How Nexora handles account, verification, order and website information.
Updated: 30 August 2026
The intended controller is Nexora Biolab Ltd, trading as Nexora, at Unit 4, City Limits, Danehill, Earley, Reading RG6 4UP, United Kingdom. The company is not yet incorporated, so this notice is not operative and the relevant registration details will be added before launch. Privacy enquiries may be sent to info@nexorabiolab.com.
We may collect account and contact details; age and identity-verification results; organisation and authorised-representative details; research-purpose declarations; order, delivery, payment-reference, invoice and support information; and technical security data such as IP address, browser, device and event records. The access screen stores a local preference on your device, but that preference cannot grant buyer approval.
Vercel Web Analytics records anonymised page-view information so we can understand which pages are visited, the general source of traffic, country and device category. It does not use cookies and does not identify a visitor across different days or websites.
Didit hosts the identity-verification journey, which may include government ID, date of birth, selfie/liveness, face match and fraud signals. Nexora is designed to receive the minimum decision data needed to approve or reject an account, including the result, age threshold, provider reference and audit status. Raw ID images are not stored in the public website or sent through ordinary email.
Information is used to provide accounts and respond to enquiries; verify age, identity, organisations and lawful research intent; prevent fraud and misuse; create, reconcile, fulfil and support orders; issue invoices and service messages; maintain security and audit records; and meet legal, tax, accounting and regulatory obligations. The final lawful-basis record for each activity must be approved before launch.
Operational providers include Supabase for authentication, database, storage and server functions; Didit for identity and business verification; Resend and Google Workspace for transactional and support email; Vercel for website hosting and delivery; and the receiving bank for bank transfers. Information may also be shared with advisers, fulfilment and delivery providers, competent authorities, or other recipients where necessary and lawful. A crypto provider is not connected.
Some providers may process information outside the United Kingdom or European Economic Area. Before launch, Nexora will document the relevant processing locations, contractual safeguards and transfer mechanism. Access controls, signed webhooks, encrypted secrets, row-level database security, audit records and restricted staff tools are used to protect the service; no internet service can guarantee absolute security.
Account, order, invoice, tax and audit records will be retained only for the period needed for the service, legal claims and applicable accounting or regulatory requirements. Verification records will follow the configured Didit retention and deletion settings. Enquiries are retained while handled and for a limited period for support and security. A specific approved retention schedule will be published before launch.
Depending on the law that applies, you may have rights of access, correction, deletion, restriction, portability and objection, and the right not to be subject to a solely automated decision where the legal conditions apply. You may also complain to the UK Information Commissioner's Office or the supervisory authority in your EEA country. Some records must be retained despite a deletion request where law requires it.
Send privacy questions or requests to info@nexorabiolab.com. Material changes will be dated on this page, and any consent-dependent change will be handled as required by law.