This document applies to the public NexViewTech website and the protected reseller portal. A signed order form, licence agreement, or other commercial agreement may add product-specific terms.
Who we are and when this policy applies
NexViewTech operates www.nexviewtech.com, its protected reseller portal, and related licensing, demo, billing, notification, and software-delivery workflows. In this policy, “NexViewTech”, “we”, “us”, and “our” mean the NexViewTech entity identified in the relevant quote, invoice, order form, or commercial agreement.
This policy explains how we handle personal information when you visit the public website, contact us, use a portal account, act for a reseller or customer, receive a client delivery email, or use a NexViewTech licensing workflow. A customer agreement or product-specific notice may provide additional information. Where we process information only on a business customer’s documented instructions, that customer may be the controller and NexViewTech may act as its processor or service provider.
Information we collect
Depending on how you interact with us, we may collect:
- Contact and organisation data: name, business email, company, product interests, client contact details, and the contents of communications.
- Portal account data: username, email, display name, role, account status, assigned products, feature and limit ceilings, billing settings, notification preferences, and MFA enrolment status.
- Authentication and security data: login challenges and results, session timestamps, a hashed browser signature, IP address, approximate city and country supplied by CloudFront, request identifiers, security events, and actions performed in the portal. Password verification is handled by Amazon Cognito; passwords are not stored in portal records.
- Customer and licensing data: demo recipient details, product choice, expiry, uploaded
.nvt-requestfiles, entitlement and revision state, TPM-derived device identifiers, public binding keys and attestation statements, selected capabilities and limits, request hashes, approval history, and activation artifact references. - Commercial data: quotes, pricing snapshots, quantities, invoice details, billing mode, payment terms, and transaction status. The current portal does not collect payment-card details.
- Delivery and communication data: email templates, recipients, delivery events, requested software platform, installer version, download history, and expiring link metadata.
We do not intentionally request special-category or sensitive personal information through the website or portal. Please do not include it in free-text fields or uploaded files.
How we collect information
We collect information directly from you, from the organisation or reseller that created or manages your account, from customers that submit client details, from NexViewTech products that create licensing requests, and automatically through the security and delivery infrastructure used to operate the service.
The contact form prepares a message in your own email application. The website does not submit that form to a NexViewTech database, although your email provider and NexViewTech will process the message when you send it.
Why we use personal information
| Purpose | Typical information | Basis where applicable |
|---|---|---|
| Provide accounts, demos, licences, installers, invoices, downloads, and support | Account, customer, licensing, commercial, and communication data | Performing a contract or taking requested pre-contract steps |
| Authenticate users, enforce permissions, investigate abuse, and protect the service | Login, MFA, IP, location, browser signature, session, and audit data | Our legitimate interests in operating a secure service and protecting users |
| Administer reseller relationships and keep immutable operational records | Roles, permissions, approvals, pricing snapshots, invoices, and audit history | Contract, legitimate interests, and legal obligations |
| Send requested service communications and client deliveries | Email address, templates, product, credentials or time-limited links | Contract, requested service delivery, or consent where required |
| Meet tax, accounting, compliance, dispute, and lawful government requirements | Commercial records, communications, and audit evidence | Legal obligations and establishment or defence of legal claims |
We do not sell personal information and do not use portal information for third-party behavioural advertising. If we introduce optional marketing or analytics later, we will update this policy and provide any choice required by law.
International processing
The production platform is configured primarily in the AWS eu-central-1 region, while CloudFront, WAF, email delivery, support recipients, resellers, and clients may operate in other countries. Information may therefore be processed outside your country.
Where applicable law requires it, we use contractual and organisational safeguards for international transfers. Contact us if you need information about the safeguard relevant to your circumstances.
How long we keep information
- Portal sessions: up to eight hours, with shorter idle timeouts; logout and revocation can end them earlier. Login challenges and rate-limit counters expire automatically.
- Audit records: seven years under the current production configuration, unless law or a dispute requires longer retention.
- Licensing, demos, invoices, approvals, and pricing snapshots: for the account or commercial relationship and afterwards as needed for licensing integrity, accounting, compliance, disputes, and legal obligations. Issued artifacts and audit history are archived or voided rather than altered through the portal.
- Uploaded requests, generated documents, and credentials: for as long as needed to provide, verify, renew, recover, or evidence the requested service. Files are stored privately; credentials available for later retrieval are encrypted with AWS KMS.
- Contact messages: according to the receiving mailbox’s business retention practices.
Backup copies and disaster-recovery records may remain for a limited additional period. We delete or de-identify information when it is no longer required, unless preserving it is necessary or permitted by law.
How we protect information
Measures implemented in the portal include mandatory TOTP MFA, staged authentication, short-lived revocable sessions with stricter superuser idle limits, origin and CSRF checks, role and ownership enforcement on the server, login throttling, AWS WAF rules, encrypted transport, KMS encryption, private S3 access, DynamoDB encryption and point-in-time recovery, restricted IAM permissions, immutable release digests, and audit redaction.
No system is completely secure. You must protect your password, MFA device, exported files, client credentials, and signed links, and notify us promptly if you suspect unauthorised access.
Your choices and privacy rights
Depending on where you live, you may have rights to request access, correction, deletion, restriction, objection, portability, withdrawal of consent, or a copy of your information. These rights can be limited where we must retain information for security, licensing integrity, accounting, legal claims, or another lawful reason.
Email info@nexviewtech.com with your request. We may need to verify your identity and relationship to the relevant organisation. If a reseller or customer controls the data, we may direct the request to that organisation or assist it in responding. You may also complain to the privacy or data-protection authority that applies where you live.
Children
The website and reseller portal are business services and are not directed to children. We do not knowingly collect personal information from children. Contact us if you believe a child has provided information so we can investigate and take appropriate action.
Automated processing
The service automatically applies authentication, rate-limit, ownership, product, feature, licence, pricing, and security rules. Superuser approval is required before a requested commercial activation is issued, and scheduled monthly invoices enter review rather than being issued automatically. We do not use personal information for solely automated decisions that produce legal or similarly significant effects unless permitted by law and accompanied by required safeguards.
Changes to this policy
We may update this policy when the website, portal, vendors, or legal requirements change. We will publish the revised policy here, update its effective date, and provide additional notice for material changes where required.
Contact and complaints
For privacy questions, requests, or complaints, email info@nexviewtech.com or use the contact page. Include enough detail for us to identify the relevant account, record, or interaction, but do not email passwords, MFA codes, private keys, or other secrets.
We will acknowledge and investigate complaints, work with the relevant reseller or customer where appropriate, and respond within the timeframe required by applicable law.
Talk to NexViewTech.
Contact us if you need clarification, an accessible copy, or help with a privacy request.