Privacy Policy

NEXQ Privacy & Secure Session Logging Policy

NEXQ is committed to privacy-forward healthcare engineering. This policy explains what data we collect, why we collect it, and how secure login telemetry is handled for protected workspace access.

Effective date: September 18, 2024

Scope

Policy Scope And Compliance Position

  • NEXQ operates privacy-forward controls aligned to healthcare security expectations, including HIPAA-aligned safeguards and GDPR-aligned governance patterns.
  • This policy applies to NEXQ public web properties, protected workspace access routes, and supporting security telemetry for authentication and session protection.
  • This page provides operational policy transparency and does not replace legal counsel for organization-specific requirements.

Automatic Sign-On Logging

What Is Automatically Logged At Login

When a user signs into a protected NEXQ workspace, authentication telemetry is automatically recorded to support security monitoring, audit readiness, and incident response.

  • IP address (network source used during authentication)
  • Device category and user agent metadata
  • Approximate location derived from network headers (city/region/country when available)
  • Authentication timestamp and account role

Minimization and Transfer Controls

Data Minimization, Confidentiality, And Transfer Safeguards

  • NEXQ applies minimum-necessary handling and stores only security-relevant login/session telemetry required for platform integrity and legal obligations.
  • Protected workspace payloads are role-scoped and delivered on a need-to-know basis.
  • Public documentation and marketing pages intentionally avoid disclosure of non-public architecture, keys, internal model parameters, or sensitive workflow internals.
  • Cross-border data handling, if applicable, is governed by contract controls and legally required transfer safeguards.

How We Use This Data

  • Validate workspace security and detect suspicious access attempts.
  • Maintain audit-ready authentication evidence for operational governance.
  • Support troubleshooting of session integrity and secure access controls.

Data Protection

  • Authentication logs are stored inside encrypted local auth infrastructure.
  • Role-scoped access applies to protected workspace activity and review surfaces.
  • NEXQ does not publish private login telemetry to public-facing pages.
  • Operational security controls are reviewed through policy and audit pathways.

Forced Logout Policy

Lifecycle-Triggered Logout And Re-Entry Notice

Protected sessions are forcibly terminated when browser/device lifecycle events occur, including refresh, hard refresh, tab/window close, and restart recovery checks. This is designed to reduce residual session risk on shared or interrupted devices.

  • Forced-logout trigger (refresh, hard refresh, tab/window close, browser shutdown/restart recovery)
  • Session identifier reference and role scope at termination time
  • Lifecycle source metadata (trigger path/source/host/device/IP/location when available)
  • Forced-logout timestamp and subsequent acknowledgement status

Retention And Deletion

How Long Data Is Kept

  • Authentication and security logs are retained only for defined security, audit, and legal obligations.
  • Retention windows are controlled by security and compliance governance and may vary by jurisdiction, contract, and incident context.
  • When retention periods expire and no legal hold applies, records are scheduled for secure deletion or irreversible de-identification.

Data Subject Rights

Your Privacy Rights

  • Request access, correction, or deletion of personal data where legally applicable.
  • Request restriction or objection processing where legally applicable.
  • Request data portability where legally applicable.
  • File a complaint with an applicable supervisory authority in your jurisdiction.

To submit a rights request, contact hello@nexq.us and include sufficient information for secure verification.

Security Controls

Security Baseline For Privacy Protection

  • Encrypted transport and role-scoped access boundaries for protected workflows.
  • Session lifecycle controls, including forced logout protections on refresh/close/restart conditions.
  • Audit and attestation lanes for authentication and high-risk actions.
  • Policy-gated release patterns for sensitive operational outputs.

Incident Response

Security Incident And Notification Posture

  • Security monitoring pathways are maintained to identify suspicious authentication, route, or session behavior.
  • Incident triage, containment, and recovery follow internal security response workflows with legal/compliance escalation ownership.
  • Where legally required, notifications are coordinated according to contractual and jurisdictional obligations.

Intellectual Property

Ownership And Proprietary Rights

  • NEXQ software, workflows, documentation, product architecture, and related materials are proprietary to NEXQ and/or its licensors.
  • No transfer of ownership is granted by site access, documentation access, or workspace usage unless explicitly stated in a signed agreement.
  • Third-party names, trademarks, service marks, and logos remain the property of their respective owners.

Legal And Medical Disclaimers

Required Acknowledgement After Forced Logout

  • Interrupted sessions can result in unsaved input, incomplete state, and data loss.
  • Platform outputs are assistive and must be independently verified by authorized professionals.
  • Users are responsible for clinical, operational, and disclosure decisions made after re-entry.
  • By continuing after the required prompt, users acknowledge these risks and accept liability for downstream use.
  • NEXQ and its affiliates disclaim liability for loss, interruption, or misuse related to forced session termination.

Policy Maintenance

  • Policy updates are validated through structured release controls with legal, security, and operations review ownership.
  • NEXQ applies repeated policy enhancement cycles prior to release, including an eight-pass integration/consistency loop for major policy revisions.
  • Material policy changes are published with an updated effective date and linked documentation references.

NEXQ may update this policy to reflect legal, regulatory, operational, or security changes. Material changes will be published on this page with an updated effective date.

Full Audited Privacy Policy

The complete audited NEXQ Privacy Policy is rendered below from the legal policy bundle source file. It keeps the September 18, 2024 paper-policy and PDF-source legal date while preserving online audit, checksum, deployment, consent, session, and runtime timestamps as factual evidence records.

Privacy Policy

Template and counsel-review notice. This document is a website/app integration template, not a legal opinion. Before publication, replace bracketed placeholders, confirm actual data flows, obtain advice from qualified counsel for each jurisdiction and regulated workflow, and approve final wording through privacy, security, product, marketing, health/clinical, and executive stakeholders. Do not promise controls, certifications, response times, retention periods, or legal rights unless they are actually implemented and operationally supported.

Effective date: September 18, 2024 Last reviewed: July 9, 2026 Last material web integration: July 10, 2026 Organization: NEXQ Inc. Services covered: NEXQ websites, web applications, protected workspace surfaces, mobile app surfaces, APIs, secure healthcare and healthtech workflow demonstrations, security and post-quantum readiness planning, diagnostics-workflow support concepts, oncology workflow research, cardiovascular longevity research, research collaboration, support, and related services Privacy contact: privacy@nexq.us or hello@nexq.us Security contact: security@nexq.us or hello@nexq.us Legal notices: legal@nexq.us or hello@nexq.us Mailing address: Irvine, CA, United States — contact hello@nexq.us for legal notices

1. Scope, roles, and conflicts

This Policy applies to websites, web applications, mobile applications, APIs, support channels, newsletters, healthcare or healthtech workflows, hospital-facing workflows, developer portals, and related services operated by NEXQ Inc.. It is intentionally modular. If a regulated-data appendix conflicts with this general policy, the stricter or more specific appendix controls for that data or workflow.

We may act as a business, controller, processor, service provider, contractor, business associate, subprocessor, vendor, or software supplier depending on the customer, integration, contract, and data flow. Product teams must complete the data inventory before publishing this policy because incorrect role language can create FTC, state privacy, contract, HIPAA, FERPA, GLBA, app-store, or customer-audit exposure.

2. Personal information we may collect

We collect only information that is reasonably necessary, proportionate, and compatible with disclosed purposes. Before launch, delete any row that does not apply and add missing categories from the data inventory.

CategoryExamplesSourceSensitive?Required publication check
Identifiersname, email, account ID, username, IP address, device IDsuser, device, customer, partnerssometimesnotice at collection; app labels; SDK inventory
Account and commercial datasubscription tier, transaction records, support historyuser, payment processor, systemssometimesretention schedule; payment/PCI disclosures
Internet/network activitypages viewed, referrers, clickstream, session logs, diagnosticsbrowser, app, SDKssometimescookie/SDK consent, GPC, analytics review
Approximate or precise locationcity, region, GPS if enableddevice, user settingprecise location is sensitiveopt-in and mobile permission review
Communicationschats, emails, support tickets, call recordings if enableduser, support toolscan be sensitiverecording consent and retention review
Professional, employment, or applicant datarole, employer, resume, interview notesuser, recruiter, employersometimesemployee/applicant notice
Health, wellness, biometric, or patient datasymptoms, care data, device readings, appointments, PHI/ePHIuser, covered entity, device, customeryesHIPAA/consumer-health review; no ad pixels by default
Student or education dataschool IDs, classroom data, assignmentsschool, parent, studentoftenFERPA/PPRA/customer contract review
Financial datacredit checks, loan, insurance, bank, tax, or customer financial recordsuser, customer, financial partneroftenGLBA/FCRA/PCI review
AI inputs and outputsprompts, uploaded files, model outputs, feedback, embeddings, evaluationsuser, product, model systemsdepends on contentAI register; retention; training opt-out
Sensitive identifiersgovernment ID, SSN, passport, biometric templatesuser, verification vendorsyesstrict minimization and encryption
Children/minors datadata from children under 13 or teens/minorsuser, parent/guardian, schoolyesCOPPA/state minor law review

3. Purposes for collection and processing

We may use personal information to provide and secure the services, authenticate users, process transactions, provide support, communicate service updates, comply with law and contracts, prevent fraud and abuse, debug and improve the services, perform privacy/security audits, maintain records, protect patient interests, support patient safety and continuity of care in healthcare or healthtech workflows, and document, monitor, and enforce client, user, and workspace adherence to NEXQ legal policies, acceptable-use rules, privacy/security requirements, customer agreements, and regulated workflow guardrails. We conduct marketing only where lawful consent, opt-out, or legitimate basis requirements are satisfied. We do not use sensitive personal information for purposes that are incompatible with the disclosed purpose without additional review and any required consent. Clients remain responsible for their own legal, clinical, institutional, and contractual obligations.

4. Cookies, SDKs, pixels, and tracking technologies

Necessary technologies may run to provide security, authentication, load balancing, fraud prevention, preference storage, and consent management. Analytics, advertising, cross-context behavioral advertising, retargeting, fingerprinting, and similar technologies must be blocked until the user has made the required choice or until another legally valid basis has been documented. Global Privacy Control or equivalent universal opt-out signals must be honored where required.

Do not deploy ad pixels, retargeting pixels, session replay, heatmaps, or third-party analytics on patient portals, appointment pages, symptom checkers, authenticated health workflows, billing pages, children-directed services, school-directed services, financial-account workflows, or sensitive-data forms without a written privacy, security, and legal assessment.

5. Sale, sharing, targeted advertising, and profiling

Some laws define “sale,” “share,” or “targeted advertising” broadly enough to include certain advertising, analytics, or cross-context tracking arrangements. Before publication, classify each vendor and SDK in the tracking-technology inventory. If we engage in sale/share/targeted advertising, we must provide required notices, opt-out links, and signal handling. If we do not engage in those activities, we must not include conflicting advertising code or vendor contracts.

6. AI, automated decision-making, and consequential decisions

AI systems, machine-learning models, rules engines, automated decision tools, and generative AI features must be listed in the AI system register. For employment, housing, lending, credit, insurance, education, healthcare, criminal justice, essential services, or other consequential decisions, complete an impact assessment, provide notices and explanations where required, support human review and appeal where required, monitor for bias and accuracy, and avoid making legal, clinical, credit, or employment determinations solely through unvalidated automation.

7. Health, healthcare, and consumer health data

Where we handle protected health information for or on behalf of a HIPAA covered entity or business associate, HIPAA contract terms and the Healthcare Privacy Policy control. Where health or wellness data is not HIPAA-regulated, the FTC Health Breach Notification Rule, state consumer-health-data laws, app-store rules, customer contracts, and state breach laws may still apply. Product teams must not assume “not HIPAA” means “not regulated.”

8. Children, teens, and students

We do not knowingly collect personal information from children under 13 without legally required parental consent. Services directed to children, school users, or minors must complete the Children Privacy Impact Assessment, COPPA review, state minor-law review, and FERPA/PPRA review where school records or school-directed services are involved.

9. Financial, payment, and regulated financial data

Payment-card processing should be handled by PCI-compliant processors. If we are a financial institution or service provider under GLBA, the Financial Data / GLBA Policy controls. Do not collect bank, loan, insurance, tax, credit, or consumer-report data unless the collection is explicitly approved, disclosed, protected, and supported by a retention/legal-basis entry.

10. Disclosure of information

We may disclose information to service providers, subprocessors, professional advisors, affiliates, corporate transaction parties, customers or account administrators, law enforcement or regulators when lawfully required, and others with user direction or consent. Contracts must require confidentiality, purpose limitation, appropriate security, deletion/return, incident notice, audit cooperation, and flow-down of special obligations for HIPAA, FERPA, GLBA, consumer health data, AI, or restricted cross-border transfers.

11. International, cross-border, and restricted-country transfers

International transfers require a transfer mechanism appropriate to the jurisdictions involved, such as contracts, approved frameworks, or other lawful mechanisms. Separate review is required for bulk sensitive personal data, government-related data, sensitive health, geolocation, biometric, genomic, financial, or other data that may be restricted by the U.S. Department of Justice Data Security Program or customer contract.

12. Retention and deletion

We retain data only for the period necessary for disclosed purposes, contract performance, legal compliance, security, fraud prevention, dispute resolution, audits, backups, and legitimate business needs. Each data category must map to the retention schedule. Backups must be protected and deleted or overwritten on a defined cycle unless a legal hold applies.

13. Security

We maintain administrative, technical, and physical safeguards appropriate to the nature of the data, including access controls, encryption in transit and at rest where appropriate, logging, vulnerability management, secure development, vendor review, incident response, workforce training, and change management. Public statements must not claim SOC 2, ISO, HITRUST, HIPAA compliance, FedRAMP, PCI, FDA clearance, or other certification/authorization unless evidence exists.

14. Privacy rights and requests

Depending on location and law, users may have rights to know/access, portability, deletion, correction, opt out of sale/share/targeted advertising, limit certain sensitive-data uses, withdraw consent, appeal a denial, avoid discrimination for exercising rights, or authorize an agent. Submit requests through https://nexq.us/legal#privacy-requests or hello@nexq.us. We verify requests proportionately, respond within legally required periods, and provide an appeal process where required.

15. Contact and escalation

Privacy requests should be routed to privacy@nexq.us or hello@nexq.us. Security reports should be routed to security@nexq.us or hello@nexq.us. Legal notices should be routed to legal@nexq.us or hello@nexq.us. If only hello@nexq.us is active for intake, NEXQ must maintain documented internal aliases and escalation workflows. Do not improvise legal or privacy answers in support tickets.

16. Protected session interruption notice

Protected sessions may terminate on refresh, hard refresh, tab or window close, browser shutdown, restart recovery, or security-risk events. Users acknowledge that interrupted sessions may result in unsaved input or incomplete state and should verify information before use. NEXQ’s liability is governed by applicable law and the relevant agreement; nothing in this notice limits non-waivable legal rights.