Legal

Privacy Policy

This Privacy Policy explains which personal data we collect, what we use it for, and which rights you have.

Version 1.0 · Effective date: entered upon publication

1. Data Controller

The controller responsible for the processing of personal data within the meaning of the General Data Protection Regulation (GDPR) is:

Majd Alnawa
Sole proprietorship (small business)

Lassallerstraße 25
99086 Erfurt
Germany

Email: support@joinnexly.com

2. Introduction

The protection of your personal data is important to us.

In this Privacy Policy we inform you which personal data we collect, for which purposes it is processed, on which legal basis this is done, and which rights you have under the General Data Protection Regulation (GDPR).

This Privacy Policy applies to:

  • the Nexly website
  • the Android app
  • future iOS applications
  • all other services of the Nexly platform

3. Definitions

Personal data means any information relating to an identified or identifiable natural person. This includes, for example:

  • name
  • username
  • email address
  • profile picture
  • location information
  • messages
  • device information
  • IP address
  • usage data

Processing means any operation performed on personal data, such as collection, storage, modification, transmission or deletion.

4. Data We Collect

Depending on how you use our platform, we may in particular process the following data:

Account data

  • name
  • username
  • email address
  • encrypted password
  • Google account (when using Google Sign-In)
  • profile picture

Profile data

  • biography
  • interests
  • preferred activities
  • voluntarily provided location
  • language preferences

Activity data

  • activities you have created
  • activity participations
  • invitations
  • join requests
  • comments
  • activity images

Communication data

The following may be processed as part of using Nexly:

  • direct messages
  • group chats
  • activity chats
  • system messages

Technical data

Depending on your device, we may process:

  • device information
  • operating system
  • app version
  • browser information
  • IP address
  • time of access
  • error logs

Push notifications

If you enable push notifications, we in particular process:

  • push token
  • device platform
  • time of registration
  • notification preferences

Push notifications can be turned off at any time via your device settings.

5. Location Data

Nexly uses location information only if you voluntarily enable this feature.

Location data is used in particular to:

  • show activities near you
  • calculate distances
  • provide local recommendations

You decide at any time whether your location may be used.

Continuous background tracking does not take place unless you have expressly consented to it.

6. Purposes of Processing

We process personal data in particular for the following purposes:

  • providing your user account
  • sign-in and authentication
  • participation in activities
  • communication between users
  • delivery of push notifications
  • improving the platform
  • error analysis
  • abuse detection
  • platform security
  • fulfilment of legal obligations
  • handling support requests

Processing takes place only for the respective purposes indicated.

7. Legal Bases for Data Processing

The processing of personal data is carried out solely within the framework of applicable data protection law, in particular the General Data Protection Regulation (GDPR).

Depending on the type of processing, we rely in particular on the following legal bases:

Art. 6(1)(a) GDPR (Consent)

For example, for:

  • voluntary location sharing
  • push notifications
  • optional features that require explicit consent

Art. 6(1)(b) GDPR (Performance of a contract)

Processing takes place where it is necessary to enable you to use the Nexly platform. This includes in particular:

  • registration
  • sign-in
  • user account
  • chats
  • activities
  • profile data
  • participation in events

Art. 6(1)(c) GDPR (Legal obligation)

Where we are required to do so by law, personal data may be processed or stored. This applies in particular to tax and regulatory requirements.

Art. 6(1)(f) GDPR (Legitimate interests)

We also process data where this is necessary to safeguard our legitimate interests, in particular:

  • platform security
  • fraud prevention
  • abuse detection
  • error analysis
  • system stability
  • platform improvement

8. Retention Period

Personal data is stored only for as long as is required for the respective purpose or as long as statutory retention obligations apply.

After deletion of a user account, personal data is generally deleted or anonymised, unless legal obligations or legitimate interests require otherwise.

Security logs and technical log data may be stored for a limited period in order to trace attacks, abuse or technical faults.

9. Supabase

To provide our platform we use Supabase as a backend service provider.

Supabase supports us in particular with:

  • authentication
  • user management
  • database
  • file storage
  • real-time communication
  • server functions

Personal data may be processed on Supabase's servers.

Further information can be found in Supabase's privacy policy.

10. Firebase Cloud Messaging

We use Firebase Cloud Messaging (FCM) for push notifications.

This may involve processing in particular:

  • device tokens
  • platform information
  • notification status

Firebase does not receive the content of your private messages solely as a result of the delivery of a push notification. Only the information required to technically deliver the notification is processed.

Push notifications can be disabled at any time via your device settings.

11. Google Sign-In and Google User Data

As an alternative to email registration, you can sign in to Nexly with your Google Account. Sign-in takes place through the OAuth procedures provided by Google. Your Google password is never transmitted to or stored by Nexly.

Data Accessed

When you sign in with Google, Nexly receives only the information that you release as part of the Google consent screen. This is limited to:

  • your name (as shown on your Google Account)
  • your email address
  • your profile picture
  • your unique Google account identifier (Google user ID)

Nexly does not request access to your Gmail messages, Google Drive files, Google Contacts, Google Calendar or any other Google service data, and does not use any restricted Google API scopes.

Data Usage

The data received from Google is used solely to:

  • create or sign in to your Nexly account
  • uniquely identify your account across future sign-ins
  • display basic profile information (name and profile picture) within Nexly
  • contact you about your account and important service messages via the email address associated with your Google Account
  • protect the security and integrity of your account (e.g. abuse detection, suspicious sign-in detection)

Nexly does not use Google user data for advertising, profiling for third parties, or the training of generalised AI or machine-learning models.

Data Sharing

Nexly does not sell Google user data and does not share it with third parties for their own independent purposes. Google user data is only shared with the technical service providers strictly required to operate the sign-in flow and the platform, in particular Supabase (authentication, database and hosting). Where legally required, we may disclose data to competent authorities in response to a valid legal request.

Data Storage and Protection

Google user data is stored on secured infrastructure operated by our backend provider. Protective measures include in particular:

  • encrypted transmission via HTTPS/TLS
  • encryption at rest for data stored in the backend database
  • role-based access controls that limit access to Google user data to authorised staff and system components
  • authentication and session management using industry-standard OAuth flows
  • logging of security-relevant events and monitoring for suspicious activity
  • regular security updates and hardening of our infrastructure

Data Retention and Deletion

Google user data is retained for as long as your Nexly account exists and is required to provide the service.

You can request deletion at any time by:

  • deleting your Nexly account inside the app (Settings → Delete account),
  • revoking Nexly's access to your Google Account at https://myaccount.google.com/permissions,
  • sending an email request to support@joinnexly.com.

Once your account is deleted, the Google user data referenced above is deleted or irreversibly anonymised, unless we are required to retain specific data to comply with legal obligations (e.g. tax record-keeping) or to defend legal claims. Backups are automatically cycled and overwritten within the retention periods set by our infrastructure provider.

12. Cookies and Local Storage

Cookies or comparable technologies may be used on our website.

These serve in particular to:

  • sign you in
  • store your session
  • provide security
  • improve usability

Within the mobile app, additional local storage mechanisms may be used to securely store settings or credentials on your device.

You can manage or delete cookies through your browser settings.

13. Data Security

To protect your personal data, we implement appropriate technical and organisational security measures.

These include in particular:

  • encrypted data transmission (HTTPS/TLS)
  • access restrictions
  • authentication mechanisms
  • regular security updates
  • logging of security-relevant events
  • protection against unauthorised access

Despite all security measures, complete security cannot be guaranteed for data transmitted over the internet.

We continuously develop our security measures further in order to ensure a level of protection appropriate to the state of the art.

14. Disclosure of Personal Data

Personal data is generally disclosed only where this is required to provide our services or where a legal obligation exists.

Recipients may in particular be:

  • technical service providers
  • hosting providers
  • cloud service providers
  • payment service providers (in the future, if integrated)
  • authorities, where a legal obligation exists

We do not sell personal data to third parties.

Disclosure for advertising purposes does not take place without your explicit consent.

15. International Data Transfers

Some of the service providers used by Nexly may process personal data outside the European Union or the European Economic Area.

Where this is the case, we take care to ensure an adequate level of data protection. This may in particular include:

  • European Commission adequacy decisions
  • Standard Contractual Clauses (SCCs)
  • other appropriate safeguards under Art. 44 et seq. GDPR

16. Your Rights under the GDPR

You have the right at any time to:

Access

You may request information about what personal data we store about you.

Rectification

You may have inaccurate or incomplete data corrected.

Erasure

You may request the deletion of your personal data, unless statutory retention obligations apply.

Restriction of processing

Under certain conditions, you may request the restriction of processing.

Data portability

You may request that the personal data you have provided be made available to you in a structured, commonly used and machine-readable format.

Objection

You may object to the processing of your personal data where such processing is based on legitimate interests.

Withdrawal of consent

Any consent you have given may be withdrawn at any time with effect for the future.

Such withdrawal does not affect the lawfulness of any processing carried out on the basis of the consent up to that point.

17. Right to Lodge a Complaint

You have the right to lodge a complaint with a data protection supervisory authority about the processing of your personal data.

For Nexly, the competent supervisory authority is generally the data protection authority of the federal state in which the operator is located.

18. Data Protection for Minors

Nexly is intended solely for persons who have reached the age of 16.

By registering, each user confirms that this age requirement is met.

If Nexly becomes aware that an account has been created in breach of this age requirement, the account may be suspended or deleted.

19. Data Security (ongoing measures)

We regularly review and improve our technical and organisational security measures.

These include in particular:

  • encryption of sensitive data
  • role-based access rights
  • regular security updates
  • protection against unauthorised access
  • logging of security-relevant events
  • protection against abuse and attacks

Our goal is to safeguard the confidentiality, integrity and availability of personal data as effectively as possible.

20. Amendments to this Privacy Policy

This Privacy Policy may be adjusted where this is necessary as a result of new legal requirements, technical developments or new features of the platform.

For material changes, registered users will be informed within the platform or by email.

Where legally required, renewed consent will be obtained before the changes take effect.

21. Contact

For questions regarding data protection or the processing of your personal data, you can contact us at any time.

Controller:

Majd Alnawa
Sole proprietorship (small business)

Lassallerstraße 25
99086 Erfurt
Germany

Email: support@joinnexly.com

22. Entry into Force

This Privacy Policy enters into force upon publication and applies to all services of the Nexly platform.

By using the platform, you confirm that you have taken note of this Privacy Policy.