How Nexgile handles your data.
We build digital workers you own and run yourself. That philosophy extends to your data: we collect very little, we sell nothing, and what you give us stays under your control. This page is the whole policy, in plain terms.
At a glance
We don't sell your data
Not to advertisers, not to data brokers, not to anyone. There is no version of our business that involves selling personal information.
We collect almost nothing
Browse the site and we see only what a standard web server logs — no analytics, no trackers. Personal details enter the picture only when you fill in a form.
Your product data is yours
The software we build is delivered as source code you own and self-host. Once delivered, it runs on your infrastructure — we are not in the loop.
Rehearsal runs on synthetic data
Simulation, preview, and red-teaming happen inside the Simulated Enterprise — a complete synthetic company — not on your production data.
Access or deletion, anytime
Email us and we will show you, fix, or delete your data within the timeframes the law requires — wherever you live.
A real inbox answers
privacy@nexgile.com is monitored by our Data Protection Officer. Questions, requests, complaints — start there.
On this page
1. Who we are & scope
In short This policy covers our website and our engagement with you — not the data inside software you self-host, where you are the controller.
Nexgile Inc. (Herndon, Virginia, USA) and its R&D subsidiary Nexgile Technologies Pvt Ltd. (Hyderabad, India) — together, "Nexgile," "we," "us" — build owned digital workforces: agentic-AI digital workers designed for your business, rehearsed against a Simulated Enterprise, and delivered as source code you own. This policy applies to:
- Website visitors — anyone browsing nexgile.com.
- Prospects and clients — people who contact us, evaluate our platform, or engage us to build digital workers.
- Candidates — people who apply for roles through our careers page.
What this policy does not cover. Once we deliver software to a client, that software runs on the client's own infrastructure. Any data processed inside a client's self-hosted systems is controlled by that client, under that client's policies. We build the software; we don't operate it, and there is no Nexgile cloud or runtime in the loop after delivery. If you interact with a system a Nexgile client operates, that client's privacy policy governs.
2. Information we collect
In short We collect what you type into our forms, the technical data a standard web server logs, and — for client engagements only — design-time inputs governed by a data-processing agreement.
Information you provide
- Contact form: your name, email address, subject, and project description. This goes to contact@nexgile.com so we can respond to you.
- Careers applications: your name, email address, phone number, LinkedIn profile if you share it, experience level, and cover letter — plus a resume/CV if you choose to send one by email.
Information collected automatically
- Technical data: IP address, browser type and version, operating system, and the pages requested — captured in the standard server and security logs every website keeps.
That is the whole list: the site sets no analytics cookies and runs no analytics scripts today (see Cookies & analytics). None of it identifies you personally unless combined with information you have chosen to provide.
Client design-time inputs. Some clients bring materials to help us design their digital workers — for example, RPA estate exports or operational logs. This happens on the client's terms, is used only to design that client's workers, and is governed by a data-processing agreement put in place before anything moves. Nothing in this category is ever collected from the website.
3. How we use information
In short We use your information to respond to you, operate and secure the site, evaluate applications, deliver client engagements, and meet legal obligations — each with a lawful basis behind it.
We use personal information only for the purposes below. Where the GDPR applies, the legal basis for each purpose is mapped alongside it.
| Purpose | What we use | Legal basis (GDPR) |
|---|---|---|
| Responding to your inquiry | Contact form details | Legitimate interests (answering you); pre-contractual steps at your request |
| Evaluating job applications | Careers application details | Pre-contractual steps at your request; legal obligation (employment law) |
| Delivering client engagements | Business contact details; design-time inputs under a DPA | Performance of a contract |
| Operating and securing the website | Technical data (server logs) | Legitimate interests (keeping the site available and safe) |
| Meeting legal requirements | Whatever the specific obligation requires | Legal obligation |
We do not use your personal information for automated decisions that produce legal or similarly significant effects about you. We do not use website visitor data, contact inquiries, or candidate applications to train AI models.
5. AI systems & your data
In short Your digital workers rehearse on synthetic data, your design inputs stay isolated from model training, and the finished product runs entirely on your infrastructure.
We are an AI company, so we hold ourselves to specifics here — scoped, honest ones.
Synthetic rehearsal. Every digital worker we design is rehearsed against a Simulated Enterprise: a complete synthetic company with synthetic data. Simulation, preview, and red-teaming all run against this synthetic environment — not against your production data. That is the scope of this pledge: rehearsal happens on data we generate, so testing your workers never requires exposing your operations.
Design-time inputs are separately governed. When a client chooses to share design-time materials — operational logs, RPA estate exports, process documentation — that is a deliberate, contracted act. It happens on the client's terms, under a data-processing agreement signed before any data moves, and the materials are used solely to design that client's workers.
Training-data isolation. We maintain training-data isolation controls: client data and design-time inputs are not used to train models for other clients or for general model improvement.
Prompt-data deletion. We maintain prompt-data deletion controls, so prompt content used during engagements can be deleted.
You own and run the result. Digital workers are delivered as source code the client owns and self-hosts. After delivery there is no Nexgile cloud or runtime in the loop, and no per-decision billing that would require us to observe your workers operating. Data your workers process in production lives on your infrastructure, under your control.
Oversight built in. The product supports human-in-the-loop oversight and tamper-evident audit trails, so the humans accountable for your operations can supervise and verify what digital workers do.
7. International transfers
In short We operate in the United States and India and use recognized legal safeguards, including standard contractual clauses, when data crosses borders.
Nexgile operates from Herndon, Virginia, USA and Hyderabad, India. Information you provide may be processed in either location.
When personal information moves across borders — including out of the European Economic Area, the United Kingdom, or other regions with transfer restrictions — we use recognized safeguards, including Standard Contractual Clauses where required, and we require equivalent protections from service providers who process data on our behalf. Wherever your data is processed, it receives the protections described in this policy.
8. Data retention
In short We keep personal information only as long as the purpose it was collected for requires, and we delete it on request.
We retain personal information no longer than needed for the purpose it was collected for, then delete or anonymize it. We do not warehouse data on the chance it becomes useful later.
| Data | Retention principle |
|---|---|
| Contact inquiries | Kept while we handle your inquiry and any follow-up conversation, then removed. |
| Careers applications | Kept for the hiring process for the role applied to, plus any period employment law requires. |
| Client engagement records | Kept for the engagement and as long as contract and legal obligations require. |
| Design-time inputs | Governed by the data-processing agreement; used only for the design engagement. |
| Server logs | Rotated and removed on the routine schedule needed to keep the site available and secure — not mined for analytics. |
You can request deletion at any time — see Your rights. Where a legal obligation requires us to keep something longer, we keep only what that obligation covers and delete the rest.
9. Security
In short We protect personal information with encryption, least-privilege access controls, and regular security reviews.
We apply security measures appropriate to the data we hold:
- Encryption in transit and at rest.
- Access controls built on least privilege — people see only what their role requires.
- Regular security reviews of our practices and systems.
- Tamper-evident audit trails in the product we deliver, so activity can be verified after the fact.
No method of transmission or storage is perfectly secure, and we don't claim otherwise. If you believe you've found a security vulnerability, email security@nexgile.com — we take reports seriously and respond promptly. Our Trust Center describes our security program, including the certifications we are pursuing, in more detail.
10. Your rights
In short Wherever you are, you can ask us to access, correct, delete, or stop processing your personal information by emailing privacy@nexgile.com.
Your rights vary by where you live, but our default is simple: if you ask us to show you, fix, or delete your data, we will, unless a legal obligation prevents it.
GDPR / UK GDPR
- Access your personal data and receive a copy
- Correct or delete it
- Restrict or object to processing
- Receive it in a portable format
- Withdraw consent at any time
- Complain to your supervisory authority
CCPA / CPRA
- Know what we collect, use, and disclose
- Request deletion or correction
- Opt out of sale or sharing — we do neither
- No discrimination for exercising rights: same service, same terms
DPDP Act, 2023
- Access a summary of your personal data
- Correction and erasure
- Grievance redressal
- Nominate a person to exercise rights on your behalf
California, specifically. We do not sell personal information and do not share it for cross-context behavioral advertising, so there is nothing to opt out of — but the right is yours regardless, and we will never discriminate against you for exercising any privacy right.
India, specifically. We are committed to alignment with the Digital Personal Data Protection Act, 2023. Requests and grievances go to the same address as everything else: privacy@nexgile.com.
How to exercise your rights
Email our Data Protection Officer. Tell us who you are and what you'd like us to do. We may need to verify your identity to protect your data from fraudulent requests. We respond within the timeframes required by applicable law, and if we ever can't fulfill a request, we'll tell you why.
Email privacy@nexgile.com11. Children's privacy
In short Our services are for businesses and are not directed to anyone under 18.
Nexgile provides business-to-business services. Our website and services are not directed to children, and we do not knowingly collect personal information from anyone under 18. If you believe a child has provided us personal information, email privacy@nexgile.com and we will delete it.
12. Changes to this policy
In short When this policy changes materially, we'll say so prominently before the change takes effect, and every version carries its date.
We update this policy as our practices, products, or legal obligations evolve. Every version is dated at the top of this page. For material changes — anything that meaningfully affects what we collect or how we use it — we will post a prominent notice on this page before the change takes effect. Continuing to use the site after a change takes effect means the updated policy applies.
This version is effective July 31, 2026. It replaces the version dated January 5, 2026.
13. Contact us
In short Privacy questions go to privacy@nexgile.com; we also keep dedicated inboxes for security and accessibility.
Data Protection Officer
privacy@nexgile.com
Nexgile Inc.
13800 Coppermine Road Dulles, 311,
Herndon, VA 20171, USA
Nexgile Technologies Pvt Ltd.
Hyderabad, India
For privacy questions, rights requests, sub-processor lists, or complaints, the DPO inbox is the fastest path.
Other inboxes
- Vulnerability reports security@nexgile.com
- Accessibility feedback accessibility@nexgile.com
- Everything else contact@nexgile.com
How we secure and govern what we build — including the certifications we're pursuing — lives in the Trust Center.