Data processing agreement
Last updated: 27 September 2026
This agreement is part of the terms of service and applies when Nexo processes personal data on behalf of your business, under Article 28 of the General Data Protection Regulation (GDPR). Your business is the controller and the owner of Nexo is the processor.
1. Subject and duration
We process the data only to provide the service you signed up for (automatic WhatsApp reception, calendar, payments and receipts, quotes, stock, team management, alerts and integrations), for as long as the subscription lasts and for the time needed to return or delete the data at the end.
2. Data and people concerned
Customers and prospective customers of your business (name, phone, email, messages, voice notes, appointments, quotes and payments) and members of your team (name, role, phone and time off).
It may include health data or other special categories if your activity involves them (for example, a clinic). In that case, your business must have the appropriate legal basis.
3. Our obligations
- Process the data only on your documented instructions, which are these terms and the settings you make in the dashboard. If an instruction seems unlawful to us, we will tell you.
- Ensure that the people authorised to process the data have committed themselves to confidentiality.
- Apply the security measures of Article 32 of the GDPR: encrypted communications, separation of each business’s data, access control, encryption of third-party credentials and activity logs.
- Help you deal with requests to exercise rights and meet your obligations on security, breach notification and impact assessments, taking into account the nature of the processing.
- Notify you without undue delay, and within 48 hours of becoming aware of it at the latest, of any security breach affecting your business’s data.
- Make available to you the information needed to demonstrate compliance with this agreement and allow reasonable audits with prior notice.
4. Sub-processors
You authorise us to use the providers on this list. We will tell you in advance about any change so that you can object; if you object on reasonable grounds and we cannot find a solution, you will be able to cancel the subscription. Each sub-processor is bound to protect the data on terms equivalent to this agreement.
- Supabase: database and sign-in, with the data hosted in the European Union (Frankfurt).
- Cloudflare: secure connection between the internet and the Nexo servers.
- WhatsApp: messages with your customers are sent and received through WhatsApp, with the number your business links.
- Google (Calendar and Gmail), Telegram and Slack: only if your business connects them; data is sent to those services according to your settings.
5. International transfers
If a sub-processor processes data outside the European Economic Area, it will do so with appropriate safeguards: an adequacy decision (such as the EU-US Data Privacy Framework) or standard contractual clauses.
6. End of the service
When the subscription ends, you can ask us for a copy of your business’s data in a structured format and for its deletion afterwards. We will delete it within 30 days of your request at the latest, unless the law requires us to keep it.
This is a translation for your convenience. If there is any difference, the Spanish version prevails.