Privacy Policy
Effective 20 September 2026. Last updated 20 September 2026.
1. Who we are
This Privacy Policy explains how Nexus Innovations Group, Inc. collects, uses, shares, and protects personal information.
Nexus Innovations Group, Inc. is a Delaware corporation trading as XPN. Where this policy says "XPN", "we", "our", or "us", it means Nexus Innovations Group, Inc.
Controller:
Nexus Innovations Group, Inc.
800 Jasper Ave, Franklin, TN 37064, United States
Privacy contact: privacy@xpn.ai
We have not appointed a Data Protection Officer. Privacy enquiries reach us at the address above.
2. What this policy covers
This policy applies to:
Visitors to xpn.ai and its subpages
Users of the XPN platform at app.xpn.ai
Prospective customers and business contacts who contact us or request a demonstration
Participants in meetings and calls with XPN
This policy does not apply to third-party websites we link to, or to an advertiser's own handling of data inside its Amazon Marketing Cloud instance.
3. Amazon Marketing Cloud data
This section is central to understanding what XPN does and does not hold.
XPN's platform analyses advertising performance data originating in a customer's own Amazon Marketing Cloud (AMC) instance. Amazon pseudonymises that data before it enters AMC. Queries run inside AMC and return threshold-aggregated outputs only. Amazon enforces minimum distinct-user counts per output row at query time and suppresses rows that fall below them.
As a result, XPN does not receive or hold:
User-level or shopper-level records
Names, email addresses, postal addresses, or other direct identifiers of shoppers
Device identifiers or advertising identifiers
The pseudonymisation key, which remains with Amazon
Any first-party customer data, which an advertiser uploads directly into its own AMC instance under Amazon's controls
XPN has carried out and documented an assessment concluding that the AMC-derived analytics data it holds is not personal data in XPN's hands. That assessment is reviewed annually and re-run if the underlying data flows change materially. The remainder of this policy therefore concerns personal information about website visitors, platform users, business contacts, and meeting participants.
4. Personal information we collect
4.1 Platform users
When a customer provisions a user on app.xpn.ai, we collect the user's email address. Authentication is handled by Auth0, using Google single sign-on, Microsoft Azure single sign-on, or a password. We also record login metadata and the role and entitlements assigned to the user.
4.2 Website visitors
We collect IP address, browser and device information, pages visited, and referring source, through our website host's built-in analytics and standard server logging. These analytics are anonymised and do not use cookies or other persistent identifiers. We do not use Google Analytics, and we do not run advertising or cross-site tracking technologies on our website.
4.3 Business contacts and enquiries
When you submit the contact form on xpn.ai, or correspond with us, we collect your name, business email address, company name, telephone number where you provide it, your company type, your area of interest, your indicated annual Amazon advertising spend, and the content of your message. This information is held in HubSpot and Google Workspace.
4.4 Meeting participants
We use Fireflies to record and transcribe business meetings and calls. This captures names, voice recordings, and transcript text, from which we produce summaries and action items. We tell participants before recording begins, and we do not record where a participant objects. We do not create voiceprints, authenticate or identify speakers by voice, perform emotion recognition or biometric categorisation, or use meeting audio to train AI models. You may object to this processing at any time under section 10.1.
4.5 Billing
We hold billing contact details and invoice records in Intuit QuickBooks. We do not collect or store payment card numbers.
5. Why we process it, and on what legal basis
The legal bases below apply to individuals in the European Economic Area and the United Kingdom. Article references are to the UK and EU General Data Protection Regulation. Each entry gives the purpose, the personal information involved, and the legal basis we rely on.
Providing the XPN platform and authenticating users. Email, login metadata, role. Performance of a contract, Art. 6(1)(b).
Platform security, access logging, abuse and fraud prevention. User ID, IP address, access logs. Legitimate interests, Art. 6(1)(f): securing our service.
Responding to demonstration requests and enquiries. Contact and company details, message content. Steps prior to entering a contract, Art. 6(1)(b), and legitimate interests, Art. 6(1)(f).
Customer relationship management, invoicing, and support. Contact and billing details. Performance of a contract, Art. 6(1)(b), and legal obligation, Art. 6(1)(c).
Recording and transcribing meetings. Name, voice, transcript. Legitimate interests, Art. 6(1)(f): accurate meeting documentation, follow-up, account management, and the establishment or defence of legal claims.
Website analytics and site security. IP address, device and usage data. Legitimate interests, Art. 6(1)(f): understanding how our website is used and keeping it secure.
Marketing communications to business contacts. Business contact details. Consent, Art. 6(1)(a).
Complying with law, and establishing or defending legal claims. Personal information as relevant to the matter. Legal obligation, Art. 6(1)(c), and legitimate interests, Art. 6(1)(f).
We do not use personal information for automated decision-making that produces legal or similarly significant effects. We do not sell personal information. We do not share personal information with advertising networks for cross-context behavioural advertising.
6. Who we share it with
We share personal information with the service providers below, each under a written data processing agreement. We also disclose information where required by law, in connection with legal claims, and to professional advisers bound by confidentiality. If XPN is involved in a merger, acquisition, or sale of assets, information may transfer as part of that transaction.
Auth0 (Okta), authentication and access control. United States.
Google Cloud (BigQuery, Cloud Storage), data storage and processing, platform telemetry. European Union and United States.
Amazon Web Services, pipeline processing and intermediate storage. European Union and United States.
Framer, website hosting and built-in site analytics. United States.
HubSpot, customer relationship management. United States.
Google Workspace, email, documents, collaboration. United States.
Notion, internal documentation. United States.
Intuit QuickBooks, accounting and invoicing. United States.
Fireflies, meeting recording and transcription. United States.
We will keep this list current and will notify customers of material changes in accordance with their agreement with us.
7. International transfers
XPN is established in the United States. Personal information relating to individuals in the European Economic Area or the United Kingdom may be transferred to and processed in the United States and in other countries where our service providers operate.
Where we make such a transfer, we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or another lawful transfer mechanism, as set out in our agreements with each provider. You may request further information using the contact details in section 12.
8. How long we keep it
We keep personal information for the periods below, unless a longer period is required by law or is necessary to establish or defend a legal claim.
Platform user accounts. Account lifetime, plus 30 days after deactivation.
Application and access logs. 90 days.
Business contacts and enquiries. Duration of the relationship, plus 24 months.
Meeting recordings (audio). 6 months.
Meeting transcripts, summaries, and action items. 24 months.
Intermediate pipeline files. 2 weeks, deleted by automated lifecycle policy.
Contracts and legal records. 10 years following termination, as required by law.
On termination of a customer agreement, we provide a 30-day export window, delete customer data from live systems within 30 days after that window closes, and purge residual copies from backups no later than 90 days from the deletion instruction. Written certification of deletion is available on request. Our cloud providers apply their own backup deletion ceilings, which may extend to 180 days.
9. How we protect it
We apply technical and organisational measures appropriate to the risk, including:
Encryption of data in transit
Encryption of data at rest across storage and backups
Single sign-on and role-based access control, enforced per customer dataset
Multi-factor authentication is available for platform accounts
Logical separation of each customer's data in dedicated datasets
We log access to production systems
Least-privilege access for personnel
No system is completely secure. We cannot guarantee that unauthorised access will never occur, and we do not represent that our security measures meet any particular certification standard.
10. Your rights
The rights available to you depend on where you live. Sections 10.1 and 10.2 set out the two main regimes. To exercise any right, contact us using section 12. We may need to verify your identity, and we will respond within the period the applicable law requires.
10.1 European Economic Area and United Kingdom
You have the right to request access to your personal data and information about how we process it; to have inaccurate data corrected; to have data erased; to restrict processing; to receive your data in a portable format; and to object to processing carried out on the basis of our legitimate interests. You may object to direct marketing at any time, without giving a reason.
Where we rely on our legitimate interests, including for meeting recording, you may object at any time and we will stop unless we have compelling grounds that override your interests.
Where we rely on your consent, you may withdraw it at any time. Withdrawal does not affect processing carried out before you withdrew.
You may lodge a complaint with your national supervisory authority. In Italy this is the Garante per la protezione dei dati personali.
10.2 United States
If you live in a US state with a comprehensive privacy law, you may have the right to know what personal information we collect and how we use it; to request a copy; to request correction; to request deletion; and to appeal a refusal. We will not discriminate against you for exercising these rights.
XPN does not sell personal information and does not share it for cross-context behavioural advertising, as those terms are defined under California law.
11. Cookies, children, and changes
11.1 Cookies
Our website uses cookies only where strictly necessary to deliver the site. We do not use analytics cookies, advertising cookies, or other non-essential tracking technologies, so no consent banner is required. If that changes, we will publish a Cookie Policy and deploy a consent mechanism before any non-essential technology goes live.
11.2 Children
XPN is a business service. It is not directed to children, and we do not knowingly collect personal information from anyone under 18. If you believe a child has provided us with personal information, contact us and we will delete it.
11.3 Changes to this policy
We may update this policy. When we do, we will change the date at the top of the page. Where a change is material, we will give notice by email or through the platform before it takes effect.

