Your data and your customers' data, handled with care.
NexxoSync moves orders and customers between your platforms. That's personal data, so we process the minimum, encrypt what matters and delete it on a schedule.
What we do, concretely.
Encryption in transit and at rest
All traffic goes over HTTPS/TLS. Platform credentials, tokens and secrets are encrypted with AES-256-GCM before they're stored.
Workspace isolation
Every query is scoped to the workspace. A company only ever sees its own connections, runs and data.
Least privilege
Roles inside each workspace, and support access to a workspace is recorded in an audit log.
Strong authentication
Password policy for users; platforms connect through their official authorization (OAuth) where they offer it, so we never see your platform password.
Encrypted backups
Database backups are encrypted (AES-256) and never left in plain text.
Incident response
A written plan to contain, investigate and notify affected customers without undue delay.
Data minimization
Orders and customers are read from one platform and written to another; there's no separate customer database for marketing. We don't sell data.
AI with limits
Assistants get only the text needed to answer, through your own AI provider account. The chatbot shows an order only after verifying the buyer.
Deleted on a schedule, automatically.
| Data | Kept for |
|---|---|
| Run history (what each sync did) | 90 days |
| Failed jobs | 30 / 90 days |
| Website chatbot conversations | 7 days |
| Audit log | 365 days |
Default periods; a workspace's data is deleted when the account is closed. Details in the Privacy Policy.
Report a vulnerability
Found a security issue? Write to [email protected] with the steps to reproduce it. Please don't access other people's data or degrade the service while testing; we'll answer and keep you posted on the fix.