Privacy Policy

Effective August 31, 2026. Little Harbor Labs is the operator of this service.

1. Who we are

Nextract is owned and operated by Little Harbor Labs. This Privacy Policy explains how we process personal data when we provide a hosted Nextract service, our marketing site, and related communications.

If you deploy Nextract on infrastructure you control, we typically do not process your Customer Content. This Policy still applies if you contact us, create an account on a site we operate, or grant us access for support.

Privacy requests: [email protected].

2. Roles: account data vs customer content

Account Data is information about you as a user of the Service (name, email, authentication data, billing contacts if any, audit of your actions in the studio).

Customer Content is data your organization processes through pipelines (files, API bodies, database rows, partner messages, and similar). For Customer Content that includes personal data, you are the controller (or processor for your own customers). We act as a processor and process that data only on your documented instructions — configuring integrations, running pipelines, storing outputs you choose, and providing support.

A data processing addendum (DPA) is available on request for hosted customers that need one for GDPR or similar laws.

3. Personal data we collect

This section is our notice at collection. Depending on how you use the Service, we may process:

  • Identity and contact: name, email address, organization name
  • Account security: password hashes, session tokens, SSO identifiers, API key prefixes (not full secrets in logs)
  • Usage and operations: studio actions, run metadata, IP addresses in logs, approximate device/browser data
  • Communications: emails you send us; transactional mail we send (invites, password reset, alerts you configure)
  • Customer Content you submit, which may incidentally include personal data of your counterparties
  • Support materials you share (screenshots, log excerpts)

4. How we use personal data

We use Account Data to:

  • Provide, secure, and improve the Service
  • Authenticate users, enforce roles, and prevent abuse
  • Send service messages (security, invitations, operational alerts you enable)
  • Comply with law and enforce our Terms

Where GDPR or UK GDPR applies, we process Account Data on the bases of contract (to provide the Service), legitimate interests (security, product improvement that does not override your rights), consent where we ask for it, and legal obligation.

We process Customer Content as your processor under Article 28 GDPR (or equivalent) according to your instructions.

6. Sharing and subprocessors

We do not sell personal information as that term is used in the CCPA/CPRA.

We share data only with: (a) infrastructure providers that host compute, databases, or object storage for a hosted instance; (b) transactional email providers when we send mail; (c) optional error-monitoring tools if enabled; (d) professional advisers under confidentiality; (e) authorities when required by law; (f) a successor in a merger or asset transfer, with notice where required.

We also transmit Customer Content to destinations you configure (partner SFTP, APIs, databases, connectors). Those recipients are your processors or controllers, not ours.

A current subprocessor list for hosted Service is available by emailing us.

We may disclose data if required by law, court order, or a valid government request. Where legally permitted, we will notify the affected customer before disclosure so they can seek a protective order.

7. Storage, location, and security

Hosted Account Data and Customer Content are stored in the region(s) of the infrastructure you or we provision (typically a PostgreSQL database for application data, and local disk or S3-compatible object storage for organization files).

Secrets you save in the Service (SFTP and database passwords, API keys, connector secrets, signing private keys, and similar credentials) are encrypted at rest at the application layer using AES-256-GCM before they are written to the database. Passwords used to sign in are stored as one-way hashes, not as recoverable plaintext. Application-layer encryption applies to stored secrets; pipeline files and ordinary database records are stored as configured on disk or object storage, which may also be encrypted by the underlying host or cloud provider.

Application traffic is designed to use TLS in transit on hosted deployments.

Organization data is scoped by project (tenant). Access inside the studio is role-based. Outbound HTTP from the Service includes controls intended to reduce server-side request forgery against private networks.

Optional virus scanning may be enabled for inbound files. Run history may be retained for a configurable period, then purged.

More detail: Security and data protection. No security program is perfect; you must evaluate whether our measures fit your risk.

8. Retention

We retain Account Data for the life of the account and a reasonable period afterward for security, dispute resolution, and legal compliance.

Customer Content is retained according to your configuration (inbound, outbound, archive, staging, quarantine, and run records). You can delete integrations, files, and projects you control. Backups may persist for a limited window.

When you close a hosted account we delete or de-identify personal data we no longer need, subject to legal holds.

9. International transfers

If personal data is transferred internationally, we use appropriate safeguards such as the European Commission’s Standard Contractual Clauses (or UK addenda) where required, plus technical measures described in this Policy.

10. Your rights

Depending on your location, you may have rights to access, correct, delete, or export personal data, to object to or restrict certain processing, and to withdraw consent. California residents may have rights to know, delete, and opt out of “sale” or “sharing” (we do not sell or share for cross-context advertising).

To exercise rights regarding Account Data, email [email protected]. To exercise rights regarding Customer Content, contact your organization (the controller). We will support controllers with reasonably necessary assistance.

You may lodge a complaint with a supervisory authority. We would appreciate the chance to resolve concerns first.

11. Cookies

We use strictly necessary cookies and similar storage for authentication and security (session management). We do not currently use advertising cookies. If we add optional analytics, we will update this Policy and obtain consent where required.

12. Children

The Service is for business users and is not directed to children under 16. We do not knowingly collect personal data from children.

13. Changes and contact

We will post updates to this Policy with a new effective date. Material changes will be notified in-product or by email where appropriate.

Controller for Account Data on sites we operate: Little Harbor Labs. Privacy: [email protected]. Legal: [email protected].