Privacy Policy

Effective date: 22 May 2024  ·  Last updated: 1 August 2026

1. Who we are

Nemax AI ("we", "us", or "our") provides an AI-assisted customer messaging service. We respect your privacy and are committed to protecting it through compliance with this policy.

This policy applies to:

  • the Nemax AI service and dashboard;
  • our website at www.nemaxai.com; and
  • our Meta Platform application "Nemax" (App ID: 4408362826095380).

2. Scope and our role

Different groups of people are covered by this policy, and our role differs for each.

2.1 People who message our own business channels

When you send a message to a WhatsApp number, Instagram account, or Facebook Page operated by Nemax AI, we determine why and how your information is used. For this information we act as the data controller.

2.2 Business customers who subscribe to Nemax AI

Businesses that subscribe to Nemax AI connect their own messaging channels using their own Meta developer applications and their own credentials. Those businesses hold their own direct relationship with Meta and remain responsible for their own compliance with Meta's terms and with applicable privacy law.

For a business customer's account, billing, and configuration information, we act as the data controller.

2.3 People who message a business that uses Nemax AI

If you contacted a business that uses our software, that business decides why and how your information is used. It is the controller. We act as a service provider, handling the information only on that business's documented instructions and only to provide the service they have contracted for.

If you want your information removed, the fastest route is to contact that business directly. You may also contact us at cs@nemaxai.com and we will act on the instruction of the relevant business customer, and will inform you when we have passed your request on.

3. Information we collect

3.1 From business customers

  • Contact and account details: name, business name, email address, phone number, job role
  • Billing and subscription details: plan tier, invoices, and payment records. Card details are handled directly by our payment processor; we do not store full card numbers or security codes
  • Knowledge base content you upload: pricing, business rules, service descriptions, FAQs, scripts, brand voice guidance, and other material you provide to configure your AI agent
  • Access credentials and tokens: access tokens for the messaging channels and connected systems you authorise
  • Configuration and usage data: agent settings, channel configurations, login timestamps, and feature usage

3.2 From people who send messages

When you send a message through WhatsApp, Instagram, or Facebook Messenger, we process:

  • Identifiers: your phone number, WhatsApp ID, Instagram-scoped ID (IGSID), Page-scoped ID (PSID), and the display name shown on your account
  • Message content: the text of the messages you send and the replies sent to you, together with any media attachments included in those messages
  • Message metadata: timestamps, message direction, and the channel used

We store the messages themselves. We do not create profiles, scores, sentiment ratings, behavioural labels, lead-qualification categories, or automated summaries about the people who message us. We do not enrich your record with information from other sources.

3.3 Collected automatically on our website

  • IP address and the approximate region derived from it
  • Browser type and device information
  • Timestamps of interactions
  • Session identifiers used to keep you signed in

4. Meta Platform data

Our application connects to the WhatsApp Business Platform, the Instagram Messaging API, and the Messenger Platform. We access and process the following categories of Meta Platform Data:

What we accessWhy we access it
WhatsApp message content, media, and sender phone numbers To receive incoming messages and deliver replies
WhatsApp Business Account configuration and phone number details To connect and manage the messaging number within our platform
Instagram direct messages and account profile information To read incoming direct messages and send replies
Facebook Page conversations and Page metadata To manage Messenger conversations and receive webhook events

Meta Platform Data is used only to provide and support the messaging service. Specifically, we do not:

  • Sell, rent, licence, or otherwise transfer Meta Platform Data to any third party for their own purposes
  • Use it for advertising, ad targeting, or building advertising audiences
  • Transfer it to a data broker, information broker, or advertising network
  • Use it to train, fine-tune, or evaluate machine learning models
  • Use it to build or augment profiles about the people who message us
  • Combine or commingle one business customer's data with another's
  • Attempt to re-identify, de-anonymise, or reverse-engineer data provided to us
  • Process it for any purpose not described in this policy

5. How and why we use information

InformationPurpose
Message content To understand your enquiry, generate a reply, and pass the conversation to a member of staff where the automated system cannot help
Conversation history To give the automated system the context of the current conversation so that replies make sense. We provide a limited number of the most recent messages in the same conversation for this purpose
Contact identifiers To route replies back to you on the channel you used, and to keep your conversation together in one place
Technical and session data Service delivery, security monitoring, fault diagnosis, and preventing abuse
Business customer account and billing data Account management, billing, customer support, and meeting statutory accounting obligations

6. AI processing and model training

Replies are generated using an automated system built on a large language model provided by a third-party AI service provider, accessed under a paid enterprise agreement.

When you send a message, the content of that message and a limited number of the most recent messages in the same conversation are transmitted to that provider to generate a reply. The reply is returned to us, stored with the conversation, and sent to you on the channel you used.

Your messages are not used to train AI models. Under the paid terms we have agreed with our AI service provider, the provider does not use the prompts we send or the responses returned to train or improve its models. The provider may retain content for a limited period for abuse monitoring and policy enforcement on its own systems; this is outside our control and is governed by that provider's own terms.

We do not use conversation content to train, fine-tune, or evaluate any model of our own.

Each business customer's AI agent is configured using only the knowledge base supplied by that customer. Knowledge bases are kept separate and are never used to configure or inform agents serving other customers.

Automated replies are not used to make decisions that produce legal or similarly significant effects about you. You can ask to speak to a person at any time by replying to any message with a request to speak to a human.

7. How we share information

We share information only as described below. We do not sell personal information.

7.1 With the business you contacted

If you messaged a business that uses Nemax AI, your conversation is made available to that business through their dashboard and any system they have connected. That business determines how it uses this information under its own privacy policy.

7.2 With service providers

We use the following third-party services to operate the platform. Each is bound by contract to process data only on our instructions, to maintain appropriate security, and not to use the data for its own purposes:

ProviderRoleData shared
AI service provider
(processing region: United States)
Large language model service: generates automated replies to messages Message content and a limited number of recent messages from the same conversation, sent as context
Cloud infrastructure provider
(data centre: United States)
Hosting for our application, database, and workflow automation All conversation data stored on the platform
Website hosting provider Website hosting for nemaxai.com Website visitor data and session identifiers
Business email provider Business email and communication Email content sent to or from our team

Our workflow automation software runs on infrastructure we control. It is not operated by a third party and message content is not shared with a third-party automation vendor.

7.3 Meta Platforms

Messages travel to and from you across Meta's messaging infrastructure: WhatsApp, Instagram, and Messenger. Meta processes that information as an independent party under its own terms and privacy policies, not on our instructions.

7.4 Legal and corporate disclosures

We may disclose information where required by law, court order, or a regulatory authority; to establish, exercise, or defend legal claims; to protect the safety of any person; or in connection with a merger, acquisition, or sale of assets, in which case we will notify affected business customers in advance where we are legally permitted to do so.

8. Where your information is stored

Our servers and databases are located in the United States. Our AI service provider processes message content in the United States.

If you are in Canada: your personal information is stored and processed outside Canada, in the countries named above. While your information is held in another country, it is subject to the laws of that country and may be accessible to the courts, law enforcement agencies, and national security authorities of that country.

If you are in the United States: your personal information is stored and processed within the United States.

We apply the security measures described in section 13 to information wherever it is held. If you have questions about a specific transfer, contact us at cs@nemaxai.com.

9. How long we keep information

Data categoryRetention period
Message content and conversation history7 days from the date of the message
Contact recordsDuration of the business customer's active contract, plus 30 days following termination
Workflow automation execution logs3 days
System and application logs3 days
Database backups1 month on a rolling basis
Business customer account and billing records6 months, to meet applicable accounting and tax obligations

We delete information sooner than the periods above where it is no longer needed for the purpose it was collected for, where we stop operating the service through which it was collected, where you ask us to delete it, or where Meta or applicable law requires us to.

When a business customer's subscription ends, we delete the associated conversation data within 30 days of termination, except where we are required to retain records by law. Deleted data is removed from backups within the backup cycle stated above.

10. How to request deletion

You can ask us to delete your personal information at any time. This right is available to everyone, wherever you are located, and there is no charge for making a request.

10.1 By email

Send a request to cs@nemaxai.com. Please include enough detail for us to find your records: for example the phone number, WhatsApp number, or Instagram handle you used, and the name of the business you contacted if it was not us.

10.2 In the conversation

You can reply to any message on WhatsApp, Instagram, or Messenger asking us to delete your data. Requests received this way are passed to a member of our team rather than answered automatically.

10.3 What we delete

When we act on a deletion request, we remove your message history and contact record from our database, remove the associated entries from our workflow automation logs, and ensure your messages are no longer included as context in any future automated reply. Copies held in encrypted backups are removed as those backups age out of the cycle described in section 9.

Content held briefly by our AI service provider for abuse monitoring, as described in section 6, expires under that provider's own retention schedule and cannot be deleted by us on request.

10.4 Business customers

Business customers can delete individual conversations and contact records directly from the Nemax AI dashboard. To delete an entire account and all associated data, email cs@nemaxai.com.

10.5 Response time

We acknowledge deletion requests within 5 business days and complete deletion within 30 days of acknowledgement. Where we act as a service provider for a business you contacted, we forward your request to that business and act on their instruction. We will tell you when we have done so.

11. Automated messaging and opt-out

Messages you receive from us are generated by an automated system unless a member of our team tells you otherwise. Every conversation identifies the business sending the message.

You can stop receiving messages at any time. Reply STOP to any message, or block the number or account in the app you are using. We action opt-out requests immediately and will not send you further messages, on any channel, unless you contact us again.

We only send messages to people who have contacted us first or who have otherwise given us permission to message them. We do not send unsolicited commercial messages.

If you are in Canada, our messages are sent in accordance with Canada's Anti-Spam Legislation (CASL). Each message identifies the sender and provides a means of unsubscribing.

12. Your privacy rights

Deletion, described in section 10, is available to everyone regardless of location. In addition, depending on where you live, you may have the following rights:

  • Access: request a copy of the personal information we hold about you
  • Correction: ask us to correct information that is inaccurate or incomplete
  • Restriction: ask us to limit how we process your information in certain circumstances
  • Objection: object to certain processing
  • Portability: receive your information in a structured, machine-readable format
  • Withdrawal of consent: withdraw consent where processing is based on consent, without affecting processing carried out before withdrawal
  • Non-discrimination: exercise any of these rights without receiving a lesser standard of service

To exercise any right, contact us at cs@nemaxai.com. We will verify your identity before acting on a request.

12.1 If you are in Canada

You have the right to access and correct your personal information, and to challenge our handling of it. If you are not satisfied with our response, you may complain to the Office of the Privacy Commissioner of Canada at priv.gc.ca.

12.2 If you are in the United States

Privacy rights vary by state. Residents of states with comprehensive privacy laws may have rights to access, correct, delete, and obtain a copy of their personal information, and to opt out of certain processing. We do not sell personal information and we do not share it for cross-context behavioural advertising. To make a request, contact us at cs@nemaxai.com.

13. Security

We maintain technical and organisational measures appropriate to the nature and sensitivity of the information we process, including:

  • Encryption of data in transit using TLS 1.2 or higher
  • Encryption of data at rest on our hosting infrastructure
  • Role-based access controls and least-privilege access for all staff
  • Access logging and monitoring for unusual activity
  • Logical separation of each business customer's data
  • Secure storage of access tokens and API credentials using recognised secret management practices
  • Periodic review of the security practices of our service providers

13.1 Reporting a security problem

If you believe you have found a security vulnerability in our service, please report it to security@nemaxai.com. We investigate all reports and will keep you informed of progress. Please do not publicly disclose a vulnerability before we have had a reasonable opportunity to address it.

13.2 Breaches

No system is completely secure. In the event of a personal data breach, we will notify affected business customers without undue delay, notify affected individuals where the breach creates a real risk of significant harm, and report to the relevant authorities where required by law.

14. Cookies and tracking

Our website uses a small number of cookies and browser session storage items to keep your session active, maintain security, and remember your preferences during a visit. These are essential for the site to function.

We do not use third-party analytics, advertising, or tracking cookies on this website.

You can control cookies through your browser settings. Disabling all cookies may affect how the website works.

15. Children

Nemax AI is a business service and is not directed to children. We do not knowingly collect personal information from anyone under 13, and our service is not intended for anyone under 16. If we learn that we have inadvertently collected such information, we will delete it promptly. If you believe a child has provided us with personal information, contact us at cs@nemaxai.com.

16. Changes to this policy

We may update this policy to reflect changes in our service, our service providers, or our legal obligations. The effective date at the top of this page shows when the current version came into force. Where changes are material, we will notify business customers by email and through a notice in the dashboard at least 14 days before the change takes effect.

17. Contact us

For any privacy question, rights request, or complaint:

We aim to respond to all enquiries within 5 business days.

Nemax AI · Meta App "Nemax" · App ID 4408362826095380 · www.nemaxai.com