Legal

Privacy Policy

Last updated: September 14, 2026

This policy explains what data Nexomech collects, why we collect it, how it is protected, and the choices you have. It applies to the Nexomech robotics learning platform and website.

01. Data We Collect

Account data: username, name, email address and a securely hashed password (we never store plaintext passwords).

Demo request data: name, email, phone, institution details and your message, used to respond to your request.

Billing data: subscription and payment records, invoices and (where provided) GSTIN. Card details are handled entirely by our payment gateway and never reach our servers.

Usage data: platform activity such as logins, AI generations, token consumption and project counts, used for quota management and service operation.

Technical data: standard server logs and security-related events (failed logins, rate limiting) used to protect the platform.

02. How We Use Data

  • Providing and operating your subscription and learning modules.
  • Enforcing usage quotas and seat limits.
  • Processing payments and issuing invoices.
  • Sending service emails: expiry warnings, credential delivery, subscription notices.
  • Responding to demo and support requests.
  • Securing the platform and maintaining audit logs.

03. AI Features

The AI Robotics Programmer sends your project prompts to our AI provider solely to generate robotics programming assistance. Prompts are restricted to robotics topics. We do not use your prompts or generated content for advertising.

04. Data Sharing

We share data only with service providers necessary to operate the platform: our payment gateway (Razorpay), our AI provider (for the Robotics Programmer) and our email delivery provider. Each receives only the data required for its function. We do not sell your data.

05. Organization Customers

For Team subscriptions, organization admins can view and manage user accounts and usage within their organization. Organization data is isolated: one organization can never access another organization's users, projects, invoices or usage.

06. Data Retention

Account, subscription, invoice and audit data is retained while your subscription is active and for the period required for legal and accounting purposes after expiry. Subscription data is retained after expiry so your data is not deleted and renewal is possible.

07. Security

  • Passwords are hashed with bcrypt — never stored in plaintext.
  • Sessions use signed, httpOnly cookies; secrets never appear in frontend code.
  • Payments are verified server-side; we never trust client-reported payment success.
  • Authorization checks run on the backend for every protected operation.
  • Important operations are audit-logged.

08. Your Rights

You may request access to, correction of, or deletion of your personal data through our contact page. Organization users should route requests through their organization admin.

09. Changes to This Policy

We may update this policy from time to time. Material changes will be communicated to active customers. The "Last updated" date above reflects the current version.