Privacy Policy
Last updated:
In plain language
We collect your account details, the business information you enter, and the chats your website visitors have with your assistant. Visitors are anonymous: no names or emails are requested, and IP addresses are used only briefly for abuse protection. To answer a question, the relevant parts of your content and the visitor’s question are sent to our AI provider; your content is never used for other customers or to train models. Data is stored in the USA. You can delete conversations, content, a business or your account at any time; backups expire within 14 days.
This summary is for convenience only; the full text below is what applies.
On this page
1.Who we are and what this policy covers
Nexoply (“we”, “us”) operates Business AI Assistant (the “Service”) at nexoply.com: a platform that lets businesses (“customers”) add an AI assistant to their website that answers visitors’ questions using only that business’s own information. This policy explains what personal data we handle, why, and what your rights are.
We act in two different roles, and it matters which one applies to you:
- For customers and their team members, we are the controller (in Canadian terms, the organisation accountable) for account, billing, usage and support data. We decide how it is used.
- For business content and visitor chat data, we are a processor (service provider) acting on the customer’s instructions. The customer is the controller of the content it enters and of the conversations its website visitors have with its assistant. If you are a visitor who chatted with an assistant on a business’s website, that business is your first point of contact (see section 10).
This policy covers the customer app at nexoply.com, our administration app at admin.nexoply.com (used only by our staff), the chat widget that customers embed on their own websites, and our emails. It does not cover customers’ websites themselves.
2.Data we collect
Account data (customers and members)
- Name, email address and password. The password is stored only as an Argon2id hash; we cannot read it.
- Email verification status, your role on the platform, and your membership and role in each business.
- Sign-in sessions: a random session token (stored as a keyed hash) in an httpOnly cookie, its creation and expiry times, and which business you are currently working on. Customer sessions expire after 30 days without activity; staff sessions in the admin app expire after 12 hours.
- Private API keys (paid plans): a name, a hash of the key, when it was created and last used. We never store the key itself.
Business content (entered by customers)
- Business profile: name, description, contact details, address, opening hours and service areas.
- Services, FAQs, policies and uploaded plain-text documents.
- Assistant settings: tone preferences, welcome and fallback messages, colours, allowed website domains.
- The knowledge base derived from the above: text passages (“chunks”) and their vector embeddings, which are numerical representations used to find the passages relevant to a question.
Business content may include personal data (for example a staff member’s name in a profile). The customer decides what to enter and must not enter sensitive data such as health, financial or government ID details about individuals.
Visitor chat data (end users of customers’ websites)
- The messages a visitor types and the assistant’s replies, with timestamps.
- A random, anonymous visitor identifier that the widget creates and keeps in the visitor’s browser (localStorage). It is not linked to a name, email or account.
- The address of the page on which the chat started, with query strings and fragments removed so that tracking parameters and tokens are not stored.
- The visitor’s IP address, used only briefly for abuse and rate limiting: it is turned into a hashed bucket key that expires after a short time and is not stored with the conversation.
- Questions the assistant could not answer, shown to the customer so it can improve its content.
The assistant does not ask visitors for their name, email address or other personal data. If a visitor types personal data into the chat anyway, it becomes part of the conversation stored for that customer.
Usage, billing and technical data
- Usage counters per business (conversations, messages, AI responses and embeddings) to enforce plan limits.
- Subscription details: plan, status, billing period and Stripe customer and subscription identifiers. Card details are held by Stripe, never by us.
- Security audit logs: sign-ins and failed sign-ins, content changes, key issuance, deletions, plan changes and staff actions, with the account involved, a timestamp and the IP address of the request.
- Rate-limit counters (hashed keys derived from IP addresses, sessions or chatbots) that expire automatically.
- Server logs and error reports that may contain request paths, timestamps and identifiers. Secrets and sensitive fields are automatically redacted from logs.
Support communications
When you email us, we keep the correspondence and any details you provide so we can help you.
3.How we use data
- To provide the Service: create and secure your account, build your knowledge base, answer your visitors’ questions, show conversations and unanswered questions in your dashboard, send transactional emails (verification, password reset, billing notices) and process payments.
- To keep the Service secure and fair: detect and block abuse, enforce rate limits and plan limits, investigate incidents, and keep audit trails of security-relevant actions.
- To operate and improve the Service: monitor health and errors, measure aggregate usage, and fix problems. We do not use your content or your visitors’ messages to train AI models.
- To communicate with you: respond to support requests and send important notices about the Service, your plan or these policies. We do not send marketing emails without your consent.
- To comply with the law: keep billing records, respond to lawful requests and protect our rights.
4.AI processing
We want to be clear about what happens when the assistant answers a question:
- When a customer adds or changes business content, we split it into passages and send those passages to an AI provider to compute embeddings, which we store with the passages.
- When a visitor asks a question, we screen it for manipulation attempts, find the passages of that one business most relevant to the question, and send the business’s fact sheet, those passages, the last few turns of the conversation and the question to the AI provider, which generates the reply.
- The model is instructed to answer only from the business’s information and to say when it does not know. We check the reply before showing it and replace it with a fallback message if it appears to break those rules.
The AI provider is an external company offering an OpenAI-compatible API, chosen and configured by us (for example OpenAI, in the United States). The provider receives the content described above for the sole purpose of generating the embedding or the reply, under its API terms, and we do not permit it to use that data to train its models where the terms give us that choice. The current provider is listed in section 6, and we may change providers over time.
Only the content of the one business whose assistant is answering is ever included in a request; no other customer’s data, and no account data, is sent to the AI provider. The assistant has no access to tools, databases or the internet.
AI answers are generated automatically and can be inaccurate. They are informational only and do not produce legal or similarly significant effects on visitors; a visitor can always contact the business directly.
5.Legal bases and regional notes
Where a law such as the EU or UK GDPR applies, we rely on the following legal bases:
- Performance of a contract: providing the Service to customers under our Terms of Service, including account, billing and support data.
- Legitimate interests: securing the Service, preventing abuse, keeping audit logs, monitoring health and errors, and improving the Service. We balance these interests against your rights and use as little data as we can.
- Consent: for anything optional, such as marketing emails, which you can withdraw at any time.
- Legal obligation: keeping billing records and responding to lawful requests from authorities.
For visitor chat data and business content, we process data as a processor on the customer’s instructions; the customer is responsible for having a legal basis and for giving its visitors the required notices.
Canada. We comply with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy laws. We collect personal information only for the purposes described here, with your knowledge and consent where required, and we limit it to what is necessary. You may contact our privacy contact (section 14) with any question or complaint, and you have the right to complain to the Office of the Privacy Commissioner of Canada.
7.International transfers
Our servers and database are located in the United States, and our providers above are based there or operate globally. If you are in Canada, the European Economic Area, the United Kingdom, Switzerland or elsewhere, your data is transferred to and stored in the USA.
Where the law requires a transfer mechanism, we rely on the safeguards offered by our providers, such as standard contractual clauses or an applicable adequacy decision or data-privacy framework certification, and we apply the security measures in section 9 regardless of where data is stored. Contact us for details about the safeguards that apply to you.
8.Retention
We keep personal data only as long as needed for the purposes above:
| Data | Kept until |
|---|---|
| Account details | You delete your account, after which they are removed immediately from the live database |
| Sign-in sessions | You sign out, reset your password, or the session expires (30 days without activity; 12 hours for staff sessions) |
| Email verification and password-reset codes | Used once, locked after 5 wrong attempts, or expiry (15 minutes) |
| Business content and knowledge base | The customer edits or deletes it, or deletes the business |
| Conversations, messages and unanswered questions | The customer deletes them (individually or all at once), deletes the chatbot, or deletes the business |
| Usage counters and subscription records | The business is deleted; billing records may be kept longer where tax or accounting law requires |
| Security audit logs | 12 months |
| Rate-limit counters | Minutes to hours; they expire automatically |
| Server logs and error reports | A short rolling period needed to operate and debug the Service |
| Encrypted backups | 14 days after they are taken; data deleted from the live database disappears from backups within that period |
| Support emails | As long as needed to resolve the request and to keep a record of it |
Customers can delete individual conversations, their entire conversation history, knowledge documents, a chatbot, a whole business (which removes everything belonging to it) or their account from the dashboard. Deletion takes effect immediately in the live database; copies in backups expire within 14 days.
9.Security
We designed the Service with security in mind and use, among other measures:
- Argon2id password hashing; session tokens stored only as keyed hashes in httpOnly, secure cookies.
- HTTPS everywhere, with HTTP Strict Transport Security and a strict Content Security Policy.
- Strict tenant isolation: every record belongs to one business and every query and search is limited to the business the signed-in user is verified to belong to.
- Encryption of stored AI provider credentials; secrets are never sent to browsers.
- Rate limiting and abuse detection on sign-in, sign-up, password reset, the chat widget and the API.
- Audit logging of security-relevant actions.
- Least privilege: the administration app is a separate application with separate, short-lived sessions, and staff access is re-checked on every request.
- Encrypted backups, and network rules that expose the database only to the application.
No system is perfectly secure. If we learn of a breach affecting your personal data we will notify you and the relevant authorities as the law requires. Please report security concerns to [email protected].
10.Your rights
Depending on where you live, you may have the right to access the personal data we hold about you, to correct it, to have it deleted, to receive a copy in a portable format, to object to or restrict certain processing, and to withdraw consent. You also have the right to complain to your data-protection authority.
Customers and members
- Update your name, email address and password in the dashboard settings.
- Delete conversations, documents, chatbots, businesses or your entire account in the dashboard; deletion is immediate.
- Export your conversations with a private API key on plans that include API access.
- For anything else, or if you cannot sign in, email [email protected]. We may ask you to confirm your identity and will respond within the time the law allows (normally 30 days).
Website visitors
If you chatted with an assistant on a business’s website, that business controls the conversation and can delete it, so please contact the business first. If you contact us instead, we will help where we can and pass your request to the business as appropriate. Because visitors are anonymous, we may need details such as the website, the date and time, and the content of the conversation to locate it.
11.Children
The Service is a business tool. Accounts may be created only by adults (18 or over), and we do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, contact us and we will delete it.
A customer’s website, and therefore its chat widget, may be visited by anyone. Customers are responsible for complying with the laws that apply to their audience, and must not direct the assistant at children or configure it to collect data from them.
13.Changes to this policy
We may update this policy as the Service or the law changes. We will post the new version here with an updated “Last updated” date, and for material changes we will notify customers by email or in the dashboard before they take effect. Earlier versions are available on request.
14.Contact
Nexoply is responsible for this policy. To exercise your rights or ask a privacy question, contact our privacy contact:
- General questions and privacy requests: [email protected]
- Legal notices: [email protected]