1. What we collect
- Account data — name, email, password, billing details.
- Business context — what you tell NexLink about your business so agents can work.
- Content — pages, posts, messages, invoices created on the platform.
- Your customers’ data — names, contacts, orders you bring in or collect through NexLink. You are its controller; we process it for you.
- Usage data — how you use the product, device and log information.
2. How we use it
To run the service: give agents the context they need, execute what you approve, keep your account secure, bill you correctly, and improve the product. Agents share context inside your workspace only. We never sell your data, and we never use your business data to train models for other customers.
3. What we share
- Payment processors — to charge you and to move money you collect.
- Infrastructure providers — hosting, email delivery, analytics, under contracts that bind them to this policy.
- Authorities — only when the law requires it, and we tell you unless legally forbidden.
4. Data retention
We keep your data while your account is active. Backups rotate within 35 days. Billing records are kept as long as tax law requires.
5. Data deletion
You can delete anything you created at any time, and you can delete your entire account in Settings → Account → Delete account — no email, no phone call needed. When you delete your account:
- All your content, business context, and customer data are permanently deleted from production systems within 30 days.
- Backups containing your data expire and are destroyed within 35 more days.
- Billing records we are legally required to keep are retained only as long as the law demands, then destroyed.
- You can also request deletion by writing to legal@nexlink.ai; we confirm completion in writing.
6. Your rights
Access, correct, export, or delete your data whenever you want. Export gives you your content and customer data in open formats. If you are in the EU/EEA, Brazil (LGPD), or California (CCPA), these rights are guaranteed by law — but we offer them to everyone, everywhere.
7. Security
Encryption in transit and at rest, isolated workspaces, least-privilege access for our team, and audit logs for every agent action. We notify you of any breach affecting your data without undue delay.
8. Changes
If we change this policy in any material way, we notify you 30 days in advance. The current version always lives at this page.
9. Google Calendar data
Connecting Google Calendar is optional. When you connect an account, NexLink accesses the account email, calendar-list metadata, and event data only for calendars you choose. The connection also permits NexLink to create, update, and delete Google events managed by NexLink in the calendar you select.
We use this data to show availability, detect scheduling conflicts, synchronize bookings, and keep events managed by NexLink up to date. Newly discovered calendars start private and disabled; you choose which calendars to import, the write destination, and whether teammates see details, busy time only, or nothing.
NexLink stores protected OAuth credentials and the calendar data needed to provide synchronization. Authorized infrastructure and service providers may process this data only to operate and secure the service. We do not sell Google Calendar data, use it for advertising, or use Google Workspace API data to develop, improve, or train generalized or non-personalized AI or machine-learning models.
You can disconnect an account in Calendar → Settings → Accounts. NexLink then attempts to revoke Google access and removes the connection, imported calendar records, and imported event data from active systems. Events already created in Google remain in Google. You can also revoke access in your Google Account under third-party connections. Backup expiration follows the retention period described above.
NexLink's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Write to legal@nexlink.ai — a person answers.