Privacy Policy
Effective Date: September 2026 • Compliant with GDPR, CCPA, and SOC 2 Type II Standards
At NexBot Inc. ("NexBot", "we", "us", or "our"), we take data privacy, user confidentiality, and enterprise security with utmost seriousness. This Privacy Policy details how we collect, process, isolate, store, and safeguard your data when utilizing the NexBot platform, studio dashboard, APIs, and embeddable chatbot widgets.
We strictly guarantee that your proprietary data, customer chat transcripts, uploaded documents, and crawl data are NEVER used to train, retrain, fine-tune, or improve public foundation AI models (including OpenAI, Anthropic, or open-weight models). Your knowledge base is partitioned inside private tenant-scoped vector indexes accessible solely by your authorized instance.
1. Security & Encryption Standards (AES-256 & TLS 1.3)
We implement defense-in-depth technical safeguards aligned with international financial and healthcare standards:
All databases, vectorized document embeddings, and chat history logs are encrypted using hardware-accelerated AES-256 encryption.
Every payload, web session, API call, and widget event is encrypted end-to-end via TLS 1.3 with automated HSTS header enforcement.
2. Information We Collect
- Account Information: Name, work email address, organization name, website domain, and encrypted authentication tokens.
- Knowledge Base Content: Document files (PDF, DOCX, CSV) and crawled website URLs that you explicitly authorize for indexing into your assistant instance.
- Conversational Data: Queries submitted by end-users to your live widget, along with timestamps and visitor lead captures if enabled by you.
- Billing Information: Payment processing is handled via certified PCI-DSS Level 1 compliant payment gateways (such as Stripe). NexBot does not store raw credit card numbers.
3. GDPR & CCPA Compliance Rights
Regardless of geographic location, NexBot affords comprehensive data rights to all account holders and their visitors under the General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA):
4. Data Retention & Infrastructure
Data is hosted within secure, audited Tier-4 cloud infrastructure providers (including Amazon Web Services and Google Cloud Platform). All compute nodes operate with automated network firewalls, DDoS mitigation, and intrusion prevention.
5. Official Contact & Data Protection Officer
If you have any questions regarding this Privacy Policy, wish to execute standard Data Processing Agreements (DPA), or request data deletion, please contact our Data Protection Office directly:
NexBot Privacy & Compliance Team
Email: support@nexbot.online
Global Data Protection & Security Office