Trust Center
Security & privacy at Nexio
Nexio handles real conversations, contacts, and profiles — for the professionals who use it and the people who reach them. This page sets out, in plain language, exactly what we collect, how it's secured, where it lives, and who else can touch it — the full picture, so you can evaluate us with confidence.
What happens to the information you share with an agent
It goes to one person: the professional whose card you scanned. Nexio stores it securely on their behalf — we never sell it, and we don't hand it to advertisers or data brokers.
The AI services that power the conversation don't train on your data and keep it no longer than 30 days.
You can ask us to delete your data at any time — email hello@nexio.bzand we remove it from our systems and our vendors'.
Information we collect
- Cardholders — your profile (name, title, company, bio, links, contact details) and, if you connect it, your LinkedIn, used to build and run your agent.
- Visitors — your conversation with the agent, and any contact details you choose to share so the cardholder can follow up.
- Payments — handled entirely by Stripe. We never see or store full card numbers.
AI processing
A cardholder's agent is built from the profile and materials they provide. When you speak with it, your messages are sent to our AI providers to generate replies and, once the conversation ends, a short summary for the cardholder. Your conversation is never used to train AI models, and any personal details it contains are tagged internally so they can be located and removed on request.
Data residency
All data is stored in the United States, on Amazon Web Services (AWS). Nexio runs on Vercel and AWS — the same infrastructure used by companies such as IBM, McDonald's, and Ticketmaster — and every provider in our data chain is independently audited to SOC 2 Type II, the recognised standard for how a service provider handles customer data.
Security controls
- Encryption — data is encrypted in transit (TLS) and at rest (AES-256).
- Tenant isolation— every request is scoped to your account. One account's data is never reachable from another's, enforced by a single centralised ownership guard and continuously verified by automated cross-account tests.
- Authentication— sign-in and session management run on Clerk, a dedicated identity provider audited to SOC 2 Type II. Passwords and login credentials are held by Clerk, never by Nexio. Our own service credentials live in an encrypted vault, never in source code.
- Supply-chain integrity— every dependency is pinned to an exact version, screened for supply-chain risk, held to a minimum age before adoption, and verified against the registry's signatures on every install.
Our commitments
- We do not sell your data, and we do not share it beyond the providers that run the service.
- We do not use it for advertising, and we do not build advertising profiles.
- We keep no personal information in our logs, analytics, or telemetry — those hold only non-identifying, structural data.
- We do not build cross-visitor profiles. Your conversation belongs to the one cardholder you reached, and no one else.
Subprocessors
We rely on a small set of specialised providers to operate the service. Each is bound to process data only on our behalf, and each is independently audited to SOC 2 Type II:
- NeonSecurely stores your account and conversation data.
- VercelRuns and serves the application.
- OpenAIPowers the AI chat and post-conversation summaries. Does not train on your data; keeps it no longer than 30 days.
- ElevenLabsPowers real-time voice conversations. 30-day retention.
- ResendDelivers emails such as booking confirmations and notifications.
Providers that handle only cardholder account data — authentication, payments, and profile enrichment — are listed in our privacy policy.
Data processing agreements
Every provider that processes data on our behalf is bound by a data processing agreement limiting them to running the service — nothing else. We review each provider's security posture and work only with those independently audited to SOC 2 Type II. If we add a new provider that handles your data, we update this page before we do.
Data retention
- Your data is retained while your account is active — conversation history is part of the product, powering cross-session memory and lead follow-up.
- We hold our external AI providers to a 30-day retention limit. OpenAI and ElevenLabs — the services that power chat and voice — delete their copies of your data within 30 days.
- You may request deletion at any time; we complete it within 30 days, across our systems and our vendors'. Billing and tax records are the sole exception, retained as long as the law requires.
Your rights
Wherever you reside, you may request access to, export of, or deletion of your personal data — and under GDPR and CCPA you hold these rights explicitly, including the right to object to certain processing. Email hello@nexio.bz; we respond within the period the law requires and complete deletion within 30 days.
Data breach policy
No system is immune to compromise. In the event of a breach affecting your information, we notify affected customers within 72 hoursof confirming it, with what occurred, what data was involved, and the steps we are taking. Where the affected data belongs to a cardholder's visitors, we notify the cardholder — the controller of that information — who in turn informs the individuals concerned.
Contact
For security questions, data requests, or to report a vulnerability, contact hello@nexio.bz.
Last reviewed July 2026 · Privacy Policy · Terms · Refunds