Privacy Policy

Last updated: [DATE — fill in when this is finalized]

This Privacy Policy describes how TixNexa ("the App," "we," "us") collects, uses, and protects information when a law firm ("your organization") and its staff use the App to manage IT support tickets, assets, and related records.

Who this applies to

The App is an internal tool: your organization's IT staff, technicians, and administrators use it to track support requests on behalf of people at your organization ("requesters"). A requester does not create an account or log in — their information appears in the App only because a staff member entered it while logging a support request.

Information we collect

Account information, for each staff member with a login: name, email address, and a password. Passwords are never stored in plain text — only a one-way cryptographic hash. Every account also enrolls two-factor authentication (an authenticator app code, optionally supplemented by a device passkey); the underlying secrets used to verify these are stored, not the codes themselves.

Ticket content: requester name, email, and (optionally) phone number; the subject and description of the issue; the full conversation (replies and internal notes) between staff and the requester; any files attached to a ticket; and resolution notes once a ticket is closed. This can include whatever information a requester or staff member chooses to include — depending on the underlying support issue, that may touch on client-matter or otherwise sensitive business context. We do not review or moderate this content; it is your organization's own data, and your organization is responsible for what staff enter here.

Asset and equipment records: hardware inventory details your organization chooses to track (device names, serial numbers, purchase and warranty information, network addresses) and, if your organization opts to use it, an encrypted BitLocker recovery key for a given device. Recovery keys are encrypted at rest and only ever decrypted on an explicit, individually-logged request by an administrator.

Usage and diagnostic information ordinary to operating a web application: login timestamps, IP addresses associated with requests, and error logs — used only to operate and secure the App, never for advertising or behavioral tracking.

How information is shared

We do not sell your organization's data, and we do not share it for advertising purposes. Information may be shared in these specific cases, only when your organization has chosen to enable the corresponding feature:

Data retention

We retain your organization's data for as long as your organization maintains an active account, so that ticket history, asset records, and audit trails remain available. If your organization cancels its subscription or requests deletion, contact us using the information below to discuss removing your organization's data.

Security

Each organization's data is logically isolated from every other organization using the App. Passwords are hashed, sensitive fields (like BitLocker recovery keys) are encrypted at rest, and access to administrative actions is restricted by role. No method of storage or transmission is perfectly secure, and we cannot guarantee absolute security, but we take reasonable, industry-standard measures to protect information in our care.

Cookies

The App uses cookies only to keep you signed in and to remember basic preferences (such as light/dark theme). We do not use cookies for advertising or cross-site tracking.

Children's privacy

The App is a business tool intended for use by adult staff of our customer organizations. It is not directed at, and we do not knowingly collect information from, children.

Changes to this policy

We may update this policy from time to time. We'll update the "Last updated" date above when we do, and material changes will be communicated to organization administrators.

Contact us

Questions about this policy or your organization's data can be sent to aflynn2912@gmail.com.