Table of Contents
Introduction
This Privacy Policy explains, in plain language, how FirstLight Technologies, Lda. ("NexiAgent", "we") collects, uses, and protects your personal data when you visit our website, create an account, or use our services.
We comply with the European Union's General Data Protection Regulation (GDPR — Regulation (EU) 2016/679) and Portuguese data protection law (Law No. 58/2019).
Our role. With regard to the website, your account, and billing, NexiAgent is the data controller of your data. When our AI assistants process the personal data of *your* end customers on your behalf, NexiAgent acts as a data processor and your company is the controller — that processing is governed by our Data Processing Agreement (see Terms of Service).
What data we collect
Data you provide directly:
- Contact form — name, email, company, phone (optional), and your message.
- Newsletter — your email address only.
- Account — name, email, and password (the password is stored encrypted and we never see it).
- Profile and company — company name, website, phone, address, tax/VAT number, and industry, if you fill them in.
- Support — the content of the messages and support requests you send us.
Data collected automatically (only with your analytics consent):
- A random visitor identifier (not your name).
- The pages you visit and the page you came from (referrer).
- Your approximate location (country and city), estimated from your IP address — we do not store the IP address, only the resulting country/city.
- Your browser and device type.
We do not run any analytics or tracking, nor create the visitor identifier, until you give your consent in the cookie banner.
Service usage data — for customers with active assistants, we store operational metrics and logs (number of interactions, success rate, average duration, cost, and summaries), linked to your account, to show you analytics and for billing.
Payment data — when you subscribe to a paid plan, the payment is processed by Stripe or PayPal. We do not store your card details; we keep only the record of the transaction (amount, currency, status, country, and the processor's reference) and your invoices.
How we use your data
- To respond to your messages and provide the service you request.
- To create and manage your account and give you access to the customer area.
- To activate, operate, and display the analytics for your AI assistants.
- To process payments, issue invoices, and meet our tax and accounting obligations.
- To send you operational emails (confirmations, receipts, subscription notices) and the newsletter, if you subscribed.
- To understand and improve how the website works (only with analytics consent).
- To keep the service secure and prevent fraud and abuse.
- To comply with our legal obligations.
Our legal basis
We only process your data when the law allows it. Depending on the case, our legal basis is:
- Performance of a contract — to create your account, provide the service, and manage your subscription.
- Consent — for website analytics, the newsletter, and marketing. You can withdraw it at any time.
- Legal obligation — to issue invoices and keep tax and accounting records.
- Legitimate interest — to keep the service secure, prevent abuse, and improve the platform, always respecting your rights.
Artificial intelligence and automated decisions
Our AI assistants process messages and tasks on behalf of our business customers. These assistants can make mistakes, and their outputs should be reviewed before they are relied upon for important decisions.
We do not make decisions producing legal effects concerning you, or similarly significant effects, based solely on automated processing within the meaning of Article 22 of the GDPR. When your company uses the assistants to process its own customers' data, it is your company that defines the purposes and limits of that processing.
Who we share it with
We do not sell your personal data. We share it only with trusted providers (processors) who help us operate the service, and only what is strictly necessary. The main ones are:
- OVHcloud — hosting of the application and database in France. Authentication is provided by our own application using Better Auth.
- Stripe and PayPal — payment and subscription processing.
- Amazon Web Services (SES) — transactional email delivery from Sweden (confirmations, receipts, notices).
- Google, Microsoft and Apple — only if you choose to sign in with those accounts.
- NexiChat — the artificial intelligence behind the assistants. It is ours, developed by us, and runs on servers in the European Union.
- Telnyx — telephone network for the call answerer (calls and verification SMS).
- Cloudflare (R2) — storage for the files you upload to the knowledge base.
- InvoiceXpress — issuing of certified invoices.
We may also disclose data if required by law, or as part of a corporate transaction (sale or reorganisation), always maintaining the protection of your data.
Where we store your data and international transfers
Your account and database data are hosted on secure servers within the European Union (França (aplicação e base de dados) e Suécia (envio de email)).
Some of our providers (for example, payment and email processors) may process data outside the EU, notably in the United States. In those cases, we ensure legally recognised safeguards, such as European Commission adequacy decisions or the Standard Contractual Clauses.
How long we keep it
We keep your data only as long as needed for the purpose for which it was collected, and then delete or anonymise it.
- Account and profile — while your account is active; we delete or anonymise it after closure, unless a legal retention obligation applies.
- Contact messages — up to 24 months after the last contact.
- Newsletter — until you unsubscribe.
- Analytics data — anonymised or aggregated within a maximum of 26 months.
- Invoices and accounting records — for the period required by Portuguese tax law.
- Support requests — as long as needed for follow-up and for evidentiary purposes.
Your rights
Under the GDPR, you have the right to:
- Access the data we hold about you.
- Correct data that is wrong or incomplete.
- Ask us to delete your data ("right to be forgotten").
- Restrict or object to how we use it.
- Receive your data in a portable format.
- Withdraw consent at any time, without affecting the lawfulness of prior processing.
To exercise any of these rights, write to [email protected]. We will respond within the legal time limit. You also have the right to lodge a complaint with the Portuguese authority, the Comissão Nacional de Proteção de Dados (CNPD), or with the supervisory authority in your EU country.
How we protect your data
We apply appropriate technical and organisational measures to keep your data secure, including:
- Encryption of data in transit (HTTPS) and at rest.
- Role-based access control (each user sees only their own data; administrative access is restricted).
- Two-factor authentication (2FA) available on your account.
- Database hosting in the European Union and backups.
If a data breach occurs that poses a risk to your rights, we will notify the supervisory authority within 72 hours and, where required, inform you.
Children
Our service is intended for businesses and is not directed at children. We do not knowingly collect data from anyone under the age of 16.
Changes to this policy
We may update this policy from time to time. When we make important changes, we update the date at the top and, where appropriate, let you know.
Contact us
For any privacy question or request, contact us:
FirstLight Technologies, Lda.
Email: [email protected]
Porto, Portugal