1. Who we are
This Privacy Policy explains how [To be completed: registered company name] (“Nexioli”, “we”, “us”) processes personal data in connection with the Nexioli website, product, and related services (the “Service”).
Controller for account and website data: [To be completed: registered company name]
- Trade name: Nexioli
- KvK: [To be completed: KvK number]
- BTW / VAT: [To be completed: BTW number]
- Registered address:
[To be completed: street address][To be completed: postal code and city]The Netherlands - Privacy contact: privacy@nexioli.com
For email content and other customer data you connect to Nexioli (for example Gmail messages and customer contact details inside those messages), you are the controller and Nexioli acts as processor on your instructions, except where we process data for our own account administration, security, or legal obligations.
2. Scope
This Policy applies to:
- Visitors of our marketing website
- People who create a Nexioli account or use the dashboard
- Personal data contained in connected inboxes, knowledge sources, and related product features, to the extent we process that data to provide the Service
It does not replace your own privacy notice to your end customers. You are responsible for telling your customers how you use Nexioli and for having a lawful basis to process their data.
3. Data we process
Depending on how you use the Service, we may process:
- Account data: name, email address, authentication details, MFA phone number (where used), company profile, role, and billing-related identifiers when payment is enabled
- Usage and device data: log data, IP address, browser type, approximate location derived from IP, pages viewed, and product interaction events needed to operate, secure, and improve the Service
- Connected inbox data: email metadata and content you authorize us to access (subjects, bodies, attachments where processed, senders, recipients, labels/history needed for sync), send-as aliases, and sync/watch status
- Knowledge and settings: company description, tone preferences, guardrails, website/FAQ content, uploaded documents, and related embeddings or search indexes we create to draft replies
- AI and review data: draft replies, confidence scores, approvals, rejections, edits, and emergency-stop / audit events
- Support communications: messages you send to us (for example via hello@nexioli.com)
We do not intentionally collect special categories of personal data, but email and knowledge content you connect may contain such data. You control what you connect and upload.
4. Why we process data (purposes and legal bases)
We process personal data for the following purposes:
- Provide the Service (contract): create accounts, authenticate users, sync connected inboxes, generate AI draft replies, operate Review Queue and related features, and provide customer support
- Secure the Service (legitimate interests / legal obligation): detect abuse, prevent fraud, enforce MFA where required, maintain logs, and protect systems and users
- Improve the product (legitimate interests): understand feature usage, fix bugs, and improve drafting quality. We do not sell personal data
- Communicate with you (contract / legitimate interests / consent where required): service notices, security alerts, and (only if permitted) product updates
- Comply with law (legal obligation): tax, accounting, and responding to lawful requests
Where we rely on legitimate interests, we balance those interests against your rights. You may object as described below.
5. Artificial intelligence and automated processing
Nexioli uses machine learning / large language models (including third-party model providers) to draft suggested replies and related assistance. Important points:
- AI outputs are suggestions. They can be incomplete, inaccurate, outdated, or inappropriate
- By default, drafts are held for human review in the Review Queue before sending
- If you enable optional automatic sending, you instruct Nexioli to send without a per-message human approval, and you remain responsible for those communications
- We process inbox and knowledge content as needed to generate drafts; model providers process prompts/outputs under our agreements with them for providing the Service
- You should not rely on Nexioli as legal, medical, financial, or other professional advice
7. International transfers
We primarily aim to process data in the EU/EEA where practicable. Some providers may process data in other countries (including the United States). Where we transfer personal data outside the EEA/UK, we use appropriate safeguards such as the European Commission’s Standard Contractual Clauses (or equivalent), plus supplementary measures where needed.
8. Retention
We keep personal data only as long as needed for the purposes above, including to provide the Service, resolve disputes, and meet legal retention duties. Typical patterns:
- Account data: for the life of the account, then a reasonable wind-down period after deletion/closure
- Connected inbox sync and drafts: while the integration is active and as needed for product history you keep in the Service
- Security and audit logs: for a limited period appropriate to security and abuse prevention
- Billing records (when applicable): as required by tax and accounting law
You can disconnect integrations and request deletion as described in “Your rights”.
9. Security
We use technical and organizational measures designed to protect personal data, including encryption in transit, access controls, secret management for tokens, and MFA for customer accounts. No method of transmission or storage is perfectly secure. See also our Security page for a product-level overview.
10. Your rights (GDPR)
If you are in the EEA/UK (or otherwise entitled), you may have the right to:
- Access your personal data
- Rectify inaccurate data
- Erase data in certain cases
- Restrict or object to processing
- Data portability
- Withdraw consent where processing is based on consent
- Lodge a complaint with a supervisory authority (in the Netherlands: Autoriteit Persoonsgegevens)
To exercise these rights, email privacy@nexioli.com. We may need to verify your identity. If you are an end customer of a Nexioli user, contact that company first — they are typically the controller of your email content.
12. Children
The Service is directed at businesses and adults. We do not knowingly collect personal data from children under 16. If you believe a child has provided us personal data, contact us and we will take appropriate steps.
13. Changes
We may update this Policy from time to time. We will post the updated version on this page and revise the “Last updated” date. Material changes may be communicated by email or in-product notice where appropriate.
14. Contact
Questions about this Policy: privacy@nexioli.com. General support: hello@nexioli.com.