Legal
Privacy Policy
Last updated September 26, 2026
This policy explains how Nextus Artificial collects, uses, shares, and protects personal data in connection with ITAD CRM.
1. Overview and our role
This Privacy Policy applies to personal data we process in connection with ITAD CRM (the Services). It is important to distinguish two roles:
- We are the controller of the account and usage data of the people who administer and use the Services (our customers and their members) — this policy governs that data.
- We are a processor of the lead and contact data that a customer imports into or generates within their workspace. For that data, the customer is the controller and determines how it is used; our handling of it is governed by our Data Processing Addendum.
2. Information we collect
2.1 Information you provide
- Account and identity data — name, email address, password (stored hashed), workspace name, and role.
- Billing data — subscription plan, seat count, and billing status. Card details are collected and stored by our payment processor, Stripe, not by us.
- Customer Data — the lead, contact, and pipeline records you and your members create or import (processed on your behalf; see the DPA).
- Support communications — messages you send us and their contents.
2.2 Information collected automatically
- Usage data — actions taken in the Services, feature usage, and log data such as timestamps.
- Device and technical data — IP address, browser type, and similar diagnostic information.
- Cookies — strictly necessary cookies used for authentication and session management (see section 5).
3. How we use personal data and our legal bases
We use personal data to:
- provide, operate, secure, and support the Services (performance of a contract);
- process subscriptions and payments and prevent fraud (contract and legitimate interests);
- communicate with you about your account, security, and service changes (contract and legitimate interests);
- improve and develop the Services, using aggregated or de-identified data where possible (legitimate interests);
- comply with legal obligations and enforce our terms (legal obligation and legitimate interests).
Where we rely on legitimate interests, we balance them against your rights. Where the law requires consent, we obtain it and you may withdraw it at any time.
4. How we share personal data
We do not sell personal data. We share it only as described here, with service providers (sub-processors) that process data on our behalf under contract:
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, and backend hosting | United States |
| Vercel | Application hosting and content delivery | United States |
| Stripe | Payment processing and subscription billing | United States |
| Resend | Transactional email delivery | United States |
| Clay | Data enrichment (only when you trigger it) | United States |
We may also disclose personal data to comply with law or valid legal process, to protect our rights, safety, or property, or in connection with a merger, acquisition, or sale of assets (with notice where required). An up-to-date list of sub-processors is maintained in our Data Processing Addendum.
5. Cookies
We use strictly necessary cookies to keep you signed in and to secure your session. These are required for the Services to function and cannot be switched off through the Services. We do not use advertising or third-party tracking cookies.
6. International transfers
We and our sub-processors may process personal data in the United States and other countries. Where we transfer personal data from the European Economic Area, the United Kingdom, or Switzerland, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.
7. Data retention
We retain account and billing data for as long as your account is active and as needed to comply with our legal obligations, resolve disputes, and enforce our agreements. Customer Data is retained according to your instructions and the DPA; after termination we make it available for export for a limited period and then delete or de-identify it.
8. Security
We use technical and organizational measures designed to protect personal data, including encryption in transit and at rest, tenant isolation enforced at the database layer, access controls, and audit logging. No system is perfectly secure, and you are responsible for keeping your credentials confidential.
9. Your rights
Depending on where you live, you may have rights to access, correct, delete, or port your personal data, to object to or restrict certain processing, and to withdraw consent. Residents of the EEA, UK, and Switzerland have rights under the GDPR; California residents have rights under the CCPA/CPRA, including the right not to be discriminated against for exercising them. We do not sell or share personal data as those terms are defined under California law.
To exercise a right, contact us at privacy@nextus.ai. If your request concerns lead or contact data held within a customer workspace, the customer is the controller and we will refer your request to them. You may also lodge a complaint with your local data protection authority.
10. Third-party services
The Services may link to or integrate with third-party products. Their handling of your data is governed by their own privacy policies, and we are not responsible for them.
11. Google user data (Gmail integration)
If you connect a Google account to use the Gmail features of the Services, we access your Google data only to provide those features. We use the Gmail “send” permission (the gmail.send scope) to send and reply to emails you compose in the Services, on your behalf, from your connected mailbox; and the Gmail “read” permission (the gmail.readonly scope) to sync your incoming email so we can show your leads' replies on their timeline and thread the conversation within your workspace. We access only your own connected mailbox's messages, and only while your account is connected.
ITAD CRM's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising; we do not sell it; and we do not transfer or disclose it except as necessary to provide or improve these user-facing features, to comply with applicable law, or with your consent. We do not allow humans to read your Google data except where you give consent for specific messages, where necessary for security purposes (such as investigating abuse), where required by law, or where the data has been aggregated and anonymized.
You can disconnect a mailbox at any time in the Services (Integrations), and you can revoke our access to your Google account at any time from your Google Account permissions page. Disconnecting stops all further access; email already logged to your leads remains in your workspace unless you delete it.
12. Children
The Services are not directed to children and are intended for business use. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us personal data, contact us and we will delete it.
13. Changes to this policy
We may update this policy from time to time. We will post the updated version with a new effective date and, for material changes, provide additional notice.
14. Contact us
For privacy questions or to exercise your rights, contact privacy@nextus.ai, or write to Nextus Artificial, 8 Gainsborough Road, London, England, E11 1HT.