N
NxtOne
  • Product ▾
  • Resources ▾
  • Pricing
  • Company ▾
Sign inGet Started →
Legal
  • Overview
  • Data We Collect
  • How We Use Data
  • Execution Data
  • Data Storage & Security
  • Data Sharing
  • Cookies & Tracking
  • Your Rights
  • Data Retention
  • International Transfers
  • Children’s Privacy
  • Changes to Policy
  • Contact Us

Privacy Policy

Updated: February 25, 2026Effective: March 1, 2026

This Privacy Policy explains how NxtOne Ltd (“NxtOne”, “we”, “us”, “our”) collects, uses, stores, and protects your information when you use our platform, website, and related services. We are committed to protecting your privacy and handling your data with transparency.

1. Overview

NxtOne is an operational intelligence platform that captures runtime execution semantics from software applications. This policy covers all data processed through our services, including our website (nxtone.ai), the NxtOne platform, agents, APIs, and related tools.

Data Controller: NxtOne Ltd, registered in England and Wales. Our registered address is in London, United Kingdom.

Legal Basis for Processing: We process personal data under the following legal bases as defined by GDPR Article 6(1): contractual necessity for providing our services, legitimate interest for improving our platform and communicating with users, consent for marketing communications and optional cookies, and legal obligation for compliance with applicable laws.

2. Data We Collect

2.1 Account Information

When you create an account or contact us, we collect your name, email address, company name, job title, and billing information. This data is necessary to provide our services and manage your account.

2.2 Usage Data

We automatically collect information about how you interact with our platform, including pages viewed, features used, investigation queries, session duration, and browser/device type. This helps us improve the product.

2.3 Execution Data (Technical)

The NxtOne agent captures semantic execution relationships from your application runtime. This is the core of our service and is covered in detail in Section 4 below.

Important: NxtOne captures execution semantics — method call relationships, service interactions, and timing data. We never capture source code, variable values, business data, PII, credentials, or request/response payloads. See Section 4 for full details.

3. How We Use Your Data

We use collected data for the following purposes:

PurposeData UsedLegal Basis
Provide the serviceAccount info, execution dataContract
AI root cause analysisExecution data onlyContract
Billing & invoicingAccount info, usage metricsContract
Product improvementAggregated usage dataLegitimate interest
Security monitoringAccess logs, IP addressesLegitimate interest
Marketing emailsEmail addressConsent
Legal complianceAs requiredLegal obligation

We never use customer execution data to train, fine-tune, or improve AI models. Your execution data is used exclusively to provide the NxtOne service to your organization. This is a contractual commitment.

4. Execution Data — What We Capture

The NxtOne agent operates at the bytecode/runtime level and captures the following semantic information:

  • Method call relationships — which services and methods call each other
  • Execution timing — when calls occurred and how long they took
  • Service and method identifiers — class names, method signatures, service names
  • Database query patterns — query structure and shape, never actual values
  • Message queue interactions — event types and routing metadata
  • HTTP endpoint metadata — paths and status codes
  • Exception types — error classifications and stack trace structure

4.1 What We Never Capture

The NxtOne agent is explicitly designed to never capture, transmit, or store:

  • Source code or file contents
  • Variable values, parameters, or return values containing business data
  • Personally identifiable information (PII) of your users
  • Authentication tokens, API keys, passwords, or credentials
  • HTTP request or response body payloads
  • Database query results or row contents
  • Environment variables, configuration secrets, or private keys

4.2 PII Filtering

All data passes through a PII sanitization layer before storage. This filter identifies and strips potential personal data patterns (email addresses, IP addresses, phone numbers, names) from any metadata that may inadvertently contain such information.

5. Data Storage & Security

All data is stored on Amazon Web Services (AWS) infrastructure in the eu-west-2 (London) region by default. Enterprise customers can request specific regional data residency.

We implement the following security measures:

  • Encryption in transit — TLS 1.3 for all data transmission
  • Encryption at rest — AES-256 for all stored data
  • Access control — RBAC with principle of least privilege
  • Network isolation — private VPC with no public-facing databases
  • Audit logging — immutable logs of all access to customer data
  • Key management — AWS KMS with automatic key rotation

For full details on our security posture, see our Security & Compliance page.

6. Data Sharing & Third Parties

We do not sell, rent, or trade your personal information. We share data only in the following limited circumstances:

  • Service providers — AWS (infrastructure), Stripe (billing), and analytics tools that process data on our behalf under strict data processing agreements
  • Legal requirements — when required by law, regulation, or valid legal process
  • Business transfers — in the event of a merger, acquisition, or sale of assets (you would be notified in advance)
  • With your consent — for any purpose you explicitly agree to

All third-party service providers are bound by Data Processing Agreements (DPAs) that ensure GDPR-compliant handling of personal data.

7. Cookies & Tracking

Our website uses the following categories of cookies:

CategoryPurposeDuration
EssentialAuthentication, security, basic functionalitySession
FunctionalPreferences, language, theme settings1 year
AnalyticsUsage patterns, feature adoption (anonymized)90 days

We do not use advertising cookies or tracking pixels. You can manage cookie preferences in your browser settings. Essential cookies cannot be disabled as they are required for the service to function.

8. Your Rights

Under GDPR, the UK Data Protection Act 2018, and other applicable legislation, you have the following rights:

  • Right of access — request a copy of your personal data
  • Right to rectification — correct inaccurate personal data
  • Right to erasure — request deletion of your personal data
  • Right to restrict processing — limit how we use your data
  • Right to data portability — receive your data in a structured, machine-readable format
  • Right to object — object to processing based on legitimate interest
  • Right to withdraw consent — withdraw marketing consent at any time

To exercise any of these rights, contact us at privacy@nxtone.ai. We will respond within 30 days. You also have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO) at ico.org.uk.

9. Data Retention

Account data is retained for the duration of your active subscription plus 30 days after cancellation to allow for data export.

Execution data is retained according to your plan’s retention policy (default: 90 days). Enterprise customers can configure custom retention periods.

Usage analytics are retained in anonymized, aggregated form and are not linked to individual users after 12 months.

Upon account deletion, all your data — including execution graphs, investigation history, and account information — is permanently and irreversibly deleted from our systems, including backups, within 30 days. We provide written confirmation upon request.

10. International Data Transfers

Your data is stored in the EU (AWS eu-west-2, London) and is not transferred outside the European Economic Area (EEA) or the United Kingdom unless you explicitly configure a different data residency region.

Where transfers to third-party processors outside the EEA are necessary (e.g., Stripe’s US-based services), we ensure appropriate safeguards are in place through Standard Contractual Clauses (SCCs) as approved by the European Commission.

11. Children’s Privacy

NxtOne is a business-to-business platform designed for software engineering teams. Our services are not directed at individuals under the age of 18. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a minor, please contact us immediately.

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. We will notify you of material changes by email and by posting a prominent notice on our platform at least 30 days before changes take effect.

Continued use of the service after the effective date constitutes acceptance of the updated policy.

13. Contact Us

For any privacy-related questions, concerns, or requests:

NxtOne Ltd — Data Protection

Email: privacy@nxtone.ai
General: hello@nxtone.ai
Address: London, United Kingdom
ICO Registration: Pending
N
NxtOne

AI-powered operational intelligence for software teams. Understand your system. Fix issues faster.

Product

FeaturesPricingChangelogDocumentation

Company

About UsBlogCareersContact

Resources

SecurityStatusEventsLegal
© 2026 NxtOne. All rights reserved.
𝕏in