What becomes of the data you submit
The Privacy page describes the site as a whole. This one covers only the two forms, and follows them from the keystroke to the mailbox that receives the request.
What becomes of the data you submit
The two forms, field by field
The contact request collects: first name, last name, role, institution, country, email address, a topic chosen from a closed list, and a message.
The estimate request collects the same identity fields, an optional telephone number, and the configuration you composed: institution type, volumes, modules, deployment mode and options. That configuration is not personal data; it is what makes the returned figure match what you asked for.
No hidden field collects anything else. The only field you do not see is a bot trap: it stays empty for a visitor, and a request that fills it is rejected.
What the site does with it, step by step
Your input is revalidated on the server — never in the browser alone — then passed through the anti-abuse guards. The site then composes two emails: a confirmation addressed to you, and a notification to the internal team that handles the chosen topic.
An estimate request also produces a PDF document, computed in memory at the time of the request, returned in the page and attached to your confirmation. It is stored nowhere: a new request recomputes it.
The site writes your details to no database, no file and no sales tool, for a simple reason: it has none. The notification sent to the team is the record of your request.
Who receives your request
The recipient is determined by the server from the topic, never by the browser: a press enquiry reaches the press mailbox, a security report the security mailbox, a privacy question the privacy mailbox. No address supplied by the request is ever used as a recipient.
These mailboxes are institutional and internal to NEXCLARA. They are not sold, shared or fed into a commercial directory, and no form data is passed to a third party for prospecting.
The two technical intermediaries
Email delivery is handled by Resend, a transactional sending provider. The content of the message necessarily passes through it, as it would through any sending service.
The institutional mailboxes are hosted by Microsoft Exchange Online. Once the email is delivered, your request sits there like any other professional message.
No other provider is involved: no customer relationship manager, no analytics tool, no prospecting platform.
How long this data exists
On the site's side, only two technical traces, both held in memory and both erased when the server restarts: the irreversible fingerprint used to recognise a duplicate submission, kept for ten minutes, and the rate-limit counter, over a rolling quarter hour. Neither contains your message.
Beyond that moment, your details exist only in the emails sent and in the mailbox that received them. Their deletion is requested, and carried out, on those mailboxes.
The two consents
Two separate boxes, neither pre-ticked. The first authorises the handling of your request: without it, the form is not sent. The second, optional, authorises a later commercial exchange; refusing it does not prevent your request from being handled.
They are never merged into a single box standing for acceptance of everything, and your choice is carried as is into the internal notification.
Exercising your rights
Any request for access, rectification, erasure or objection should be sent to privacy@nexclara.com. The “Privacy” topic of the contact form leads there directly.
Data processing by the NEXCLARA platform, once deployed at a financial institution, follows an entirely separate framework: the institution is the controller there, and NEXCLARA the technical processor. This page does not cover it.