Skip to content
← Back

Privacy policy

Last updated 9 September 2026

This describes exactly what this site collects, why, where it goes, and how to get rid of it. It is written to match what the code actually does rather than to cover every eventuality, so if something here is unclear, ask and we will tell you plainly.

Who is responsible

NIX operates this site and decides how the information described below is used. For anything in this policy, including any request to see or delete your data, write to hello@nixagency.space. A real person reads that inbox.

What is collected, and when

Nothing is collected simply from reading this site. There is no analytics script, no advertising pixel, no third-party tracker and no cookie banner, because there is nothing to consent to.

If you send an enquiry, the form collects your name and email address, and optionally your company, which service you are asking about, a rough budget, and your message. Alongside it, the server records the IP address the request came from and your browser’s user-agent string. Those two are kept to identify and block form spam, which is the only reason they exist.

If you book a call, the form collects your name, email address, the time you chose, and optionally your company and a note about what you want to discuss. The same IP address and user-agent are recorded for the same spam-prevention reason.

If you create an account, your email address and a password are stored. The password is never stored as you typed it: it is hashed by Supabase Auth using bcrypt, a deliberately slow one-way function. Nobody can read it back, including us. A session cookie is then set so you stay signed in; it is strictly necessary and is not used for tracking.

Why

  • To reply to you. An enquiry cannot be answered without a name and an address to answer it at.
  • To keep a record of the conversation so a project discussed in March still makes sense in June.
  • To stop abuse of the contact form.
  • To sign you in, if you use the sign-in page.

Where the law requires a lawful basis, sending an enquiry is a step taken at your request before entering a contract; spam prevention rests on a legitimate interest in the site continuing to work.

Where it is stored, and who else can see it

Enquiries and bookings are stored in a Postgres database hosted by Supabase. The database has row-level security enabled: the public key used by this website can create a new enquiry or booking and can do nothing else — it cannot read, change or delete anything, including your own submission. Reading them requires a private key held only by us.

The booking calendar is worth being specific about. When it shows which times are taken, it asks the database for start times only — never names, emails or notes. Other visitors cannot see that you booked, or what you wrote.

The site itself is hosted on Vercel, which processes the network requests needed to serve pages. When email is enabled, your confirmation and our notification pass through Resend. Sign-in is handled by Supabase Auth.

Those three companies are the only processors involved. Your information is never sold, never rented, never used to train a model, and never shared with anyone for marketing.

Servers may be located outside your country — the database region is in Asia and the hosting is distributed globally — so an enquiry sent from elsewhere will be transferred internationally in order to reach us.

How long it is kept

  • Enquiries that become projects: kept for the life of the working relationship and up to seven years afterwards, because tax and contract records have to be retainable.
  • Enquiries that go nowhere: deleted within twenty-four months.
  • Bookings: kept for twenty-four months after the call, so we can remember what we discussed if you come back.
  • Spam-prevention records (IP and user-agent): deleted with the enquiry or booking they belong to.
  • Sign-in sessions: until you sign out or the session expires.

What you can ask for

You can ask for a copy of everything held about you, ask for it to be corrected, or ask for it to be deleted outright. You can object to it being held at all. Depending on where you live, these rights come from the GDPR, the UK GDPR, India’s Digital Personal Data Protection Act, or your local equivalent — but you do not need to cite a law, and we will not ask which one applies to you.

Email hello@nixagency.space and we will action it within thirty days, usually the same week. There is no form to fill in and no charge.

Children

This is a business-to-business site and is not directed at anyone under 16. If a child has sent an enquiry, email us and we will delete it.

If something goes wrong

If a breach occurs that puts your information at risk, we will tell the people affected directly, and any regulator that has to be told, within the time the law allows. You will hear it from us rather than from someone else.

Changes

If this policy changes in a way that affects what happens to information already collected, we will email the people it affects rather than quietly changing the date at the top.