This Privacy Policy explains how Nexforum collects, uses, stores and protects your personal data when you use our forum hosting service. We collect only what we need to provide the Service, we do not sell your data to anyone, and we give you clear controls over what we hold. If you have any questions, contact us at hello@nexforum.net.
Nexforum operates the forum hosting platform at nexforum.net ("the Service"). For the purposes of UK and EU data protection law, Nexforum is the data controller in respect of personal data collected through the sign-up and billing process.
You — as the operator of a forum hosted on Nexforum — are a separate data controller in respect of the personal data collected from your forum's members. Section 11 of this policy addresses your responsibilities in that regard.
We collect only the personal data necessary to provide and operate the Service:
| Data category | What it includes | Why we collect it |
|---|---|---|
| Account data | Name, email address, username | To create and manage your hosting account |
| Billing data | Billing address, payment method token (via Stripe — we never see your full card number) | To process subscription payments |
| Hosting data | Domain name, server logs, IP address, files and databases in your hosting account | To provide the hosting service and maintain security |
| Communications | Emails you send to our support address | To respond to support requests and maintain records |
| Usage data | Pages visited on nexforum.net, browser type, referring URL | To understand how the website is used and improve it |
We do not collect sensitive personal data (such as health information, racial or ethnic origin, or political opinions) and we do not purchase data from third parties.
We use your personal data only for the following purposes:
We do not use your personal data for automated decision-making or profiling that produces legal or similarly significant effects.
For users in the UK and European Economic Area, we process your personal data under the following legal bases as defined in the UK GDPR and EU GDPR:
We share your personal data with a small number of third-party service providers who process it on our behalf. All third-party processors are bound by data processing agreements and are required to handle your data in accordance with applicable data protection law.
| Provider | Purpose | Data shared |
|---|---|---|
| Stripe | Payment processing | Billing name, email, payment method details |
| ClientExec | Billing portal and account management | Account data, billing history |
| Hosting infrastructure provider | Server infrastructure in Montreal, Canada | Hosting account data, files and databases |
| Email delivery provider | Sending transactional emails | Your email address and email content |
We do not share your personal data with any other third parties except where required by law, court order or to protect the rights and safety of Nexforum, our customers or the public.
We retain your personal data only for as long as necessary for the purposes for which it was collected:
After the applicable retention period, data is securely deleted or anonymised.
Under UK and EU data protection law, you have the following rights in relation to your personal data:
To exercise any of these rights, contact us at hello@nexforum.net. We will respond within 30 days. We may need to verify your identity before processing your request.
You also have the right to lodge a complaint with a supervisory authority. In the UK, this is the Information Commissioner's Office (ICO) at ico.org.uk.
Nexforum's main website (nexforum.net) uses a small number of cookies:
We do not use advertising cookies, tracking pixels or third-party retargeting technologies on nexforum.net.
You can control cookies through your browser settings. Blocking strictly necessary cookies may affect your ability to use the billing portal.
Your hosting data (files and databases) is stored on servers located in Montreal, Canada. Canada has been recognised by the European Commission as providing an adequate level of data protection for commercial organisations under PIPEDA.
Payment data is processed by Stripe, which operates globally and maintains appropriate safeguards including Standard Contractual Clauses for transfers outside the UK and EEA.
Where we transfer personal data outside the UK or EEA for other purposes, we ensure appropriate safeguards are in place in accordance with applicable data protection law.
The Nexforum Service is intended for users aged 18 and over. We do not knowingly collect personal data from anyone under 18. If you believe we have inadvertently collected data from a minor, please contact us immediately at hello@nexforum.net and we will delete it promptly.
As a forum operator, you are responsible for implementing appropriate age verification and content controls on your forum if it is accessible to or intended for minors.
When you operate a forum hosted on Nexforum, your forum members provide personal data to your forum (such as usernames, email addresses and post content). You are the data controller of that data — not Nexforum.
As a forum operator, you have independent obligations under applicable data protection law. These include:
Nexforum processes your forum data (the files and databases in your hosting account) solely as a data processor acting on your instructions. We do not access, read or analyse your members' data except where necessary for security, technical support or legal compliance as described in this policy.
We may update this Privacy Policy from time to time. When we make significant changes, we will notify you by email to your registered address and update the "Last updated" date at the top of this page. We will provide at least 14 days' notice before significant changes take effect.
Your continued use of the Service after the effective date of an updated Privacy Policy constitutes your acceptance of the changes.
For any questions about this Privacy Policy, to exercise your data subject rights or to raise a data protection concern, please contact us:
We aim to respond to all data protection enquiries within 5 business days and to fulfil data subject requests within 30 days as required by law.
If you are not satisfied with our response, you have the right to complain to the UK Information Commissioner's Office at ico.org.uk or your local supervisory authority if you are based in the EEA.