Last Updated: May 25, 2026
NexaCore CMMS ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how personal data is collected, used, stored, and protected within the NexaCore computerized maintenance management platform and mobile application.
1. Personal Data We Collect
To provide the CMMS features, we collect and store the following employee and user profile details:
• **Identity Data:** Full name, username, and assigned user role (e.g., Administrator, Manager, Supervisor, Planner, Technician, Requester).
• **Contact Data:** Work email address and phone number (if provided).
• **Profile Media:** Profile avatar pictures uploaded by the user to the secure storage buckets.
• **Operational Assignments:** Facility location, department, shift logs, safety training certifications, and team memberships.
2. How Personal Data is Stored & Secured
Secure Database Hosting
All user data, transactional logs, and operational reports are stored in a secure cloud database hosted by Supabase using enterprise-grade PostgreSQL. All data is encrypted in transit using TLS/SSL and encrypted at rest.
Row-Level Security (RLS) & Multi-Plant Scoping
Your data is strictly partitioned. Row-Level Security (RLS) is active at the database level across all tables, ensuring users can only read and write data mapped to their active facility (plant_id) or assigned permission scope.
3. Who Can See Personal Data
Personal and operational data is accessible only to authenticated users within your organization, strictly scoped by their authorization role:
• **Admins/Managers:** Can view all user profiles, work orders, parts inventory, shifts, and audit logs across their assigned plant location.
• **Supervisors/Planners:** Can view profiles, assign technicians to tasks, and schedule shifts or preventive maintenance work.
• **Technicians:** Can view profiles of team members, see shift plans, and view details of work orders assigned to them or their department.
• **Requesters:** Can only see their own submitted requests and basic contact profiles.
We do not sell, rent, or trade personal data to third parties. Data is only disclosed as required to fulfill operational tasks (such as sending transactional email alerts via Resend API) or to comply with legal regulations.
4. Data Retention & Deletion
We retain personal data and maintenance records for as long as your organization maintains an active subscription agreement. If an account is deactivated by an administrator, the corresponding profile remains stored in a disabled state to maintain referential integrity in historical work order audit logs. Complete deletion of organizational records can be requested by authorized facility administrators.
5. Contact Information
If you have questions regarding this Privacy Policy, database security measures, or data access requests, please contact your NexaCore plant administrator or system support at support@nexacorecmms.com.