Privacy Policy
Last updated: May 15, 2026
1. Data Controller
Bigei SRL · VAT IT15197391004 · Registered in Italy.
Privacy contact: privacy@usenexus.im
2. Data we collect
We collect the following personal data:
- Registration data: name, email, phone number, business name, VAT
- Usage data: access logs, dashboard events, conversations handled by the AI
- Payment data: handled by Stripe (PCI-DSS compliant), not stored on our servers
- Technical and analytics cookies (see Cookie Policy)
3. Purposes of processing
- Delivery of the Nexus AI service
- Invoicing and tax compliance
- Customer support
- Service communications (no marketing without explicit consent)
- Security and fraud prevention
4. Legal basis
Processing is based on:
- Contract performance (GDPR Art. 6(1)(b))
- Legal obligations (GDPR Art. 6(1)(c))
- Legitimate interest for security and analytics (GDPR Art. 6(1)(f))
- Explicit consent for direct marketing (GDPR Art. 6(1)(a))
5. Data retention
Data is retained for the duration of the contract and, after cancellation, for an additional 30 days (to allow recovery in case of error). Tax data is retained for 10 years per Italian law.
6. Data transfers
Data is hosted on Microsoft Azure, EU regions (Italy North, West Europe). We never transfer data outside the European Union. For more details on AI models used and where data lives, see the AI Transparency page.
7. Your rights
You have the right to:
- Access your personal data
- Request rectification
- Request erasure
- Object to processing
- Request portability in structured format (JSON/CSV)
- Lodge a complaint with the Italian Privacy Authority
To exercise your rights: privacy@usenexus.im
8. Security
We adopt adequate technical and organizational measures: AES-256 encryption at rest, TLS 1.3 in transit, restricted data access, audit logs, daily backups. 99.9% SLA guaranteed on Pro and Enterprise plans.
9. Cookies
We use technical cookies (necessary) and analytics cookies (PostHog, Microsoft Clarity). Consent for analytics and marketing cookies is requested on first access via banner. See Cookie Policy for details.
10. Policy changes
Any changes will be communicated via email at least 30 days before they take effect.