Privacy policy
Last updated: 27 September 2026
Here we explain what personal data we process when you visit the Nexo website, create an account or use the service, what we use it for, how long we keep it and what rights you have.
1. Controller
The controller of the data of Nexo accounts is the owner of Nexo. You can reach us through the contact form.
2. What data we process
- Your account data: first and last name, email address, mobile phone, your business name if you give it, the service you sign in with (Google, Microsoft, Apple or Facebook) and your Nexo password, which is stored encrypted and which we cannot see.
- Billing data: handled by Stripe. We do not see or store your card number; only the status of the subscription and the amounts.
- Data about your businesses and their activity: the assistant settings, WhatsApp conversations (including voice note transcripts), appointments, payments, quotes, stock and team details. We process it on behalf of your business (explained below).
- Technical data: security and operation logs, such as the IP address and time of each request, to protect the service and fix errors.
- The messages you send us through the contact form and the reviews you publish about Nexo.
3. What we use it for and on what legal basis
- Providing the service, managing your account, charging the subscription and supporting you: performance of the contract.
- Protecting the service and preventing fraud and abuse: our legitimate interest.
- Meeting tax and accounting obligations: legal obligation.
- Publishing your review with the name you choose: your consent, which you can withdraw at any time.
- Answering your messages: your consent or steps taken at your request before entering into a contract.
We do not sell your data or use it for advertising, and we do not take decisions that significantly affect you based solely on automated processing.
4. Data of your business’s customers
When Nexo looks after your business’s customers, we process their data (name, phone, messages, appointments and payments) as a data processor, following your instructions and the data processing agreement. The controller is your business: if one of your customers wants to exercise their rights, they should contact your business, and we will help it handle the request.
If that data includes health information (for example, in a clinic), your business must have an adequate legal basis and apply the measures required by law.
5. Google
If you connect Google Calendar or Gmail, Nexo only accesses what it needs: checking your free time and creating appointments in your primary calendar and, if you turn it on, sending receipts by email from your account, without reading your mail.
Nexo’s use of information received from Google APIs, and its transfer to any other app, adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use that data for advertising or to train artificial intelligence models, and you can remove access at any time from your Google account.
6. Artificial intelligence
The assistant and the transcription of voice notes run on Nexo’s servers: conversations are not sent to external artificial intelligence providers or used to train models. If we use an external provider in the future, we will add it to the list of processors first.
7. Who we share data with
Only with the providers we need to run the service, under contracts that oblige them to protect the data:
- Supabase: database and sign-in, with the data hosted in the European Union (Frankfurt).
- Stripe: payments and subscriptions.
- Resend: sending Nexo’s emails, such as the link to confirm your email or change your password.
- Cloudflare: secure connection between the internet and the Nexo servers.
- Google: sign-in and, if you connect them, Calendar and Gmail.
- Microsoft, Apple or Facebook: only if you use them to sign in.
- WhatsApp, Telegram and Slack: messages go through these services when you connect and use them.
Some of these providers are in the United States or may access data from there. In those cases, transfers rely on the EU-US Data Privacy Framework or on standard contractual clauses approved by the European Commission. We may also disclose data to the authorities when the law requires it.
8. How long we keep it
- Your account and business data, while you have the account. If you cancel, we keep it so that you can reactivate the account until you ask us to delete it, and we delete it within 30 days of your request at the latest.
- Billing data, for the periods required by tax and commercial law.
- The short memory the assistant uses in each conversation is deleted automatically after 24 hours; the full history stays in your dashboard until you delete it.
- Contact messages, for as long as they are needed to deal with your request.
9. Your rights
You can ask for access to your data, its rectification or erasure, the restriction of or objection to its processing and its portability, and withdraw your consent at any time, by writing to us through the contact form. We will reply within one month at the latest.
If you think we have not handled your data properly, you can complain to the data protection authority of your country; in Spain, the Spanish Data Protection Agency (aepd.es).
10. Security
We apply appropriate technical and organisational measures: encrypted connections (HTTPS), separation of the data of each account and each business, access control, encryption of Google and other service credentials, and passwords managed by the identity provider. If a security breach affected your data, we would tell you without delay whenever the law requires it.
11. Minors
Nexo is not intended for people under 18.
12. Changes
If we make significant changes to this policy, we will tell you in the dashboard or by email.
This is a translation for your convenience. If there is any difference, the Spanish version prevails.