Last updated: 6/29/2025
Nexogen AI is fully compliant with the General Data Protection Regulation (GDPR), ensuring the highest standards of data protection and privacy for EU residents. This document outlines our comprehensive approach to GDPR compliance.
All Nexogen AI services are hosted on EU-based infrastructure to ensure data sovereignty and compliance with GDPR requirements. Our data centers are located within the European Union, providing guaranteed data residency and protection under EU law.
We maintain full control over data location and processing, ensuring that EU user data remains within EU borders and is subject to EU data protection laws.
We implement industry-leading encryption standards to protect your data at every stage of processing and storage.
We process personal data based on the following legal grounds under GDPR Article 6:
Processing is necessary for the performance of our transcription services contract with you.
Processing is necessary for our legitimate interests in providing and improving our services, ensuring security, and preventing fraud.
Where required, we obtain explicit consent for specific processing activities, such as marketing communications.
Processing is necessary to comply with legal obligations, such as tax requirements and data retention laws.
Under GDPR Articles 15-22, you have the following rights regarding your personal data:
You can request confirmation of whether we process your personal data and receive a copy of the data we hold about you, including information about the processing purposes, categories of data, recipients, and retention periods.
You can request correction of inaccurate personal data and completion of incomplete data. We will respond to such requests without undue delay.
You can request deletion of your personal data in specific circumstances, such as when the data is no longer necessary, consent is withdrawn, or processing is unlawful.
You can receive your personal data in a structured, commonly used, machine-readable format and transmit it to another controller without hindrance.
You can object to processing based on legitimate interests or for direct marketing purposes. We will stop processing unless we demonstrate compelling legitimate grounds.
You can request restriction of processing in specific circumstances, such as when you contest data accuracy or object to processing.
AES-256 encryption for data at rest, TLS 1.3 for data in transit
Multi-factor authentication, role-based access, session management
Comprehensive audit trails for all data access and modifications
Logical and physical separation of different data categories
For GDPR-related inquiries and to exercise your rights:
dpo@nexogen.ai
privacy@nexogen.ai
You have the right to lodge a complaint with your local data protection supervisory authority if you believe we have not addressed your concerns adequately.