Security
Your data is well protected.
Naxerio protects property, compliance and contract information with data isolation per organization, protected document storage and role-based access.

Data isolation per organization
Customer data is logically separated per organization, enforced in the application and in the database. Users only see data from the organization they are authorized for.
Roles and permissions
Access requires a signed-in user with the right permissions. Roles determine which data you see and which actions you can take.
Protected documents
Documents are not publicly accessible by default. Access depends on the user, the organization and their permissions.
Audit trail
Critical changes to dossiers are recorded: who changed what, when and in what context.
Hosting and data location
The primary production environment runs in the EU/EEA. Where supporting services process data outside the EEA, appropriate safeguards apply under the GDPR. Connections are encrypted, and backup and recovery measures are in place.
Subprocessors
These parties process data on behalf of Naxerio to deliver the platform. We announce intended changes in advance; customers can object within thirty days.
| Subprocessor | Purpose | Data | Location and safeguards |
|---|---|---|---|
| Supabase | Database, authentication and storage for the platform | Application data, accounts, documents and metadata | EU/EEA-oriented production configuration, with contractual, technical and organizational safeguards |
| Vercel | Hosting and running the platform | Technical metadata and limited request and log data | Configured execution regions, with GDPR safeguards and data minimization |
| Resend | Transactional email: invitations, notifications and system emails | Email address, name, necessary email content and technical metadata | Selected sending region where available, with GDPR safeguards |
| OpenAI | AI features: AI document chat, document analysis, classification, extraction and embeddings | Document content, metadata, questions, context and output where needed | According to the chosen provider configuration, with GDPR safeguards. No training of public models on customer data |
| Microsoft Azure (AI Document Intelligence) | Text recognition and document processing for AI document import | Document content, pages, metadata and processing data | Within the chosen Azure configuration, with contractual, technical and GDPR safeguards |
As of 8 October 2026, in line with part 9 of the General Terms and Conditions.
Data location and transfers
- Primary customer content and the production database are in an EU/EEA-oriented production environment.
- For processing or access outside the EEA, we apply safeguards under Article 44 and onwards of the GDPR, such as an adequacy decision or standard contractual clauses.
- Specific arrangements for EU/EEA-only processing are made in writing only.
Export and switching
- While using Naxerio, you export overviews and registers to Excel (XLSX) yourself, and the audit trail to CSV. You download documents in their original format.
- We put together a full export of your organization on request; ask for it via support@naxerio.com. After termination, we make it securely available within thirty days, in a structured, commonly used and machine-readable format, with documents in their original format where possible.
- The export contains your input, output and the related metadata, such as object data, documents, status and workflow data, roles and records. Software, generic models and other customers' data are not included.
- Where the EU Data Act applies, you can switch to another provider or to your own infrastructure. From 12 January 2027, we charge no switching fees for this.
- After the export period, we delete your data, including backups, within thirty days, unless a statutory retention obligation applies.
Want to know more about security?
Want to know more about our infrastructure, security measures or the data processing agreement? We're happy to share this with a proposal, during due diligence or on request.

