This Privacy Policy explains how NexxoSync ("NexxoSync", "we", "us"), tax ID CUIT 27-30709054-1 (sole proprietor, Monotributo regime), with registered address in the Province of Mendoza (the full address is provided to the competent authority and to any Customer who requests it in writing), Argentina, processes personal data on the website https://nexxosync.com and in the application https://app.nexxosync.com (the "Service").
NexxoSync connects a merchant's online stores, marketplaces and ERP — Mercado Libre, Shopify, WooCommerce, Tiendanube, Odoo and Producteca — and keeps products, stock, prices, orders and customers in sync. It also offers AI assistants: a chatbot the merchant can place on its own website, and assistants that draft or publish answers to marketplace questions.
For privacy questions or to exercise your rights, write to [email protected].
01Who is responsible for your data
NexxoSync plays two different roles, and which one applies depends on whose data it is:
| Data | Our role | Who you should contact first |
|---|---|---|
| Merchant account, team members, billing, support, website visitors and contact form messages | Controller: we decide why and how this data is processed | NexxoSync, at [email protected] |
| Data of the merchant's own customers (orders, customer records, chatbot conversations, marketplace questions) | Processor (service provider): we process it only on the merchant's instructions, to provide the Service | The merchant you bought from or chatted with; we assist them |
When we act as a processor, the merchant is the controller and our obligations are set out in the Data Processing Agreement. This policy still describes, for transparency, how that data flows through NexxoSync.
02Applicable law
NexxoSync serves merchants in many countries. We apply this policy to everyone and, in addition, honour the rights that the law of your place of residence grants you, including:
- the EU General Data Protection Regulation (GDPR) and the UK GDPR with the Data Protection Act 2018;
- the California Consumer Privacy Act as amended by the CPRA (CCPA) and similar US state laws;
- Brazil's Lei Geral de Proteção de Dados (LGPD, Law 13.709/2018);
- Argentina's Personal Data Protection Law 25.326 and its regulations, supervised by the Agencia de Acceso a la Información Pública (AAIP).
03What data we process
a) Merchant account and team members
- Name, email address and workspace (company) name; the role of each team member.
- Password, stored only as a bcrypt hash: we never store or see the password itself.
- Session records: a hash of the session token (never the token itself), IP address and browser user agent, so you can see and close your active sessions.
- Activity log: actions taken in the workspace, date and time, and IP address.
b) Platform credentials
Access and refresh tokens, API keys and webhook secrets for the platforms you connect, and the API keys of the AI provider you configure. They are encrypted at rest with AES-256-GCM, with a key kept outside the database, and decrypted only in memory when used.
c) Catalog and operational data
Products, variations, prices, stock, images and attributes; the links between a product on one platform and its counterpart on another; your sync rules; and the history of each run. This is business data and rarely contains personal data.
d) Data of the merchant's customers (as processor)
When a sync or an assistant needs it: name, email, phone, ID/tax document number, shipping and billing addresses, and order details (products, quantities, amounts, status, tracking). Also the questions and claims of marketplace buyers that the merchant chooses to handle with an assistant, and the messages that visitors write to the merchant's website chatbot.
NexxoSync does not keep its own customer database. Orders and customers are read from one platform and created in another within the same operation. What remains is limited: order identifiers that prevent duplicates, run history (which can include customer names and order totals), failed jobs awaiting review (which keep the data they were queued with) and chatbot conversations. Each is deleted automatically after the periods set out under "How long we keep data" below.
e) Billing
Plan, amount, currency, status, billing period and the identifiers of the subscription and each payment at the payment processor (PayPal for USD, Mercado Pago for ARS in Argentina), together with the notification the processor sends us. We never receive or store card, bank account or wallet details: you enter them directly with the processor.
f) Website visitors and contact forms
- The website sets no cookies by itself. Usage statistics (Google Analytics 4) are collected only if you accept them, as explained in the Cookie Policy.
- What you write in the contact or withdrawal form: name, email, subject and message, plus your IP address, used only to limit abuse.
- Technical data that any web request carries (IP address, browser, requested page), processed by our infrastructure and network providers to deliver and protect the site.
04Why we use it and on what legal basis
For the data we control, these are the purposes and the legal bases under art. 6(1) GDPR (and their equivalents under other laws):
| Purpose | Data | Legal basis |
|---|---|---|
| Create the account, authenticate users and provide the Service | Account, credentials, catalog and operational data | Performance of a contract (art. 6(1)(b)) |
| Charge the subscription and keep billing records | Billing | Contract (art. 6(1)(b)) and legal obligation (art. 6(1)(c)) |
| Answer enquiries and provide support | Account, contact form messages, technical logs | Contract, or our legitimate interest in answering whoever writes to us (art. 6(1)(f)) |
| Send service notices (incidents, security, billing, changes to terms) | Account email | Contract (art. 6(1)(b)) |
| Enforce plan limits and keep the Service stable | Usage counters, run history | Contract and legitimate interest (art. 6(1)(f)) |
| Prevent fraud, abuse and security incidents | Activity and session logs, IP addresses, rate-limit counters | Legitimate interest (art. 6(1)(f)) |
| Comply with tax, accounting and lawful authority requests | Billing and account data | Legal obligation (art. 6(1)(c)) |
| Measure website usage | Analytics identifiers and page views | Consent (art. 6(1)(a)), which you can withdraw at any time |
Where we rely on legitimate interest, we have weighed it against your rights; you can object as described under "Your rights". Data of the merchant's customers is processed on the merchant's instructions and on the legal basis the merchant determines.
Service notices are part of the Service and cannot be switched off while the account is active. We would only send marketing emails with your prior consent, and you could withdraw it at any time.
05AI assistants
The merchant chooses which AI provider powers its assistants and configures it in the app with its own account and credentials (supported providers are listed in Subprocessors). To answer a question we send that provider only the text needed: the conversation, the merchant's instructions and knowledge base, and the catalog or order data relevant to the question.
- The website chatbot searches the merchant's catalog and can report an order's status only after the buyer gives the order number and a matching email, phone or document number of the purchase. It never says which of the two did not match, and order lookups are rate-limited per visitor to prevent guessing. The answer includes status, date, shipping and tracking, and the items — not the buyer's address or other personal details.
- Marketplace assistants draft answers to buyers' questions and claims on Mercado Libre; depending on the merchant's settings an answer is published, kept as a draft for review, or escalated to a person.
We do not use merchants' data, or their customers' data, to train AI models, and we do not allow it to be used for that purpose on our side. How the selected provider handles the data it receives is governed by the provider's terms and the merchant's agreement with it; most business API offerings do not train on API data by default, and the merchant should verify that in its provider's settings.
06Automated decisions
We make no decisions based solely on automated processing that produce legal or similarly significant effects on anyone, and we do not profile people for advertising. The assistants answer questions with catalog and order data; they do not decide on refunds, credit or eligibility. Sync rules apply the merchant's own business rules (for example, price or stock adjustments) to products, not to people.
08International transfers
Our providers may process data outside your country. When personal data from the European Economic Area, the United Kingdom, Switzerland, Brazil or Argentina is transferred to a country without an adequacy decision, we rely on an appropriate safeguard:
- an adequacy decision — for example, the European Commission recognises Argentina (Decision 2003/490/EC) and the EU-U.S. Data Privacy Framework for certified US companies;
- the European Commission's Standard Contractual Clauses (2021/914), with the UK International Data Transfer Addendum where applicable;
- the model clauses approved by the AAIP for transfers from Argentina, and the standard contractual clauses of Brazil's ANPD for transfers from Brazil.
The location of each provider and the safeguard used are listed in Subprocessors. You can ask us for a copy of the relevant safeguard at [email protected].
09How long we keep data
We keep personal data only as long as needed. Most deletions are automatic: a background job runs every six hours. The periods below are the defaults; the operator can shorten them, and can lengthen some only within fixed maximums.
| Data | Retention |
|---|---|
| Account, workspace, configuration and catalog | While the account is active; deleted within thirty (30) days of closure |
| Platform and AI provider credentials | Until you delete the connection or provider, or close the account; deleted at that moment |
| Run and sync history (may include customer names, order totals and chatbot message excerpts) | Ninety (90) days |
| Failed jobs awaiting review (keep the data they were queued with) | Thirty (30) days once resolved; ninety (90) days while still pending |
| Chatbot conversations | The assistant forgets the context after thirty (30) minutes of inactivity; the stored conversation is deleted after at most seven (7) days of inactivity |
| Order identifiers used to prevent duplicate orders | While the connection exists; they contain no personal data |
| Activity and audit logs (including IP addresses) | Three hundred sixty-five (365) days |
| Sessions | Until you log out or the session expires (seven (7) days) |
| Billing records | For the period required by tax and accounting law (in Argentina, up to ten (10) years) |
| Contact and withdrawal form messages | Not stored in our database; kept in our mailbox as long as needed to handle the request and any follow-up, and no longer than twenty-four (24) months |
| Encrypted backups | Overwritten on a rolling basis within [30] days |
When a period ends, data is deleted or irreversibly anonymised. Records kept because the law requires it are restricted and accessed only for that purpose. How to delete a connection or close an account is explained in Data deletion.
10How we protect data
- Encryption in transit: all traffic to the website, the app and the APIs uses HTTPS/TLS.
- Encryption at rest of secrets: platform credentials, AI provider keys and other secrets are encrypted with AES-256-GCM, with a key held outside the database.
- Encrypted backups, with a separate key stored outside the server; no plaintext database dumps are kept.
- Workspace isolation: every query is scoped to the workspace that makes it, so a merchant can only access its own data.
- Limited, logged staff access: only the platform administrator can enter another workspace, for support, and each entry and administrative change is recorded in an audit log.
- Strong authentication: passwords hashed with bcrypt and subject to a minimum strength policy; session tokens stored only as hashes; two-step verification on our infrastructure and platform accounts.
- Verified webhooks and rate limits on public endpoints such as the chatbot and the contact form.
- A documented incident response procedure.
No system is risk-free. If a security incident affects personal data, we will notify affected merchants without undue delay and, where feasible, within seventy-two (72) hours of becoming aware of it, and the competent authorities when the law requires it. More detail in Security.
11Privacy requests from connected platforms
Some platforms send apps mandatory privacy notifications. We process Tiendanube's store/redact, customers/redact and customers/data_request notifications: their signature is verified, each one is recorded, and store/redact disconnects the store's connections. Because NexxoSync keeps no customer database of its own, the remaining traces of a customer (run history, failed jobs, chatbot conversations) are removed within the retention periods above, or earlier on request.
12Your rights
Depending on where you live, you have some or all of these rights:
- Access: know what data we hold about you and get a copy.
- Rectification: correct inaccurate or incomplete data.
- Erasure: have your data deleted, except where we must keep it by law.
- Restriction: ask us to limit processing while a dispute is resolved.
- Objection: object to processing based on legitimate interest.
- Portability: receive your data in a structured, commonly used format.
- Withdraw consent at any time, without affecting earlier processing.
- Not to be subject to solely automated decisions with legal or similarly significant effects (we make none).
- Complain to a data protection authority.
California (CCPA/CPRA)
California residents may request to know, delete and correct personal information, and to limit the use of sensitive personal information. We do not sell or share personal information as those terms are defined by the CCPA, and we do not use sensitive personal information to infer characteristics. We will not discriminate against you for exercising your rights. You may use an authorised agent; we may ask it to prove its authority and ask you to verify your identity.
Brazil (LGPD)
Data subjects in Brazil also have the rights in art. 18 LGPD, including confirmation of processing, anonymisation, information about the entities with which data is shared, and the right to petition the Autoridade Nacional de Proteção de Dados (ANPD).
Argentina (Law 25.326)
You may exercise access, rectification, update and deletion rights. Access is free of charge at intervals of no less than six months, unless a legitimate interest is shown.
Mandatory notice (AAIP Provision 10/2008): "The data subject has the right to access their personal data free of charge at intervals of no less than six months, unless a legitimate interest is shown, as provided in article 14, paragraph 3 of Law 25.326. The AGENCIA DE ACCESO A LA INFORMACIÓN PÚBLICA, as the Supervisory Authority of Law 25.326, has the power to handle complaints and claims filed by those whose rights are affected by non-compliance with the rules in force on personal data protection."
13How to exercise your rights
Write to [email protected], preferably from the email address linked to your account, saying which right you want to exercise. If we cannot verify your identity from that address, we may ask for reasonable additional information, which we will use only for that purpose. Exercising your rights is free of charge.
We acknowledge requests promptly and answer within one month at the latest (extendable by two further months for complex requests, as the GDPR allows), or within the shorter period your law sets — for example, 10 calendar days for access and 5 business days for rectification or deletion under Argentine Law 25.326, 15 days for a complete access report under the LGPD, and 45 days under the CCPA.
If you are a customer of a merchant that uses NexxoSync (you bought from its store or wrote to its chatbot), please send your request to that merchant: it controls your data and keeps it in its own systems. If you write to us, we will forward your request to the merchant and assist it in responding.
If you are not satisfied with our answer, you can complain to the data protection authority of your country — in the EU, the authority of your Member State; in the UK, the ICO; in Brazil, the ANPD; in Argentina, the AAIP.
14Children
The Service is for businesses and adults with legal capacity to contract. It is not directed at children, and we do not knowingly collect children's data for our own purposes. If we learn that an account was created by a minor, we will delete it. Merchants are responsible for the data their own customers provide to them.
15Changes to this policy
We may update this policy when the Service or the law changes. We publish every version on this page with its effective date and, if a change materially affects how we process your data, we notify merchants by email at least thirty (30) days in advance.
16Contact
- Privacy and data protection: [email protected].
- Security issues and vulnerability reports: [email protected].
- Postal address: NexxoSync, the Province of Mendoza (the full address is provided to the competent authority and to any Customer who requests it in writing), Argentina.