Members, fees, attendance, schedules and more. Built for schools, gyms, academies, coaching centers, libraries and every membership-based business.
Built for membership-based businesses across India
Effective date: 1 July 2026 · Last updated: 19 July 2026
This Privacy Policy explains how Nxiora("we", "us", or "our") collects, uses, discloses, and safeguards personal information when you use the Nxiora platform and related services (the "Service"). This policy applies to administrators, staff users, and member-portal users of the Service. It is compliant with the Information Technology Act, 2000 (India) and its rules, and aligns with the principles of the General Data Protection Regulation (GDPR) for users in the European Economic Area.
By using the Service you agree to the collection and use of information as described in this policy.
1.1 Information you provide directly
1.2 Information collected automatically
1.3 Information from third parties
We process personal information for the following purposes:
Legal bases (GDPR): We rely on the following legal bases for processing: (a) performance of a contract — to provide the Service you have signed up for; (b) legitimate interests — analytics, security, and fraud prevention; (c) legal obligation — where required by law; and (d) consent — for optional marketing communications and cookies.
We do not sell, rent, or trade your personal data. We share data only in the following circumstances:
3.1 Sub-processors (third-party service providers)
We engage the following sub-processors to operate the Service. Each is bound by contractual obligations that restrict their use of your data to the provision of services to us:
| Provider | Purpose | Data location |
|---|---|---|
| Vercel | Cloud hosting & edge delivery | Global (primary: US) |
| Neon / PostgreSQL | Primary database | US-East (AWS) |
| Cloudflare R2 | File & document storage | Global (Cloudflare network) |
| Resend | Transactional email delivery | US |
| Gupshup | WhatsApp messaging | India / US |
| Razorpay | Payment processing | India |
| Google (OAuth) | Optional social sign-in | Global |
| Sentry | Error monitoring | US |
| Google Analytics | Aggregate usage analytics | Global |
3.2 Legal disclosures
We may disclose personal information where required by applicable law, court order, regulatory authority, or government request. We will, where legally permitted, notify you of such a request before disclosing your data.
3.3 Business transfers
If Nxiora is involved in a merger, acquisition, or sale of assets, your data may be transferred as part of that transaction. We will notify you by email and provide 30 days' notice before your data is transferred to a new entity under a different privacy policy.
Your data may be processed in countries outside India, including the United States and the European Union, by the sub-processors listed above. Where data is transferred outside India, we ensure appropriate safeguards are in place in accordance with the Information Technology Act, 2000 and its rules, including contractual data processing agreements with our sub-processors.
For transfers from the EEA, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission.
We use the following categories of cookies:
You can manage cookie preferences via the cookie consent banner shown on your first visit, or by configuring your browser settings. Disabling analytics cookies does not affect core platform functionality.
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, disclosure, alteration, or destruction:
Despite our best efforts, no method of transmission over the internet is 100% secure. If you discover a security vulnerability, please report it responsibly to security@nxiora.com.
Depending on your jurisdiction, you may have the following rights with respect to your personal data. To exercise any of these rights, email privacy@nxiora.com. We will respond within 30 days.
The Service is intended for use by organisations, not individual consumers. Accounts may only be created by individuals aged 18 or over. However, we recognise that our customers (e.g., schools, coaching centres) may store records for minor members.
As the data controller for their members' information, our customers are responsible for:
We act as a data processor with respect to minor member data and process it only on the documented instructions of our customer.
IT Act, 2000 (India): We comply with the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011. We maintain a comprehensive information security programme and publish this Privacy Policy as required.
GDPR (European Economic Area): For users in the EEA, we act as a data controller with respect to account and usage data, and as a data processor with respect to Customer Data. We provide Data Processing Agreements (DPAs) upon request. Contact privacy@nxiora.com to request a DPA.
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will post the revised policy on this page with an updated "Last updated" date. For material changes, we will send an email notification to the registered administrator at least 14 days before the changes take effect. Continued use of the Service after the effective date constitutes acceptance of the revised policy.
For any privacy-related questions, to exercise your rights, or to request a Data Processing Agreement, please contact:
Nxiora — Privacy Team
Email: privacy@nxiora.com
Security disclosures: security@nxiora.com
Website: https://nxiora.com
We aim to respond to all privacy inquiries within 30 days. For urgent security matters, please indicate "URGENT" in the subject line.