Privacy Policy
Last updated: July 2026
Protecting your data matters to us. This policy explains which personal data we process when you visit and use NexoVirt. We only collect what is needed to run the site, to register an account and, if you use a paid plan, to process payments. We use only privacy-friendly, cookieless analytics (self-hosted Plausible) that stores no personal data — no advertising cookies, no cross-site tracking and no profiling.
1. Controller
The controller responsible for data processing on this website is:
Bjarne Arik Fomferra – Nucez Software
c/o SourceArt
Fritz-Thiele-Straße 3
28279 Bremen, Germany
Email: [email protected]
2. Hosting & server logs
The website and customer portal run on a virtual private server hosted by IONOS SE (Elgendorfer Str. 57, 56410 Montabaur, Germany) in an EU data centre, managed with the Plesk control panel. Traffic is routed through Cloudflare (Cloudflare, Inc., USA) as a content-delivery network and reverse proxy for delivery, attack protection and reliability. When you open the site, technical access data is processed in server log files:
- shortened / anonymised IP address
- date and time of the request
- requested resource / page
- HTTP status code and amount of data transferred
- referrer URL and browser type/version (user agent)
The legal basis is Art. 6(1)(f) GDPR (legitimate interest in a secure, stable website). Log files are deleted after a short time unless needed to investigate faults or abuse. Data-processing agreements (Art. 28 GDPR) are in place with IONOS (EU) and with Cloudflare; transfers to the USA via Cloudflare are covered by the EU Standard Contractual Clauses and/or the EU-US Data Privacy Framework.
3. Cookies
We set only strictly necessary cookies (Art. 6(1)(f) GDPR). We do not use any analytics, statistics, marketing or tracking cookies. Only the following necessary cookies are used:
| Cookie | Purpose | Category | Lifetime |
|---|---|---|---|
ci_session | Session / technical operation (incl. login) | Necessary | 2 hours |
csrf_cookie_name | Protection against cross-site request forgery | Necessary | 2 hours |
nx_consent | Stores your cookie consent choice | Necessary | 180 days |
nx_theme | Light/dark mode | Necessary | 1 year |
__cf_bm | Cloudflare bot-management / security (set by Cloudflare, not by us) | Necessary | ~30 minutes |
The __cf_bm cookie is set automatically by our reverse proxy Cloudflare to distinguish
humans from bots and protect the site; it does not track you across other websites.
For web analytics we run our own self-hosted, cookieless Plausible instance: it
collects only aggregated, anonymized statistics (page views, referrers, country derived from a
truncated IP address), stores no personal data or cross-site identifiers, and is processed on the
basis of our legitimate interest in understanding site usage (Art. 6(1)(f) GDPR).
4. Registration & account
When you create an account, we process the data you provide, in particular your email address, name/username and a password (the password is only ever stored as a cryptographic hash, never in clear text). We use this data to provide your account, authenticate you, grant access to the service and send the emails required for the service (e.g. confirmation, login and service messages).
The legal basis is Art. 6(1)(b) GDPR (pre-contractual measures and performance of the usage relationship). Account data is stored for as long as your account exists and removed afterwards unless statutory retention obligations apply.
When you use the customer portal, we additionally process the data required to provision and manage the servers you create — for example any SSH public keys you add and the metadata of your VMs/containers (name, resources, status, IP). This is processed to deliver the service (Art. 6(1)(b) GDPR) and is deleted when you remove the resource or your account.
5. Payments via Stripe
If you use a paid plan, payments are handled by the payment provider Stripe (Stripe Payments Europe, Ltd., Ireland; where applicable Stripe, Inc., USA). The data required for payment (e.g. name, email address, billing data and payment/card details) is collected and processed directly by Stripe; we do not store full card data. The legal basis is Art. 6(1)(b) GDPR (performance of contract).
Stripe processes data partly in the USA; transfers are covered by the EU Standard Contractual Clauses and/or the EU-US Data Privacy Framework. See Stripe’s privacy policy for details: stripe.com/privacy.
6. Email
Transactional and service emails (e.g. registration confirmation, security notices) are sent via an SMTP service, processing your email address and the message content. The legal basis is Art. 6(1)(b) or Art. 6(1)(f) GDPR (reliable delivery). We do not send marketing newsletters without separate consent.
7. Sharing with third parties
Your data is only shared with the service providers named here (hosting/Cloudflare, Stripe, email delivery), acting as processors or independent controllers solely to deliver the respective service, or where we are legally required to. We do not sell data.
8. Your rights
You have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object (Art. 21 GDPR). You can withdraw any consent at any time with future effect. Contact us at [email protected]. You also have the right to lodge a complaint with a data-protection supervisory authority.
This policy describes the current processing for the service and will be updated when things change.