Privacy in the apps
The privacy page covers this website. This one covers the products — what they hold about a person, for how long, and what they deliberately do not do. Last updated 2026-09-12.
Who is responsible for what
When an organisation uses these apps, that organisation decides what to collect and why. Under the GDPR they are the controller and we are the processor acting on their instructions — see the Data Processing Agreement. Where we decide things for ourselves, such as who may hold an account with us, we are the controller. We are established in Ireland, so our supervisory authority is the Irish Data Protection Commission.
What each app holds
nex-meet — meetings
| What | Why | How long |
|---|---|---|
| An account holder's name and email address | To sign them in and to address mail to them. There is no password — a one-time code is sent to the address we already hold. | While the account exists |
| A guest's display name, and the email address they were invited at | To show who is in the room, and to send the invitation. | 30 days after the meeting |
| The meeting's subject, its code and passcode, who attended and when | To run the meeting and to show the organiser their own history. | 30 days |
| Audio and video | Carried between participants while the call is happening. | Never stored. Not recorded at any point |
| Chat messages | Sent directly between participants. | Never stored. They do not reach our servers |
nex-cal — booking pages
| What | Why | How long |
|---|---|---|
| The page owner's name, email address and working hours | To draw the page and to address the confirmations. | While the page exists |
| A visitor's name, email address, anything they typed in the note field, and the timezone their browser reported | To make the booking, confirm it, and show times in their own clock. | 90 days after the meeting |
| The cancellation link in a confirmation email | So somebody with no account can cancel. | 120 days |
nex-remind — reminders
| What | Why | How long |
|---|---|---|
| The recipient's address, the text to be sent, and when to send it | To send the reminder. | 30 days after it has been sent or given up on |
| Whether each attempt succeeded, and the provider's reason if it did not | So a failure is visible and can be retried rather than disappearing. | 30 days |
Every one of these is enforced by an expiry stamped on the record itself, not by a cleanup job somebody has to remember to run. When the date passes, the database deletes it.
What is stored on your device
No cookies, in any of the apps. Two things are kept in your browser's own storage and never sent anywhere except back to us:
- A sign-in token, so you are not asked for a code on every page. In nex-cal it lives in session storage and is gone when you close the tab.
- A seat token in nex-meet, if you have joined a meeting as a guest, so that reconnecting after losing your connection does not mean asking to be let in again.
Both are cleared by signing out, or by clearing site data in your browser. There is no advertising identifier and nothing that follows you to another site.
Where it is
Ireland, in Amazon Web Services, with one exception: the control interface for meeting media sits in Frankfurt because AWS publishes no equivalent in Ireland. Both are inside the EU, so nothing here is an international transfer. The full list is on the sub-processors page.
Your rights
You can ask for a copy of what we hold about you, ask for it to be corrected, ask for it to be deleted, ask us to stop, or complain to a supervisory authority — in Ireland, the Data Protection Commission. Ask through the contact form and we will reply within a month.
If your details are in one of these apps because an organisation invited you to a meeting or you booked time with them, that organisation decides what happens to the record. Ask them first; if it is easier to ask us, we will pass it on and help them answer.
What we will not claim
Meeting audio and video are encrypted in transit and are decryptable by the service that carries them, which is how Zoom, Google Meet and Microsoft Teams all work by default. We are not going to call that end-to-end encryption, because it is not. If we ever offer end-to-end encrypted meetings, this page will say so plainly and will say what stops working in that mode.