Nuxa

Privacy Policy

Last Updated: December 10, 2025

This Privacy Policy describes how NUXA, Inc. ("Nuxa", "Company", "we", "us", or "our"), a Delaware corporation located at 2093 Philadelphia Pike 1110, Claymont, DE 19703, USA, collects, uses, discloses, and protects personal data — including data obtained from Google APIs (including Google Workspace APIs) — and your rights and controls regarding that data.

By using or accessing the Service, you confirm that you have read and understood this Privacy Policy, and you consent to the collection, use, and disclosure of your information as described herein.

Definitions

For the purposes of this Privacy Policy:

  • Application or Service means the Nuxa web or mobile application or related services.
  • Account means a unique account created for You to access our Service or parts of our Service.
  • Company refers to NUXA, Inc., a Delaware corporation. For the purpose of the GDPR, the Company is the Data Controller.
  • Personal Data is any information that relates to an identified or identifiable individual.
  • Google Data means any data, content, or metadata obtained via Google APIs.
  • Generalized AI/ML model means an AI or ML model intended to be broadly trained across multiple users.
  • User-facing features means features directly visible or used by the individual user through the app UI.
  • Sensitive Personal Data means Personal Data revealing racial or ethnic origin, political opinions, religious beliefs, health information, etc.
  • Usage Data refers to data collected automatically from the Service.

1. Information We Collect

Personal Data You Provide

When you sign up, link accounts, or use features, you may provide Personal Data such as:

  • Name and email address
  • Phone number and mailing address
  • Profile picture, settings, and preferences
  • Company name, job title, and business information
  • Content you upload (e.g., documents, files) within Nuxa
  • Any data you explicitly input or connect, including via Google integrations

Google Data via API Scopes

If you choose to connect your Google account, we may request specific scopes including:

  • Basic profile (name, email)
  • Drive files and documents
  • Calendar events
  • Contacts
  • Gmail messages (only if explicitly requested for a specific feature)
  • Google Sheets data
  • Other Google Workspace content or metadata as needed per feature

Important: We only request the minimal scopes necessary for the features you enable. We do not request scopes for unimplemented features. You can revoke access to any connected Google account at any time through your account settings.

Usage Data

We may also collect information on how the Service is accessed and used, including IP address, browser type, pages visited, time spent, and device identifiers.

Tracking & Cookies Data

We use the following types of cookies:

  • Essential Cookies: Required for the Service to function properly
  • Functional Cookies: Remember your preferences and settings
  • Analytics Cookies: Help us understand how visitors interact with the Service
  • Marketing Cookies: Track visitors across websites for advertising purposes

2. How We Use Your Information

We use the collected data for various purposes:

  • To provide, operate, and maintain our Service
  • To notify you about changes to our Service
  • To allow you to participate in interactive features
  • To provide customer care and support
  • To provide analysis and improvement of the Service
  • To monitor the usage of the Service
  • To detect, prevent, and address technical issues
  • To manage Your Account and provide you with access to features
  • To contact You regarding updates and administrative messages
  • To enable integrations with Google services
  • To detect and prevent fraud, abuse, or security incidents

Critical AI/ML Commitment: Any Google Data used within Nuxa is used only for features tied to that specific user (user-facing features), and never for generalized AI/ML training or shared model improvement across users.

3. Legal Bases for Processing (GDPR)

If you are located in the EEA, UK, or Switzerland, we rely on the following legal bases:

  • Contract: Processing necessary to perform our contract with you
  • Consent: Where you have given explicit consent
  • Legitimate Interests: Processing necessary for our legitimate business interests
  • Legal Obligation: Processing necessary to comply with applicable laws

4. Transfer of Data

Primary Data Location: Our primary data storage facilities are located in the United States.

International Transfer Safeguards: For transfers from the EEA, UK, or Switzerland, we implement:

  • Standard Contractual Clauses (SCCs)
  • EU-U.S. Data Privacy Framework certification (where applicable)
  • Additional technical and organizational measures

5. Disclosure of Data

Service Providers

Our key service providers include:

  • Cloud Infrastructure: Amazon Web Services (AWS)
  • Payment Processing: Stripe
  • Email Communications: Resend
  • Analytics: PostHog
  • Error Monitoring: Sentry
  • AI Model Providers: OpenAI, Anthropic, Google, and others

Important: We do not sell your Personal Data to third parties. We do not share your Personal Data with third parties for their own marketing purposes without your explicit consent.

Business Transactions

If the Company is involved in a merger, acquisition, or asset sale, Your Personal Data may be transferred. We will provide notice before Your Personal Data is transferred.

Law Enforcement & Legal Requirements

Nuxa may disclose your Personal Data in the good faith belief that such action is necessary to:

  • Comply with a legal obligation
  • Protect and defend the rights or property of Nuxa
  • Prevent or investigate possible wrongdoing
  • Protect the personal safety of users or the public
  • Protect against legal liability

6. Data Retention

  • Account Data: Retained during active account + 30 days after deletion request
  • Google API Data: Retained during feature use + 7 days after revocation
  • Usage Logs: 90 days for analytics; up to 1 year for security
  • Transaction Records: Up to 7 years for legal compliance
  • Communications: 3 years after resolution

7. Security of Data

  • Encryption: Data encrypted in transit (TLS 1.2+) and at rest (AES-256)
  • Access Controls: Role-based access controls and least-privilege principles
  • Authentication: Multi-factor authentication for administrative access
  • Monitoring: Continuous security monitoring, logging, and alerting
  • Secure Development: Security testing and code review practices
  • Vendor Management: Security assessments of third-party providers

8. Analytics

We use PostHog for product analytics. We may aggregate or anonymize non-Google data for internal analytics, product improvement, and performance monitoring. This data cannot be tied back to individual users and is not used for generalized AI/ML training.

9. Behavioral Remarketing

The Company uses remarketing services to advertise on third-party websites. You can opt-out of Google Analytics for Display Advertising at the Google Ads Settings page or the Digital Advertising Alliance opt-out page.

10. Payments

We use Stripe for payment processing. We will not store or collect Your payment card details. That information is provided directly to Stripe whose use of Your personal information is governed by their Privacy Policy.

11. Use of Google / Workspace APIs & Data — Limited Use

Affirmative Statement & Compliance

Nuxa's use of Google Data strictly adheres to the Google API Services User Data Policy, including the Limited Use requirements. We explicitly affirm that:

  • Nuxa does not use Google Data to train generalized AI/ML models.
  • Any processing of Google Data is limited to user-facing features.
  • We do not allow third parties to access Google Data for training purposes.

Human Access Restrictions

No employee may view Google Data unless:

  • The user gave explicit, documented consent to view specific items.
  • It is necessary for security, abuse investigation, or legal process.
  • Data is aggregated and anonymized for internal operations only.

12. Links to Other Sites

Our Service may contain links to other sites that are not operated by us. We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party sites.

13. Children's Privacy

Our Service does not address anyone under the age of 18. We do not knowingly collect personally identifiable information from anyone under the age of 18.

14. Changes to This Privacy Policy

We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page. For material changes, we will let you know via email and/or a prominent notice on our Service.

15. Your Data Protection Rights Under GDPR

If you are a resident of the EEA, UK, or Switzerland, you have the following rights:

  • Right of Access: The right to access, update, or delete your information.
  • Right of Rectification: The right to have inaccurate information rectified.
  • Right to Object: The right to object to our processing of your Personal Data.
  • Right of Restriction: The right to request restriction of processing.
  • Right to Data Portability: The right to receive your data in a structured format.
  • Right to Withdraw Consent: The right to withdraw consent at any time.
  • Right to Lodge a Complaint: The right to lodge a complaint with a supervisory authority.

To exercise any of these rights, please contact us at privacy@nuxa.ai.

16. California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have specific rights:

  • Right to Know: What personal information we collect, use, disclose, and sell.
  • Right to Delete: Request deletion of your personal information.
  • Right to Correct: Request correction of inaccurate information.
  • Right to Opt-Out: Opt-out of the sale or sharing of your personal information.
  • Right to Non-Discrimination: Not be discriminated against for exercising your rights.

Do Not Sell or Share My Personal Information

We do not sell your personal information for monetary consideration. To opt-out of data sharing, contact us at privacy@nuxa.ai.

Global Privacy Control (GPC)

We recognize and honor Global Privacy Control (GPC) signals. When your browser sends a GPC signal, we will treat it as a valid request to opt-out of the sale or sharing of your personal information.

17. Canadian Privacy Rights

If you are a Canadian resident, you have rights under PIPEDA:

  • Right to Access: The right to access your personal information held by us.
  • Right to Challenge: The right to challenge the accuracy of your information.
  • Right to Withdraw Consent: The right to withdraw consent.

18. Do Not Track Signals

We honor Global Privacy Control (GPC) signals. If your browser sends a GPC signal, we will treat it as an opt-out of the sale or sharing of your personal information.

19. Vulnerability Disclosure Policy

Nuxa is dedicated to preserving data security. To report any security flaws, send an email to security@nuxa.ai. We will acknowledge receipt within one business day.

Security research carried out in conformity with this policy is deemed permissible.

20. Data Protection Officer

For questions about our privacy practices, please contact:

  • Email: dpo@nuxa.ai
  • Address: NUXA, Inc., Attn: Data Protection, 2093 Philadelphia Pike 1110, Claymont, DE 19703, USA

21. Contact & Dispute Resolution

If you have questions, requests, or complaints, you may contact us at:

We will respond to your request within 30 days. For complex requests, we may extend this period by an additional 60 days with notice.

If you are not satisfied with our response, you have the right to lodge a complaint with the relevant data protection authority in your jurisdiction.

Nuxa
AI that runs your restaurant. Never calls in sick.
© 2026 Nuxa AI. All rights reserved.

NUXA, Inc.

2093 Philadelphia Pike 1110

Claymont, DE 19703, USA

hello@nuxa.ai

Nuxa