Overview
NexusForm4 ("we," "us," or "our") operates www.nexusform4.com and the NexusForm4 API infrastructure. This Privacy Policy outlines how we handle data when you access our website, use our data streams, or integrate our API (collectively, the "Services").
A Note on API Data Collection
While NexusForm4 delivers a downstream public data feed and does not ingest or store your application's private end-user data, we do collect necessary account, billing, and technical usage data to manage your subscription, prevent API abuse, and authenticate requests.
1. Information We Collect
We collect information directly from you, automatically via your API requests and website usage, and from third-party payment processors.
1.1 Information You Provide Directly. Account Data: When you register for an API key, we collect your email address, name, organization name, and authentication tokens (e.g., via Google OAuth or standard login).
Support and Feedback Data. If you contact us for technical assistance, reporting data anomalies, or requesting quota increases, we collect any information you choose to include in that communication.
1.2 Information Collected Automatically (API and Website Usage). When your applications execute queries against the NexusForm4 API stream, our servers automatically log technical metadata necessary to maintain uptime and verify quotas.
- Service Usage & Telemetry: We log the date and time of API requests, the specific endpoints targeted, total bandwidth consumed, query parameters, error rates, and response latencies.
- Device & Network Telemetry: We collect originating IP addresses (used to authenticate requests and detect geographical abuse), user-agent strings, and operating system variants.
- Website Analytics: We track basic interactions on our dashboard (e.g., referring pages, documentation sections viewed) to optimize our developer documentation.
1.3 Information from Third Parties. Billing Metadata: For paid subscription tiers, all payment information is handled directly by our processor, Stripe. NexusForm4 does not store or process raw credit card numbers. We only receive metadata such as billing ZIP code, country, card type expiration, and transaction success logs.
2. How We Use Your Information
We process your data for the following operational and legitimate business purposes:
- API Authentication & Provisioning: To generate your unique API keys, manage rate limits, enforce subscription tier quotas, and track usage balances.
- System Integrity & Security: To monitor for malicious burst queries, scraping variations designed to circumvent caching, unauthorized key sharing, or Distributed Denial of Service (DDoS) attacks.
- Infrastructure Optimization: Analyzing telemetry data to identify high-traffic endpoints, optimize database indexing, and reduce API payload delivery latencies.
- Transactional Communications: Sending system updates, schema deprecation notices, billing reminders, and critical infrastructure downtime alerts.
5. Data Security
NexusForm4 implements enterprise-grade technical guards to isolate and protect your account structure:
Data in Transit. All API traffic and dashboard interactions require mandatory TLS 1.3 encryption.
Credential Isolation. API keys are cryptographically hashed on our back-end layers.
Network Protections. We utilize gateway rate limiting, firewall configurations, and IP monitoring to thwart unauthorized access and system degradation.
6. Data Retention and Account Deletion
Technical Server Logs. Raw API request server logs (IP addresses, specific query strings) are kept for a limited operational window (typically 30–90 days) to diagnose network bugs and analyze abuse patterns, after which they are automatically pruned or aggregated into anonymous volume metrics.
Account Retention. We preserve your profile configuration, historical billing receipts, and tier details for the active lifespan of your account subscription.
Account Deletion Requests. You can request permanent account deletion by contacting support@nexusform4.com. Upon verification, we will remove your identity records, rotate/nullify your API keys, and flush your billing linkages from live production systems within standard legal timeframes.
7. Global Compliance Rights (GDPR & CCPA)
Depending on your local legal jurisdiction (such as California or the European Union), you possess the right to:
- Request Access to the category logs or precise account elements we maintain regarding your profile.
- Request Erasure or rectification of outdated contact parameters.
- Object to Processing arrangements predicated on balancing legitimate business interests.
To initiate a formal statutory request, contact us at support@nexusform4.com with the subject heading "Privacy Request." Because we do not store end-user records or downstream consumer data, requests must correspond strictly to your authenticated developer login properties.