Terms of Service

Last updated: September 2026

These terms govern your use of the NexPhase platform. By creating an account or accessing the service, you agree to these terms on behalf of yourself and your organisation.

Important disclaimer — analysis and advice only

NexPhase provides AI-assisted analysis, recommendations, and draft documents as decision-support only. It does not provide engineering certification, statutory compliance sign-off, or professional advice. All output — including FMEA results, maintenance intervals, service sheets, work orders, gap analyses, and any statutory or compliance indications — must be independently verified by a suitably qualified and competent person before it is relied upon, actioned in the field, or entered into a CMMS or other system of record.

You are solely responsible for decisions made and actions taken based on platform output. Never use unverified output for safety-critical work, isolation or permit procedures, statutory inspections, or regulatory submissions.

Use of the service

You may use NexPhase only for lawful business purposes related to reliability and maintenance management. You are responsible for the accuracy of data you upload and for having the right to upload it.

Accounts & access

You are responsible for safeguarding your credentials. Administrators may manage organisational access. Notify us promptly of unauthorised access.

Privacy and data handling

Our Privacy Policy explains collection, use and protection, service providers, retention, and access, correction or deletion requests. The Privacy Policy forms part of these terms; using NexPhase acknowledges those practices. You must not upload personal information unless authorised and after required notices or consents. Privacy Policy

AI-generated output

The platform uses AI for extraction, analysis and document generation. Output is a starting point and must be reviewed by a qualified person before safety-critical decisions or formal CMMS records.

Availability

We aim for high availability but do not guarantee uninterrupted service. Scheduled maintenance and emergency fixes may occur.

Limitation of liability

To the maximum extent permitted by law, NexPhase is not liable for indirect or consequential losses, or loss from reliance on unverified AI output. Liability for direct loss is limited to fees paid in the preceding 12 months.

Termination

Either party may terminate access under the applicable subscription agreement. On termination, customer data will be deleted in line with our Privacy Policy. Privacy Policy

Contact

Questions about these terms: contact@nexphase.biz.

Privacy Policy

Last updated: May 2026

NexPhase (“we”, “us”) provides a reliability and maintenance management platform to industrial operators. This page summarises how we handle data. For a copy of our full privacy notice, contact contact@nexphase.biz.

What we collect

Account information (name, email, organisation), customer-uploaded documents and equipment data, and standard server logs (IP, user-agent, request times) for security and reliability.

How we use it

Data is used solely to provide the service to your organisation: extracting maintenance tasks, running analyses and producing reports. Customer data is isolated per tenant and is not used to train third-party models.

Sub-processors

We use vetted infrastructure and AI providers. Current sub-processors include Replit Deployments on Google Cloud Platform (GCE) for hosting and storage, and OpenAI, Anthropic and DeepSeek for analysis. All AI providers are configured not to retain or train on customer data. A current list is available on request.

Hosting & data residency

The platform is hosted on Google Cloud Platform (GCE). Customer data is stored in managed services with encryption at rest. Production-region and regional-alternative details are available from contact@nexphase.biz.

Retention & deletion

Customer data is retained for the subscription. On termination, it is deleted within 30 days unless a longer period is required by contract or law.

International users (GDPR & equivalents)

NexPhase operates from Australia. EEA, UK and equivalent-jurisdiction users have access, correction, deletion and portability rights, and may object to or restrict certain processing. Requests to contact@nexphase.biz are actioned within 30 days. A Data Processing Addendum can be entered into where required.

Security

Traffic is encrypted in transit (TLS 1.2+ with HSTS). Data uses access-controlled managed services with encryption at rest. Authentication is per organisation and administrative actions are logged. Report issues to contact@nexphase.biz or /.well-known/security.txt.

Compliance status

NexPhase is not currently certified to SOC 2, ISO 27001 or equivalent third-party audit standards. Customers may request a security questionnaire response, vendor assessment or Data Processing Addendum at contact@nexphase.biz.

Contact

Questions, data access or deletion requests: contact@nexphase.biz.