Privacy Policy
Last updated: 13 August 2026
This policy explains what personal data nxip collects, why, and what rights you have over it. It covers nxip.dev and nx-ip.com, operated by Sonny Wigmore, trading as nxip, of Poole, Dorset, United Kingdom ("nxip", "we", "us"), the controller of the data described below.
1. What we collect
- Account data: the email address and organization name you sign up with.
- IPAM data: the pools, subnets, and allocations you create through the API or Terraform provider. This may include names or descriptions you choose to give them; it does not include any data about the actual hosts or traffic on your networks.
- API key material: we store a one-way cryptographic hash and a short prefix of each API key, never the raw key itself.
- Request logs: for every API request: the requesting IP address, user agent, endpoint, and outcome, kept as an audit trail for security and abuse prevention. Retention is tied to your account's tier (currently 7 days on Free, 30 on Starter, 90 on Team, custom for Enterprise).
We do not directly collect or store payment card information. Starter tier payments are handled entirely by our payment processor, Stripe (see Section 3); nxip only ever receives your subscription status, not card details. We do not use cookies, browser tracking, or advertising identifiers of any kind. Our infrastructure providers (see Section 3) may set minimal operational cookies of their own as part of running their networks (for example, security/DDoS protection at the edge); we do not control or read these.
2. Why we collect it, and our legal basis
| Data | Purpose | Legal basis |
|---|---|---|
| Email, org name | Create and operate your account | Performance of a contract |
| IPAM data | Deliver the Service itself | Performance of a contract |
| Request logs | Security, abuse prevention, debugging | Legitimate interest |
| Email (verification/contact) | Send verification and service emails | Performance of a contract |
| Email (product updates) | Occasional email about new features, sent to existing users about our own product. Unsubscribe any time, does not affect verification/service email. | Legitimate interest (soft opt-in) |
"Soft opt-in" means: because your email was collected when you created your account, and this is us marketing our own product to an existing user rather than a cold contact, UK electronic-marketing rules (PECR) let us send these without a separate consent checkbox at signup, provided we say so clearly at that point (we do, on the signup page) and give a working opt-out on every email (we do, a one-click link that needs no login). Unsubscribing only stops product-update email; account and service email (like billing or security notices) continues regardless, since that's sent under a different legal basis (performance of a contract) that doesn't depend on this consent mechanism.
3. Who we share it with
We use a small number of infrastructure providers to run the Service. We don't sell data to anyone.
- Fly.io (US): hosts the API and database.
- Resend (US): sends verification, transactional, and product-update email.
- Cloudflare (US, global network): hosts and serves the nx-ip.com website, and proxies nxip.dev.
- Brevo (EU): relays messages sent to hello@nx-ip.com.
- Stripe (US): processes payments for Starter tier subscriptions. See Stripe's own privacy policy for how they handle payment data directly.
Some of these providers process data outside the UK. Resend's and Cloudflare's data processing agreements (Resend's DPA, Cloudflare's DPA) incorporate the UK and EU Standard Contractual Clauses for this kind of transfer. Fly.io self-certifies under the EU-U.S. and UK-U.S. Data Privacy Frameworks. Brevo is based in France, which the UK's own data-transfer adequacy regulations already recognize, so no additional mechanism applies there. We do not otherwise share your data with third parties, except where required by law.
If your organization requires its own signed Data Processing Agreement covering how nxip processes personal data on your behalf (for example, if a subnet or pool description you create happens to include someone's name), email hello@nx-ip.com and we'll provide one.
4. How long we keep it
Account and IPAM data is kept for as long as your account is active. Request/audit logs are kept per the retention periods in Section 1. If you delete your account (via hello@nx-ip.com), we delete the associated organization, pool, subnet, and allocation data; a residual record may be kept briefly where needed for security or legal purposes.
5. Free tier data note
The Free tier is an evaluation offering with no guaranteed data durability. See Section 5 of our Terms of Service for details. This is a service-level position, not a change to how we handle personal data under this policy: your account email is still processed as described above regardless of tier.
6. Your rights
Depending on your location, you may have the right to:
- Access the personal data we hold about you;
- Correct inaccurate data;
- Request erasure of your data;
- Restrict or object to certain processing;
- Receive your data in a portable format.
To exercise any of these, email hello@nx-ip.com. If you're in the UK and unhappy with our response, you can complain to the Information Commissioner's Office.
7. Security
API keys are never stored in raw form, only a salted hash, following the same approach used for password storage. Access to production infrastructure is limited to the people operating the Service. No method of transmission or storage is perfectly secure, so we can't guarantee absolute security.
8. Data breach notification
If we become aware of a security incident that puts your personal data at risk, we will notify affected users without undue delay, and notify the ICO where the law requires it, consistent with our obligations under UK GDPR.
9. Children
The Service is not directed at, and we do not knowingly collect data from, anyone under 16.
10. Changes to this policy
We may update this policy from time to time. Material changes will be reflected by updating the "Last updated" date above.
11. Contact
Questions about this policy: hello@nx-ip.com.
