This privacy policy describes how AHA Associates Limited collects, uses and protects personal information when you visit our website, create an account, request a trial, apply for an Education licence, or use any Nexar product, including Nexar Docs, Nexar Plan and Nexar Core. Nexar is the product line of AHA Associates Limited, a company registered in England and Wales under number 14887702, whose registered office is 12 Saxon Road, Walton-on-Thames, England, KT12 3HD. We are the data controller.
Account information such as your name, email address and company name. Authentication data handled by Firebase Authentication. Billing details processed by Stripe, which never reach our servers. Licence and seat data: a SHA-256 hardware fingerprint, a licence token, the product and Revit version, plus per-licence counts of how many seats were in use each hour and how many checkouts were refused because every seat was busy. Education applications also include institution and eligibility fields, the email used for Autodesk Marketplace and a current proof document. The content of enquiries you send us. Posts you publish in Nexar Workspaces. We do not set cookies, we run no third-party analytics, and the Nexar products send no usage telemetry.
Your Revit models never reach us. Nexar runs inside Revit on your own machines and the automation is performed locally. If you connect Nexar to Autodesk Construction Cloud or BIM 360, you sign in to Autodesk in your own browser, the resulting access token is stored encrypted on your machine and is never sent to us, and the model is opened by your own installation of Revit. We hold no copy of your project data, drawings or models.
To create and manage your account, process payments and subscriptions through Stripe, generate and deliver licence keys, send transactional email such as verification and password reset, host the posts you publish in Nexar Workspaces, respond to enquiries and provide support, and to email you when Nexar Core launches if you joined the waitlist. We do not profile you and we do not use your data to train machine learning models.
Under UK GDPR we rely on performance of a contract for account, licensing and support activity; legal obligation for retaining financial records; legitimate interests for keeping the service secure and preventing licence abuse; and consent for the Nexar Core waitlist.
We use four processors: Google (Firebase authentication and database), Stripe (payments), Resend (transactional email) and Cloudflare (licence issuance and validation). Each receives only the minimum data needed and is contractually barred from using it for anything else. We do not sell personal data and we do not share it with advertising networks or data brokers. Where these providers process data outside the UK we rely on the UK International Data Transfer Addendum, UK adequacy regulations or an equivalent approved safeguard.
Account data is retained while your account is active and removed within 30 days of a deletion request. Education proof documents are deleted after approval or rejection, or automatically after 30 days if unresolved; decision metadata is retained for two years. Backups run on a rolling 30-day cycle, so a deleted record is purged from every backup within a further 30 days. Invoices and other financial records are kept for 6 years. Support correspondence is kept for 2 years.
Under UK GDPR you may access, correct, delete or port your personal data, restrict or object to processing carried out under legitimate interests, and withdraw consent. Email [email protected] and we will confirm receipt within 5 business days and complete the request within 30 days. You may also complain to the Information Commissioner's Office at ico.org.uk. For related legal terms see our terms of service, or return to the Nexar homepage.