRA rights disclosure.
- Right to Know, Delete, and Correct: Same as the GDPR rights listed above.
To exercise any of these rights, contact our Data Protection Officer / Grievance Officer at [email protected]. We will respond within the timelines set out in Section 12 below.
8. Cookies and Tracking
This site sets no session or authentication cookies — there is no login. With your consent, we use first-party analytics cookies to understand how visitors use the site. We do not use third-party advertising trackers or cross-site tracking pixels.
You may manage cookie preferences through the consent banner on our website or your browser settings. Full detail: our Cookie Policy.
9. Sub-Processors and Third-Party Recipients
We share data with the following sub-processors and third-party service providers solely to operate this site. Each processes data only as instructed by us and under binding Data Processing Agreements (DPAs):
| Sub-Processor | Purpose | Location | Safeguard |
|---|---|---|---|
| Razorpay | Payment processing (cards, UPI, net banking) | India | Razorpay DPA, RBI PPI norms, PCI-DSS |
| Resend | Transactional email delivery (waitlist confirmations, purchase/contribution receipts) | USA | Resend DPA, EU SCCs |
| Cloudflare (Turnstile) | Bot and spam verification on waitlist/purchase forms (processes IP address and challenge token) | USA / Global | Cloudflare DPA, EU SCCs |
| Amazon Web Services | Application hosting and database infrastructure | Region selected at deployment | AWS DPA, EU SCCs |
| Google (Google Analytics) | Website analytics (page views, feature usage) — only loaded once you consent to analytics cookies via the cookie banner | USA / Global | Google DPA, EU SCCs |
We do not sell personal data to data brokers, advertisers, or any other third party.
10. Children's Privacy
NexaSocial is not directed to individuals under 16 years of age. We do not knowingly collect personal information from children under 16. If you believe we have inadvertently collected such data, please contact us immediately at [email protected].
11. International Data Transfers
RAMSIO CLOUDSERVE INFOTECH PRIVATE LIMITED is incorporated in India. Our sub-processors are located primarily in the United States and, once deployed, our hosting infrastructure will run on AWS in a region selected at deployment time. Personal data may therefore be transferred to and processed outside India.
For EEA / UK residents (GDPR):
When your personal data is transferred from the EEA or UK to a country not deemed adequate by the European Commission, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission (Decision 2021/914) as the transfer mechanism. Copies of applicable SCCs are available upon request by contacting [email protected].
For India residents (DPDP Act 2023, S.16):
Under the Digital Personal Data Protection Act, 2023, personal data of Indian Data Principals may be transferred to countries outside India, subject to the restrictions notified by the Central Government under Section 16 of the DPDP Act. We transfer data only to countries and sub-processors that meet the requirements notified by the Central Government or where contractual safeguards (such as DPAs with equivalent protections) are in place. We will update this section if the Central Government issues specific country restrictions or whitelists under S.16.
12. Contact — Data Protection Officer & Grievance Officer
For any questions, requests, or concerns regarding this Privacy Policy or your personal data, please contact:
Data Protection Officer (GDPR)
RAMSIO CLOUDSERVE INFOTECH PRIVATE LIMITED
Data Protection Officer
Email: [email protected]
General Support: [email protected]
Grievance Officer (India DPDP Act 2023 / IT Act 2000)
In accordance with the Digital Personal Data Protection Act, 2023 and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, the details of our Grievance Officer are:
Santhosh Suryavanshi
RAMSIO CLOUDSERVE INFOTECH PRIVATE LIMITED
#36, WeWork Prestige Central, Infantry Road, MG Road, Bengaluru, Karnataka 560001, India
Email: [email protected]
Grievance redressal timelines (DPDP Rules):
— Acknowledgement of grievance: within 24 hours of receipt
— Resolution of grievance: within 30 days of receipt
If you are not satisfied with our response, you may escalate your complaint to the Data Protection Board of India once constituted, or to the appropriate appellate authority under the DPDP Act.
13. Changes to This Policy
We may update this Privacy Policy from time to time — including when the full NexaSocial platform launches and begins collecting additional data types (e.g., connected social account tokens, AI-generated content) not covered above. Material changes will be communicated via email to your registered address or via a prominent notice on this site at least 14 days before the changes take effect. Your continued use of the service after the effective date constitutes acceptance of the updated policy.