1. What we collect
- Account details — name, email address, and optionally organisation and phone number.
- Sign-in data — a hashed password, session records, sign-in timestamps, and failed-attempt counts used to lock an account after repeated failures.
- Single sign-on — if you sign in with GitHub or Google, we store the provider's user identifier, your username and your verified email address. We never receive your password with them.
- Service records — demo requests, lab bookings, lab usage minutes, exam assignments and scores, certificates issued, plan and payment references.
- Technical data — IP address and browser user-agent, recorded against requests for security and abuse prevention.
2. Why we hold it
To create and run your account, provide lab access, mark exams and issue certificates, take and reconcile payment, prevent abuse of a platform that contains real network equipment, and meet our legal and accounting obligations.
3. Certificates are public by design
A certificate you earn can be checked by anyone holding its identifier at verify.nxsvl.com. That page shows your name, what you passed, the dates and whether it is still valid. It does not show your email address, your account or any other detail, and certificates cannot be listed or searched — a checker must already have the identifier.
4. Passwords
Passwords are stored only as a one-way hash. We cannot read them, recover them or tell you what yours is. Lab platform passwords we email you are generated for that lease and rotated when it ends.
5. Sharing
We do not sell personal information. We share it only with providers who help us run the service — hosting, email delivery and the lab platform itself — and where the law requires it. If you are on a cohort (team) plan, your membership and lab activity are visible to your cohort manager.
6. Cookies
We use two cookies, both strictly necessary: a session cookie and a sign-in cookie. Both are Secure, HttpOnly and SameSite=Lax. We do not use advertising or cross-site tracking cookies, and there is no third-party analytics on the portal.
7. Retention
Account and certificate records are kept while your account exists and afterwards where needed for accounting, dispute resolution or to keep issued certificates verifiable. Lab environments and their contents are deleted when a lease is reclaimed. Rate-limit counters are discarded within hours.
8. Your rights
Subject to applicable law you may ask for a copy of the information we hold about you, ask us to correct it, or ask us to delete it. Write to vlabs@nxsvl.com. We may need to verify your identity first. Note that deleting an account does not automatically invalidate a certificate already issued to you — tell us if you want it revoked as well.
9. Security
Traffic is encrypted in transit. Sign-in is rate limited and locks after repeated failures. Administrative functions are separated from customer accounts. No system is perfectly secure, but we assess ours regularly and fix what we find.
10. Contact
Privacy questions and requests: vlabs@nxsvl.com, NexusSec Labs, Navi Mumbai, Maharashtra, India.
Last updated: 23 August 2026 · NexusSec Labs, Navi Mumbai, Maharashtra, India · vlabs@nxsvl.com