Privacy
Privacy Policy
Updated 2026-08-11
This policy explains what personal data Nextelio SAS collects, why we collect it, how we protect it, and the rights you have over it. It applies to our website at nextelio.io and to our products, including Nextelio WhatsApp Suite, AMP Compiler and Easy AMP4Email.
Who we are
Nextelio SAS is a company registered in France (headquarters: Paris, France). SIRET and VAT identifiers are available on request, or in the footer of an executed order form. For any question about this policy, or to exercise your rights under applicable data protection law, write to privacy@nextelio.io. For security matters, use security@nextelio.io.
The data we collect
When you visit the website
We keep the website purposefully thin. We do not run third-party analytics or advertising trackers. Our host (Vercel) records standard server logs (IP, user agent, request path, response status). These logs are retained for a short operational window and are used only to keep the site reliable and secure.
When you use our products
We collect the minimum needed to deliver the service:
- Account identifiers — name, email address, workspace name, role, and (where applicable) the identity provider you signed in through.
- WhatsApp Business Account credentials — access tokens and account identifiers you (or Meta’s Embedded Signup flow) provide when connecting a WABA. These are encrypted at rest with AES 256 GCM and never displayed to our staff.
- Template content — the WhatsApp templates, AMPscript, SSJS or AMP4Email you compose in our products, together with their approval status and version history.
- Delivery metadata — status transitions from Meta, timestamps, error messages and other operational signals we need to run the service.
- Support correspondence — email or ticket content you send us, retained for as long as needed to resolve the issue and for a reasonable period after.
Message content of end recipients
Where the Suite passes messages to Meta’s WhatsApp Business Cloud API on your behalf, we handle those payloads only for the time strictly needed to deliver them. We do not read, mine, sell or share message content with any third party for advertising or model training.
Why we collect it
We use personal data to:
- Provide, secure and improve our products and consulting services.
- Fulfil our obligations under a contract with you or your employer.
- Communicate about the service, including operational notices, security alerts and material changes to these terms.
- Detect abuse, prevent fraud and comply with legal obligations.
- Produce aggregated, non identifying analytics that help us understand product usage. These are never shared with third parties in a form that could identify a person.
Legal basis (EU/UK)
For visitors and customers in the European Union or United Kingdom, we rely on the following legal bases under Article 6 GDPR:
- Performance of a contract for anything necessary to deliver the product or engagement you signed up for.
- Legitimate interest for reliability, security, fraud prevention, and administering our business, weighed against your rights.
- Consent for anything that requires it, including non essential cookies (there are none at time of writing) and marketing emails you opt in to.
- Legal obligation where we must retain records for tax, accounting, or law enforcement purposes.
How we share it
We share personal data only with the sub-processors listed on our Sub-processors page, and only for the purposes described there. We never sell personal data.
We may disclose data to comply with a valid legal request, to protect our rights or the safety of a person, or as part of a corporate transaction (merger, acquisition, asset sale) provided the successor is bound by terms at least as protective as these.
International transfers
Some of our sub-processors are located outside the European Economic Area (notably in the United States). Where personal data is transferred outside the EEA, we rely on the European Commission’s Standard Contractual Clauses and, where relevant, supplementary measures. Details are in each sub-processor’s public data processing terms.
How long we keep it
- Account data is kept for the life of your account and for up to 90 days after account deletion, so we can restore an account in case of accidental deletion.
- Encrypted WABA tokens are kept only while the connection is active. Disconnecting a WABA removes the token permanently within 24 hours.
- Template content and delivery metadata are kept for as long as the template is approved plus two years, unless you delete them earlier.
- Support correspondence is kept for up to 36 months.
- Server and audit logs are kept for up to 12 months for security, fraud prevention and legal purposes.
- Billing and tax records are kept for the period required by French law (currently ten years).
To request earlier deletion, see our Data Deletion instructions.
Your rights
Under GDPR (and analogous laws), you have the right to:
- Access the personal data we hold about you.
- Correct data that is inaccurate or incomplete.
- Delete data, subject to our legal obligations to retain certain records.
- Restrict or object to certain processing activities.
- Receive your data in a portable format.
- Withdraw consent at any time, without affecting the lawfulness of processing that took place before the withdrawal.
- Lodge a complaint with your local supervisory authority. In France, that is the CNIL.
To exercise these rights, write to privacy@nextelio.io. We reply within one working day and complete verified requests within 30 days.
Cookies and similar technologies
At time of writing, our website uses only strictly necessary cookies to keep the site functioning (for example, a language preference or CSRF token if a form is submitted). We do not use third party advertising or analytics cookies. If this changes, we will publish a cookie policy and, where required, prompt you for consent.
Children
Our products are intended for business use and are not directed at children under 16. If we learn that we have collected data from a child without parental consent, we will delete it promptly.
Security
A summary of the technical and organisational measures we apply is published on our Security overview. For enterprise agreements, we sign a Data Processing Addendum that mirrors these measures.
Changes to this policy
We update this policy from time to time. Material changes are announced in the product and by email to account owners at least 30 days before they take effect. The current version, and the date of last update, are always shown at the top of this page.
Contact
Privacy queries: privacy@nextelio.io.
Security queries: security@nextelio.io.
General: Nextelio SAS, Paris, France.