Skip to content
Legal

Privacy & Safeguards Policy

NEXACC LLC handles accounting, payroll, tax, and medical billing data for businesses and practices nationwide. This policy explains what we collect, how it is used, and the safeguards that protect it. Effective August 31, 2026.

IRS Pub. 4557 safeguards TLS encrypted site-wideSecurity program details

Information we collect

Contact details you submit through our forms, estimators, scheduling pages, and onboarding flow: name, business or practice name, email address, telephone number, state, and the notes you choose to include.

Engagement information needed to deliver bookkeeping, payroll, tax, medical billing, credentialing, and advisory services — including accounting records, payroll data, tax documents, and, where a signed Business Associate Agreement is in place, protected health information used for claims work.

Limited technical information from your visit: pages viewed, referring source, and campaign parameters. Analytics only run after you give consent on the banner, and are disabled when your browser sends Do Not Track or Global Privacy Control signals.

How we use information

To respond to your request, prepare a proposal, deliver contracted services, and support you through the engagement.

To meet legal, regulatory, and professional obligations, including IRS e-file program requirements and record-retention rules.

To improve the accuracy and security of our own systems. We do not sell, rent, or trade client or taxpayer information, and we do not use taxpayer information for marketing.

Taxpayer information (IRC §7216)

Tax return information is used solely to prepare and file your return and to support the engagement you hired us for. We do not disclose or use tax return information for any other purpose without your prior written consent, as required by Internal Revenue Code §7216 and Treasury Regulation §301.7216.

As an IRS Authorized e-file Provider (EFIN 868369), we follow IRS Publication 1345 and Publication 4557 for the handling, transmission, and storage of taxpayer data.

Protected health information (HIPAA)

For medical billing, credentialing, and revenue cycle engagements, NEXACC acts as a Business Associate. We execute a Business Associate Agreement before receiving protected health information, restrict access to assigned staff, and use only encrypted, access-controlled channels for PHI.

Never send PHI, full Social Security numbers, or bank credentials through website forms or ordinary email. Use the secure upload link we provide during onboarding.

How we protect information

All pages and form submissions on this site are transmitted over TLS with HTTPS enforced site-wide. Client data at rest is stored in access-controlled, encrypted systems with row-level security so records are only readable by authorized accounts.

Access is granted on a least-privilege basis, protected by unique credentials and multi-factor authentication, and reviewed when roles change. Our written Information Security Plan, external vulnerability scanning schedule, and incident response procedure are summarized on our security page.

Retention and disposal

Engagement and tax records are retained for the period required by IRS and state rules — generally a minimum of three years from the later of the return due date or filing date — and longer where a contract, statute, or open matter requires it.

Records past retention are destroyed securely: electronic media is wiped or cryptographically erased, and paper is cross-cut shredded.

When we share information

With service providers who process data on our behalf under written confidentiality and security terms (for example, our accounting, payroll, e-file transmission, clearinghouse, email delivery, and hosting platforms).

With taxing authorities, payers, or agencies where you have authorized the filing or submission.

Where required by law, subpoena, or a lawful government request. We do not share information with advertisers or data brokers.

Your choices and rights

You may request a copy of the personal information we hold about you, ask us to correct it, withdraw marketing consent, or request deletion where no legal retention duty applies. Email info@nexacc.com and we will respond within 30 days.

You can decline analytics cookies on the consent banner at any time; declining does not affect your ability to use the site or submit a form.

Children's information

This site and our services are directed to businesses and practices. We do not knowingly collect information from children under 13 except as it appears inside a client's tax or payroll records provided by the responsible adult.

Changes to this policy

We review this policy at least annually and whenever our systems or obligations change. The effective date below reflects the latest revision. Material changes are noted on this page.

Privacy contact

Direct privacy questions, access requests, or concerns about how your data was handled to our privacy contact at NEXACC LLC.

Text us on WhatsApp
TextInstagram