Legal
Privacy policy
This policy explains how personal data is handled when you visit Nexra, use the developer console, or contact us about the platform.
Last updated 25 July 2026
Who is responsible for your data
Amakora Group LTD is the controller of personal data processed through Nexra unless a separate agreement says otherwise. Nexra is the product and service name used for the developer platform.
Information we collect
- Identity and profile details supplied through sign in and account onboarding.
- Workspace membership, roles, application metadata, and configuration choices.
- API, sandbox, MCP, webhook, AI usage, audit, security, and diagnostic records needed to operate and protect the platform.
- Billing and subscription status when paid services are enabled.
- Messages and information you provide when requesting support or making an inquiry.
- Device, browser, network, and essential storage information used to provide and secure the service.
Raw credentials and secret values are not intended to be retained in browser facing logs. Where a secret is generated for one time display, you are responsible for storing it securely.
How and why we use information
We process information to provide the service, authenticate users, enforce workspace and application permissions, operate sandbox and integration workflows, respond to requests, prevent abuse, maintain audit evidence, improve reliability, and meet legal obligations.
Depending on the activity, our UK GDPR lawful basis is performance of a contract, legitimate interests in operating and securing the platform, compliance with legal obligations, or consent where consent is required.
AI assisted features
When an authorised user invokes an AI assisted feature, the platform may send relevant documentation, schemas, error context, or user supplied prompts to the configured model provider. The service is designed to redact recognised credentials and secret fields before provider calls. Do not include secrets or unnecessary personal data in prompts.
Who we share information with
We may use vetted service providers for cloud hosting, identity, monitoring, email, payments, and AI processing. Providers may only process information for the contracted purpose and are subject to appropriate safeguards. We do not sell personal data.
International transfers
If information is processed outside the United Kingdom, we use an applicable adequacy regulation or contractual and organisational safeguards recognised under UK data protection law.
Retention and security
We retain information only for as long as it is needed for service delivery, security, audit, billing, dispute resolution, and legal requirements. Retention periods vary by record type and contractual commitment. We use access controls, encryption, logging, environment separation, and secret management measures appropriate to the service.
Your rights
Under UK data protection law, you may have rights to access, correct, erase, restrict, or object to processing of your personal data, and to request portability. You may also withdraw consent where processing relies on consent.
You can complain to the UK Information Commissioner's Office if you are not satisfied with how a data protection concern is handled.
Changes to this policy
We may update this policy when the service, providers, or legal requirements change. The latest version and its update date will be published on this page.
Contact us
Questions about these terms or privacy matters can be sent to contact@amakoragroup.com. Technical and developer support requests can be sent to developers@amakoragroup.com.
Nexra is operated by Amakora Group LTD, a UK registered company based in London, United Kingdom.