Legal
Privacy Policy
Last updated August 10, 2026
This policy explains how [Company Legal Name] collects, uses, shares, and protects personal data in connection with ITAD CRM.
1. Overview and our role
This Privacy Policy applies to personal data we process in connection with ITAD CRM (the Services). It is important to distinguish two roles:
- We are the controller of the account and usage data of the people who administer and use the Services (our customers and their members) — this policy governs that data.
- We are a processor of the lead and contact data that a customer imports into or generates within their workspace. For that data, the customer is the controller and determines how it is used; our handling of it is governed by our Data Processing Addendum.
2. Information we collect
2.1 Information you provide
- Account and identity data — name, email address, password (stored hashed), workspace name, and role.
- Billing data — subscription plan, seat count, and billing status. Card details are collected and stored by our payment processor, Stripe, not by us.
- Customer Data — the lead, contact, and pipeline records you and your members create or import (processed on your behalf; see the DPA).
- Support communications — messages you send us and their contents.
2.2 Information collected automatically
- Usage data — actions taken in the Services, feature usage, and log data such as timestamps.
- Device and technical data — IP address, browser type, and similar diagnostic information.
- Cookies — strictly necessary cookies used for authentication and session management (see section 5).
3. How we use personal data and our legal bases
We use personal data to:
- provide, operate, secure, and support the Services (performance of a contract);
- process subscriptions and payments and prevent fraud (contract and legitimate interests);
- communicate with you about your account, security, and service changes (contract and legitimate interests);
- improve and develop the Services, using aggregated or de-identified data where possible (legitimate interests);
- comply with legal obligations and enforce our terms (legal obligation and legitimate interests).
Where we rely on legitimate interests, we balance them against your rights. Where the law requires consent, we obtain it and you may withdraw it at any time.
4. How we share personal data
We do not sell personal data. We share it only as described here, with service providers (sub-processors) that process data on our behalf under contract:
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, and backend hosting | United States |
| Vercel | Application hosting and content delivery | United States |
| Stripe | Payment processing and subscription billing | United States |
| Resend | Transactional email delivery | United States |
| Clay | Data enrichment (only when you trigger it) | United States |
We may also disclose personal data to comply with law or valid legal process, to protect our rights, safety, or property, or in connection with a merger, acquisition, or sale of assets (with notice where required). An up-to-date list of sub-processors is maintained in our Data Processing Addendum.
5. Cookies
We use strictly necessary cookies to keep you signed in and to secure your session. These are required for the Services to function and cannot be switched off through the Services. We do not use advertising or third-party tracking cookies.
6. International transfers
We and our sub-processors may process personal data in the United States and other countries. Where we transfer personal data from the European Economic Area, the United Kingdom, or Switzerland, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.
7. Data retention
We retain account and billing data for as long as your account is active and as needed to comply with our legal obligations, resolve disputes, and enforce our agreements. Customer Data is retained according to your instructions and the DPA; after termination we make it available for export for a limited period and then delete or de-identify it.
8. Security
We use technical and organizational measures designed to protect personal data, including encryption in transit and at rest, tenant isolation enforced at the database layer, access controls, and audit logging. No system is perfectly secure, and you are responsible for keeping your credentials confidential.
9. Your rights
Depending on where you live, you may have rights to access, correct, delete, or port your personal data, to object to or restrict certain processing, and to withdraw consent. Residents of the EEA, UK, and Switzerland have rights under the GDPR; California residents have rights under the CCPA/CPRA, including the right not to be discriminated against for exercising them. We do not sell or share personal data as those terms are defined under California law.
To exercise a right, contact us at privacy@nextus.ai. If your request concerns lead or contact data held within a customer workspace, the customer is the controller and we will refer your request to them. You may also lodge a complaint with your local data protection authority.
10. Third-party services
The Services may link to or integrate with third-party products. Their handling of your data is governed by their own privacy policies, and we are not responsible for them.
11. Children
The Services are not directed to children and are intended for business use. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us personal data, contact us and we will delete it.
12. Changes to this policy
We may update this policy from time to time. We will post the updated version with a new effective date and, for material changes, provide additional notice.
13. Contact us
For privacy questions or to exercise your rights, contact privacy@nextus.ai, or write to [Company Legal Name], [Company registered address].