Privacy Policy
Protecting personal data matters to us. This privacy policy explains the nature, scope, and purpose of processing personal data in connection with the Nexoro CRM software and this website.
1. Controller
The controller for data processing is DAR LEAN DACH GmbH, Siezenheimer Straße 35, 5020 Salzburg, Austria (see the imprint). Contact for privacy matters: office@nexoro.net.
2. Data we process
- Master data (e.g. name, company, contact details) — for example when submitting a demo or contact request through this website.
- Usage data (e.g. login times, in-application activity) for Nexoro customers.
- Content data — CRM, order, and communication data entered by the customer into its own tenant instance.
3. Purposes and legal bases
Processing takes place to perform the contract (Art. 6(1)(b) GDPR), to comply with legal obligations (lit. c), and on the basis of legitimate interests (lit. f) where applicable — for example, to respond to inquiries submitted through the contact or demo form.
4. Data processing on our behalf
Insofar as personal data is processed on the customer's behalf within its Nexoro tenant instance, the customer is the controller and we are the processor within the meaning of Art. 28 GDPR. Details are governed by the data processing agreement (DPA), which forms part of the usage contract.
5. Retention period
Personal data is stored only as long as necessary for the stated purposes, or as long as statutory retention obligations require. For data within a Nexoro tenant instance, the deletion period after contract end set out in the usage contract applies in addition.
6. Your rights
| Right | Legal basis |
|---|---|
| Access | Art. 15 DSGVO |
| Rectification | Art. 16 DSGVO |
| Erasure | Art. 17 DSGVO |
| Restriction of processing | Art. 18 DSGVO |
| Data portability | Art. 20 DSGVO |
| Objection | Art. 21 DSGVO |
In addition, you have the right to withdraw any consent given at any time with effect for the future, and the right to lodge a complaint with a data protection supervisory authority (in Austria: the Datenschutzbehörde).
7. Data security
We take technical and organizational measures appropriate to the risk, such as encrypted transmission and access controls. Every Nexoro tenant instance runs on its own database, physically separated from other tenants.
8. Cookies and this website
For details on the cookies used on this website and how consent is managed, see the cookie policy.
Contact for privacy requests
office@nexoro.net
