Sign inTalk to specialists

Privacy Policy

Describes what personal data NEXEFII collects, how it is used, with whom it is shared, and what rights data subjects may exercise.

Version
2026.3
Last updated
2026-07-23

Who we are and data controller

The NEXEFII platform is operated by NEXEFII LLC, a limited liability company formed in the State of Florida, United States, registered under number Florida Document Number L26000282400, with registered address at 12955 Biscayne Blvd, Suite 200, PMB 726, Miami, FL 33181, United States.

The data controller responsible for the processing of personal information described in this policy is the Customer, as controller of Customer Data, with NEXEFII acting as processor.

The Data Protection Officer (DPO) can be contacted at: contact@nexefii.com.

Scope of this policy

This policy applies to the processing of personal data arising from use of the NEXEFII platform — including the NEXE Store, Master Control and Smartbot modules — as well as use of the NEXEFII institutional website.

It does not cover third-party systems, integrations contracted by customers in their own name, or environments outside NEXEFII's direct control. Subprocessors and external partners are identified in the relevant section.

Data collected

In the context of account and platform use, we collect data such as name, email address, access credentials (stored in a protected form), organization settings, records of actions on the platform, and session metadata.

In the context of support, we collect the content of communications that users send us voluntarily, as well as diagnostic information necessary to resolve the request.

The Smartbot assistant receives and processes the messages that users type directly into the interface. These messages are handled in accordance with our AI data use policy.

On the institutional website, we use only strictly necessary cookies for the technical functioning of the page. We do not use analytics trackers, advertising pixels, or third-party cookies for marketing or profiling purposes.

Purposes and legal bases

Data is processed for the following primary purposes: providing and operating the platform; account authentication and security; fulfilling contractual obligations to customers; processing payments (via Stripe); technical support; and complying with legal obligations.

The applicable legal bases are: the legal bases applicable to service delivery and compliance with legal obligations. Where processing is based on consent, the data subject may withdraw it at any time without affecting the lawfulness of processing carried out previously.

Sharing and subprocessors

We do not sell personal data. We share data only to the extent necessary to operate the services, comply with legal obligations, or as instructed by the data subject themselves.

Payments on the platform are processed by Stripe, Inc., which acts as a payment processor. Stripe operates under its own terms and privacy policies, available on its website.

The full and current list of authorized subprocessors is: NEXEFII's Subprocessor List. This list is reviewed periodically and material updates will be communicated through the mechanisms provided in the applicable terms.

International transfers

Personal data may be transferred to servers or subprocessors located outside the data subject's country of origin. Such transfers are made on the basis of: appropriate contractual safeguards for international transfers, where they occur.

The hosting regions in use are: managed cloud infrastructure (Railway). We do not transfer data to countries lacking an adequate level of protection without the safeguards required by applicable law.

Data retention

Personal data is retained for the period necessary for the purposes described in this policy, or as required by law. Retention periods by data category are: the periods defined in the Data Retention and Deletion Policy.

Following account closure or contract termination, data is handled in accordance with the deletion and portability procedure described in the applicable terms and governing legislation.

Data subject rights

Depending on applicable law, data subjects may have the following rights: access to data; rectification of inaccurate data; erasure ("right to be forgotten"); portability; objection to processing; restriction of processing; and withdrawal of consent.

To exercise any of these rights, contact us at: contact@nexefii.com. We will review your request and respond within the timeframes provided by applicable law.

Security

We adopt technical controls to protect the personal data we process. Controls present in the platform include: multi-factor authentication (MFA); role-based access control (RBAC); session cookies marked HttpOnly and Secure; session expiry by idle timeout and absolute lifetime; server-side session revocation; per-organization data isolation (multi-tenant); immutable audit trails of sensitive actions; and protection of traffic in transit via TLS/HTTPS.

Encryption of data at rest is not asserted here; data is hosted on managed cloud infrastructure and at-rest storage specifics are subject to review. No system is perfectly secure and we do not claim absence of incidents or absolute security.

Children

The NEXEFII platform is intended for corporate users aged 18 and over. We do not intentionally collect data from children or minors below the applicable age of majority. If we become aware that data from minors has been collected without proper authorization, we will take the necessary steps to delete it.

Changes to this policy

This policy may be updated periodically to reflect changes to our services, processing practices, or applicable law. When material changes occur, we will notify affected users through the means available on the platform, with reasonable notice.

The current version will always be identified by the last updated date stated in this document.

Contact

For questions about this policy or about the processing of personal data by NEXEFII, contact us at the privacy email: contact@nexefii.com.

For legal matters: contact@nexefii.com. For security matters: contact@nexefii.com.

Support access to your data

When NEXEFII technical support needs to access personal data processed in your organization, such access occurs only under authorization, in a minimized manner, and recorded in an audit trail. NEXEFII does not maintain permanent or standing access to your data.

Support team access is nominative, temporary, limited to what is strictly necessary to handle the request, and revocable. We do not use shared credentials and do not access your data outside the authorized scope. Relevant actions are logged for accountability purposes.

For questions about how support accesses personal data, or to exercise your rights, contact us at the privacy email: contact@nexefii.com.