Privacy Policy
Effective 1 September 2026
NexaFlow is a customer relationship management service for real-estate teams. This policy explains what personal information we handle, why, where it is stored, and the choices you have. We store customer data in Canada, we do not sell personal information, and we do not use your data or your clients' data to train AI models.
1. Who we are
NexaFlow Systems (“NexaFlow”, “we”, “us”) provides the NexaFlow CRM at nexaflowsystems.com. We are the organization accountable for the personal information described in this policy, in accordance with Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA).
Privacy questions and requests: info@nexaflowsystems.com or +1 844-482-3336.
2. Two different roles
It matters which of these applies, because your rights and our obligations differ.
- When we act for ourselves. Information about the people who sign up for and administer a NexaFlow account — names, work email addresses, billing details, and how the product is used. We decide how this is handled, and this policy governs it directly.
- When we act for our customers. A brokerage using NexaFlow puts information about their clients and prospects into the service — contact details, notes, emails, appointments. That brokerage decides what to collect and why. We process it on their instructions under our Terms of Service. If you are a client of a brokerage that uses NexaFlow and want your information corrected or removed, contact that brokerage; we will support them in responding.
3. What we collect
| Category | Examples | Why |
|---|---|---|
| Account information | Name, work email, password hash, organization name, role, time zone | To create and secure your account and identify you across sessions |
| Billing information | Billing address, tax status, subscription and invoice history, card brand and last four digits | To charge for the subscription and meet tax and accounting obligations |
| Customer content | Leads, contacts, properties, deals, notes, tasks, appointments and files you add | To provide the service you are paying for |
| Connected mailbox and calendar data | Email messages, attachments, addresses and calendar events from a Google or Microsoft account you choose to connect | To show conversations alongside the related record and to send and schedule from within NexaFlow |
| Lead source data | Form responses delivered by Meta, LinkedIn, TikTok, Google, your website or Zapier | To create leads in your account from the advertising and web forms you have connected |
| Usage and technical data | IP address, browser and device type, pages and features used, timestamps, error reports | To keep the service secure and reliable, and to diagnose faults |
We do not ask for and do not want special categories of information such as health data or government identifiers. Please do not put them into free-text fields.
4. Google user data, and our Limited Use commitment
If you connect a Google account, NexaFlow requests only the access needed for the features you turn on: your basic profile and email address to identify the account, Gmail access to read and send messages within NexaFlow, and Google Calendar access to read and write appointments. You are shown these permissions before you grant them and can revoke them at any time from your Google account permissions page or from Settings inside NexaFlow.
NexaFlow’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: we use Google user data only to provide and improve the features you have enabled; we do not transfer it to others except as necessary to provide those features, to comply with applicable law, or as part of a merger or acquisition; we do not use it for advertising; we do not allow humans to read it except with your explicit consent, where necessary for security purposes such as investigating abuse, to comply with applicable law, or where the data is aggregated and anonymized; and we do not use Google user data to develop, improve or train generalized artificial intelligence models.
Disconnecting a mailbox stops all further access immediately and deletes the stored credentials. Messages already synchronized into your CRM remain until you or your organization delete them, or until your account is deleted under section 8.
5. Microsoft account data
Connecting a Microsoft or Microsoft 365 account works the same way and requests the equivalent mail and calendar permissions. The commitments in section 4 — no advertising use, no sale, no AI model training on your data, and deletion of credentials on disconnect — apply identically to Microsoft data.
6. How AI features handle your data
NexaFlow includes AI features (“Nexa”) that draft emails, summarize records and suggest next steps. These matter to your privacy, so we are specific about them.
- An AI request sends only the context needed for that task — for example, the relevant contact, recent activity on it, and the message being replied to. Every request records which categories of context were included, and you can see this in the product.
- Requests are sent to the AI provider your organization has selected: Anthropic, OpenAI, or Google. Your administrator chooses the provider and can turn AI features off entirely for the whole organization.
- We use these providers under agreements that prohibit training their models on our customers’ data. We do not train any model, our own or a third party’s, on your content or your clients’ content.
- AI output is a draft. Nothing is sent to a client until a person reviews and approves it. Automated workflows that send email require human approval by default.
- We keep AI outputs for 30 days to investigate quality problems. Your administrator can turn this off, in which case only counts of usage are retained for billing.
7. Service providers
We use the following providers to run NexaFlow. Each is bound by contract to protect the information they handle and to use it only to provide their service to us.
| Provider | Purpose | Where it processes data |
|---|---|---|
| Amazon Web Services | Application hosting, database, file storage, backups | Canada (Montréal) |
| Stripe | Subscription billing and payment processing | United States, Canada |
| Resend | Transactional email from NexaFlow (verification, invitations, alerts) | United States |
| Anthropic, OpenAI, Google | AI features, where enabled by your organization | United States |
| Sentry, Grafana Labs | Error reporting and performance monitoring | United States, European Union |
| Cloudflare | Bot protection on public lead forms | Global edge network |
We will update this list before adding a provider that handles personal information. Some providers are located outside Canada, which means the information they hold may be accessible to the courts and law enforcement of those countries. We use them under contractual protections comparable to those required by PIPEDA.
8. Where data is stored, and for how long
- Customer content and account data are stored in Canada, in the AWS Montréal region, and backed up within Canada.
- While your subscription is active we keep your data until you delete it. Deleted records remain recoverable in backups for up to 30 days.
- After cancellation we keep your organization’s data for 60 days so it can be reactivated or exported, then delete it. Tell us sooner and we will delete it sooner.
- Billing records are kept for seven years, as Canadian tax law requires. Audit logs are kept for the period in your plan.
9. How we protect information
- Encryption in transit (TLS) and at rest for stored data and backups.
- Access tokens for connected accounts and any AI keys you supply are individually encrypted with AES-256-GCM.
- Passwords are stored only as Argon2id hashes; we never see or store your password.
- Each organization’s data is isolated at the database level, enforced independently of application code.
- Access to production systems is limited to staff who need it, and is logged.
No service can promise perfect security. If a breach creates a real risk of significant harm, we will notify affected customers and the Office of the Privacy Commissioner of Canada as PIPEDA requires.
10. Your choices and rights
Under PIPEDA you may:
- Ask what personal information we hold about you and receive a copy.
- Ask us to correct information that is inaccurate or incomplete.
- Withdraw consent for optional processing, subject to legal and contractual limits — withdrawing consent for essential processing means we can no longer provide the service.
- Ask us to delete your personal information, subject to records we must keep by law.
- Complain to us first, and then to the Office of the Privacy Commissioner of Canada if you are not satisfied.
Write to info@nexaflowsystems.com. We respond within 30 days. We may need to verify your identity before acting.
11. Email we send you
We send account email you cannot opt out of while you have an account — verification, invitations, security notices, billing. Marketing email is sent only with consent that meets Canada’s Anti-Spam Legislation (CASL), identifies us, and includes a working unsubscribe link.
When you send email through NexaFlow to your own clients, you are the sender and you are responsible for having consent under CASL and for honouring unsubscribe requests.
13. Children
NexaFlow is a business product and is not directed at anyone under 18. We do not knowingly collect information from children. If you believe a child’s information has reached us, contact us and we will delete it.
14. Changes to this policy
We will post any change here and update the effective date. For a change that materially affects how we handle personal information, we will notify account administrators by email at least 30 days before it takes effect.