Bu hukuki belge İngilizce olarak sunulmaktadır. Bağlayıcı olan İngilizce sürümdür.

Privacy Policy

This policy explains what personal data Nexus collects, why we collect it, who we share it with, how long we keep it, and the rights you have over it. It covers our website, the bot builder, hosted bot runtimes, integrations, billing, and the template marketplace.

Effective July 28, 2026 · Last updated July 28, 2026

Registration details pending. The registered company number and office address for Nexus Bots B.V. are being finalised and will be published here. Until then, reach us at the contact addresses below.

1. Who we are and our role

Nexus Bots B.V. operates Nexus, a platform for building automation flows and deploying them as bots across messaging channels.

Our role depends on whose data is involved, and the distinction determines who you should contact about it:

  • We are the controller of account data. For the personal data of Nexus users — your account, workspace memberships, billing records, support requests, and the flows you build — we decide why and how it is processed.
  • We are a processor for end-user data. When a customer deploys a bot, the people who message that bot are the customer's end users. The customer decides what data the bot collects and why; we process it on their instructions. If you messaged a bot and want your data removed, contact the operator of that bot. If you cannot identify them, write to us and we will route the request.

Customers acting as controllers are responsible for having a lawful basis to process their end users' data, for giving those people notice, and for honouring their rights.

2. Data we collect

Data you give us

  • Account and profile: name, email address, hashed password, profile image, email-verification state, and two-factor secrets and recovery codes if you enable them.
  • Workspace: workspace names, memberships and roles, invitations, invite codes, referrals, and single sign-on configuration.
  • Product content: bot flows and versions, flow revision history, node configuration, schedules, key-value state your flows write, uploaded media, and marketplace listings you publish.
  • Integration credentials: OAuth tokens, API keys, and channel tokens for the services you connect. These are encrypted at rest and are never shown back to you in full.
  • Commercial: billing contact details, subscription and plan history, marketplace purchases, refunds, reviews, reports, and payout account references.
  • Communications: support tickets and messages, and correspondence you send us.

Data generated by using the service

  • Authentication and session records, including sign-in events, active sessions, device and browser identifiers, and rate-limit counters.
  • Bot run records: execution logs, per-node outcomes, errors, queue jobs, pending waits, alerts, and daily aggregate statistics.
  • Conversation analytics: daily counts and a salted, bot-scoped hash of the channel participant identifier. Analytics tables do not store the raw phone number, session id, or platform user id.
  • Conversation state for each channel a bot serves, so a flow can remember where a conversation left off.
  • Security and operational logs, including IP address, user agent, request metadata, and audit records of administrative actions.
  • Onboarding funnel events that tell us where in setup people get stuck.

Data we receive from connected services

When you connect a channel or integration, that service sends us the data your bot needs to function — inbound message content, platform user identifiers, display names, delivery receipts, and, for the Google integrations you authorise, the spreadsheet, calendar, or live-chat data covered by the scopes you granted. We receive this only for the accounts and channels you connect, and only while the connection is active.

Data we do not collect

We do not buy personal data from data brokers, we do not sell or share personal data for advertising, we do not run advertising or cross-site tracking on our site, and we do not use Google user data or the contents of your bot conversations to train machine-learning models.

3. How and why we use data

  • Provide the service: authenticate you, run the builder, execute flows, deliver and receive messages, and keep conversation state.
  • Integrations: connect, refresh, and call the third-party services you authorise, on your instruction.
  • Billing: process subscriptions, enforce plan limits and quotas, handle marketplace purchases, refunds, and payouts, and calculate tax.
  • Support and communication: respond to tickets, send transactional email such as verification, password reset, and operational alerts.
  • Safety and integrity: detect and prevent abuse, spam, fraud, and unauthorised access; enforce our Terms; moderate marketplace listings and reports.
  • Reliability: monitor errors, capacity, and queue health, and diagnose faults.
  • Legal: comply with legal obligations, respond to lawful requests, and establish or defend legal claims.
  • Improve the product: understand aggregate usage patterns and where setup fails, and improve the AI flow generator from the prompts and results described in section 8. This never uses the contents of your bot conversations or Google user data.

4. Lawful bases

We are established in the European Union, so the EU General Data Protection Regulation applies to our processing. The UK GDPR applies in addition where we process the data of people in the United Kingdom. Where more than one basis could apply, the primary one is listed.

Lawful basis for each processing purpose
PurposeLawful basis
Creating and operating your account; providing the builder, runtimes, and integrationsPerformance of a contract
Billing, subscriptions, marketplace payoutsPerformance of a contract
Transactional email required to operate the accountPerformance of a contract
Security monitoring, abuse and fraud prevention, audit loggingLegitimate interests in keeping the service and its users safe
Reliability monitoring and product improvement from aggregate usageLegitimate interests in maintaining and improving the service
Improving the AI flow generator from builder prompts and their resultsLegitimate interests in improving a feature you use, subject to your right to object
Optional features you switch on, such as connecting a Google accountConsent, which you may withdraw at any time by disconnecting
Tax, accounting, and responding to lawful requestsLegal obligation

Where we rely on legitimate interests we have balanced those interests against your rights and concluded the processing is proportionate. You can object at any time — see section 13.

5. Google user data

Nexus can connect to Google Sheets, Google Calendar, Gmail, and YouTube so your flows can act on your behalf. These connections are entirely optional. We request access only when you start a connection, only for the scopes that specific integration needs, and you can revoke access at any time.

Limited Use disclosure

Nexus's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Scopes we request and why

Google OAuth scopes requested by Nexus
ScopeGoogle productClassificationWhy we request it
openid, emailGoogle Sign-InBasicIdentify the Google account being connected and label the connection in your workspace. Also used when you choose to sign in to Nexus with Google.
https://www.googleapis.com/auth/spreadsheetsGoogle SheetsSensitiveRead and append rows in the specific spreadsheets your flow references, so a Sheets node can look up or record data while a bot runs.
https://www.googleapis.com/auth/calendar.eventsGoogle CalendarSensitiveCreate, read, and update calendar events on your behalf when a flow contains a Calendar node — for example booking an appointment a bot user requested.
https://www.googleapis.com/auth/gmail.sendGmailRestrictedSend an email that your flow composes. This scope grants send-only access: it does not permit Nexus to read, search, delete, or modify any message in your mailbox.
https://www.googleapis.com/auth/youtube.readonlyYouTubeSensitiveDetect when a connected channel is live and read the live chat associated with that broadcast, so a bot can respond during a stream.
https://www.googleapis.com/auth/youtube.force-sslYouTubeSensitivePost the replies your flow generates into the live chat of your own connected channel.

How we handle Google user data

  • Use is limited to providing the user-facing integration features you invoked. Data obtained through these scopes is not used for any other purpose.
  • We do not transfer or sell Google user data to third parties, including advertising platforms, data brokers, or information resellers, and we do not use it for advertising, retargeting, credit assessment, or lending decisions.
  • We do not use Google user data — raw, aggregated, anonymised, or derived — to develop, improve, or train generalised artificial-intelligence or machine-learning models.
  • No human at Nexus reads your Google user data, except where you have given specific affirmative agreement for us to look at particular data to support you, where it is strictly necessary for security purposes such as investigating abuse or a specific bug, or where the law requires it.
  • OAuth access and refresh tokens are encrypted at rest with a dedicated application key and are only decrypted in memory at the moment a flow calls the relevant API.
  • Google user data is transmitted over TLS and is not written to our general application logs.
  • The Gmail scope we request is send-only. It does not permit us to read, search, delete, or modify anything in your mailbox.

Revoking access and deletion

You can disconnect a Google integration from Settings → Connections in Nexus, which deletes the stored tokens immediately. You can also revoke access directly from your Google Account at https://myaccount.google.com/permissions. Once access is revoked we stop calling the API, and we delete cached Google user data associated with the connection within 30 days.

Google's own handling of your data is governed by the Google Privacy Policy. Our use of Google APIs is governed by the Google API Services User Data Policy.

6. YouTube API Services

The YouTube integration uses YouTube API Services. By connecting a YouTube channel to Nexus, you agree to be bound by the YouTube Terms of Service.

  • We use YouTube API Services to detect when your connected channel goes live, read the live chat for that broadcast, and post the replies your flow generates into your own channel’s live chat.
  • Data obtained through YouTube API Services is handled in accordance with the Google Privacy Policy.
  • You can revoke our access to your YouTube data at any time through the Google security settings page at https://myaccount.google.com/permissions, or by disconnecting the channel in Settings → Connections.
  • We store live-chat data only for as long as needed to run the flow that responds to it, and we delete stored YouTube data within 30 days of a deletion request or of you revoking access.
  • We do not use YouTube data to derive independent metrics, we do not combine it with data from other sources, and we do not make it available to any third party.

7. Meta and other messaging channels

When you connect WhatsApp, Messenger, Instagram, Telegram, Discord, Slack, Twitch, or a Twilio phone number, we receive inbound messages and platform identifiers for the accounts you connect, and we send the outbound messages your flow produces. We process this material as your processor, for the purpose of running your bot.

  • Message content and platform user identifiers are stored only as needed to maintain conversation state and to produce the run records described in section 11.
  • Platform data is not used for advertising, is not sold, and is not used to train models.
  • Inbound images are fetched from the platform while the flow runs and are not stored by us. Images your flow generates are stored for 30 days and then pruned automatically.
  • Delivery and event receipts used to deduplicate webhook traffic are kept for 24 hours (Slack) and 7 days (WhatsApp) and then deleted.
  • Each platform also processes data under its own terms — for Meta products, see the Meta Privacy Policy.
  • For instructions on deleting data associated with a Meta channel, see our data deletion page.

8. AI features

Nexus uses AI in two places, and they work differently in a way that matters for your data — in particular, whose account pays for the call determines who is responsible for the data afterwards.

Generate with AI — runs on our account

The flow generator in the builder drafts or modifies a flow from a prompt you write. It runs on our own OpenAI account, and is available on Pro and Team. We are the controller for this processing.

  • Your prompt, and the existing flow if you asked for a modification, are sent to OpenAI under our account.
  • Prompts are screened for values that look like secrets and rejected before they are sent. Do not paste credentials or other people’s personal data into a prompt.
  • Generated flows are never saved, run, or deployed automatically — nothing happens until you review and save it.

AI nodes — run on your account

When a deployed flow reaches an AI node, the request is sent using the API key from a connection you configured, directly to that provider. We do not fund or route these calls through our own provider account.

  • Your own agreement with that provider governs what they do with the data, including whether they retain it or use it to improve their models. We are not a party to that agreement and cannot make commitments on their behalf. Review their terms and their data controls.
  • If a flow has no AI connection configured, no request is made and the node returns placeholder text instead. Nothing leaves our systems.
  • We never use the content passed to an AI node to improve our own features — see the exclusions below.
  • Your stored credentials are decrypted only in memory at the moment of the call and are never sent to any other party.

Model output can be wrong in both cases. Do not rely on it for decisions that need to be correct without checking it first.

Improving the flow generator

We use material from Generate with AI, the server-funded flow generator in the builder to evaluate and improve how well it works. This is on by default for accounts that have access to that feature. Specifically, we may use:

  • the prompt you write describing the bot you want
  • the existing flow you submit when you ask for a modification or explanation
  • the flow structure the model returns
  • whether you accepted, edited, regenerated, or discarded the suggestion, and any validation errors it produced

Free accounts have no flow-generation allowance and therefore contribute nothing. Where this processing relies on our legitimate interest in improving the service, you have the right to object under Article 21 of the GDPR — email privacy@hmcelik.com and we will exclude your workspace, without affecting your access to the feature.

What we never train on

The following are excluded from any use in developing or improving AI models, on every plan and in every feature:

  • data obtained through Google APIs, including Sheets, Calendar, Gmail, and YouTube
  • the content of conversations between your bots and their end users, including anything processed by AI nodes at run time
  • data received from Meta, Telegram, Discord, Slack, Twitch, Twilio, or HubSpot
  • integration credentials, API keys, and OAuth tokens
  • billing, payment, and payout details

The exclusion of Google data is required by the Limited Use terms in section 5. The exclusion of bot conversation content follows from our role: that data belongs to the customer who operates the bot, and we hold it only as their processor.

This material is shared with OpenAI, which processes it under our account so that we can evaluate and improve the generator. OpenAI may also use it to improve its own models. If you would rather that did not happen to your prompts, object using the address above and we will exclude your workspace. We do not sell this material, and we do not share it with any other third party.

9. Sharing and sub-processors

We share personal data only as described here. We do not sell personal data, and we do not share it for cross-context behavioural advertising.

Sub-processors and connected services
RecipientPurposeData involvedRole
VercelApplication hosting, edge network, and request logs for the web appRequest metadata, IP address, account identifiersProcessor
Fly.ioHosting for the durable execution workerQueued job payloads, bot message content in transitProcessor
Managed PostgreSQL providerPrimary database for all account, workspace, and bot dataAll stored account, flow, conversation, and billing recordsProcessor
S3-compatible object storageMedia uploaded to, or generated by, bot flowsImages and files, with derived object keysProcessor
StripeSubscription billing, tax calculation, and marketplace payoutsBilling contact, payment references, payout and tax detailsIndependent controller and processor
ResendTransactional email (verification, password reset, alerts)Email address, message contentProcessor
OpenAI (flow generator)Generating and modifying flows in the builder, on our own OpenAI account, and evaluating how well that feature worksThe prompt you write, the flow you submit for modification, and the generated resultProcessor
OpenAI, Anthropic, or Google (AI nodes at run time)Running an AI node inside a deployed flow, using the API key from a connection you configuredPrompt text and the conversation context your flow passes inAt your direction
Google (Sheets, Calendar, Gmail, YouTube)The Google integrations you explicitly connectThe spreadsheet, calendar, message, or live-chat data covered by the scopes you grantedAt your direction
Meta (WhatsApp, Messenger, Instagram)Delivering and receiving messages on channels you connectMessage content, platform user IDs, delivery receiptsAt your direction
Telegram, Discord, Slack, TwitchDelivering and receiving messages on channels you connectMessage content, platform user IDsAt your direction
TwilioSMS and voice channels you connectPhone numbers, message and call contentAt your direction
HubSpotCRM integration you connectContact records your flow reads or writesAt your direction

"At your direction" means the transfer happens only because you connected that service or built a flow that calls it. The current list is maintained at /legal/subprocessors.

We may also disclose data:

  • to professional advisers such as lawyers, auditors, and accountants, under a duty of confidentiality;
  • where required by law, court order, or a valid request from a public authority, after assessing whether the request is legally valid and no broader than necessary;
  • to protect the rights, property, or safety of Nexus, our users, or the public, including investigating suspected fraud or abuse; and
  • in connection with a merger, acquisition, financing, or sale of assets, in which case we will give notice before your data becomes subject to a different privacy policy.

10. International transfers

We are established in the Netherlands, and several of our sub-processors are located outside the European Economic Area, principally in the United States. Where we transfer personal data out of the EEA to a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914), supplemented by the UK International Data Transfer Addendum for transfers of UK personal data. In each case we carry out a transfer impact assessment and apply technical measures including encryption in transit and encryption of stored credentials at rest. Some US recipients are certified under the EU–US Data Privacy Framework, which we rely on where it applies.

You can request a copy of the safeguards applying to a specific transfer by writing to privacy@hmcelik.com.

11. Retention

We keep personal data only as long as we need it for the purpose it was collected for, or as long as the law requires.

Retention periods
DataRetention period
Account, workspace, and flow contentUntil you delete it, or until the account is deleted
Raw bot run records7 days on Free, 30 days on Pro, 90 days on Team
Aggregate daily statisticsRetained after the underlying runs expire; these contain counts, not message content
Hashed analytics participant stateUntil the bot or workspace is deleted; the raw participant identifier is not stored in analytics tables
Inbound images from a messaging platformNot stored — fetched from the platform during the run and discarded
Runtime-generated images30 days, then pruned automatically
Unclaimed marketplace screenshots24 hours
Slack event receipts24 hours
WhatsApp delivery status receipts7 days
Google user data cached to run a flowDeleted within 30 days of disconnection, revocation, or a deletion request
Integration credentialsDeleted when you disconnect the integration or delete the workspace
Billing, invoice, and payout recordsUp to 7 years, to meet tax and accounting obligations
Security and audit logsUp to 12 months, or longer where needed for an active investigation
BackupsRolling backups are overwritten on a schedule; deleted data persists in backups until they cycle out, and is not restored into production

12. Security

  • Transport encryption (TLS) for all traffic to the application and to third-party APIs.
  • Integration credentials and OAuth tokens encrypted at rest with a dedicated application key, separate from the database.
  • Passwords stored using bcrypt; optional two-factor authentication with recovery codes.
  • Workspace-scoped access control on every data path, with tenant isolation enforced server-side rather than in the UI.
  • Signed, expiring state for OAuth flows; signed webhook verification for inbound platform traffic; rate limiting on authentication and webhook endpoints.
  • Public media served from a separate, cookie-free origin, with uploads validated by magic bytes and SVG never hosted.
  • Audit logging of administrative actions, including every emergency access use.
  • Operational alerting on error spikes, dead-lettered jobs, and quota thresholds.

No system is perfectly secure. If you believe you have found a vulnerability, please report it to security@hmcelik.com rather than disclosing it publicly, and give us a reasonable opportunity to fix it. We will not pursue legal action against good-faith security research conducted under those terms.

13. Your rights

Depending on where you live, you may have the right to:

  • access the personal data we hold about you and receive a copy;
  • have inaccurate data corrected;
  • have data deleted, subject to obligations that require us to keep some records;
  • restrict or object to processing, including processing based on legitimate interests;
  • receive your data in a portable, machine-readable format;
  • withdraw consent at any time, without affecting processing already carried out; and
  • not be subject to a decision based solely on automated processing that produces legal or similarly significant effects. We do not make such decisions.

Exercising them yourself

Account settings lets you download a complete JSON export of your data once every 24 hours, and permanently delete your account. Deletion requires your password, and is blocked while you are the sole owner of a team workspace or hold an active subscription, so that you do not lose access to something you are still paying for or strand your collaborators. Resolve those first, then retry. You can also disconnect integrations and manage workspace access at any time.

For anything you cannot do yourself, write to privacy@hmcelik.com. We respond within 30 days, and will tell you if we need an extension. We may ask you to verify your identity before acting. We do not charge for these requests unless they are manifestly unfounded or excessive.

Step-by-step deletion instructions, including for data tied to a specific messaging channel, are at /legal/data-deletion.

14. Regional disclosures

European Economic Area

Our lead supervisory authority is the Dutch Data Protection Authority (Autoriteit Persoonsgegevens), at www.autoriteitpersoonsgegevens.nl. You may lodge a complaint with it, or with the supervisory authority in your country of residence or work, or where you believe the issue occurred. We would appreciate the chance to address your concern first.

We have assessed that our processing does not require a data protection officer under Article 37 of the GDPR, because it does not involve large-scale monitoring or large-scale processing of special-category data as our core activity. Privacy questions still reach a named owner at the address below.

United Kingdom

Where the UK GDPR applies, you may complain to the Information Commissioner's Office (ico.org.uk).

California

In the past 12 months we collected the categories of personal information described in section 2 — identifiers, commercial information, internet activity, and the contents of communications you route through the service — for the business purposes in section 3, from the sources in section 2, and disclosed them to the service providers in section 9.

We do not sell personal information, and we do not share it for cross-context behavioural advertising. We do not knowingly collect or sell the personal information of anyone under 16. You have the right to know, delete, correct, and to be free from discrimination for exercising these rights. Use the account tools above or write to privacy@hmcelik.com. An authorised agent may submit a request with written proof of authorisation.

Other US states

Residents of states with comprehensive privacy laws — including Colorado, Connecticut, Virginia, Utah, Texas, Oregon, and Montana — have comparable rights to access, correct, delete, and obtain a portable copy of their data, and to appeal a refused request. To appeal, reply to our decision and we will review it and respond with our reasoning.

15. Cookies and similar technologies

Nexus sets only first-party cookies. We run no advertising cookies, no cross-site trackers, and no third-party analytics on our own site.

Cookies set by Nexus
CookiePurposeCategory
Session and CSRF cookies (NextAuth)Keep you signed in and protect against cross-site request forgeryStrictly necessary
nexus-workspaceRemember which workspace you are currently viewingStrictly necessary
nexus-google-oauth-nonce, nexus-hubspot-oauth-nonce, nexus_twitch_oauthShort-lived, signed values that bind an OAuth response to the request that started itStrictly necessary
nexus_oauth_inviteCarry a pending workspace invitation through a sign-in redirectStrictly necessary
nexus_funnel_id, nexus_flow_graphFirst-party onboarding state — measure where setup is abandoned and restore an in-progress canvas. Not shared with any third party.Functional

Strictly necessary cookies cannot be switched off without breaking sign-in. You can clear or block cookies in your browser, but the application will not work correctly without the session cookies. Bots you embed on your own website are subject to your site's cookie notice, not ours.

16. Children

Nexus is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16 (or under 13 where that is the applicable threshold). If you believe a child has provided us with personal data, write to privacy@hmcelik.com and we will delete it. If your bot may interact with children, you are responsible for the additional obligations that creates for you.

17. Changes to this policy

We update this policy when the product or the law changes. We revise the "last updated" date on every change. For material changes — a new category of data, a new purpose, or a new type of recipient — we give notice by email or in the application before the change takes effect, and where a change affects data obtained through Google APIs we will prompt you to consent before accessing that data in the new way.

18. Contact

Privacy questions and rights requests: privacy@hmcelik.com
Legal notices: huseyinmelihcelik@gmail.com
Security reports: security@hmcelik.com

Nexus Bots B.V.

See also our Terms of Service, sub-processor list, and data deletion instructions.