1. Controller and scope
The controller of personal data relating to NexNode is M.O. Società a Responsabilità Limitata Semplificata, VAT and tax code 09508751212, registered at Piazza Montessori 11, 80011 Acerra (NA), Italy. Contact: info@movara.it; certified email (PEC): mosrls@pec.cgn.it.
This notice covers the NexNode website, accounts, dashboards, Server & Bot hosting, Web Hosting, hosted websites, File Manager and SFTP, paid plans, credits, referrals, support systems, and related features. External services reached through links apply their own notices.
2. Personal data processed
- Technical and browsing data: IP address, date and time, requested resources, user-agent, request identifiers, security logs, errors, and network or hosting data.
- Pseudonymous security signals: keyed HMACs of the exact IP, approximate network and a random signed device identifier; ASN and VPN, proxy, Tor or hosting indicators; registration velocity and early credit, Shop and server events. NexNode does not use a hardware fingerprint and does not store raw IPs, network prefixes or device identifiers in the graph.
- Approximate location: country inferred from the IP address and browser language settings, used to propose an available language. NexNode does not determine or store precise GPS location.
- Account data: username, email address, authentication credentials, account identifier, session status, and account-panel information.
- Discord data: Discord identifiers and username, temporary linking tokens, communities, and interactions needed to link an account and use requested Discord features.
- Service data: servers, game and version, settings, permissions, status, operational logs, allocated resources, user files and content, backups where available, and administrative actions.
- Web Hosting data: domains and DNS, application and runtime, site and provider identifiers, SSL, deployments, jobs, databases, backups, SFTP, public keys, file operations, disk and traffic use, web logs, and technical measurements.
- Commercial data: plan, orders, quantities, period, price, tax and invoice details, payment status and references, credit ledger, Shop purchases, refunds, and referrals.
- Communications: support requests, abuse reports, appeals, emails, and messages voluntarily sent through official channels.
- Device preferences: privacy choice, language, and browser access token as described in the Cookie Policy.
3. Sources of data
- The User, during registration, login, dashboard use, server configuration, or support contact.
- Discord and the bot when the User starts or confirms account linking.
- Network protocols, hosting infrastructure, security systems, and service operation.
- Server or community administrators who authorise access to a shared resource.
4. Purposes and legal bases
Website and service deliveryAccounts, authentication, Server & Bot hosting, Web Hosting, websites, dashboards, and requested features.Contract or pre-contractual steps, Art. 6(1)(b) GDPR.
Orders and billingPlans, payments, credits, renewals, invoices, refunds, and referrals.Contract, Art. 6(1)(b); legal duties, Art. 6(1)(c); anti-fraud legitimate interest, Art. 6(1)(f).
Language and accessibilityPropose a language from IP country and browser settings; remember it only with consent.Legitimate interest, Art. 6(1)(f); consent for optional storage, Art. 6(1)(a).
Security and abuse preventionProtect accounts, Users, servers, and infrastructure; detect fraud, malware, attacks, and violations.Legitimate interest, Art. 6(1)(f), and legal obligations where applicable, Art. 6(1)(c).
Support and communicationsHandle requests, reports, appeals, and operational communications.Contract, Art. 6(1)(b), or legitimate interest, Art. 6(1)(f).
Compliance and disputesMeet legal duties and authority requests; establish, exercise, or defend legal claims.Legal obligation, Art. 6(1)(c), and legitimate interest, Art. 6(1)(f).
5. Required and optional data
Strictly necessary technical data are provided automatically when a page or Service feature is requested. Without them, the feature cannot be supplied securely.
Username, email, and credentials are required for an account. Discord data are required only for Discord-linked features. Service content depends on the functions selected by the User.
Consent to remember the language is optional. Refusal does not prevent use of the website or Service, but the choice may not persist on the next visit.
6. Cookies and equivalent storage
The frontend does not install analytics, advertising, or profiling cookies. The API uses a signed, Secure and HttpOnly technical cookie to recognise the device pseudonymously only for security and abuse prevention; it is not a hardware fingerprint. The website also uses technical local storage for the privacy choice and, after login, for the account access token. The selected language is stored only with consent.
The storage list, duration, and choice controls are described at /cookies. Cookie settings can be reopened from the footer at any time.
7. Recipients and processors
Data may be processed by authorised personnel and contracted processors under Art. 28 GDPR, including xCloud and providers of hosting, CDN, infrastructure, DNS, security, transactional email, payments, support, and technical maintenance.
When a User links Discord or uses the bot, necessary data are exchanged with Discord and NexNode integration systems. Discord also acts as an independent controller for its platform.
Data may be disclosed to authorities, law enforcement, advisers, or rights holders where required by law or necessary to protect rights and security. Personal data are not sold or disclosed for behavioural advertising.
8. International transfers
Some technology providers or Discord may process data outside the European Economic Area. Transfers rely, as applicable, on an adequacy decision, the Data Privacy Framework, European Commission Standard Contractual Clauses, or another safeguard under Articles 44 and following GDPR.
Information on applicable safeguards may be requested at info@movara.it.
9. Retention
- Account and profile: for the account lifetime and the technical deletion period, unless legal duties, security, or disputes require retention.
- Browser access token: until logout, expiry or invalidation, browser-data deletion, or automatic removal after an invalid session.
- Servers, settings, and files: for the server lifetime and according to inactivity, deletion, and backup periods shown in the plan or dashboard. Deleted data may remain temporarily in isolated backups until overwritten.
- Hosted websites, files, databases, and settings: for the site lifetime and according to inactivity, deletion, and backup periods shown in the plan or Web Control.
- Orders, invoices, payments, and credit entries: for statutory accounting, tax, anti-fraud, refund, and dispute periods or as needed to defend rights.
- Technical and security logs: for a period proportionate to security, diagnosis, abuse prevention, and incident investigation; longer only for a specific incident or obligation.
- Trust & Abuse Graph events: normally 90 days. The device cookie normally expires after 180 days; account-linked HMAC signals follow the account lifetime, while signals included in a security decision may be retained longer to prevent circumvention and handle appeals.
- Support, abuse, and appeal records: for handling and then as needed for legal obligations and defence of rights.
- Privacy choice and language: no more than six months unless changed or deleted earlier.
- Records subject to tax, accounting, or legal duties: for statutory periods.
10. Security
NexNode applies risk-appropriate technical and organisational safeguards, including HTTPS encryption in transit, access controls, role separation, security-event logging, updates, backups where available, browser security policies, and incident procedures.
No system is risk-free. Users must protect credentials, use unique passwords, keep independent copies of important data, and report suspicious access promptly.
11. Children
The Service is not intended for anyone under 13 or any higher age required by Discord or local law. Consent-based processing for information-society services follows the age set by national law; in Italy, a child may consent from age 14, otherwise parental-authority authorisation is required.
NexNode may verify age or authorisation where reasonably necessary and delete data collected contrary to these rules.
12. Automated decisions and profiling
NexNode does not perform advertising profiling or make decisions based solely on automated processing that produce legal or similarly significant effects under Art. 22 GDPR.
Automated systems may flag anomalies, abuse, or security risks. Relevant measures may be reviewed and challenged through support.
13. Data subject rights
- Access and a copy of personal data.
- Rectification of inaccurate or incomplete data.
- Erasure and restriction where the legal conditions apply.
- Portability of data provided by the User, where applicable.
- Objection to processing based on legitimate interests.
- Withdrawal of consent at any time, without affecting prior lawful processing.
- Information on safeguards for international transfers.
Requests may be sent to info@movara.it or mosrls@pec.cgn.it. The controller normally responds within one month and may request proportionate information to verify identity.
14. Complaints
A data subject may complain to the Italian Data Protection Authority at www.garanteprivacy.it or to the competent supervisory authority in their Member State, without prejudice to other administrative or judicial remedies.
15. Updates and contacts
This notice may be updated when features, providers, legal bases, or applicable law change. Material changes will be communicated appropriately before taking effect where required.
Privacy information and rights: info@movara.it. Formal communications: mosrls@pec.cgn.it.
16. Web Hosting data and the User's role
For Web Hosting, NexNode may process site name, domain and DNS configuration, application and runtime choices, xCloud or infrastructure identifiers and status, SSL information, deployment and job status, database and backup metadata, File Manager and SFTP operations, SFTP username and public key, technical logs, disk use, monthly HTTP traffic, response measurements, and support or staff audit events.
For WordPress, NexNode may process the administrator username and email selected for provisioning. A generated initial password is transmitted for one-time display or reset and is not intended to be retained in readable form after delivery. Full payment-card data and private SSH keys are not required by NexNode.
When the User hosts a website that collects personal data, the User normally determines the purpose and means of that collection and is responsible for the visitor notice, lawful basis, cookies, rights requests, and any required processor agreement. NexNode processes hosted data on the User's behalf only to the extent and for the duration necessary to provide the hosting service, unless NexNode independently determines a security or legal purpose.
17. Orders, payments, credits, and referrals
For paid services NexNode processes order, plan, quantity, billing period, price, tax and invoice details, payment status and provider identifiers, credit ledger entries, Shop purchases, refunds, chargebacks, and fraud-prevention events. The payment provider processes payment credentials under its own or contracted responsibilities; NexNode normally receives only the result and limited transaction references.
Referral processing includes the referral code or link, referring account, attributed registration, eligibility checks, and bonus-credit ledger. These data are used to perform the requested promotion, prevent duplicate rewards and abuse, and maintain accounting and dispute records.
18. Providers, authorised access, and retention
Hosting and website management may involve xCloud, infrastructure and DNS providers, transactional email providers, payment processors, security services, and authorised NexNode support personnel. Provider identifiers and operational responses are kept from end users where they contain internal or security information, but are processed by NexNode to operate and diagnose the Service.
Hosted files and site configuration follow the site's lifetime, deletion, inactivity, and backup cycle. Web access logs and usage measurements are retained for periods proportionate to billing, capacity, security, and diagnosis. Orders, invoices, payments, and credit ledgers are retained for statutory accounting, tax, anti-fraud, and dispute periods. Staff actions and support tickets are retained for accountability and defence of rights.