Privacy Policy.
Last updated: May 3, 2026
Version 2.0
01. Introduction
At Nexaflow, we are committed to protecting your privacy and ensuring the security of your data. This Privacy Policy outlines how we collect, process, and safeguard information when you use our platform to build, manage, and scale agentic workflows, particularly through WhatsApp Business Platform (WABA) and our various business modules.
Nexaflow acts as a Data Processor for the information processed through our bots and modules on behalf of our Customers. Our Customers are the Data Controllers regarding their End-Users' data.
02. Data Collection
Information You Provide
- Account details (name, email, organization)
- Business Data: CRM contact lists, lead details, and interaction history
- Catalog Data: Product descriptions, pricing, and images for the store module
- Support Data: Support tickets, issue descriptions, and resolution notes
- Billing information and tax IDs
- Knowledge base documents and training data
Automated Collection
- Service Data: Messages and replies processed through WhatsApp (WABA)
- Interaction Data: Inputs from chat interfaces, user queries, and LLM responses
- IP addresses, device identifiers, and browser metadata
- Usage logs, performance metrics, and interaction history
03. Module Processing
Nexaflow provides specialized modules that handle distinct types of data to enable agentic automation across your business functions.
WhatsApp Business (WABA)
Facilitates enterprise-grade messaging through the WhatsApp Business Platform. We process message content and metadata to enable AI-powered automated replies, template management, and broadcast orchestration.
Data Points Processed:Includes sender phone numbers, incoming message text, media attachments, delivery statuses, and template opt-in history.
Order Management & Store
Powers e-commerce agentic workflows by managing your product catalog and processing incoming orders through chat or web interfaces.
Data Points Processed:Handles product SKU data, pricing, images, customer shipping addresses, transaction totals, and order fulfillment status.
CRM & Lead Management
Centralizes your business contacts and interaction history to drive personalized agentic sales and support experiences.
Data Points Processed:Processes contact names, emails, custom lead properties, lead scores, and a chronological feed of all interactions.
Scheduling & Appointments
Automates booking workflows by synchronizing with your business calendars and managing real-time availability for services or meetings.
Data Points Processed:Synchronizes calendar event titles, attendee names, appointment durations, and resource availability across timezones.
Ticketing & Support
Tracks and resolves customer issues through structured ticketing threads, enabling AI agents to handle support end-to-end.
Data Points Processed:Stores ticket subject lines, issue descriptions, priority levels, resolution notes, and the full history of comment threads.
04. How We Use Data
We use the collected information for the following primary purposes:
- Service Provision: Operating the platform, delivering messages, and executing your configured workflows.
- Product Improvement: Analyzing usage patterns to enhance our AI models and user interface using aggregated, de-identified data.
- Security: Detecting and preventing fraud, abuse, and security incidents.
- Compliance: Meeting legal obligations and enforcing our terms of service.
Note on AI Training: Nexaflow does not use Customer conversation data or private Knowledge Base files to train public foundational AI models. Your proprietary data remains yours.
06. Security & Retention
Security Measures
We implement enterprise-grade security including AES-256 encryption at rest, TLS 1.3 in transit, and regular vulnerability assessments. Our infrastructure is designed for 99.9% availability.
Data Retention
We retain data only as long as your account is active. Logs are purged after 90 days, while transactional records are kept for 7 years to meet tax and legal obligations.
07. Your Rights
Depending on your jurisdiction, you may have the following rights:
Access
View your data
Correction
Update errors
Portability
Export records
Erasure
Delete account
Questions about your privacy?
Our dedicated privacy team is here to help with any concerns, data requests, or compliance inquiries you may have.
Contact Privacy Team