Skip to content

Privacy Policy

Last updated:

In plain language

We collect your account details, the business information you enter, and the chats your website visitors have with your assistant. Visitors are anonymous: no names or emails are requested, and IP addresses are used only briefly for abuse protection. To answer a question, the relevant parts of your content and the visitor’s question are sent to our AI provider; your content is never used for other customers or to train models. Data is stored in the USA. You can delete conversations, content, a business or your account at any time; backups expire within 14 days.

This summary is for convenience only; the full text below is what applies.

On this page
  1. 1.Who we are and what this policy covers
  2. 2.Data we collect
  3. 3.How we use data
  4. 4.AI processing
  5. 5.Legal bases and regional notes
  6. 6.Sharing and subprocessors
  7. 7.International transfers
  8. 8.Retention
  9. 9.Security
  10. 10.Your rights
  11. 11.Children
  12. 12.Cookies and browser storage
  13. 13.Changes to this policy
  14. 14.Contact

1.Who we are and what this policy covers

Nexoply (“we”, “us”) operates Business AI Assistant (the “Service”) at nexoply.com: a platform that lets businesses (“customers”) add an AI assistant to their website that answers visitors’ questions using only that business’s own information. This policy explains what personal data we handle, why, and what your rights are.

We act in two different roles, and it matters which one applies to you:

  • For customers and their team members, we are the controller (in Canadian terms, the organisation accountable) for account, billing, usage and support data. We decide how it is used.
  • For business content and visitor chat data, we are a processor (service provider) acting on the customer’s instructions. The customer is the controller of the content it enters and of the conversations its website visitors have with its assistant. If you are a visitor who chatted with an assistant on a business’s website, that business is your first point of contact (see section 10).

This policy covers the customer app at nexoply.com, our administration app at admin.nexoply.com (used only by our staff), the chat widget that customers embed on their own websites, and our emails. It does not cover customers’ websites themselves.

2.Data we collect

Account data (customers and members)

  • Name, email address and password. The password is stored only as an Argon2id hash; we cannot read it.
  • Email verification status, your role on the platform, and your membership and role in each business.
  • Sign-in sessions: a random session token (stored as a keyed hash) in an httpOnly cookie, its creation and expiry times, and which business you are currently working on. Customer sessions expire after 30 days without activity; staff sessions in the admin app expire after 12 hours.
  • Private API keys (paid plans): a name, a hash of the key, when it was created and last used. We never store the key itself.

Business content (entered by customers)

  • Business profile: name, description, contact details, address, opening hours and service areas.
  • Services, FAQs, policies and uploaded plain-text documents.
  • Assistant settings: tone preferences, welcome and fallback messages, colours, allowed website domains.
  • The knowledge base derived from the above: text passages (“chunks”) and their vector embeddings, which are numerical representations used to find the passages relevant to a question.

Business content may include personal data (for example a staff member’s name in a profile). The customer decides what to enter and must not enter sensitive data such as health, financial or government ID details about individuals.

Visitor chat data (end users of customers’ websites)

  • The messages a visitor types and the assistant’s replies, with timestamps.
  • A random, anonymous visitor identifier that the widget creates and keeps in the visitor’s browser (localStorage). It is not linked to a name, email or account.
  • The address of the page on which the chat started, with query strings and fragments removed so that tracking parameters and tokens are not stored.
  • The visitor’s IP address, used only briefly for abuse and rate limiting: it is turned into a hashed bucket key that expires after a short time and is not stored with the conversation.
  • Questions the assistant could not answer, shown to the customer so it can improve its content.

The assistant does not ask visitors for their name, email address or other personal data. If a visitor types personal data into the chat anyway, it becomes part of the conversation stored for that customer.

Usage, billing and technical data

  • Usage counters per business (conversations, messages, AI responses and embeddings) to enforce plan limits.
  • Subscription details: plan, status, billing period and Stripe customer and subscription identifiers. Card details are held by Stripe, never by us.
  • Security audit logs: sign-ins and failed sign-ins, content changes, key issuance, deletions, plan changes and staff actions, with the account involved, a timestamp and the IP address of the request.
  • Rate-limit counters (hashed keys derived from IP addresses, sessions or chatbots) that expire automatically.
  • Server logs and error reports that may contain request paths, timestamps and identifiers. Secrets and sensitive fields are automatically redacted from logs.

Support communications

When you email us, we keep the correspondence and any details you provide so we can help you.

3.How we use data

  • To provide the Service: create and secure your account, build your knowledge base, answer your visitors’ questions, show conversations and unanswered questions in your dashboard, send transactional emails (verification, password reset, billing notices) and process payments.
  • To keep the Service secure and fair: detect and block abuse, enforce rate limits and plan limits, investigate incidents, and keep audit trails of security-relevant actions.
  • To operate and improve the Service: monitor health and errors, measure aggregate usage, and fix problems. We do not use your content or your visitors’ messages to train AI models.
  • To communicate with you: respond to support requests and send important notices about the Service, your plan or these policies. We do not send marketing emails without your consent.
  • To comply with the law: keep billing records, respond to lawful requests and protect our rights.

4.AI processing

We want to be clear about what happens when the assistant answers a question:

  1. When a customer adds or changes business content, we split it into passages and send those passages to an AI provider to compute embeddings, which we store with the passages.
  2. When a visitor asks a question, we screen it for manipulation attempts, find the passages of that one business most relevant to the question, and send the business’s fact sheet, those passages, the last few turns of the conversation and the question to the AI provider, which generates the reply.
  3. The model is instructed to answer only from the business’s information and to say when it does not know. We check the reply before showing it and replace it with a fallback message if it appears to break those rules.

The AI provider is an external company offering an OpenAI-compatible API, chosen and configured by us (for example OpenAI, in the United States). The provider receives the content described above for the sole purpose of generating the embedding or the reply, under its API terms, and we do not permit it to use that data to train its models where the terms give us that choice. The current provider is listed in section 6, and we may change providers over time.

Only the content of the one business whose assistant is answering is ever included in a request; no other customer’s data, and no account data, is sent to the AI provider. The assistant has no access to tools, databases or the internet.

AI answers are generated automatically and can be inaccurate. They are informational only and do not produce legal or similarly significant effects on visitors; a visitor can always contact the business directly.

6.Sharing and subprocessors

We do not sell personal data, and we do not share it with third parties for their own marketing. We share data only with the service providers below, which process it on our behalf and under contract, and otherwise only as described after the table.

Service providers that process data on our behalf
ProviderPurposeData involvedLocation
DigitalOcean, LLCCloud hosting of the application and database, encrypted backups; object storage for images you upload for your chat widget (button image, avatar, logo)All data described in this policy; uploaded images are publicly accessible at an unguessable address so your website can display themData centres in New York and San Francisco, USA
Cloudflare, Inc.DNS, reverse proxy, DDoS and bot protection in front of our serversIP addresses, request metadata, encrypted traffic passing through its networkGlobal network; company in the USA
AI provider (currently OpenAI, L.L.C.)Generating embeddings and answersBusiness content passages, visitor questions and recent conversation turns; no account dataUSA
Resend, Inc.Sending transactional email (verification codes, password resets, security notices)Your name, email address and the content of those emailsUSA
Stripe, Inc. (when billing is enabled)Subscription payments, invoices, customer billing portalName, email, billing address, payment details (held by Stripe), plan and subscription statusUSA; Stripe may process in other regions
Transactional email provider (SMTP)Sending verification, password-reset and billing emailsEmail address, name and the content of the emailDepends on the provider configured; see section 14 to ask

We may also disclose data:

  • to the customer whose assistant a visitor used: the customer sees the conversations on its own website in its dashboard and may export them;
  • when required by law, such as in response to a valid court order or to protect the rights, safety or property of anyone;
  • in a business transfer, such as a merger or sale, in which case this policy continues to apply and we will notify you of any change in who is responsible.

We will update this list when we add or change providers. You can ask us for the current list at any time.

7.International transfers

Our servers and database are located in the United States, and our providers above are based there or operate globally. If you are in Canada, the European Economic Area, the United Kingdom, Switzerland or elsewhere, your data is transferred to and stored in the USA.

Where the law requires a transfer mechanism, we rely on the safeguards offered by our providers, such as standard contractual clauses or an applicable adequacy decision or data-privacy framework certification, and we apply the security measures in section 9 regardless of where data is stored. Contact us for details about the safeguards that apply to you.

8.Retention

We keep personal data only as long as needed for the purposes above:

How long we keep each kind of data
DataKept until
Account detailsYou delete your account, after which they are removed immediately from the live database
Sign-in sessionsYou sign out, reset your password, or the session expires (30 days without activity; 12 hours for staff sessions)
Email verification and password-reset codesUsed once, locked after 5 wrong attempts, or expiry (15 minutes)
Business content and knowledge baseThe customer edits or deletes it, or deletes the business
Conversations, messages and unanswered questionsThe customer deletes them (individually or all at once), deletes the chatbot, or deletes the business
Usage counters and subscription recordsThe business is deleted; billing records may be kept longer where tax or accounting law requires
Security audit logs12 months
Rate-limit countersMinutes to hours; they expire automatically
Server logs and error reportsA short rolling period needed to operate and debug the Service
Encrypted backups14 days after they are taken; data deleted from the live database disappears from backups within that period
Support emailsAs long as needed to resolve the request and to keep a record of it

Customers can delete individual conversations, their entire conversation history, knowledge documents, a chatbot, a whole business (which removes everything belonging to it) or their account from the dashboard. Deletion takes effect immediately in the live database; copies in backups expire within 14 days.

9.Security

We designed the Service with security in mind and use, among other measures:

  • Argon2id password hashing; session tokens stored only as keyed hashes in httpOnly, secure cookies.
  • HTTPS everywhere, with HTTP Strict Transport Security and a strict Content Security Policy.
  • Strict tenant isolation: every record belongs to one business and every query and search is limited to the business the signed-in user is verified to belong to.
  • Encryption of stored AI provider credentials; secrets are never sent to browsers.
  • Rate limiting and abuse detection on sign-in, sign-up, password reset, the chat widget and the API.
  • Audit logging of security-relevant actions.
  • Least privilege: the administration app is a separate application with separate, short-lived sessions, and staff access is re-checked on every request.
  • Encrypted backups, and network rules that expose the database only to the application.

No system is perfectly secure. If we learn of a breach affecting your personal data we will notify you and the relevant authorities as the law requires. Please report security concerns to [email protected].

10.Your rights

Depending on where you live, you may have the right to access the personal data we hold about you, to correct it, to have it deleted, to receive a copy in a portable format, to object to or restrict certain processing, and to withdraw consent. You also have the right to complain to your data-protection authority.

Customers and members

  • Update your name, email address and password in the dashboard settings.
  • Delete conversations, documents, chatbots, businesses or your entire account in the dashboard; deletion is immediate.
  • Export your conversations with a private API key on plans that include API access.
  • For anything else, or if you cannot sign in, email [email protected]. We may ask you to confirm your identity and will respond within the time the law allows (normally 30 days).

Website visitors

If you chatted with an assistant on a business’s website, that business controls the conversation and can delete it, so please contact the business first. If you contact us instead, we will help where we can and pass your request to the business as appropriate. Because visitors are anonymous, we may need details such as the website, the date and time, and the content of the conversation to locate it.

11.Children

The Service is a business tool. Accounts may be created only by adults (18 or over), and we do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, contact us and we will delete it.

A customer’s website, and therefore its chat widget, may be visited by anyone. Customers are responsible for complying with the laws that apply to their audience, and must not direct the assistant at children or configure it to collect data from them.

12.Cookies and browser storage

The customer app uses one strictly necessary session cookie and no advertising or analytics cookies. The chat widget uses no cookies at all; it keeps a random visitor identifier and the current conversation in the visitor’s browser storage. Our Cookie Policy lists every cookie and storage item, including the security cookies Cloudflare may set.

13.Changes to this policy

We may update this policy as the Service or the law changes. We will post the new version here with an updated “Last updated” date, and for material changes we will notify customers by email or in the dashboard before they take effect. Earlier versions are available on request.

14.Contact

Nexoply is responsible for this policy. To exercise your rights or ask a privacy question, contact our privacy contact: