Nexis Business Os

Privacy Policy

How NexisDigital collects, uses, and protects your personal data.

Last updated: 28 August 2026

This policy covers the NexisDigital website and Nexis Digital Business OS. Specific client agreements may add processing instructions, retention requirements, and jurisdiction-specific safeguards.

Service data and connected providers

Updated 20 September 2026. This notice covers nexisdigital.tech and app.nexisdigital.tech. Operator: NexisDigital, BIN 031105651391, Dostyk 5/2, Astana 010017, Republic of Kazakhstan. Privacy and copyright contact: privacy@nexisdigital.tech.

For account and billing information, NexisDigital determines the processing purposes. A business using a workspace determines the purposes for its customer records, messages and appointments; NexisDigital processes those records to provide the service. Businesses must inform their customers and establish the necessary permissions before connecting services.

  • Website and infrastructure: Cloudflare serves and protects the public site; the app runs on Netcup infrastructure. These services receive technical connection information. Web3Forms receives the information submitted through the website contact form. Google Analytics receives website activity only after analytics consent.
  • WhatsApp: connecting a QR code authorises a linked device on our server. The connector processes sender identifiers and new direct-message text for the workspace inbox and replies. The server can read this content to provide the service. WhatsApp transport encryption does not make the Nexis inbox or AI processing end-to-end encrypted against NexisDigital. Disconnect in the app or WhatsApp Linked devices to revoke the connection.
  • AI, when configured and enabled: customer message text can be sent to OpenRouter for TypeSafe/Jev classification. Google Gemini or OpenAI can receive prompts, relevant conversation context and approved business knowledge to generate replies. The selected model provider also processes the request. Avoid submitting sensitive information that is unnecessary for the task.
  • CRM, when connected: Pipedrive, Bitrix24 or Kommo can receive customer names, telephone numbers, enquiry or booking information and related tasks according to the enabled workflow. OAuth providers also receive authorisation requests. Connecting a CRM does not automatically establish a historical import or complete two-way synchronisation.
  • Billing: Paddle handles checkout and payment information under its own privacy notice. NexisDigital processes subscription identifiers, plan and payment status to manage access. Optional external payment links on a business’s public page are operated by that business’s chosen provider.

Connected services are used according to configuration; this list does not mean every workspace sends data to every provider. Provider location, contracts, retention and international-transfer safeguards must be considered for each enabled service. Backup destinations and retention depend on the deployment configuration; a deletion request does not instantly erase every backup or legally required accounting record.

Public signup requires confirmation that the applicant is at least 13 years old. We record the confirmation, terms version and acceptance time, not a date of birth. This is a self-declaration, not identity verification or parental consent. For a suspected under-age account or an access, correction or deletion request, contact the privacy address above.

See our data deletion instructions and copyright reporting policy.

Paddle billing, cancellation and refunds

Updated 20 September 2026. These provisions apply to Nexis Business Os purchases made through Paddle. They apply when your checkout or receipt identifies Paddle as the seller.

Payment and subscription information

When you use Paddle checkout, Paddle collects the billing and payment information needed to sell the subscription, process payment, handle tax, prevent fraud and provide buyer support. Paddle handles that information under its own privacy notice as an independent controller for its transaction activities.

To provide access and support, NexisDigital may receive purchaser contact details, billing country, transaction and subscription identifiers, purchased plan, payment or renewal status, and refund or cancellation records. We use these records to fulfil the subscription, resolve billing enquiries, protect against abuse and meet applicable accounting obligations. Full card numbers and card security codes should only be entered in the payment provider’s checkout, never sent to our support team.

Payment records are retained as needed for the subscription, disputes and applicable accounting requirements; deletion requests may not remove records that must legally be retained. For our records, contact privacy@nexisdigital.tech. For Paddle’s processing, international transfers, retention and privacy rights, see the Paddle Privacy Notice.

1. Who We Are (Data Controller)

This website is operated by NexisDigital ("NexisDigital", "we", "us", "our"), a web development agency registered under Business Identification Number (BIN) 031105651391 in the Republic of Kazakhstan, with registered office at Dostyk 5/2, Astana 010017, Republic of Kazakhstan, serving clients internationally. NexisDigital is the data controller responsible for your personal data. For any privacy question or to exercise your rights, contact us at privacy@nexisdigital.tech. This policy applies to nexisdigital.tech and all its subdomains and language versions (EN/DE/RU/KZ).

2. Personal Data We Collect

We collect only what we need. (a) Data you give us: when you submit the contact form we collect your name, email address, project type if you choose to provide it, and the content of your message. If you contact us by email, WhatsApp, or Instagram, we receive whatever you choose to share. (b) Data collected automatically: standard technical data your browser sends (including IP address, browser type, device, and timestamps), which our hosting provider may process in server and security logs. (c) Cookies: see section 4. We do not use advertising or profiling cookies. If you explicitly accept analytics, we load Google Analytics 4 to measure site use. We do not knowingly collect special-category data.

3. Why We Use It and Our Legal Bases

We process your data to: respond to your enquiries and take steps to enter into a contract at your request (legal basis: consent and/or pre-contractual steps under GDPR Art. 6(1)(a)/(b)); operate, secure, and improve the website and prevent spam or abuse (legal basis: our legitimate interests, GDPR Art. 6(1)(f)); and comply with legal obligations that apply to us (GDPR Art. 6(1)(c)). We do not use your data for automated decision-making or for selling to third parties.

4. Cookies and Consent

We use one necessary, host-only cookie named 'nexis-klaro-consent' to store your consent choice for up to 183 days. Optional Google Analytics 4 (Measurement ID G-HBB2VWE15L) loads only after you select 'Accept analytics'. Before consent, the site does not render the Google Analytics script or contact Google's analytics endpoints. After consent, GA4 may set first-party cookies named _ga and _ga_*. You can change your choice through 'Cookie Settings' in the footer; withdrawing consent disables analytics and asks Klaro to remove matching GA cookies. Deleting the consent cookie makes the banner appear again.

5. Service Providers and Third Parties

We share data only with trusted providers who help us run the site, and only as needed: Web3Forms (api.web3forms.com) processes and relays contact-form submissions to us; Proton Mail receives and stores the enquiry emails; Cloudflare hosts the website on its global edge network and processes technical data (including IP addresses) in server and security logs; Google Ireland (Google LLC) provides Google Analytics 4 and processes aggregate usage data under the Google Data Processing Terms. Each acts as our processor or an independent controller for their own infrastructure. We also link to third-party platforms (Instagram, WhatsApp); once you leave our site, their own privacy policies apply. We never sell or rent your personal data.

6. International Data Transfers

NexisDigital serves an international audience and some of our providers store or process data outside your country of residence, including in the United States, the European Union, and Switzerland. Where data is transferred out of the EEA/UK, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses or an adequacy decision, so your data receives an equivalent level of protection.

7. How Long We Keep Your Data

We keep contact-form and email enquiries only as long as necessary to handle your request and for a reasonable period afterwards for our legitimate business records, after which they are deleted. Cookies expire according to the lifespan described in section 4. Server logs held by our hosting provider are retained for a limited period for security and diagnostics.

8. Your Rights

Depending on where you live, you have rights over your personal data. Under the EU/UK GDPR you may request access to, correction, or erasure of your data; restrict or object to processing; request portability; and withdraw consent at any time. Under the California CCPA/CPRA you may request to know, delete, or correct your data and opt out of its 'sale' or 'sharing' — note that we do not sell or share personal data. You also have the right to lodge a complaint with your local data protection authority. To exercise any right, email privacy@nexisdigital.tech; we will respond within the timeframe required by applicable law.

9. Data Security and Breach Response

We protect your data with industry-standard measures: all traffic is encrypted in transit via HTTPS/TLS, the contact form uses anti-spam protection (a honeypot field), and access to enquiry data is limited to authorised personnel. No method of transmission or storage is ever completely secure, but we work to protect your information and to address any incident promptly. We maintain an internal breach response process: in the event of a personal-data breach that is likely to result in a risk to your rights and freedoms, we will document the incident, notify the competent supervisory authority without undue delay and, where feasible, no later than 72 hours after becoming aware of it (GDPR Art. 33), and communicate to affected data subjects without undue delay where the breach is likely to result in a high risk to your rights and freedoms (GDPR Art. 34). To report a suspected breach or ask about our process, email privacy@nexisdigital.tech.

10. Children's Privacy

Our website and services are intended for businesses and adults. We do not knowingly collect personal data from children under the age of 16. If you believe a child has provided us personal data, contact us and we will delete it.

11. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes to our practices or the law. The 'Last updated' date at the top shows the current version. For material changes we will take reasonable steps to notify you. Your continued use of the website after an update constitutes acceptance of the revised policy.

12. Contact Us

For any question about this policy or your personal data, or to exercise your privacy rights, contact NexisDigital at privacy@nexisdigital.tech. You can also reach us on LinkedIn at https://www.linkedin.com/company/nexisdigital/. We will be glad to help.

13. EEA privacy enquiries

NexisDigital is established outside the European Economic Area in the Republic of Kazakhstan. EEA users can send privacy enquiries and rights requests directly to privacy@nexisdigital.tech. Any jurisdiction-specific representative or authority contact required for a particular client engagement will be identified in the applicable agreement or an update to this policy.

14. Free Website Scan

When you use the free website scan, NexisDigital's Cloudflare-hosted scan endpoint fetches the public URL you enter and inspects a limited set of HTML and response signals. Cloudflare may process technical request data, including IP addresses, in its infrastructure and security logs. No email is required to view the first findings. If you request the complete report, we also collect your name, company, business email, consent, the submitted URL, and the visible scan summary through Web3Forms so we can review the evidence and contact you about that request. Automated results are not used for automated decision-making and may be incomplete or unavailable.