NXO
Legal · Privacy

Privacy Policy

Last updated · April 30, 2026

This policy explains what personal data NXO collects, what we use it for, who we share it with and how you can exercise your rights. It is part of the legal framework of the app, together with the Terms and Conditions.

Contents
  1. Data controller
  2. Data we collect
  3. Purposes and legal bases
  4. Camera and gallery permission
  5. Processors and providers
  6. International transfers
  7. Retention periods
  8. Your rights
  9. Minimum age
  10. Security
  11. Changes to this policy
  12. Contact

1. Data controller

Riverlab S.L.U. (“Riverlab”, “we”, “our”) is the data controller for the personal data we process through the NXO mobile application (the “app”).

2. Data we collect

To run the service we collect the following categories of data:

3. Purposes and legal bases

We process your data for the following purposes, on the indicated legal basis:

4. Camera and gallery permission

On Android, the system permission to read your images is labelled as “camera”. NXO requests it for a single purpose: to let you pick and upload a profile picture. The image is sent directly to our identity provider (Clerk), which hosts it as part of your account; we do not keep an additional copy on our servers. You can deny the permission and continue using the app without a photo, or remove the image at any time from the profile editor.

5. Processors and third-party providers

We do not sell your data. To run the service we rely on the following processors, all bound by the corresponding data processing agreements:

6. International transfers

Some of the providers above are established outside the European Economic Area, mainly in the United States. These transfers are covered by the safeguards set out in articles 45 and 46 GDPR: Standard Contractual Clauses approved by the European Commission, or the EU–U.S. Data Privacy Framework where applicable.

7. Retention periods

We keep your data for as long as your account is active. When you delete your account from within the app, all profile data, projects, connections and messages are wiped immediately from our database.

Technical logs may be retained for a short period (typically no more than 30 days) for security and diagnostic purposes before automatic deletion.

8. Your rights

Under the GDPR and LOPDGDD you may at any time:

To exercise any of these rights, write to riverlabsl@gmail.com. If you believe your request has not been properly handled, you may lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos, www.aepd.es).

9. Minimum age

NXO is intended for people aged 16 or older. That is why date of birth is mandatory at sign-up: it allows us to verify that you meet that requirement. We will remove any account that does not, along with its associated data.

10. Security

We apply reasonable technical and organisational measures to protect your data: HTTPS encryption in transit, secure credential storage on the device (Expo SecureStore, Android Keystore or Apple Keychain), database access controls and periodic reviews. No system is 100% bulletproof, but we work to keep risks as low as possible.

11. Changes to this policy

We may update this policy to reflect legal, technical or functional changes. If the changes are material, we will give you at least 15 days' notice by email or in the app. The “last updated” date in the header always indicates the version in force.

12. Contact

For any question about this policy or how we handle your data, write to riverlabsl@gmail.com. Postal address: Riverlab S.L.U., Calle Santa Bárbara 18, 18001 Granada (Spain).

© 2026 Riverlab S.L.U. · Home · Privacy · Terms · Delete account · Child safety