Legal
Privacy Policy
Last updated August 02, 2026
Zenno AI Inc operates Nexie, an AI-powered email marketing platform for businesses and agencies. This Privacy Policy explains how we handle Personal Information when we act as a controller and how our role differs when we process recipient data for our customers.
TABLE OF CONTENTS
1. Scope Of This Privacy Policy
3. Our Role For Customer Personal Data
4. Personal Information We Collect
5. Customer Personal Data Processed Through The Services
6. How We Use Personal Information
8. Cookies And Similar Technologies
9. Ai, Model Training, And Product Improvement
10. How We Disclose Personal Information
11. International Data Transfers
14. Your Privacy Rights And Choices
15. United States State Privacy Disclosures
17. Third-Party Sites And Services
1. SCOPE OF THIS PRIVACY POLICY
This Privacy Policy explains how Zenno AI Inc (“Nexie,” “we,” “us,” or “our”) collects, uses, discloses, and protects Personal Information when you visit nexie.ai, create or use a Nexie account, communicate with us, participate in our marketing activities, or otherwise interact with us.
“Personal Information” means information that identifies, relates to, describes, or can reasonably be linked with an individual. It does not include information that has been aggregated or de-identified so that it cannot reasonably identify an individual.
This Privacy Policy applies when Nexie determines the purposes and means of processing Personal Information, sometimes called acting as a “controller” or “business.” It does not govern Customer Personal Data that Nexie processes solely on behalf of a business customer, as explained in Section 3.
Our Services are intended for businesses and agencies, not for personal, family, or household use. This Privacy Policy does not apply to job applicants or employees where a separate notice is provided.
2. WHO WE ARE
Nexie provides AI-powered email marketing, campaign creation, analytics, optimization, and automation technologies for B2C companies and agencies.
108 W. 13th Street, Suite 100
Wilmington, Delaware 19801
United States
Privacy contact: legal@nexie.ai
3. OUR ROLE FOR CUSTOMER PERSONAL DATA
Nexie customers may provide or connect information about their own customers, subscribers, prospects, and website visitors (“Customer Personal Data”). Customer Personal Data may include contact and profile information, order and browsing activity, campaign content, and email engagement information.
For Customer Personal Data, the applicable Nexie customer determines why and how the information is processed. Nexie acts as the customer’s processor or service provider and processes that information only to provide the Services, follow the customer’s documented instructions, secure and support the Services, and meet applicable legal obligations.
The customer’s own privacy policy—not this Privacy Policy—governs the customer’s collection and use of Customer Personal Data. If you received an email from a Nexie customer, interacted with that customer’s website, or want to exercise rights relating to information the customer controls, please contact that customer directly. We will assist our customers with verified requests as required by our agreements and applicable law.
Our processing of Customer Personal Data is governed by our customer agreements and Data Processing Addendum (“DPA”). Customers and agencies are responsible for providing required notices, obtaining lawful consent or another lawful basis, and ensuring that their instructions comply with applicable law.
4. PERSONAL INFORMATION WE COLLECT
Information You Provide Directly
- Account and business contact information, such as your name, business email address, telephone number, job title, company, business address, and account identifiers;
- Account authentication information, such as your username, password hash, multifactor-authentication settings, and security preferences;
- Billing and transaction information, such as billing address, subscription plan, invoice details, tax information, and payment status. Payment-card information may be collected directly by our payment processor rather than stored by Nexie;
- Communications and support information, including messages, support tickets, meeting notes, survey responses, and feedback;
- Marketing and event information, such as newsletter preferences, event registrations, and interactions with our sales and marketing teams; and
- Content you submit to the Services in your capacity as an account user, including prompts, instructions, campaign drafts, and configuration choices.
Information Collected Automatically
- Device and technical information, including IP address, browser type, operating system, device type, language, approximate location derived from IP address, and device or session identifiers;
- Usage information, including pages and features viewed, links clicked, login activity, actions taken within the Services, referral URLs, timestamps, error reports, and performance data;
- Security and audit information, including authentication events, access logs, administrative activity, and signals used to detect fraud, abuse, or compromised accounts; and
- Cookie and similar-technology information as described in Section 8 and our Cookie Policy.
Information From Other Sources
- Information provided by your employer, account administrator, agency, client, or another Authorized User;
- Information from connected ecommerce, email, analytics, and other services that you instruct us to integrate with your Nexie account;
- Business contact information from service providers, referral partners, event organizers, and publicly available professional sources; and
- Information from vendors that help us prevent fraud, secure accounts, analyze use of the Services, or manage business relationships.
5. CUSTOMER PERSONAL DATA PROCESSED THROUGH THE SERVICES
Depending on how a customer configures Nexie, the Services may process the following categories of Customer Personal Data:
- Contact and profile data, such as name, email address, telephone number, location, customer identifiers, subscription status, preferences, tags, segments, and profile attributes;
- Commerce and transaction data, such as orders, products viewed or purchased, cart and checkout events, purchase value, returns, discounts, and customer-lifetime metrics;
- Browsing and behavioral activity, such as website or product-page views, searches, clicks, referral information, session events, and associated technical identifiers;
- Campaign and engagement data, such as email content, campaign membership, sends, deliveries, bounces, opens, clicks, conversions, unsubscribes, complaints, and suppression status; and
- Predictions, segments, recommendations, and other inferences generated from the preceding information for the customer’s email-marketing purposes.
Customers are prohibited from using the Services to store or process payment-card numbers, account passwords, government identification numbers, health or medical information, biometric information, precise geolocation, or other sensitive or special-category Personal Information unless Nexie has expressly authorized the applicable data type in writing.
6. HOW WE USE PERSONAL INFORMATION
Nexie may use Personal Information for the following purposes:
- Provide, operate, maintain, configure, and support the Site and Services;
- Create and administer accounts, authenticate users, manage permissions, and process subscriptions and payments;
- Respond to inquiries, provide customer support, deliver service notices, and manage our business relationship;
- Analyze usage, diagnose errors, monitor performance, develop features, conduct research, and improve the Site and Services;
- Generate AI-assisted outputs and perform customer-authorized campaign actions as part of providing the Services;
- Protect accounts, recipients, infrastructure, and the Services; prevent spam, fraud, abuse, security incidents, and unlawful activity; and enforce our agreements;
- Send business-to-business marketing communications, product updates, invitations, and information that may be relevant to you, subject to your communication choices;
- Comply with law, respond to legal process, establish or defend legal claims, and meet accounting, tax, and regulatory obligations; and
- Complete a financing, merger, acquisition, reorganization, or sale of all or part of our business, subject to appropriate confidentiality and legal safeguards.
7. LEGAL BASES FOR PROCESSING
Where applicable law requires a legal basis, we rely on one or more of the following:
- Contract: processing needed to enter into or perform a contract with you or the business you represent;
- Legitimate interests: operating, securing, supporting, improving, and marketing our business and Services, provided those interests are not overridden by your rights and interests;
- Consent: where we ask for and receive your consent, including for certain cookies or marketing activities. You may withdraw consent at any time; and
- Legal obligation: processing needed to comply with applicable law, legal process, tax, accounting, or regulatory requirements.
For Customer Personal Data, the Nexie customer determines the lawful basis for the processing it instructs Nexie to perform.
8. COOKIES AND SIMILAR TECHNOLOGIES
We use cookies and similar technologies to operate the Site and Services, maintain sessions, remember preferences, protect accounts, understand performance, and analyze how our Site and Services are used.
Where required by law, we obtain consent before using non-essential analytics or functional cookies. You may manage available choices through our cookie-consent tool and browser settings. Disabling some cookies may affect Site or Service functionality.
Nexie does not sell Personal Information and does not share Personal Information for cross-context behavioral advertising. We do not knowingly use information collected through the Site to build advertising profiles for unrelated third-party advertising.
We recognize legally required opt-out preference signals, such as Global Privacy Control, in contexts where they apply. Because we do not sell or share Personal Information for cross-context behavioral advertising, such a signal generally will not change how we process information necessary to provide the Site and Services.
Additional information about the cookies in use, their providers, purposes, and duration should be maintained in our Cookie Policy and consent manager.
9. AI, MODEL TRAINING, AND PRODUCT IMPROVEMENT
Nexie uses artificial intelligence and machine-learning technologies to provide campaign drafting, analysis, segmentation, recommendations, optimization, and automation features. These technologies may be provided in part by contracted AI and infrastructure subprocessors.
We do not use identifiable Customer Personal Data to train generalized AI models for the benefit of other customers, and we do not permit third-party AI subprocessors to use Customer Personal Data to train their own generalized models, unless the applicable customer gives separate, explicit authorization.
We may use aggregated or de-identified information that does not identify a customer, recipient, or other individual to evaluate performance, develop features, improve the Services, and create generalized benchmarks or learnings. We do not attempt to re-identify de-identified information except to test and validate our de-identification processes.
Nexie may generate predictions, segments, and recommendations concerning recipients on behalf of customers. Nexie does not use automated decision-making concerning its own account users that produces legal or similarly significant effects. Customers remain responsible for determining whether their use of profiling or automated decision-making complies with applicable law.
10. HOW WE DISCLOSE PERSONAL INFORMATION
We may disclose Personal Information to the following categories of recipients for the purposes described in this Privacy Policy:
- Service providers and subprocessors that provide cloud hosting, infrastructure, security, analytics, communications, customer support, payment processing, email delivery, professional services, and AI functionality;
- Your organization’s account administrators, Authorized Users, agencies, clients, or other persons authorized to administer or access the applicable account;
- Connected services when you or your organization enables an integration or instructs us to exchange information with that service;
- Professional advisers, auditors, insurers, financing sources, and counterparties subject to appropriate confidentiality obligations;
- Government authorities, regulators, courts, law enforcement, and other parties where disclosure is required or permitted by law or reasonably necessary to protect rights, safety, and security; and
- A buyer, successor, investor, or other participant in a proposed or completed merger, acquisition, financing, reorganization, bankruptcy, or sale of assets.
We do not sell Customer Personal Data or disclose it for another company’s independent advertising purposes. Service providers and subprocessors may process Personal Information only for contracted purposes and subject to applicable confidentiality and data-protection obligations.
11. INTERNATIONAL DATA TRANSFERS
Nexie is based in the United States, and Personal Information may be processed in the United States and other countries where we or our service providers operate. These countries may have data-protection laws that differ from those in your jurisdiction.
Where required, we use recognized safeguards for international transfers, such as the European Commission’s Standard Contractual Clauses, the United Kingdom International Data Transfer Addendum or Agreement, contractual protections, and supplementary technical and organizational measures. Our DPA describes the transfer mechanisms applicable to Customer Personal Data.
We will not claim reliance on a certification-based transfer framework unless Nexie has completed and maintains the applicable certification.
12. DATA RETENTION
We retain Personal Information only for as long as reasonably necessary for the purposes described in this Privacy Policy, including to provide the Services, comply with legal obligations, resolve disputes, maintain security, and enforce agreements. The following summarizes our intended retention approach:
| Category | Typical retention approach |
|---|---|
| Account and business-contact information | For the duration of the business relationship and generally up to three years afterward, unless a longer period is required for legal, security, or dispute purposes. |
| Billing, tax, and transaction records | Generally up to seven years after the relevant transaction or longer where required by law. |
| Support communications and business records | Generally up to three years after resolution or the end of the relationship, with longer retention where needed for legal claims or compliance. |
| Security, access, and audit logs | Generally up to twenty-four months, with longer retention where needed to investigate an incident, prevent abuse, or comply with law. |
| Marketing and prospect information | Until you opt out or the information is no longer reasonably needed, with inactive records reviewed and generally deleted or de-identified within twenty-four months after the last meaningful interaction. |
| Cookie and website analytics information | For the duration disclosed in the Cookie Policy or consent manager, generally no longer than twenty-four months for non-essential technologies. |
| Customer Personal Data | As directed by the customer during the subscription. After termination, Customer Personal Data will be deleted from active systems within ninety days unless the customer retrieves it or law requires retention; residual backup copies may remain temporarily until overwritten in ordinary backup cycles. |
We may retain limited information longer where necessary to maintain suppression lists, detect fraud and abuse, comply with legal obligations, or establish, exercise, or defend legal claims. When retention is no longer necessary, we delete or de-identify the information.
13. DATA SECURITY
We use commercially reasonable administrative, technical, and organizational measures designed to protect Personal Information against unauthorized access, acquisition, loss, misuse, alteration, or disclosure. These measures may include encryption, access controls, authentication controls, monitoring, secure development practices, employee confidentiality obligations, vendor diligence, and incident-response procedures.
No internet transmission, storage system, or security measure is completely secure. You are responsible for using strong credentials, enabling available security features, limiting account permissions, and promptly notifying us of suspected unauthorized access.
14. YOUR PRIVACY RIGHTS AND CHOICES
Depending on your location and subject to legal exceptions, you may have rights to:
- request information about our processing and access a copy of your Personal Information;
- correct inaccurate or incomplete Personal Information;
- request deletion of Personal Information;
- request restriction of or object to certain processing;
- receive certain Personal Information in a portable format;
- withdraw consent where processing is based on consent;
- opt out of marketing communications;
- appeal a denial of a privacy-rights request where applicable; and
- complain to a competent data-protection authority.
To exercise a right concerning Personal Information that Nexie controls, email legal@nexie.ai with the subject “Privacy Request.” We may request information reasonably necessary to verify your identity and authority. Authorized agents may submit requests where permitted by law, subject to verification of their authority.
We will not discriminate against you for exercising an applicable privacy right. Rights are not absolute, and we may deny or limit a request where permitted by law.
For Customer Personal Data processed on behalf of a Nexie customer, contact the applicable customer first. If you submit the request to Nexie, we may direct or transmit the request to that customer.
Marketing Communications
You may unsubscribe from Nexie marketing emails using the unsubscribe link in the message or by contacting us. You may continue to receive transactional, security, legal, and service-related communications that are necessary for the business relationship.
15. UNITED STATES STATE PRIVACY DISCLOSURES
This section applies where United States state privacy laws grant rights concerning Personal Information that Nexie controls. It does not apply to Customer Personal Data that Nexie processes solely as a service provider or processor for a customer.
During the preceding twelve months, we may have collected the categories below. The examples, sources, purposes, disclosures, and retention periods are described elsewhere in this Privacy Policy.
| Statutory category | Examples collected | Categories of recipients |
|---|---|---|
| Identifiers and customer records | Name, business email, telephone number, postal address, IP address, account identifier | Infrastructure, security, support, communications, payment, and professional-service providers |
| Commercial information | Subscription, billing, purchase, and transaction information | Payment processors, accounting providers, and professional advisers |
| Internet or electronic-network activity | Device data, browsing activity, Service usage, access logs, and cookie information | Hosting, security, analytics, and support providers |
| Professional or employment-related information | Employer, job title, industry, and business relationship | CRM, communications, event, and business-development providers |
| Audio, electronic, or visual information | Support-call recordings or meeting recordings where notice is provided | Communications, transcription, and support providers |
| Inferences | Business interests, product preferences, account-health signals, and likely Service needs | Analytics, CRM, and internal business teams |
Nexie does not sell Personal Information and does not share Personal Information for cross-context behavioral advertising. Nexie has no actual knowledge that it sells or shares Personal Information of individuals under 16.
We do not use or disclose Sensitive Personal Information for purposes that create a right to limit under the California Consumer Privacy Act. We do not offer financial incentives in exchange for Personal Information.
Applicable state rights may include access, correction, deletion, portability, opt-out rights, and appeal rights. Requests may be submitted as described in Section 14. Where legally required, we honor recognized opt-out preference signals.
16. CHILDREN
The Site and Services are not directed to children, and account users must be at least 18 years old. We do not knowingly collect Personal Information directly from children under 16 through our Site or account-registration process.
Customers are responsible for determining whether their Customer Personal Data includes information about minors and for complying with all laws governing that information. If you believe a child has provided Personal Information directly to Nexie in violation of this section, contact us so that we can investigate and take appropriate action.
17. THIRD-PARTY SITES AND SERVICES
The Site and Services may link to or integrate with websites, platforms, and services controlled by third parties. Their privacy practices are governed by their own policies, and Nexie is not responsible for their independent processing. Review the privacy terms of a third-party service before enabling an integration or providing information to it.
18. CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy to reflect changes in our practices, technologies, legal requirements, or Services. We will update the “Last updated” date and provide additional notice of material changes where required by law, such as through the Site, the Services, or email.
19. CONTACT US
For questions, complaints, or requests concerning this Privacy Policy or Nexie’s privacy practices, contact:
Attention: Privacy
108 W. 13th Street, Suite 100
Wilmington, Delaware 19801
United States
legal@nexie.ai
