Legal
Privacy Policy
This policy explains what data NEXZ collects, how we use it, which third parties are involved, how long we keep it, and the rights you have over it.
Last updated: 30 July 2026
1. Who we are
NEXZ provides an AI employee platform that helps companies handle customer communication, scheduling and internal knowledge work. This Privacy Policy explains what data we process when you use nexz-ai.com and the NEXZ web application, and it applies to all NEXZ accounts and connected workspaces.
For privacy questions or requests, contact us at privacy@nexz-ai.com.
2. Data we collect
We collect only the data needed to operate the service:
- Account data: name, email address, password hash (managed by our authentication provider), and authentication events.
- Workspace data: company name, industry, website, country, language and AI employee configuration you enter.
- Connected service data: messages, calendar events and documents you explicitly authorize NEXZ to access.
- Content you upload: files added to your knowledge base for AI retrieval.
- Billing data: subscription status, plan, invoices and payment metadata processed by Stripe. We never store full card numbers.
- Technical data: IP address, browser and device information, timestamps and error logs used for security and reliability.
3. Cookies and similar technologies
We use strictly necessary cookies and local browser storage to keep you signed in, maintain your session securely, remember interface preferences such as theme, and protect against fraud and abuse.
We do not use advertising cookies and we do not sell data to advertising networks. Where analytics are used, they are limited to aggregated product usage. You can clear cookies and local storage at any time in your browser, but signing in requires session cookies.
4. Google OAuth authentication
You can sign in to NEXZ with your Google account. When you do, Google shares a limited profile with us: your email address, basic profile information and a stable account identifier. We use this only to create and authenticate your NEXZ account.
We never receive or store your Google password. You can revoke NEXZ's access at any time at https://myaccount.google.com/permissions.
5. Gmail access
If you connect Gmail, NEXZ requests the minimum scopes needed to read, draft and send messages on your behalf so your AI employee can triage your inbox and prepare or send replies you configure or approve.
Email content is processed to generate summaries, classifications and draft replies. NEXZ does not use your Gmail content to train generalized AI models, does not sell it, and does not share it with third parties for advertising. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
6. Google Calendar access
If you connect Google Calendar, NEXZ reads availability and event details in order to answer scheduling questions and, where you allow it, create or update meetings resulting from approved workflows. Calendar data is used only for these scheduling features inside your workspace.
7. Google Drive access
If you connect Google Drive, NEXZ accesses only the files you select so they can be indexed as private company knowledge for your AI employee. Indexed content is stored in your private workspace and used solely to answer questions and produce work inside that workspace. NEXZ does not modify or delete your Drive files unless you explicitly request an action that does so.
8. AI processing
To generate answers, summaries, offers and drafts, relevant content from your workspace is sent to our AI model providers over encrypted connections and processed transiently to produce the requested output.
AI output can be inaccurate or incomplete. You remain responsible for reviewing AI-generated content before it is sent externally or relied upon for decisions. Your workspace content is not used to train third-party foundation models.
9. Third-party services
We rely on a small set of processors, each bound by contractual data-protection obligations:
- Supabase — authentication, database and file storage.
- Google (Gmail, Calendar, Drive, OAuth) — only for the integrations you connect.
- AI model providers — transient processing of prompts and workspace context.
- Stripe — subscription billing, payments and invoices.
- Email delivery provider — transactional and authentication emails sent from notify.nexz-ai.com.
- Cloud hosting and CDN providers — serving the application and static assets.
10. Legal bases for processing
Where the GDPR applies we process personal data on the basis of contract performance (providing the service you signed up for), your consent (connecting Google services and optional features), our legitimate interests (security, abuse prevention, service improvement) and legal obligations (accounting and tax records).
11. Data retention
Account and workspace data is retained while your account is active. Connected-service tokens are deleted immediately when you disconnect an integration. Synced messages, events and indexed documents are retained until you delete them or close your workspace.
After account deletion, workspace content is removed from production systems within 30 days and from encrypted backups within 90 days. Billing and invoice records are retained for as long as required by applicable tax law.
12. Security
Data is encrypted in transit with TLS and at rest by our infrastructure providers. Access to workspace data is enforced by row-level security policies scoped to your organization, and OAuth tokens are stored server-side and never exposed to the browser.
Administrative access is restricted to the minimum number of people required to operate the service, and we monitor for suspicious activity. No system is perfectly secure; if a breach affects your personal data we will notify you and the competent authorities as required by law.
13. International data transfers
NEXZ uses providers that may process data outside your country, including in the United States. Where data leaves the European Economic Area we rely on appropriate safeguards such as the EU Standard Contractual Clauses and, where applicable, the EU-U.S. Data Privacy Framework, together with technical measures like encryption in transit and at rest.
14. Your rights
Subject to applicable law, and in particular the GDPR, you have the right to access your data, correct inaccurate data, request deletion, restrict or object to processing, receive a portable copy of your data, and withdraw consent for any connected integration at any time.
To exercise these rights, email privacy@nexz-ai.com. We respond within 30 days. You may also lodge a complaint with your local data protection authority.
15. Children
NEXZ is a business product and is not directed to children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact privacy@nexz-ai.com and we will delete it.
16. Changes to this policy
We may update this Privacy Policy as the product evolves. Material changes will be announced in the application or by email, and the 'last updated' date above will always reflect the current version.
17. Contact
Privacy requests: privacy@nexz-ai.com · General support: support@nexz-ai.com · Website: https://nexz-ai.com