NEXORELAY — LEGAL

Privacy Policy

Last updated · 2026-09-08

This document is maintained in English and Chinese — showing the English version. 本文件以英文与中文为准,此处显示英文版。

NexoRelay ("we") is a multi-tenant email sending platform. This policy explains what data we collect, why, how long we keep it, and your rights. Using our services means you have read and understood it.

1. Who we are

Data controller: NexoRelay. Contact: . We act as controller of tenant account data and as processor of recipient data on tenants' behalf (see the Data Processing Agreement).

2. Data we collect

Account data: name, email, password hash (argon2, one-way), roles and sign-in records.

Content you send: senders, recipients, subjects, bodies, attachments — required to deliver email, never used for any other purpose, never used to train models.

Engagement events: delivery, open, click, bounce and complaint timestamps, plus IP and User-Agent on opens/clicks (aggregated statistics only).

Technical logs: request and audit logs (who did what, when) for security and debugging.

AI assistant conversations: chat content and tool-call records used to provide the service; not used to train third-party models.

3. Purposes and legal bases (GDPR)

Contract: delivering the emails you entrust to us; providing the console and APIs.

Legitimate interests: abuse and spam prevention (bounce/complaint risk controls, suppression lists) and platform security.

Consent: marketing recipients require double opt-in; cookies are strictly-necessary and functional only (see Cookie Policy).

4. Sharing and subprocessors

We never sell your data. We share only as needed to deliver the service: AWS (SES delivery, us-east-1), Railway (hosting), Cloudflare (DNS), OpenRouter (AI assistant), Google (optional OAuth sign-in). Full list and transfer arrangements: see the Data Processing Agreement.

5. Retention

Business data is kept while your account is active; event details auto-expire after 90 days, delivery records after 30 days, idempotency keys after 24 hours; audit logs are kept 2 years. Closed tenants' business data is cascade-deleted within 30 days (audit logs retained as required by law).

6. Your rights

Access, rectification, export, erasure, restriction, and withdrawal of consent. Contact export/deletion is self-service in the console; other requests to — we respond within 30 days.

7. Security

HTTPS everywhere; sensitive fields (TOTP secrets, third-party tokens) encrypted with AES-256-GCM; passwords hashed with argon2id; production secrets live only in infrastructure variables, never in the database; every privileged action leaves an audit trail.

8. Children

Our services target businesses and developers, not children under 16. Contact us to remove any accidentally collected data.

9. Changes

Updates are published here with a new date; material changes are announced in-app or by email. Continued use means acceptance.

Privacy Policy · NexoRelay · NexoRelay