Privacy notice

Framework notice on the processing of personal data for the institutional portal of NexStudio S.r.l., registered office in Italy, [INDIRIZZO_COMPLETO], and for the LexAura and MediAura SaaS services. This notice distinguishes the NexStudio institutional portal from the LexAura and MediAura SaaS services; the product-specific privacy notices published on the respective application portals remain the detailed reference for product use.

Version 1.1 · In force from [DATA] · Last updated [DATA]

Related documents: Terms of use · Cookie policy · GDPR rights

Contents

  1. 1. Scope of this notice
  2. 2. Controller identity and contact points
  3. 3. Categories of data processed
  4. 4. Purposes and legal bases of processing
  5. 5. Privacy roles specific to LexAura and MediAura
  6. 6. Retention periods
  7. 7. Recipients and categories of authorized parties
  8. 8. International data transfers
  9. 9. Security measures and governance
  10. 10. Data subject rights and how to exercise them
  11. 11. Cookies, analytics, and tracking
  12. 12. Processing of children’s data
  13. 13. Policy updates

1. Scope of this notice

This notice describes the general framework under which NexStudio S.r.l. processes personal data collected through the public institutional website and corporate channels (also linked to the LexAura and MediAura products).

For operational use of the SaaS products, the level of detail and the privacy role may vary: NexStudio may act as controller, joint controller, or processor depending on the service and contractual agreements.

In case of conflict between this page and a Data Processing Agreement (DPA), a framework agreement, or signed special terms, the contractual documents specific to the purchased service prevail.

2. Controller identity and contact points

Data controller: NexStudio S.r.l., registered office in Italy, [INDIRIZZO_COMPLETO], VAT [DA_INSERIRE].

Channels for privacy requests:

  • Email: privacy@nexstudio.com
  • Contact form on nexstudio.ai
  • For SaaS customers: authenticated channels/tickets provided in the respective portals (LexAura, MediAura)

The Data Protection Officer (DPO) can be contacted at the same addresses.

3. Categories of data processed

Data categories vary depending on the channel used and the active modules/features.

  • NexStudio portal: browsing data (technical logs, IP, user agent), contact data submitted voluntarily (name, email, company, message content), cookie preferences, and aggregate metrics.
  • LexAura (Legal Tech): account and user profile data, workspace metadata, legal documents uploaded or generated, text requests to analysis/summarization engines, audit logs of access and operations.
  • MediAura (Health Tech): account and role data, organizational metadata, health or administrative documentation, voice inputs and related transcripts, technical and security logs.
  • Special categories under Art. 9 GDPR: may arise in MediAura (and, in specific cases, in LexAura) when customers upload content including health data or other sensitive data; processing occurs only within the limits of the service and the instructions received from the customer controller.

4. Purposes and legal bases of processing

  • Operation of the institutional website, security, and operational continuity (basis: legitimate interest in security, abuse prevention, and service maintenance).
  • Handling of pre-contractual requests, demos, commercial contacts, and support (basis: pre-contractual measures at the data subject’s request; legitimate interest in B2B management).
  • Provision of LexAura and MediAura SaaS, user authentication, tenant management, and technical support (basis: performance of the contract with the business customer).
  • Regulatory compliance, administrative/tax obligations, dispute management, and defense of rights (basis: legal obligation and legitimate interest in legal protection).
  • Marketing/newsletter communications, where active (basis: consent, subject to soft-spam exceptions permitted by applicable law).
  • Service improvement and AI feature development: only if provided for by contract or documented instructions; absent such a basis, data are not used for general-purpose training.

5. Privacy roles specific to LexAura and MediAura

For B2B SaaS services, the customer normally determines the purposes and means of processing relating to data uploaded into its application environment, acting as controller. NexStudio generally acts as processor on behalf of the customer, under contractual appointment and documented instructions.

Where NexStudio independently determines specific purposes (e.g. fraud prevention, infrastructure security, aggregate metrics not attributable to an individual data subject), it acts as an independent controller for such processing.

The dedicated LexAura and MediAura privacy notices, published on the respective sites or application environments, provide further detail on data categories, flows, retention periods, and legal bases specific to each product.

6. Retention periods

  • Website contact data: 24 months from the last interaction.
  • SaaS account data: for the entire duration of the contractual relationship + 30 days from deletion.
  • Technical and security logs: maximum 30 days.
  • Billing data: 10 years as required by Italian tax law.
  • Health data: according to the controller (customer) instructions and legal obligations.
  • Aggregate analytics data: indefinitely in anonymous form.

7. Recipients and categories of authorized parties

Data may be processed by authorized and instructed NexStudio personnel, as well as by qualified suppliers acting as processors/sub-processors (e.g. cloud hosting, infrastructure services, security monitoring, communication tools).

The up-to-date list of processors and sub-processors relevant to SaaS customers is made available through contractual channels or upon request.

8. International data transfers

Due to the use of global cloud providers, some processing may involve transfers to countries outside the EEA/EU. Where required by law, NexStudio adopts appropriate safeguards (e.g. standard contractual clauses, supplementary technical/organizational measures, transfer impact assessments) and limits transfers to necessary data only.

Data are preferably processed within the European Economic Area. Cloudflare Inc. adheres to the EU-US Data Privacy Framework and adopts Standard Contractual Clauses (SCCs).

9. Security measures and governance

NexStudio adopts technical and organizational measures proportionate to the risk:

  • Role-based access controls, authentication, logical segregation of customer environments, and the principle of least privilege.
  • Encryption of data in transit (TLS 1.3) and at rest; secure key management.
  • Logging, monitoring, audit trails, and incident management procedures.
  • Backup, operational continuity, and disaster recovery procedures.

10. Data subject rights and how to exercise them

Data subjects may exercise the rights provided by applicable law (access, rectification, erasure, restriction, objection, portability, withdrawal of consent, complaint to the competent authority).

For data processed in the SaaS context, the request should normally be addressed first to the customer controller (e.g. law firm or healthcare organization). NexStudio supports the customer controller under contract.

For data processed by NexStudio as controller (e.g. website contacts, its own security logs), requests may be sent to privacy@nexstudio.com or via the form on nexstudio.ai.

Competent supervisory authority: Garante per la protezione dei dati personali (www.garanteprivacy.it).

12. Processing of children’s data

NexStudio services are designed for professional and business users. They are not intentionally directed at children.

13. Policy updates

NexStudio may update this notice for regulatory adjustments, service evolution, organizational changes, or introduction of new features. Material changes will be published on this page with an updated version and date.