Legal document

Privacy Policy and information about data processing

This document explains what data we collect through nexinlab.com, why we collect it, how it is used and how long it is retained. Last updated: June 2026.

warning

Please note: Do not submit another person's personal data, private email addresses, sensitive data or information about children through the form.

1. Data controller

NEXINLAB is a project and service brand presented on the website nexinlab.com.

The controller of personal data submitted through this website is:

[LEGAL OPERATOR / INCUBATOR LEGAL NAME TO BE COMPLETED]
Address: [TO BE COMPLETED]
Registration / tax number: [TO BE COMPLETED]
Contact email: contact@nexinlab.com

The legal operator may act as the contracting and billing entity for paid services provided under the NEXINLAB brand. The exact legal entity responsible for a paid engagement will be identified in the relevant proposal, contract, invoice or payment document before payment is made.

2. Data we collect

We collect only the information necessary to handle enquiries, prepare proposals, provide services and maintain basic business records.

Depending on how you contact us, this may include:

  • Company name
  • Full name of the contact person
  • Business email address
  • Phone number, if provided
  • Website address
  • Industry or business type
  • Description of your situation, website issue, project request or business context
  • Preferred next step or type of service
  • Messages sent through the contact form or by email
  • Technical and campaign information connected with the enquiry, such as landing page URL, referrer, UTM parameters, campaign ID or similar URL parameters, if present

We do not intentionally collect sensitive data, private personal information, information about children or information that is unnecessary to handle your enquiry.

3. Campaign and URL parameters

If you arrive at nexinlab.com through a campaign link, the URL may contain parameters such as source, medium, campaign name, campaign ID or similar identifiers.

These parameters may be used to understand which campaign or source led to the enquiry. If you submit a form, such parameters may be included in hidden form fields together with your enquiry, where technically available.

If analytics or marketing cookies are used, they are used only according to the cookie consent choices shown on the website. If consent is not given, campaign parameters may still remain visible in the URL and may be submitted with the form only from the current URL/session context, without storing them in non-essential cookies or browser storage.

4. Purpose of processing

We process submitted data to:

  • Assess your enquiry
  • Contact you about your request
  • Understand whether our services fit your situation
  • Prepare a proposal, quote or next-step recommendation
  • Provide agreed services
  • Handle project communication and delivery
  • Issue or process documents related to payment, invoicing or accounting through the legal operator / incubator
  • Maintain basic records required for legal, tax, accounting or dispute-related purposes
  • Improve the website, forms and service communication

Depending on the situation, we process personal data on one or more of the following legal bases:

  • Your consent, where you submit data through a form or consent to optional communication
  • Taking steps at your request before entering into a service agreement
  • Performance of a service agreement, if you decide to proceed
  • Legal obligations related to accounting, tax, invoicing and business records
  • Legitimate interest in handling business enquiries, protecting legal claims, maintaining basic business communication and improving the website

Where processing is based on consent, you may withdraw consent at any time. Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn.

If you separately consent to marketing communication, we may send you messages about NEXINLAB services, website improvement, analytics, conversion improvement, automation, digital service delivery and related topics.

This consent is voluntary. Refusing it does not affect how we handle your enquiry. You may withdraw it at any time by emailing contact@nexinlab.com.

We do not send mass automated marketing emails without an appropriate legal basis and consent where required.

7. Business prospect data

In some cases, we may manually review publicly available business information about companies that may be relevant to NEXINLAB services.

This may include:

  • Company name
  • Website address
  • Public business email address
  • Public contact form URL
  • Public company phone number
  • Industry or business category
  • Public business source where the company was found
  • Basic notes about visible website issues relevant to business communication

We aim to minimise personal data and prefer general company contact channels such as contact forms, office emails or publicly listed business contacts.

We do not intentionally collect private personal information, sensitive data, family information, private social media data or unrelated personal details for outreach.

If you do not want to be contacted, you may request deletion or mark your company as “do not contact” by emailing contact@nexinlab.com.

8. Data sharing and processors

We do not sell your personal data.

To operate the website and provide services, data may be processed by selected service providers, including:

  • Website hosting and infrastructure providers
  • Form handling and email service providers
  • Analytics providers, if enabled and consented to where required
  • CRM, spreadsheet or project management tools used to handle enquiries and delivery
  • The legal operator / incubator used for contracting, payments, invoicing and accounting
  • Accounting, legal or administrative service providers, where required
  • Technical subcontractors, only where necessary for agreed service delivery

Each processor or service provider should process data only for the relevant purpose and in accordance with applicable data protection rules.

Paid services may be contracted, invoiced and paid through [LEGAL OPERATOR / INCUBATOR LEGAL NAME TO BE COMPLETED] or another legal operator identified before payment.

For this purpose, your company and contact data may be shared with the legal operator to:

  • Prepare a proposal, agreement, order confirmation or invoice
  • Process payment
  • Maintain accounting and tax records
  • Confirm the scope and status of the service
  • Handle disputes, refunds or formal communication if needed

Payment details, invoice data and contractual information are processed according to the rules of the legal operator and applicable law.

10. Retention period

We keep personal data only as long as necessary for the purpose for which it was collected.

Typical retention periods:

  • Enquiry data: up to 12 months from the last interaction, unless further cooperation begins
  • Prospect data with no response: usually deleted or reviewed within 60-90 days
  • Opt-out / do-not-contact records: retained as long as necessary to respect the opt-out
  • Client and project records: retained for the duration of cooperation and then as required for accounting, tax, legal or dispute-related purposes
  • Technical logs and security data: retained for the period necessary to ensure website security and diagnose problems

After the relevant period, data is deleted or anonymised unless the law requires longer retention.

11. Your rights

In relation to your personal data, you have the right to:

  • Access — ask what personal data we hold about you
  • Rectification — ask us to correct inaccurate data
  • Erasure — ask us to delete your data
  • Restriction of processing — ask us to limit how we process your data
  • Object — object to further processing, including direct marketing
  • Withdraw consent — where processing is based on consent
  • Data portability — where this right applies
  • Not to be subject to automated decision-making — where such processing would apply

To exercise these rights, contact contact@nexinlab.com.

You may withdraw consent, request deletion or ask us to stop contacting you by emailing:

contact@nexinlab.com

We will handle the request without undue delay and, where possible, within 7 working days. Some data may need to be retained if required by law, accounting obligations or legal claims.

The website may use:

  • Essential cookies or similar technologies required for the website to work
  • Consent-related cookies used to remember your cookie choices
  • Analytics cookies, only if enabled and consented to where required
  • Campaign or attribution-related technologies, only according to your consent choices where required

You can manage cookies through the website consent banner and through your browser settings.

Blocking non-essential cookies should not prevent you from using the core website or submitting an enquiry.

14. What we do not do

  • We do not sell personal data
  • We do not collect sensitive data intentionally
  • We do not collect information about children
  • We do not use private personal information for outreach
  • We do not use personal data for automated decision-making that produces legal or similarly significant effects
  • We do not use campaign data to track you across unrelated websites without appropriate consent

15. International transfers

Some service providers may process data outside the European Economic Area.

Where this happens, appropriate safeguards should be used, such as an adequacy decision, standard contractual clauses or another mechanism allowed by applicable data protection law.

16. Security

We use reasonable organisational and technical measures to protect data against unauthorised access, loss, misuse or disclosure.

However, no website, email system or online service can be guaranteed to be completely secure. Please do not submit confidential, sensitive or unnecessary personal information through the contact form.

17. Complaint to supervisory authority

If you believe that your personal data is processed in breach of applicable data protection law, you may lodge a complaint with the President of the Polish Personal Data Protection Office (UODO).

Before lodging a complaint, you may also contact us directly at contact@nexinlab.com so that we can review and respond to your request.

18. Contact

For questions about this Privacy Policy or personal data processing, contact:

contact@nexinlab.com

We aim to respond within 3 working days.

Do you have questions about our services?

arrow_back Return to the enquiry form
chat_bubble Request a review