Skip to content
HIVA·Nexus
Sign in
Back to home

Privacy

Privacy Notice

How we collect, use and protect personal data of HIVA Nexus users.

Data controller
Kernel Servicios en Informatica S.A. de C.V.
Domain
hivanexus.com
Last updated
May 6, 2026
Jurisdiction
Mexico City, Mexico

1. General Information

HIVA Nexus is a product operated by Kernel Servicios en Informatica S.A. de C.V., the same company behind the HIVA family. This notice describes how we process personal data of the people who use the service and the companies (tenants) who contract it.

Processing complies with Mexico's Federal Law on the Protection of Personal Data Held by Private Parties (LFPDPPP) and, where applicable, with the European Union's General Data Protection Regulation (GDPR).

Our guiding principle: collect the minimum necessary, keep it secure and respect the data subject's rights over their information.

2. Personal Data We Collect

We collect four categories of data:

  • Identity data: name, work email and, optionally, profile photo. Authentication runs through Microsoft Entra External ID.
  • Company (tenant) data: legal name, address, user role.
  • Service usage data: artifacts created, comments, approvals and audit records.
  • Technical data: IP address, user agent and aggregated performance metrics, with no individual profiling.

We do not request sensitive data (health, ethnic origin, political opinions) and we ask users not to include any in product artifacts.

3. Purposes of Processing

We process data for primary purposes, necessary to deliver the service:

  • Service delivery: artifact creation, editing and approval; impact analysis; RAG search.
  • Authentication and access control via Entra.
  • Technical support and incident response.
  • Billing and collection, where applicable.
  • Compliance with legal and tax obligations.

Secondary purposes — product improvement communications, experience surveys, aggregated internal research — require explicit consent and can be revoked at any time by writing to privacidad@hivanexus.com.

4. Transfers and Processors

To run HIVA Nexus we use processors that may have access to personal data, all under a data processing agreement:

  • Microsoft Azure: infrastructure, database, vector store, storage and telemetry. Primary region East US 2.
  • Microsoft Entra External ID: identity and authentication.
  • LLM providers: by default, Anthropic and/or OpenAI; with BYOK, whichever your organization configures.
  • Voyage AI: embedding models for semantic search.
  • Payment providers, when billing applies.

We do not sell or transfer personal data to third parties for marketing purposes.

5. Data Subject Rights (ARCO)

You have the right to Access, Rectify, Cancel or Object to the processing of your personal data, and to revoke your consent.

To exercise any of these rights, write to privacidad@hivanexus.com with your name and registered email, the right you wish to exercise, and a valid ID to verify your identity. We will reply within 20 business days.

6. Data Security

We apply technical and administrative controls proportional to risk:

  • Encryption in transit (TLS 1.2+) and at rest, with keys managed in Azure Key Vault. BYOK available for Enterprise.
  • Multi-tenant isolation in defense-in-depth: Row-Level Security in PostgreSQL, per-tenant collections in the vector store, tenant filter on the graph.
  • Hash-chained audit log; any tampering breaks the chain and leaves evidence.
  • Staff access role-bounded and logged.
  • Regular team training in privacy and security.

If an incident affects personal data, we will notify affected subjects and the relevant authorities within the legal timeframes.

7. Cookies and Similar Technologies

We use strictly essential cookies and local storage: session, language and theme preference. For analytics we use aggregated metrics that do not allow individual user identification. We do not use third-party advertising cookies.

8. Data Retention

We keep personal data while the account is active. After deletion, identity data is removed or anonymized within 90 days, except for what we are legally required to retain.

Signed official versions and the audit log are kept encrypted for up to 5 years for contractual and audit reasons. The deletion process is detailed in the Data Deletion page.

9. Changes to This Notice

We may update this notice to reflect changes in the service or in regulation. We will announce material changes at least 15 days in advance, in-product and by email. The last-updated date appears at the top of this document.

10. Contact

Data controller: Kernel Servicios en Informatica S.A. de C.V.

Product: HIVA Nexus

Privacy email: privacidad@hivanexus.com