Privacy
Privacy Policy
Last updated July 2026
This policy explains what Nexio (“we,” “us”) collects, why, and the choices you have. It covers both account holders and the people who interact with a Nexio card. For a plain-language summary of our security posture, see our Trust Center.
What we collect
- Account data — your name, email, and profile details (title, company, bio, links, avatar).
- Imported data — information you choose to bring in, such as a LinkedIn profile, to build your AI agent.
- Visitor interactions — when someone scans your card, the messages they exchange with your agent and any contact details (email, phone) they choose to share.
- Payment data — handled by our payment processor (Stripe); we never see or store your full card number.
- Usage data — basic analytics about how the Service is used, to operate and improve it. This contains no personal information — only non-identifying, structural data.
How we use it
To provide the Service: run your AI agent, host your profile, process payments and card orders, summarise visitor conversations for you, send you relevant emails, and keep the Service secure. We do not sell your personal data, and we do not use it for advertising.
We may also use de-identified information — with personal details such as names, email addresses, and phone numbers removed — to analyse, improve, and develop the Service, including the quality of our AI agents. We do not use identifiable personal data for this purpose, and you can ask us to exclude your data from it at any time by emailing hello@nexio.bz.
Who we share it with
We share data with service providers that help us operate, only as needed: payment processing, authentication, AI response generation, data enrichment, hosting/database, and email delivery. These providers process data on our behalf under a data processing agreement, and each is independently audited to SOC 2 Type II. The providers that handle conversation data are listed on our Trust Center; a full current list is available on request. We may also disclose data if required by law.
AI processing
Your profile content and visitor messages are sent to AI providers to generate agent responses and post-conversation summaries. These providers do not train on your data and retain it for no more than 30 days. Don't put anything into the Service that you wouldn't want processed this way.
Retention
We keep data for as long as your account is active or as needed to provide the Service and meet legal obligations. You can ask us to delete your account and associated data at any time; we complete deletion within 30 days, across our systems and our vendors'. Billing and tax records are retained as long as the law requires.
Your rights
Depending on where you live (including under GDPR and CCPA), you may have the right to access, correct, export, or delete your personal data, and to object to certain processing. To exercise these rights, email us and we'll respond within the time the law requires.
Data breaches
If a breach affects your personal data, we notify affected customers within 72 hours of confirming it — and the relevant authorities where the law requires. For data belonging to a cardholder's visitors, we notify the cardholder, who is the controller of that information.
Cookies & security
We use essential cookies to sign you in and keep the Service working. We apply reasonable technical and organisational measures to protect your data — encryption in transit and at rest, strict access controls, and account-level isolation — though no system is perfectly secure.
Children
The Service isn't intended for anyone under 18, and we don't knowingly collect their data.
Changes & contact
We'll post updates here with a new date. Questions or requests? Email hello@nexio.bz.