Legal

Privacy Policy

Effective date: February 1, 2026

1. Overview

This Privacy Policy explains how Nexari Health ("Nexari", "we", "us") collects, uses, shares, and protects information when you use the Nexari Health workforce-compliance platform and related services (the "Service"). By using the Service, you agree to the practices described here.

Nexari Health is not a HIPAA-covered entity and does not process PHI. The Service handles only employee/workforce data — names, emails, role assignments, and credential documents (certifications, licenses, background checks). Please do not upload patient records, care plans, diagnoses, or any protected health information through the Service.

2. Information We Collect

We collect the following categories of information:

  • Account information: name, email, organization name, role (agency, family, subcontractor, admin), and password (hashed).
  • Customer Content: credential documents you upload (e.g., HHA certificates, CPR cards, TB test results, driver's licenses, background-check confirmations, training records), employee profiles, and internal notes.
  • Workforce data: employee names, roles, supervisor assignments, credential expiration dates, and compliance scores submitted by authorized users for the purpose of workforce compliance tracking.
  • Billing information: we use Stripe to process payments. Stripe collects your card details directly; Nexari only stores Stripe customer and subscription identifiers, plan selection, and billing status.
  • Usage data: log data such as IP address, browser type, pages visited, referrer, and timestamps, collected for security and product improvement.
  • Cookies and similar technologies: session cookies for authentication and essential site functionality.

3. How We Use Information

We use the information we collect to:

  • Provide, operate, and improve the Service;
  • Process documents and generate AI-powered summaries, classifications, compliance flags, and suggested replies;
  • Authenticate users and protect against fraud and abuse;
  • Process payments through Stripe;
  • Communicate with you about your account, updates, and support requests;
  • Comply with legal obligations and enforce our Terms of Service.

4. AI Processing & Subprocessors

To deliver document analysis, smart summaries, translations, and suggested replies, Nexari sends Customer Content to OpenAI, our AI subprocessor. OpenAI processes the content solely to return results to Nexari and does not, per its API data policy, use API submissions to train its models.

Our other key subprocessors include:

  • Stripe, Inc. — payment processing
  • MongoDB Atlas (or equivalent managed database provider) — data storage
  • Cloud hosting provider — application hosting and content delivery

We require subprocessors to maintain appropriate security and confidentiality safeguards.

5. How We Share Information

We do not sell your personal information. We share information only:

  • With subprocessors, as described above, to deliver the Service;
  • Within your organization (e.g., agency admins can see content uploaded by users in the same agency workspace);
  • With your explicit consent;
  • When required by law, subpoena, or to protect the rights, property, or safety of Nexari, our users, or the public;
  • In connection with a merger, acquisition, or sale of assets, in which case we will provide notice before personal information is transferred.

6. Data Retention

We retain account information and Customer Content for as long as your account is active or as needed to provide the Service. After account deletion, we may retain limited data (such as billing records and audit logs) as required by law or for legitimate business purposes (typically up to seven years).

You can request deletion of your account and associated content at any time by contacting us at the email below.

7. Security

We use industry-standard technical and organizational measures to protect your information, including encryption in transit (TLS), access controls, hashed passwords, and audit logging. No method of transmission or storage is 100% secure; we cannot guarantee absolute security.

8. Your Rights

Depending on where you live, you may have rights regarding your personal information, including the right to access, correct, delete, or port your data, and to opt out of certain processing. To exercise these rights, contact us at the email below. We will respond within the time required by applicable law.

California residents (CCPA/CPRA): you have the right to know what personal information we collect, request deletion, and opt out of the sale or sharing of personal information (we do not sell personal information).

EEA / UK residents (GDPR): our legal bases for processing include contract performance, legitimate interest, consent, and legal obligation. You have the right to lodge a complaint with your supervisory authority.

9. Children's Privacy

The Service is not directed to children under 16, and we do not knowingly collect personal information from children. If you believe a child has provided us information, contact us so we can delete it.

10. International Transfers

Nexari is operated from the United States. If you access the Service from outside the U.S., your information may be transferred to and processed in the U.S. and other countries where our subprocessors operate.

11. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated by email or through the Service. The "Effective date" above will be updated accordingly.

12. Contact Us

Privacy questions or requests? Contact us at nexari@nexarihealth.com.

Made with Emergent