GDPR Policy

Effective Date: July 2025

This GDPR Policy outlines how NexaLeader (“we”, “our”, or “us”) processes personal data in accordance with the General Data Protection Regulation (GDPR) (EU) 2016/679. This policy applies to individuals within the European Economic Area (EEA) who use our services or access our website.

1. Legal Basis for Processing

We process personal data under the following legal grounds: your explicit consent, performance of a contract, compliance with legal obligations, and legitimate interests in delivering and improving our services.

2. Categories of Personal Data

We may collect data such as name, email address, profession, communication history, session notes, and site usage behavior.

3. Purpose of Processing

We use your data to provide coaching services, manage accounts, personalize your experience, conduct research, and comply with legal requirements.

4. Your Rights Under GDPR

You have the right to access, rectify, erase, or restrict processing of your personal data. You may also object to data processing and request data portability.

5. Data Transfers Outside the EEA

Personal data may be transferred to and processed in Singapore or other jurisdictions. We use standard contractual clauses and other safeguards to ensure adequate protection.

6. Data Retention

We retain personal data only as long as necessary to fulfill the stated purposes or to meet legal obligations. Data is securely deleted or anonymized upon request or after expiry of retention periods.

7. Data Protection Measures

We implement appropriate security measures including encryption, secure access controls, and regular audits to protect your data from unauthorized access or misuse.

8. Consent and Withdrawal

Where consent is the basis for processing, you may withdraw your consent at any time by contacting privacy@nexaleader.com. This will not affect the lawfulness of processing prior to withdrawal.

9. Use of Processors

We may use third-party processors to manage data (e.g., cloud hosting, analytics). All processors are contractually obligated to comply with GDPR standards.

10. Complaints

If you believe your data rights have been violated, you have the right to lodge a complaint with your local data protection authority in the EU or EEA.

11. Contact Us

If you have questions about this GDPR Policy or your personal data, please contact us at privacy@nexaleader.com.