NexBot
Compliance & Legal

Privacy Policy

Effective Date: September 2026 • Compliant with GDPR, CCPA, and SOC 2 Type II Standards

At NexBot Inc. ("NexBot", "we", "us", or "our"), we take data privacy, user confidentiality, and enterprise security with utmost seriousness. This Privacy Policy details how we collect, process, isolate, store, and safeguard your data when utilizing the NexBot platform, studio dashboard, APIs, and embeddable chatbot widgets.

Zero-Model-Training Guarantee (Enterprise Commitment)

We strictly guarantee that your proprietary data, customer chat transcripts, uploaded documents, and crawl data are NEVER used to train, retrain, fine-tune, or improve public foundation AI models (including OpenAI, Anthropic, or open-weight models). Your knowledge base is partitioned inside private tenant-scoped vector indexes accessible solely by your authorized instance.

1. Security & Encryption Standards (AES-256 & TLS 1.3)

We implement defense-in-depth technical safeguards aligned with international financial and healthcare standards:

Encryption at Rest (AES-256)

All databases, vectorized document embeddings, and chat history logs are encrypted using hardware-accelerated AES-256 encryption.

Encryption in Transit (TLS 1.3)

Every payload, web session, API call, and widget event is encrypted end-to-end via TLS 1.3 with automated HSTS header enforcement.

2. Information We Collect

  • Account Information: Name, work email address, organization name, website domain, and encrypted authentication tokens.
  • Knowledge Base Content: Document files (PDF, DOCX, CSV) and crawled website URLs that you explicitly authorize for indexing into your assistant instance.
  • Conversational Data: Queries submitted by end-users to your live widget, along with timestamps and visitor lead captures if enabled by you.
  • Billing Information: Payment processing is handled via certified PCI-DSS Level 1 compliant payment gateways (such as Stripe). NexBot does not store raw credit card numbers.

3. GDPR & CCPA Compliance Rights

Regardless of geographic location, NexBot affords comprehensive data rights to all account holders and their visitors under the General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA):

Right of Access & Portability: You may export your entire knowledge base, training sources, and conversation history in standard JSON/CSV format at any time.
Right to Rectification: You have full control to update, replace, or re-crawl indexed data instantly through your NexBot Studio dashboard.
Right to Erasure ("Right to be Forgotten"): Requesting account termination triggers complete, permanent deletion of your isolated vectors and backups within 30 days.
Right to Opt-Out & No Sale of Personal Information: NexBot has never sold, rented, or monetized customer personal data or training files to third-party data brokers.

4. Data Retention & Infrastructure

Data is hosted within secure, audited Tier-4 cloud infrastructure providers (including Amazon Web Services and Google Cloud Platform). All compute nodes operate with automated network firewalls, DDoS mitigation, and intrusion prevention.

5. Official Contact & Data Protection Officer

If you have any questions regarding this Privacy Policy, wish to execute standard Data Processing Agreements (DPA), or request data deletion, please contact our Data Protection Office directly:

NexBot Privacy & Compliance Team

Email: support@nexbot.online

Global Data Protection & Security Office

Contact Officer