1. Introduction
This Privacy Policy explains how Alliance Estate Index 1 (“we”, “us”, “our”) collects, uses, stores, and shares personal information when you use the Nexus workflow platform, including the Nexus web application and the C4E Nexus mobile application (collectively, the “Service”). The Service is an internal business tool used by employees, contractors, and authorized partners of our organization to submit, review, and audit workflow requests across business units.
By accessing or using the Service, you agree to the collection and use of information in accordance with this policy. If you do not agree, please do not use the Service.
2. Information We Collect
We collect the following categories of information:
a. Account & identity information
- Full name and display name
- Work email address
- Phone number (used for SMS one-time-password sign-in where enabled)
- Google account identifier (when signing in with Google)
- Role(s), business unit, and permissions assigned by your organization’s administrator
b. Workflow content
- Information you submit in forms (request details, comments, approvals, rejections, status updates)
- Photos and files you attach to requests, approvals, IT asset records, or delivery proofs
- Audit events generated automatically by your activity within the Service (immutable, append-only)
c. Device & technical data
- Mobile device push notification token (Expo / Apple / Google push services), used only to deliver workflow notifications
- Device model, operating system, and app version (for compatibility and crash reporting)
- IP address, request timestamps, and basic session metadata
- Diagnostic and crash reports if you opt in (via Sentry); these may include stack traces, breadcrumbs, and the screen where an error occurred
3. How We Use Information
We use information to:
- Authenticate you and maintain your session
- Route requests, approvals, and notifications to the correct people based on your organization’s configured rules
- Maintain an immutable audit log of workflow events as required for compliance and internal review
- Send transactional notifications (push, email, SMS) about requests, approvals, reminders, and security events
- Diagnose problems, investigate abuse, and improve the reliability and security of the Service
We do not sell personal information, use it for behavioral advertising, or share it with third parties for their own marketing.
4. Legal Basis for Processing
Where applicable law requires a legal basis, we process personal information based on one or more of the following: (i) the contractual relationship between you (or your employer) and us; (ii) our legitimate interests in operating, securing, and improving the Service; (iii) compliance with legal obligations; and (iv) your consent, where it is required (for example, for optional crash diagnostics).
5. Service Providers & Sub-processors
We use the following service providers to operate the Service. Data shared with each is limited to what is necessary for the listed purpose:
- Supabase — authentication, database, storage, and real-time messaging infrastructure
- Google (OAuth) — sign-in with your Google account
- Apple Push Notification service / Firebase Cloud Messaging (via Expo) — delivery of push notifications to your mobile device
- Resend — transactional email delivery
- SMS provider — delivery of one-time passwords for phone-based sign-in
- Vercel — web application hosting
- Upstash QStash — scheduled background jobs
- Sentry — optional crash and error reporting
6. Data Retention
Account, workflow, and audit information is retained for as long as your organization continues to use the Service, plus a reasonable period thereafter to satisfy legal, tax, and audit requirements. Audit events are immutable and are retained for the lifetime of the workspace. Diagnostic logs are typically retained for up to 90 days unless required for an active investigation.
7. Security
We use industry-standard safeguards to protect personal information, including encryption in transit (HTTPS/TLS), encryption at rest for databases and file storage, role-based access control, row-level security policies, and audit logging of administrative actions. No system is perfectly secure; please report any suspected vulnerabilities to privacy@alesindex1.com.
8. Your Rights
Subject to applicable law, you may have the right to: access the personal information we hold about you; request correction of inaccurate information; request deletion of your account and associated data (subject to retention requirements for audit records); object to or restrict certain processing; and lodge a complaint with a supervisory authority. To exercise these rights, contact your organization’s administrator or email us at privacy@alesindex1.com.
9. Children
The Service is not directed to children under 16, and we do not knowingly collect personal information from children. The Service is provided to authorized users of an organization for business use only.
10. International Transfers
The Service may store and process information in regions different from where you live, including the United States and the European Union. Where required, we rely on appropriate transfer mechanisms (such as Standard Contractual Clauses) to protect your information.
11. Push Notifications & Permissions
The mobile app may request the following permissions:
- Notifications — to deliver workflow updates and reminders. You can disable this in your device settings.
- Camera — to capture photos for requests, approvals, and delivery proofs.
- Photo library — to attach existing photos to requests, approvals, and delivery proofs.
Permissions are requested only when the related feature is used. You can revoke any permission at any time from your device settings.
12. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, notify you through the Service.
13. Contact Us
If you have questions about this Privacy Policy or our data practices, contact us at privacy@alesindex1.com.