Privacy Policy
Last updated: August 4, 2026
1. Identity, effective dates, and scope
This Privacy Policy describes the practices of Nexor AI, Inc. ("Nexor", "we", or "the Company") with respect to the personal data processed through its websites, platform, applications, integrations, support channels, and artificial intelligence agents (the "Services"). Nexor AI, Inc. is a corporation organized under the laws of the State of Delaware, United States, with registered address at 1209 Orange Street, Wilmington, DE 19801, United States.
Scope of application
This Policy applies to:
- Website visitors.
- Representatives, employees, and authorized users of business Customers.
- Nexor's commercial prospects.
- Individuals with whom Customers interact through the Services, to the extent Nexor processes their data on behalf of those Customers.
Applicable legal framework and effective dates
In Chile, Ley N° 19.628, as currently in force, applies until November 30, 2026. As of December 1, 2026, this Policy must be construed in accordance with Ley N° 19.628 as amended by Ley N° 21.719, its implementing regulations, and the instructions issued by the Agencia de Protección de Datos Personales (Chilean Data Protection Agency). In California, CalOPPA, the CCPA/CPRA, and their implementing regulations will apply solely to the extent they are applicable by reason of their material and territorial scope.
B2B Services
The Services are offered to businesses and are not intended for the personal or household use of individual consumers. When a Customer uses Nexor to communicate with its own Leads, the Customer retains primary responsibility for the lawfulness of that campaign and for the information provided to the data subject.
SMS communications and mobile information
If you separately opt in, Nexor AI may send recurring SMS messages about your request, sales follow-up, and scheduling. Message frequency varies and message and data rates may apply. Consent to SMS is optional and is not a condition of purchase. Reply STOP to opt out or HELP for help. We do not sell, rent, or share mobile phone numbers or SMS consent information with third parties or affiliates for their own marketing or promotional purposes. We may share this information only with service providers that help us deliver the SMS program and are contractually restricted from using it for other purposes, or when required by law. Opt-out requests are honored promptly.
2. Definitions and roles
- Customer: the legal entity or business that contracts for the Services.
- Customer Data: data, content, contact lists, configurations, instructions (prompts), documents, records, recordings, transcripts, and other information that the Customer or its users upload to or generate within the Services.
- Data subject: an identified or identifiable natural person to whom the personal data relates.
- Authorized User: an individual enabled by the Customer to access the platform.
- End User or Lead: an individual with whom the Customer communicates or intends to communicate using the Services.
- Subprocessor: a vendor engaged by Nexor that processes personal data to support the provision of the Services.
2.1 Nexor as controller or business
Nexor acts as a controller (or as a "business" under the CCPA, where applicable) with respect to the data it determines to process in order to administer accounts, billing, security, support, its own sales, legal compliance, and the operation of its website.
2.2 Nexor as processor or service provider
Nexor acts as a processor, service provider, or contractor with respect to Customer Data processed solely on behalf of and under the documented instructions of the Customer. In that context, the Customer is the party that determines the purposes and essential means of the processing and must provide End Users with the corresponding privacy notice.
3. Categories of data and sources
Nexor processes the following categories of personal data, with the examples and principal sources indicated in each case.
- Identifiers and contact information: name, email address, telephone number, job title, company, and account identifiers. Obtained directly from the individual, from the Customer, or from authorized integrations.
- Commercial and account data: name, email address, and telephone number of administrative users; plan, usage, invoices, payment status, support requests, and preferences. Full payment card details and other payment instrument details are processed by the payment provider and are not stored directly in Nexor's systems. Obtained from the Customer, its users, and external billing and payment providers.
- Communications content: messages, emails, audio, recordings, transcripts, files, responses, and outcomes of outreach activity. Obtained from the Customer, the End User, the integrated channels, and the artificial intelligence agents.
- Technical and usage data: IP address, device, browser, logs, events, authentication, feature usage, and diagnostics. Collected automatically through use of the Services.
- Integration data: data obtained from CRM systems, WhatsApp, email, telephony, social media, or other connected tools. Obtained from the providers integrated at the Customer's instruction.
- Operational inferences: Lead classification, intent, priority, summary, sentiment, or estimated likelihood of response. Generated by the Services from Customer Data.
- Sensitive or regulated data: health, financial, biometric, or children's information, or other special categories, only if the Customer elects to include them. Obtained from the Customer or the End User; Nexor does not request these categories absent a documented need.
Other sources and limits on data uploads
Nexor may also receive data from public sources or legitimate commercial providers for its own B2B activities, always within the limits of applicable law. The Customer must not upload unlawfully obtained data or data that is excessive for the stated purpose.
4. Purposes and legal bases
Nexor processes personal data for the following purposes, with the uses and customary legal bases indicated in each case.
- Provision of the Services: configuring agents, processing communications, synchronizing integrations, reporting, and support. Customary legal basis: performance of the contract and the Customer's instructions.
- Commercial administration: creating accounts, billing, managing renewals, service communications, and the B2B relationship. Customary legal basis: contract, legal obligations, and legitimate interest where recognized.
- Security and fraud prevention: authentication, activity logs, investigation of abuse, access control, and continuity. Customary legal basis: legitimate interest, security, and legal compliance.
- Product improvement: analyzing aggregate metrics, errors, and performance, and testing features. Customary legal basis: legitimate interest and aggregated or deidentified data; consent where required.
- Compliance and defense: responding to authorities, exercising rights, preserving evidence, and meeting tax obligations. Customary legal basis: legal obligation and the establishment, exercise, or defense of claims.
- Nexor's own marketing: contacting business prospects and sending commercial information with an opt-out option. Customary legal basis: consent or legitimate interest, subject to applicable marketing rules.
Withdrawal of consent
Where Nexor relies on consent, that consent may be withdrawn through free and reasonably straightforward means. Withdrawal does not affect the lawfulness of processing carried out beforehand.
5. Artificial intelligence, training, and automated decisions
- Artificial intelligence processing: the Services may summarize, classify, generate responses, recommend actions, and maintain context across channels.
- No guarantee of accuracy: outputs may contain errors, omissions, or unexpected results. They must be reviewed before being used in material decisions.
- Training: Nexor will not use Customer Data to train general purpose models or models intended for other customers, absent the Customer's prior, express, written authorization.
- Agent configuration: customization of the Service is carried out primarily through business rules, instructions, flows, variables, examples, knowledge supplied by the Customer, and semantic search over documents, websites, catalogs, or authorized integrations. By default, this process does not involve model fine-tuning or the training of a general model with Customer Data. The Customer may test and review the agent's behavior before activating it and may approve the changes proposed during its refinement.
- Model providers: to provide the Services, Nexor may use models from OpenAI, xAI, Anthropic, and Google (Gemini), accessed and managed through Vercel AI Gateway. The instructions, messages, files, and outputs necessary to execute a request may be transmitted to the selected provider solely to provide the Service, in accordance with the DPA, the applicable configuration, and the contractual terms in force. Nexor may select or alternate models based on functionality, availability, performance, and Service configuration, without using Customer Data to train general purpose models, absent the Customer's prior, express, written authorization.
- High impact decisions: the Services must not be used as the sole basis for decisions that produce legal effects or similarly significant effects concerning an individual, absent a written agreement, a risk assessment, transparency, and adequate human review.
6. Recordings, transcripts, and transparency toward the End User
Calls and other interactions may be recorded or transcribed when the Customer enables those features. The Customer must clearly and promptly disclose that the interaction may be conducted by an automated or artificial intelligence system, identify the responsible business, and obtain any consent required to record, transcribe, or send communications.
Technical disclosures and escalation mechanisms
Nexor may incorporate technical disclosures, opt-out keywords, or mechanisms to escalate to a human. The Customer may not remove them where they are necessary to comply with the law, with the policies of an integrated platform, or with Nexor's security measures.
7. Disclosure of data and recipients
Nexor may disclose personal data to the following categories of recipients, only where necessary and subject to confidentiality and security obligations:
- Infrastructure and observability: providers of infrastructure, hosting, databases, security, and observability.
- Models and communication channels: providers of artificial intelligence models, voice, transcription, messaging, email, telephony, and social media.
- Corporate services: providers of billing, payments, support, business analytics, and professional advisory services.
- Corporate transactions: affiliated companies or successors in a merger, acquisition, financing, or reorganization, with appropriate safeguards.
- Authorities and third parties: authorities, courts, or third parties where there is a legal obligation, a valid order, or a need to protect rights and safety.
Nexor does not sell personal data
Nexor does not sell personal information or Customer Data to third parties. Disclosures to Subprocessors that are necessary to provide the Services do not constitute a sale and are made under contracts, instructions, and use restrictions. Processing carried out through cookies, pixels, or other website tools is governed by this Policy and by the consent or opt-out mechanisms that are legally required.
8. Subprocessors
Nexor maintains a current list of the relevant Subprocessors, their functions, and the general processing locations. The Customer grants a general authorization for their use in accordance with the DPA, with the right to receive notice of material changes and to raise reasonable objections on data protection grounds.
Relevant Subprocessors
The relevant Subprocessors include:
- Vercel: application infrastructure, Vercel AI Gateway, and security controls.
- Cloudflare: edge security, Web Application Firewall, request rate limiting, mitigation of automated or bot traffic, and protection against DDoS attacks.
- Supabase: database, authentication, storage, and backups.
- Render: managed compute and server services.
- Stripe: billing and payment processing.
- OpenAI, xAI, Anthropic, and Google (Gemini): processing of requests through artificial intelligence models.
Underlying infrastructure and current list
These providers may use underlying cloud infrastructure, including Amazon Web Services (AWS), depending on the applicable service and region. The list in force, together with the providers' functions and general processing locations, may be requested by writing to gabriel@getnexor.ai.
9. International transfers
Because Nexor is established in the United States and provides services to Customers in Chile, data may be processed in the United States and in other countries where Nexor or its Subprocessors operate. Nexor will implement the safeguards required by applicable law, which may include transfer agreements, data protection clauses, risk assessments, supplementary technical measures, and adequacy mechanisms adopted by the competent authority.
Integrations chosen by the Customer
The Customer acknowledges that certain integrations it chooses may transfer data to different countries and that its own agreements with those platforms also govern the processing.
10. Retention and deletion
- Account data: retained for as long as the contractual relationship exists and thereafter for the time necessary for billing, legal obligations, audits, and the defense of rights.
- Customer Data: retained for the contracted term and in accordance with the Customer's instructions, the Service configuration, and the DPA.
- Security logs: retained for periods proportionate to incident investigation, fraud prevention, and Service continuity.
- Backup copies: Nexor maintains daily backups of its primary data stores and point-in-time recovery mechanisms where the infrastructure used allows for it. Copies remain within protected backup cycles and are deleted or overwritten in accordance with the configured retention and with ordinary processes, absent a preservation obligation.
- Aggregated or deidentified data: may be retained for as long as it does not reasonably permit the identification of an individual and controls against reidentification are maintained.
Deletion or return upon termination of the Service
Nexor will delete or return Customer Data upon termination of the Service or upon receipt of a valid, documented instruction from the Customer, in accordance with the DPA and subject to the reasonable technical limitations of backup cycles, unless a law requires retention or a documented legal hold is in place.
11. Security
Nexor implements administrative, technical, and organizational measures that are reasonable and proportionate to the risk. Where applicable, the infrastructure uses ephemeral compute on managed containers, so that ordinary operations do not depend on direct SSH access to servers or on stable public IP addresses. Data is protected using TLS 1.2 or higher in transit and AES-256, or equivalent provider controls, at rest. Isolation between customers is enforced through logical segregation and Row Level Security (RLS) policies at the database layer, designed to prevent access across customers regardless of application logic. Nexor applies least privilege access, mandatory MFA on its administrative consoles, role based access control, service keys used only on the server side, encrypted secrets management outside the code repository, logging and monitoring, vulnerability management, daily backups, point-in-time recovery where applicable, and incident response procedures. Public traffic is protected through Cloudflare controls, including WAF, request rate limiting, mitigation of automated or bot traffic, and protection against DDoS attacks, and through Vercel firewall or WAF controls where applicable. Development and security review take into account the principal risks described in the OWASP Top 10.
Compliance status
Nexor is developing its compliance program with a view to ISO/IEC 27001 and SOC 2 Type II, but does not currently claim to hold those certifications or attestations. Nexor uses infrastructure and payment providers that maintain their own independent programs and certifications. A provider's certifications do not constitute a certification of Nexor and do not eliminate the shared responsibility model.
No absolute guarantee
No system is completely secure. Nexor applies measures that are reasonable and proportionate to the risk, but does not guarantee that the Services are immune to every instance of unauthorized access, loss, alteration, or security incident.
12. Security incidents
Nexor will maintain procedures to identify, investigate, contain, and remediate incidents. Where an incident affects Customer Data, Nexor will notify the Customer without undue delay after confirming it, will provide reasonably available information, and will cooperate with the applicable obligations to notify data subjects and authorities. Where Nexor acts as controller, it will directly make the notifications required by applicable law.
13. Data subject rights
Depending on the applicable jurisdiction, data subjects may exercise rights of access, information, rectification, updating, erasure or deletion, objection, blocking or restriction, portability, withdrawal of consent, the right not to be subject to discrimination, and review of certain automated decisions.
Verification, deadlines, and costs
To protect privacy, Nexor may verify the identity and authority of the requester. Requests will be answered within the statutory deadlines and may be subject to legitimate exceptions. No fee will be charged for ordinary requests, unless the law permits a fee for manifestly unfounded or excessive requests.
Requests concerning data processed on behalf of a Customer
Where a request concerns data processed on behalf of a Customer, Nexor may redirect it to that Customer or assist that Customer in responding in accordance with the DPA. End Users should identify, where possible, the business with which they interacted. Privacy requests and inquiries may be sent to gabriel@getnexor.ai.
14. Additional information for California residents
This section applies only to the extent Nexor is subject to the CCPA with respect to the individual and the processing at issue. During the past twelve months, Nexor may have collected the categories described in Section 3 and disclosed them to the categories of recipients described in Section 7 for business purposes. Nexor does not sell personal information or Customer Data. When acting as a service provider or contractor, Nexor likewise does not sell or share Customer Data for behavioral advertising across contexts. Processing carried out through cookies or the website's own tools is governed by Section 15 and by the legally applicable consent or opt-out mechanisms.
- Right to know and access categories and specific pieces of personal information.
- Right to request deletion and correction, subject to exceptions.
- Right to opt out of the sale or sharing of personal information, where it occurs.
- Right to limit certain uses of sensitive personal information, where applicable.
- Right not to receive discriminatory treatment for exercising privacy rights.
Request channels, authorized agents, and opt-out signals
Nexor will accept requests through the privacy email address and any other method that is legally required. An authorized agent may submit a request with proof of authorization. Nexor will honor legally required universal opt-out signals where its use and configuration make that obligation applicable.
Do Not Track
Because there is no uniform standard for "Do Not Track" signals, the site may not respond to them. This does not limit the recognition of Global Privacy Control or other required signals where the CCPA applies.
15. Cookies and similar technologies
The website may use strictly necessary, preference, and analytics cookies and, if enabled, marketing cookies. Nexor must provide notice at the point of collection and a preference mechanism where the law so requires. Non essential cookies must not be activated before consent in jurisdictions that require it. Nexor will implement the notices and the preference, consent, or opt-out mechanisms that correspond to the cookies, analytics tools, and pixels enabled on the website.
16. Minors
The Services are not directed to individuals under 18 years of age. Customers may not use the Services to intentionally target children or adolescents, or to process their data without complying with the applicable special rules, legal bases, parental authorizations, and safeguards. If Nexor becomes aware that it has received data from a minor outside these conditions, it will take reasonable measures to delete that data or restrict its processing.
17. Changes to this Policy
Nexor may update this Policy to reflect legal, technical, or commercial changes. The version in force will indicate the date of the update. Where changes are material, Nexor will provide reasonable notice through the site, the account, or email. Changes incompatible with the purposes disclosed will not be applied retroactively absent a valid legal basis.
18. Contact
Privacy inquiries, requests, and complaints may be directed to Nexor's privacy contact. For matters relating to Customer Data, the Customer may use the support channels defined in its Commercial Terms. For unresolved complaints, data subjects may turn to the competent authority where the law so permits.
- Company: Nexor AI, Inc.
- Privacy: gabriel@getnexor.ai
- Support: soporte@getnexor.ai
- Website: https://www.getnexor.ai
Registered address: 1209 Orange Street, Wilmington, DE 19801, United States.