PRIVACY AND PERSONAL DATA PROCESSING POLICY

General Provisions

This Policy applies to the website https://nexifyneo.com / , the Platform https://crm.nexifyneo.com/, related NN Agent interfaces, and support communications.

The Controller of personal data processed by NN Agent for its own purposes (registration, contract, security, support, and service management) is Individual Entrepreneur Tatiana Reznikova.

This Policy is developed primarily in accordance with the Law of Georgia on Personal Data Protection. Where specific processing falls within the territorial scope of the GDPR, the relevant GDPR requirements apply additionally.

The Platform is intended for entrepreneurs, organizations, and individuals using it in connection with their business or professional activities. It is not designed for household consumer use.

The Terms of Service are available at https://nexifyneo.com/policy/terms/en. This Policy is available at. https://nexifyneo.com/policy/privacy/en.

Key Terms and Role Allocation

"Personal data", "Controller", "Processor", "consent", "international transfer", "security incident", and other terms are used as defined in the Law of Georgia on Personal Data Protection.

With respect to data of the User, their representatives, website visitors, and persons contacting support, NN Agent acts as the Controller.

With respect to data that the User uploads, receives, or creates in the Platform about their clients, leads, candidates, employees, counterparties, and other persons ("Customer Data"), the User determines the purposes and essential means of processing and acts as the Controller, while NN Agent processes such data under the User's documented instructions as the Processor.

The terms of Customer Data processing are additionally governed by the Data Processing Agreement (DPA). In the event of a conflict regarding Customer Data processing, the DPA shall take precedence over this Policy.

What Data Is Processed

Media files from Telegram (photos, voice messages, documents) are not, per information provided by the team, stored by the Platform as standalone files; the message text and / or attachment type may be processed.

The User must not intentionally upload special categories of personal data unless such processing is necessary for a legitimate purpose and a separate legal basis has been established. The incidental appearance of such information in correspondence does not mean that NN Agent has independently determined the purpose of its processing.

Purposes and Legal Bases

NN Agent does not use consent as a universal basis for processing that is objectively necessary for the performance of the Terms of Service. Withdrawal of consent does not terminate processing if it may lawfully continue on another basis.

Customer Data, Outbound Campaigns, and User Obligations

The User independently determines whom to include in the CRM and outbound campaigns, what data to upload, and how to use the Platform.

Prior to transferring Customer Data to NN Agent, the User must have an applicable legal basis for processing it, comply with direct marketing requirements, and inform data subjects to the extent and within the timeframes required by the law applicable to the User.

Where data has not been obtained directly from the data subject, the Law of Georgia requires, in applicable cases, that the prescribed information be provided within a reasonable period, upon first contact / first disclosure, and, as a general rule, no later than 10 business days after the data is received, unless a statutory exception applies.

NN Agent does not acquire an independent right to use Customer Data for its own marketing purposes.

Artificial Intelligence and Automated Processing

Depending on the subscription plan and settings, the User may activate an AI agent, AI conversation analysis, automatic task creation, and deal movement through funnel stages. The User may transmit to the AI provider limited conversation context necessary to fulfil a request.

The Platform supports the connection of third-party AI providers, including OpenAI, Anthropic and aggregator services (e.g. OpenRouter). The actual provider and model may be determined by the User's settings.

Where the User connects their own API key or their own AI provider account, the respective provider is a third-party service chosen by the User, and its processing is additionally governed by that provider's terms.

Where an AI provider is engaged by NN Agent on its own behalf to process Customer Data, it is treated as a sub-processor and is subject to the terms of the DPA and international transfer rules.

Customer Data and Knowledge Base materials are not used by NN Agent to train a publicly available or shared-across-users NN Agent model. Materials of one User must not become the Knowledge Base of another User.

AI features of NN Agent are designed to automate workflows, not to make decisions that in themselves have legal or comparably significant consequences for an individual. If the User configures the Platform such that an automated output is used for a significant decision about an individual, the User must independently assess the applicability of specific requirements, ensure the required disclosure, human oversight, and right to contest.

Recipients and Third-Party Services

International Data Transfers

NN Agent carries out international transfers only where a legally permissible mechanism exists. The User's consent under a contract with NN Agent, or signing of the DPA, does not substitute for a legal basis for the international transfer of personal data.

Depending on the circumstances, such a mechanism may include, in particular: (a) transfer to a country providing adequate safeguards; (b) contractual safeguards with the required authorisation of the State Audit Office of Georgia; (c) separate written / electronic consent of the relevant data subject following disclosure of the absence of adequate safeguards in the destination country and the potential risks; or another mechanism expressly provided for by law.

Where the required mechanism for a specific transfer has not yet been implemented, the relevant transfer or feature must not be activated until it is. For Customer Data, the cross-border transfer framework is additionally set out in the DPA.

Retention Periods and Deletion

The User may delete individual data within the interface where such functionality is available, or submit a request to [email protected]. Deletion does not apply to data that NN Agent is legally obliged to retain or reasonably retains to protect rights within the period of the relevant purpose.

Rights of Data Subjects

In the cases and to the extent provided for by the Law of Georgia, a data subject has the right to request information about processing, obtain access and a copy of data, require rectification, erasure, or cessation of processing, blocking, data portability, withdraw consent, and make use of safeguards in relation to automated decisions and challenge processing.

Submit your request to [email protected]. NN Agent may request the minimum information necessary to verify identity and prevent disclosure to an unauthorised person.

Where a request relates to Customer Data in respect of which NN Agent acts as the Processor, the request is generally forwarded to the relevant User as Controller, and NN Agent provides assistance under the DPA.

Data Security

The Controller applies technical and organisational measures proportionate to the risk of processing, including, per available technical documentation:

  • encryption of data in transit using secure protocols;
  • storage of passwords as a cryptographic hash (bcrypt), with no storage of passwords in plain text;
  • access control based on the principle of least privilege;
  • maintenance of server logs and activity logs for diagnostics, auditing, and incident investigation;
  • network security measures, software updates, and remediation of known vulnerabilities;
  • backup and recovery procedures;
  • restriction of the number of employees / contractors with access to data, and confidentiality obligations.

The User is responsible for the security of their credentials, API keys, Telegram access credentials, and other secrets under their control.

Security Incidents

NN Agent records and assesses incidents involving personal data. In cases provided for by the Law of Georgia, the Controller notifies the State Audit Office of Georgia no later than 72 hours after discovering the incident, unless a statutory exception applies.

Where an incident may create a high risk to the rights and freedoms of a data subject, the data subject is informed without undue delay in the cases provided for by law.

With respect to Customer Data, NN Agent as the Processor notifies the User as Controller without undue delay and provides reasonably available information to enable the Controller to fulfil its obligations.

Cookies and Marketing Technologies

The website uses technical cookies necessary to maintain the session and ensure correct operation of the interface. A separate Cookie Policy is available at Cookieshttps://nexifyneo.com/policy/cookies/en.

Analytical, advertising cookies, Meta Pixel, and comparable optional technologies must not be activated until the user has been provided with transparent information and, where required for the relevant processing, consent has been obtained.

Google Fonts or another external resource loaded directly from a third-party server may result in the transmission of an IP address and technical data. Self-hosting of fonts and other static assets is recommended to minimise cross-border transfers.

Policy Changes and Contacts

NN Agent may update this Policy when there are changes to functionality, providers, purposes, data categories, or legislation. Material changes are communicated to Users via the website, personal account, or e-mail prior to taking effect, where this is reasonable and required by law.

Controller contact details: Individual Entrepreneur Tatiana Reznikova; Identification Number 345835901; Georgia, Batumi, 4 Giorgi Leonidze St., Building 2, Floor 6, Apartment 75; e-mail [email protected]; website https://nexifyneo.com/.

Supervision of compliance with personal data protection legislation in Georgia from 2 March 2026 is carried out by the State Audit Office of Georgia. A data subject may apply to the supervisory authority and / or a court in the manner provided for by law.