Privacy Policy
Last updated: February 25, 2026
This Privacy Policy describes how Nexap LLC ("Nexap", "we", "us", or "our") collects, uses, shares, and protects personal information when you interact with our AI-powered services. By using our services, you acknowledge that you have read and understood this policy.
1. Who We Are
Nexap LLC is a technology company incorporated in San Francisco, California, United States. We provide an AI-powered agent platform that enables businesses to deploy intelligent conversational agents across messaging channels such as WhatsApp.
In the context of data protection, Nexap acts as a data processor on behalf of its business clients (the data controllers). Each business that uses Nexap's platform is responsible for their own customers' data and determines the purposes for which it is processed. Nexap processes this data strictly in accordance with the instructions of the business client and as described in this policy.
2. Data We Collect
We collect and process the following categories of personal data when you interact with our AI agent services:
Personal Information
- Full name
- Phone number (provided via WhatsApp)
- Document type and identification number
- Email address
Conversation Data
- Chat history and messages exchanged with AI agents
- Interaction metadata (timestamps, session identifiers, message types)
Payment Information
- Transaction records processed through Nexap Pay (pay.nexap.ai)
Nexap does not directly store credit card numbers or sensitive payment credentials. All payment processing is handled by third-party payment gateways with their own security certifications.
3. Why We Collect Your Data
We process your personal data for the following purposes:
- Providing AI agent services on behalf of the business you are interacting with (e.g., appointment scheduling, information inquiries, customer support)
- Processing payments through third-party payment gateways when transactions are initiated via the AI agent
- Improving the quality and accuracy of our AI services
- Maintaining service security and preventing misuse
- Complying with applicable legal obligations
4. Legal Basis for Processing
For Colombian Users
Processing of your personal data is based on your explicit consent (habeas data authorization) in accordance with Colombia's Ley 1581 de 2012 (Ley de Protección de Datos Personales) and its regulatory decrees. When you interact with our WhatsApp agent and accept the data consent prompt, you authorize the collection, storage, and processing of your personal data as described in this policy. You may revoke this authorization at any time.
For California Residents
If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA). We do not sell your personal information. You have the right to know what personal information we collect, the right to request deletion, and the right to non-discrimination for exercising your privacy rights. See Section 7 for details on how to exercise these rights.
For All Users
For all users, we may also process data based on legitimate interest (to provide and improve our services) and contractual necessity (to fulfill the services requested by the business you are interacting with).
5. Data Sharing
We share your personal data only with the following parties and only to the extent necessary to provide our services:
- Business Clients (Data Controllers): The business you are interacting with receives your data to provide their services to you. They are the data controller and determine how your data is used.
- AI/LLM Providers (OpenAI, Anthropic): Conversation data is processed by large language model providers to generate AI responses. These providers do not retain personally identifiable information beyond the duration of the interaction, in accordance with their data processing agreements.
- Payment Processors: When you make a payment through Nexap Pay, transaction data is shared with third-party payment gateways to process your transaction securely.
- Messaging Providers (Twilio): Message content and phone numbers are processed through Twilio to enable WhatsApp message delivery.
We never sell your personal data to third parties.
6. Data Retention
We retain your personal data for as long as necessary to provide the services requested by the business client, and for any additional period required by applicable law or regulation. Conversation data is retained for the duration of the business relationship and may be kept for a reasonable period afterward for audit and compliance purposes.
You may request deletion of your personal data at any time by contacting us at info@nexap.ai. Upon receiving a valid deletion request, we will erase your data within 30 days, unless retention is required by law.
7. Your Rights
Regardless of your location, you have the following rights with respect to your personal data:
- Right to know what personal data we hold about you
- Right to update or correct inaccurate data
- Right to request deletion of your data
- Right to revoke consent at any time
Additional Rights for California Residents (CCPA/CPRA)
California residents have the right to request disclosure of the categories and specific pieces of personal information collected, the right to opt out of the sale of personal information (note: we do not sell personal data), and the right to non-discrimination for exercising privacy rights.
Additional Rights Under Colombian Law (Ley 1581 de 2012)
Colombian users have the right to access their personal data free of charge, to request updates and corrections, to request proof of consent, to file complaints with the Superintendencia de Industria y Comercio (SIC), and to revoke their habeas data authorization when applicable.
8. How to Exercise Your Rights
To exercise any of the rights described above, please contact us at:
We will respond to your request within 15 business days for Colombian users (as required by Ley 1581 de 2012) and within 45 days for California residents (as required by CCPA/CPRA). For all other users, we will respond within 30 days.
9. Security Measures
We implement appropriate technical and organizational measures to protect your personal data, including:
- Encryption of data in transit (TLS/HTTPS) and at rest
- Strict access controls limiting data access to authorized personnel only
- Audit logging to track data access and modifications
- Regular security assessments and monitoring
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will update the "Last updated" date at the top of this page. For significant changes that affect how we process your data, we will notify users through the AI agent or via the business client's communication channels.
12. Contact Us
If you have any questions about this Privacy Policy, wish to exercise your data rights, or have concerns about how your data is being processed, please contact us: