NexaFlow
API Gateway Enquiry Pricing Portal Admin API Docs Terms

Privacy Policy

Last updated: May 29, 2026

Data We Process

  • Account identifiers, billing email, plan, subscription status, and API key prefix.
  • Usage metadata such as timestamps, provider, model, token counts, credit spend, costs, and request previews.
  • Enquiry product data such as lead name, phone, email, enquiry message, intent, follow-up focus, reply draft, follow-up date, deal value, internal merchant notes, consent timestamp, and consent notice.
  • Operational records such as webhook deliveries, customer notifications, backups, and admin actions.

Why We Process Data

We process data to provide the service, bill customers, handle customer enquiries, notify merchants, prepare follow-up drafts, prevent abuse, monitor reliability, send account notifications, diagnose incidents, and maintain required business records.

Enquiry form submissions are used only for enquiry handling, merchant follow-up, support, security, and record keeping. They are not sold as marketing lists.

PDPA-Style Notice for Enquiry Forms

Before submitting an enquiry, individuals are shown a notice explaining that their contact details and message will be collected, used, and disclosed to the relevant business and NexaFlow service providers for enquiry follow-up, support, security, and record keeping.

The service records the consent status, consent timestamp, and consent notice used at the time of submission.

Merchants should use exported leads and internal notes only for the stated enquiry follow-up purpose and should handle any access, correction, withdrawal, or deletion request in accordance with applicable law.

Subprocessors

The service may use infrastructure, payment, email, model, and backup providers such as Railway, Stripe, Resend, OpenAI, OpenRouter, Cloudflare, and GitHub.

Retention and Security

API keys are stored as hashes where possible and are not shown again after creation or rotation.

Merchant inboxes are protected by business access keys. Public enquiry responses do not expose internal reply drafts, WhatsApp follow-up links, internal notes, lead value, or follow-up dates.

Operational data is retained as needed for billing, support, security, taxes, and product improvement. Backups may retain data until their scheduled retention window expires.

Customer Choices

Customers may request account help, correction, export, or deletion where legally and operationally possible by contacting nexaflowinfra@gmail.com.

NexaFlow AI Gateway
Terms Privacy Data Deletion Refunds Acceptable Use