Privacy Policy
Last updated: June 25, 2026
1. Introduction
NEXOS, operated by Titan Innovations LLC ("NEXOS," "we," "our," or "us"), is a business-to-business software-as-a-service platform that serves as a back-office operating system for multi-location businesses. The Service includes invoice and receipt capture with AI-assisted data extraction; expense, spend, and vendor-cost management; profit-and-loss and financial reporting; inventory and recipe-cost tracking; employee scheduling, time tracking, and labor management; AI-powered analytics, cost categorization, and an in-product and website assistant; and optional integrations with third-party accounting, banking, and point-of-sale systems. This Privacy Policy explains how we collect, use, disclose, store, and safeguard your information when you use our website, mobile applications, application programming interfaces (APIs), and related services (collectively, the "Service").
This Privacy Policy is designed to comply with applicable privacy and data protection laws, including but not limited to the New York SHIELD Act (Stop Hacks and Improve Electronic Data Security Act), the New York General Business Law Section 899-bb, the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"), the General Data Protection Regulation ("GDPR"), the Children's Online Privacy Protection Act ("COPPA"), the CAN-SPAM Act, the Electronic Communications Privacy Act ("ECPA"), and Section 5 of the Federal Trade Commission Act.
Please read this Privacy Policy carefully. By accessing or using our Service, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree with the terms of this Privacy Policy, please do not access the Service.
2. Information We Collect
We collect information from multiple sources and through various mechanisms as described below.
2.1 Personal Information You Provide
We collect personal information that you voluntarily provide to us when you register for an account, subscribe to our Service, contact us for support, or otherwise interact with us. This information may include:
- Full name
- Email address
- Phone number
- Company name and business address
- Job title and role within your organization
- Billing information (billing address, company tax ID)
- Account credentials (email and encrypted password)
- The content of messages and conversations you exchange with our in-product and website assistant ("Ava") or chat widget, including any name, email, phone number, or company details you provide when requesting a demo, contacting sales, or seeking support
- Any other information you choose to provide to us (e.g., support ticket content, feedback)
2.2 Invoice, Receipt & Business Data
When you use our Service, we collect and process the following business document data:
- Uploaded Documents: Invoice and receipt images (JPEG, PNG, HEIC) and PDF files that you upload or capture through our mobile application
- Extracted Data: Vendor names, invoice amounts, line item details, dates, due dates, invoice numbers, tax categories, and payment terms extracted from your documents through our automated processing pipeline
- Vendor Information: Vendor names, addresses, and contact information derived from your uploaded documents
- Spending Analytics: Aggregated spending data, category breakdowns, trend analyses, and reports generated from your document data
- Expense Records: Manually entered expense descriptions, amounts, categories, dates, and associated location or project assignments
- Mileage & GPS Data: Trip start/end locations, GPS coordinates (when GPS tracking is enabled), distances, trip purposes, and IRS mileage rate deductions. When live mileage tracking is active, GPS data is collected in the background using the iOS location indicator (blue status bar) and an Android foreground service notification. Background GPS collection occurs only while a trip is in progress and stops automatically when the trip ends.
- Reimbursement Requests: Reimbursement amounts, descriptions, approval status, and associated receipt or mileage records submitted through the reimbursement workflow
- Multi-Currency Data: Detected currency codes from scanned documents and real-time exchange rates obtained from third-party foreign exchange rate providers for currency conversion purposes
- Imported Data: Historical business records uploaded via CSV/Excel import, bulk document upload, REST API ingestion, or email-based document forwarding
- Profit & Loss Data: Revenue and expense aggregations, category-level financial summaries, and trend analyses derived from your invoice, receipt, and expense data
- Project Data: Project names, descriptions, start and end dates, budgets, assigned team members, and linked invoices or expenses used for project-based cost tracking
- Subcontractor Data: Subcontractor names, trade specialties, contact information, quoted amounts, payment records, and project assignments
- Role Hierarchy Data: User roles within your organization (e.g., Account Owner, CEO, Executive, Accounting, Location Manager), invitation relationships, role change history, and permission configurations
- Workforce & Scheduling Data: Employee and team-member profiles (names, contact information, assigned roles and locations), stated availability, published shift schedules, shift swap and drop requests, and per-location labor-budget data used by our scheduling features
- Time & Attendance Data: Clock-in and clock-out timestamps, recorded work hours, and timesheets. Where the geofenced time clock is enabled by your organization, we collect the device's geographic location at the moment of a clock event for the limited purpose of verifying on-site attendance and flagging out-of-area punches
- Point-of-Sale (POS) Data: If you connect a POS system, we receive sales and order data, item-level sales, and labor data, which we use to power analytics, schedule recommendations, prime-cost reporting, and reconciliation
2.3 Integration Data
If you choose to connect third-party accounting software, we collect:
- QuickBooks / Xero OAuth Tokens: Encrypted access and refresh tokens to maintain your authorized connection. We never access your accounting software credentials directly.
- Chart of Accounts: Account categories and codes from your connected accounting software to enable accurate categorization
- Vendor Lists: Vendor records from your connected accounting software for matching and reconciliation
- Sync Data: Invoice and receipt data that you choose to sync to your accounting software, along with sync history and status logs
- Plaid Bank Connection: If you connect a bank account via Plaid, we receive a secure access token, account names, masked account numbers (last 4 digits), balances, and transaction history. We never see your bank login credentials — authentication is handled entirely by Plaid.
- Point-of-Sale (POS) Connections: If you connect a POS system (e.g., Square, Clover, Revel, Toast), we store encrypted OAuth access and refresh tokens to maintain the authorized connection and to retrieve sales, order, and labor data at your direction. We never receive your POS login credentials.
2.4 Device & Usage Information
When you access our Service, we automatically collect:
- Device type, manufacturer, and model
- Operating system and version
- Browser type and version (for web application)
- IP address and approximate geographic location derived from your IP address
- Usage patterns, including pages and screens visited, features used, actions taken, and session duration
- Server-side error logs and request traces written to Amazon CloudWatch from our API for debugging, support, and security review
- Real-user monitoring data on our web application, collected through Amazon CloudWatch RUM — including page-load timing, Core Web Vitals, browser and device type, approximate geographic region (derived from IP address), and page navigation and interaction events — used to diagnose performance issues and errors
- Error and crash reports from our web, API, and mobile (iOS and Android) applications, collected through Sentry, with personal information minimized to a non-personal user identifier and corporation tag (email addresses and names are not transmitted to Sentry)
- On our web application, Sentry Session Replay may capture a privacy-masked reconstruction of a browser session (page structure and navigation) to help us diagnose errors. All text and media are masked by default; we do not capture keystrokes or the contents of form fields
- Network request logs and response times
2.5 Cookies & Tracking Technologies
We use cookies and similar tracking technologies on our website and web application:
- Session Cookies: Essential cookies required for authentication, session management, and security. These are strictly necessary for the Service to function.
- Google Analytics: Used on our marketing website to understand visitor behavior, traffic sources, and page performance. Google Analytics may set its own cookies. You can opt out using Google's opt-out browser add-on.
- LinkedIn Insight Tag: Used on our marketing website only to measure the effectiveness of LinkedIn advertising campaigns and to understand professional demographics of visitors. This tag does not appear within the authenticated application. You can opt out through LinkedIn's opt-out settings.
Most web browsers are set to accept cookies by default. You can usually modify your browser settings to decline cookies. If you disable essential cookies, certain parts of the Service may not function properly.
2.6 Push Notification Data
If you enable push notifications on our mobile application:
- We collect your Expo push notification token, which is a unique identifier for your device
- Push tokens are stored server-side and linked to your user account
- Push tokens are used exclusively for delivering notifications you have opted into (e.g., processing completion alerts, sync status updates)
- You can disable push notifications at any time through your device settings or within the application
2.7 Sales Representative & Partner Data
If you participate in our sales representative or partner programs, we additionally collect:
- Sales Representative Data: Name, email, phone number, assigned territory, Stripe Connect account details for commission payouts, commission records, pipeline and prospect data, referral codes, and client attribution data. Banking and payout account details are collected directly by Stripe via Stripe Connect — NEXOS never receives, processes, or stores sales representative banking credentials or account numbers.
- Partner Data: Partner organization information, custom branding assets (logos, colors), custom domain records, client management data, and commission and billing records
3. How We Use Your Information
We use the information we collect for the following purposes:
- Service Delivery: To provide, operate, maintain, and improve our invoice and receipt scanning platform, including automated data extraction, analytics, and reporting
- Document Processing: To process uploaded invoices and receipts using our automated extraction pipeline, including image preprocessing, data extraction, and confidence scoring
- AI-Powered Analysis & Assistance: To analyze your business data — including invoices, receipts, expenses, sales, vendor records, recipes, inventory, and operational data — using artificial intelligence in order to generate cost categorizations, vendor and spend insights, draft staff schedules, summaries, and recommendations, and to power our in-product and website assistant ("Ava"). This processing is performed by vetted AI sub-processors bound by contractual confidentiality and data-protection obligations. Your data is not used to train third-party AI models.
- Accounting Integration: To sync your extracted data with connected accounting software at your direction
- Email Ingestion: To process emails forwarded to your designated location email address via AWS SES, extract attachments for scanning, and discard email content after attachment extraction
- Payment Processing: To process subscription payments, manage billing, and facilitate sales representative commission payouts through Stripe
- Communications: To send transactional emails (receipts, notifications, alerts, processing confirmations) and, with your consent, marketing communications
- Customer Support: To respond to your inquiries, troubleshoot issues, and provide technical assistance
- Application Monitoring: To monitor application performance, detect crashes and errors, and improve reliability through Amazon CloudWatch (server-side logs and web real-user monitoring) and Sentry (error and crash reporting across our web, API, and mobile applications)
- Analytics & Improvement: To analyze usage patterns, understand feature adoption, and improve the user experience
- Security & Fraud Prevention: To detect, prevent, and address fraud, unauthorized access, and other security issues
- Legal Compliance: To comply with applicable laws, regulations, legal processes, and governmental requests
- Partner & Sales Programs: To manage partner relationships, track commissions, process referrals, and administer the sales representative program
4. Document Processing
Transparency about how we process your documents is important to us. This section describes our processing pipeline in detail.
Processing Architecture
When you upload an invoice or receipt, the document goes through the following pipeline:
- Image Preprocessing: Documents undergo automated preprocessing, including auto-rotation correction, histogram normalization, and image sharpening to optimize extraction accuracy
- Two-Pass Extraction: Documents are processed using NexosIQ's two-pass extraction architecture. The first pass extracts primary document fields, and the second pass validates and refines the results
- Confidence Scoring: Each extracted field receives a per-field confidence score, allowing you to identify and review data points that may require manual verification
Third-Party Processing Infrastructure
NexosIQ utilizes third-party infrastructure to perform document data extraction. Documents are transmitted to a third-party API for processing over modern encrypted connections. Per our infrastructure provider's data policy, documents are not retained after processing.
- Documents are transmitted over modern encrypted connections
- Documents are not retained by the provider after processing
- Your document data is not used to train or improve any models
- Data is processed solely to provide the extraction results back to NEXOS
5. Biometric Authentication Disclosure
Our mobile application supports biometric authentication (Face ID and Touch ID) as a convenience feature for logging into your account. This section provides a clear disclosure of how biometric data is handled.
- No Biometric Data Collection: NEXOS does not collect, store, transmit, or have access to your actual biometric data (fingerprints, facial geometry, or biometric templates)
- On-Device Processing Only: All biometric verification occurs entirely on your device through native iOS (Face ID / Touch ID) or Android biometric APIs. Biometric templates never leave your device's secure hardware
- Credential Storage: When you enable biometric login, we store your encrypted login credentials in your device's secure enclave -- the iOS Keychain (protected by Secure Enclave) or Android Keystore (protected by hardware-backed security). These credentials are released to our authentication system only after your device's biometric verification succeeds
- No Server-Side Biometrics: No biometric data, biometric templates, or biometric identifiers are ever transmitted to our servers, stored in our databases, or shared with any third party
- Opt-In Only: Biometric login is entirely optional. You can enable or disable it at any time in your application settings without affecting your ability to use the Service
6. Data Storage and Security
We take the security of your information seriously and implement reasonable safeguards in compliance with the New York SHIELD Act and New York General Business Law Section 899-bb.
Infrastructure
Your data is stored on secure cloud infrastructure provided by Amazon Web Services (AWS) in the United States. This includes:
- Database: managed database services with encryption at rest and automated backups with point-in-time recovery
- File Storage: managed object storage for documents with server-side encryption
- Content Delivery: managed edge content delivery network with strict transport security
- Email Processing: managed transactional email service for delivery and ingestion
Administrative Safeguards
- Designated personnel responsible for security program coordination
- Risk assessments of existing data handling practices
- Employee training on data security practices and incident response
- Selection of service providers capable of maintaining appropriate safeguards, with contractual requirements to maintain those safeguards
- Regular review and adjustment of the security program based on business changes, monitoring results, and evolving threats
Technical Safeguards
- Encryption of data in transit using current industry-standard transport security
- Encryption of data at rest using current industry-standard algorithms
- OAuth tokens encrypted at rest before storage
- Regular security assessments and vulnerability scanning
- Monitoring, detection, and logging of system access and security events
- Role-based access controls with least-privilege principles
- Optional two-factor authentication for user accounts via any standard authenticator app
- Password hashing using a modern memory-hard algorithm; minimum 12-character passwords with complexity requirements
- Session inactivity timeout (30 minutes) and secure session management
- PII masking in application logs — email addresses and sensitive data are redacted before logging
- Immutable audit log backups stored in encrypted object storage
- Secure credential storage using platform-native secure enclaves (iOS Keychain, Android Keystore)
Physical Safeguards
- Data hosted in cloud-provider data centers, which maintain industry-recognized security certifications
- Physical access to data centers is strictly controlled by the cloud provider
- Secure disposal and destruction of data when no longer needed
Mobile Application Local Data
- Our mobile application caches data locally using SQLite and AsyncStorage for offline functionality
- Cached data has a 24-hour freshness window and is automatically refreshed
- Notification preferences are stored locally on your device
- Document uploads that cannot be completed immediately are queued on-device and synced when connectivity is restored
- Local data is deleted when you log out of the application
Banking Data (Plaid)
Bank account connections are facilitated through Plaid, a SOC 2 Type II certified financial data platform. NEXOS receives read-only access to transaction data only for the purpose of receipt matching and reconciliation. We never receive, store, or have access to your banking credentials, account numbers, or login information. All credential handling occurs directly between you and your financial institution via Plaid's secure interface.
While we implement safeguards designed to protect your information, no electronic transmission or storage method is 100% secure. We cannot guarantee absolute security but are committed to maintaining and continuously improving our security practices.
7. Third-Party Services
We share data with the following third-party service providers to operate and deliver the Service. Each provider receives only the data necessary to fulfill its function. A complete, dated list of sub-processors is maintained at /sub-processors and is the authoritative version for GDPR Article 28 disclosures.
Stripe
Purpose: Payment processing, subscription management, and sales representative commission payouts via Stripe Connect
Data Shared: Billing information, subscription metadata, Stripe Customer ID. For sales representatives: Stripe Connect account details and commission payout data. We never see or store full credit card numbers -- payment card information is transmitted directly to Stripe.
Amazon Web Services (AWS)
Purpose: Cloud hosting, managed database services, file storage, content delivery, transactional email processing, and application monitoring (CloudWatch logs and CloudWatch RUM real-user monitoring of our web application)
Data Shared: All Service data is hosted on AWS infrastructure. AWS processes inbound and outbound email, including emails forwarded to location addresses for attachment extraction. CloudWatch RUM additionally collects web performance and page-navigation telemetry (page-load timing, Core Web Vitals, browser/device type, approximate region, and interaction events).
AI Inference & Embedding Providers
Purpose: Infrastructure for NexosIQ document extraction, AI-powered analysis and categorization of business data, semantic search, and the NEXOS assistant ("Ava")
Data Shared: Document images and the business text content you submit for the relevant feature (e.g., invoice line items, vendor names, the content of your assistant messages). AI providers do not receive billing data, banking credentials, password material, or biometric data. Submitted data is processed solely to return results to NEXOS, is not retained by the providers to train their models, and is governed by Data Processing Agreements. Specific providers are disclosed through our sub-processor list and disclosure process.
Intuit QuickBooks
Purpose: Accounting software integration (optional, user-initiated)
Data Shared: Invoice and receipt data synced to QuickBooks at your direction. We receive chart of accounts and vendor lists via OAuth-authorized API access.
Xero
Purpose: Accounting software integration (optional, user-initiated)
Data Shared: Invoice and receipt data synced to Xero at your direction. We receive chart of accounts and vendor lists via OAuth-authorized API access.
Sentry
Purpose: Error and crash reporting across our web application, API, and iOS/Android mobile applications, plus privacy-masked Session Replay on the web application to aid error diagnosis. AWS CloudWatch is used in parallel for server-side request and access logs.
Data Shared: Error and crash stack traces, device and browser information (model, OS/browser version), and a minimal user context (non-personal user identifier and corporation ID). On the web, Session Replay captures a fully masked reconstruction of the page — no text, media, keystrokes, or form-field contents are recorded. Email addresses and names are not sent to Sentry.
Plaid
Purpose: Bank account linking and transaction data retrieval (optional, user-initiated)
Data Shared: We receive account names, masked account numbers (last 4 digits), balances, and transaction history via Plaid's API. Your bank login credentials are handled entirely by Plaid — we never see or store them.
Purpose: Google Places API for address autocomplete; Google Analytics for marketing website analytics
Data Shared: Address search queries (Places API); website usage data, IP address, browser information (Google Analytics, marketing site only).
Purpose: LinkedIn Insight Tag for marketing site analytics and advertising measurement only
Data Shared: Page visit data, IP address, and browser information on the marketing website only. The Insight Tag is not present within the authenticated application.
Expo
Purpose: Push notification delivery service for our mobile application
Data Shared: Expo push notification tokens and notification content/payloads.
8. Data Sharing and Disclosure
We Do Not Sell Your Data
We do not sell, rent, or trade your personal information to third parties for their marketing purposes. We do not "share" your personal information for cross-context behavioral advertising as defined under the CCPA/CPRA.
When We May Disclose Your Information
We may disclose your information in the following limited circumstances:
- Service Providers: To the third-party service providers listed in Section 7, solely to provide and improve the Service
- With Your Consent: When you explicitly direct us to share data, such as syncing data to connected accounting software
- Business Transfers: In connection with a merger, acquisition, reorganization, sale of assets, or bankruptcy, in which case your information may be transferred as part of the transaction. We will notify you of any such change in ownership or control of your personal information
- Legal Requirements: When required by law, regulation, legal process, or governmental request, including to meet national security or law enforcement requirements
- Protection of Rights: When we believe in good faith that disclosure is necessary to protect our rights, your safety or the safety of others, investigate fraud, or respond to a government request
- Aggregated or De-Identified Data: We may share aggregated or de-identified data that cannot reasonably be used to identify you
9. Data Retention
Active Accounts
- Invoice & Receipt Data: Retained for the life of your active account on all plans. Your document data remains accessible as long as your subscription is active.
- Account Information: Retained for the duration of your active account
- Usage & Monitoring Data: Server-side and web error logs written to Amazon CloudWatch are retained for 14 days. CloudWatch RUM real-user monitoring data, and error and crash reports submitted to Sentry across web, API, and mobile, are retained per each provider's standard retention period. All personal information is masked before logging.
- Assistant Conversation Logs: Messages exchanged with our assistant or chat widget are retained for up to 90 days to provide responses, follow up on inquiries, and improve the assistant, after which they are deleted or de-identified.
- Integration Tokens: Retained while the integration connection is active. Deleted upon disconnection.
- Email Ingestion Data: Email content is discarded immediately after attachments are extracted. Extracted attachments follow standard document retention.
After Account Termination
- Your data will be retained for up to 30 days to allow for account reactivation
- After 30 days, your data will be permanently deleted from our active systems
- Backup copies may be retained for up to 12 months for disaster recovery purposes, after which they are permanently deleted
- We may retain certain information as required by law or for legitimate business purposes (e.g., fraud prevention, dispute resolution)
Consent Records
We retain records of your consent to our Terms of Service and Privacy Policy for a minimum of 2 years as required for legal compliance. These records include the date and time of consent, the version of documents you agreed to, and your IP address at the time of consent.
Sales Representative & Partner Data
Commission records and payout history are retained for a minimum of 7 years for tax and regulatory compliance purposes, even after a sales representative or partner relationship ends.
You may request deletion of your data at any time by contacting us at privacy@nexosscan.com. Deletion requests are subject to the retention requirements described above and applicable legal obligations.
10. Your Rights and Choices
Regardless of your location, we provide all users with the following rights:
Access and Portability
You have the right to access the personal information we hold about you and to receive a copy of your data in a structured, commonly used, and machine-readable format.
Correction
You may update or correct your personal information at any time through your account settings or by contacting us.
Deletion
You may request deletion of your personal information, subject to certain exceptions required by law (such as information we are required to retain for tax, legal, or fraud prevention purposes).
Marketing Communications
You may opt out of marketing emails at any time by clicking the "unsubscribe" link in any marketing email or by contacting us. Opting out of marketing emails does not affect transactional communications related to your account.
Push Notifications
You may disable push notifications at any time through your device's notification settings or within the application settings.
Integration Disconnection
You may disconnect any connected accounting software at any time from your NEXOS settings. Upon disconnection, we revoke our access and delete stored OAuth tokens.
Cookies
You can manage your cookie preferences through your browser settings. Note that disabling essential cookies may affect the functionality of the Service.
To exercise any of these rights, please contact us at privacy@nexosscan.com. We will respond to your request within 30 days. We may ask you to verify your identity before processing your request.
11. New York Residents
If you are a New York resident, you are entitled to the following disclosures and protections under the New York SHIELD Act (General Business Law Section 899-aa) and New York General Business Law Section 899-bb.
Private Information We Hold
Under the SHIELD Act, "private information" includes your name in combination with any of the following: Social Security number, driver's license or non-driver identification card number, financial account number (with or without security code, access code, or password), biometric information, or your username or email address in combination with a password or security question and answer that permits access to an online account. Of these categories, NEXOS may hold your name, email address, and password (stored in encrypted/hashed form), as well as financial account information associated with your billing profile (processed by Stripe -- we do not store full payment card numbers).
Security Practices
In compliance with the SHIELD Act's requirement for "reasonable safeguards," we maintain a comprehensive data security program that includes administrative, technical, and physical safeguards as described in Section 6 of this Privacy Policy. Our security program is designed to:
- Identify reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of private information
- Assess the sufficiency of safeguards in place to control those risks
- Train and manage employees in security practices and procedures
- Select service providers capable of maintaining appropriate safeguards and require those safeguards by contract
- Adjust the security program in light of business changes or new circumstances
Breach Notification
In the event of a breach of the security of the system involving private information of New York residents, we will comply with the notification requirements of the SHIELD Act, including notification to affected individuals, the New York State Attorney General, the New York Department of State Division of Consumer Protection, and the New York State Division of State Police, in the most expedient time possible and without unreasonable delay, consistent with the legitimate needs of law enforcement and any measures necessary to determine the scope of the breach and restore the integrity of the data system. See Section 16 (Data Breach Notification) for further details.
12. California Residents (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA") provides you with specific rights regarding your personal information.
Categories of Personal Information Collected
In the preceding 12 months, we have collected the following categories of personal information as defined by the CCPA:
- Identifiers: Name, email address, phone number, IP address, account ID, Expo push notification tokens
- Customer Records: Name, company name, address, phone number, billing information
- Commercial Information: Invoice data, receipt data, vendor information, purchase history, spending analytics, subscription records
- Internet/Network Activity: Browsing history, search history, interaction with our website and application, session data
- Geolocation Data: Approximate location derived from IP address; and, where you enable the corresponding features, precise device location for mileage tracking and for geofenced time-clock attendance verification
- Professional/Employment Information: Job title, role, company name, work schedules, time-clock records, and labor data
- Inferences: Spending patterns, usage preferences, feature adoption derived from the above categories
Business Purposes for Collection
We collect personal information for the business purposes described in Section 3, including providing the Service, processing documents, managing accounts, processing payments, providing customer support, maintaining security, and complying with legal obligations.
Your California Rights
- Right to Know: You may request information about the categories and specific pieces of personal information we have collected, the categories of sources, the business purposes for collection, and the categories of third parties with whom we share your information
- Right to Delete: You may request deletion of your personal information, subject to certain exceptions (such as completing a transaction, detecting security incidents, complying with legal obligations, or other permitted uses)
- Right to Correct: You may request correction of inaccurate personal information
- Right to Opt-Out of Sale/Sharing: We do not sell or share your personal information for cross-context behavioral advertising. As such, there is no need to opt out, but you may still submit a request.
- Right to Limit Use of Sensitive Personal Information: We only use sensitive personal information (such as login credentials) for purposes authorized by the CCPA/CPRA, including performing our services and maintaining security
- Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA/CPRA rights. You will not receive different pricing or quality of service for exercising your rights.
Exercising Your Rights
To exercise your CCPA/CPRA rights, contact us at privacy@nexosscan.com or legal@nexosscan.com. We will verify your identity before processing your request and respond within 45 days. You may also designate an authorized agent to make a request on your behalf.
Data Retention Disclosures
The retention periods for each category of personal information are described in Section 9 of this Privacy Policy. We retain personal information only for as long as necessary to fulfill the purposes described in this policy, unless a longer retention period is required by law.
13. European Users (GDPR)
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, the General Data Protection Regulation (GDPR) and applicable local data protection laws provide you with additional rights and protections.
Lawful Basis for Processing
We process your personal data under the following legal bases:
- Contractual Necessity (Article 6(1)(b)): Processing necessary to perform our contract with you, including providing the Service, processing your documents, and managing your account
- Consent (Article 6(1)(a)): Where you have given explicit consent, such as for marketing communications, optional analytics cookies, or connecting third-party integrations
- Legitimate Interests (Article 6(1)(f)): Processing necessary for our legitimate interests, including improving our Service, ensuring security, preventing fraud, and conducting business analytics, provided these interests are not overridden by your rights and freedoms
- Legal Obligation (Article 6(1)(c)): Processing necessary to comply with applicable laws, such as tax regulations and financial reporting requirements
Your GDPR Rights
- Right of Access (Article 15): You may request a copy of the personal data we hold about you
- Right to Rectification (Article 16): You may request correction of inaccurate or incomplete personal data
- Right to Erasure (Article 17): You may request deletion of your personal data, subject to certain exceptions
- Right to Restriction of Processing (Article 18): You may request that we restrict processing of your personal data in certain circumstances
- Right to Data Portability (Article 20): You may receive your personal data in a structured, commonly used, and machine-readable format. Use the data export feature in your account settings (GET /api/auth/me/export) to download all your data as JSON.
- Right to Object (Article 21): You may object to processing based on legitimate interests or for direct marketing purposes
- Right to Withdraw Consent: Where processing is based on consent, you may withdraw your consent at any time without affecting the lawfulness of processing carried out before withdrawal
- Right to Lodge a Complaint: You have the right to lodge a complaint with your local data protection supervisory authority
Data Protection Contact
For GDPR-related inquiries, please contact us at privacy@nexosscan.com. We will respond to your request within 30 days.
Cross-Border Transfers
Your personal data is transferred to and processed in the United States. For transfers of personal data from the EEA, UK, or Switzerland, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission as our data transfer mechanism, supplemented by additional safeguards where appropriate. You may request a copy of the applicable SCCs by contacting us.
14. Children's Privacy
Our Service is a business-to-business platform designed for use by businesses and professionals. The Service is not directed to and is not intended for individuals under the age of 18. Use of the Service requires users to be at least 18 years of age.
In compliance with the Children's Online Privacy Protection Act ("COPPA"), we do not knowingly collect, use, or disclose personal information from children under the age of 13. If we become aware that we have inadvertently collected personal information from a child under 13, we will take prompt steps to delete that information from our systems.
If you are a parent or guardian and believe that your child under 13 has provided us with personal information, please contact us immediately at privacy@nexosscan.com so that we can take appropriate action.
15. International Data Transfers
NEXOS is based in the United States, and your information is processed and stored on servers located in the United States. If you access our Service from outside the United States, your information will be transferred to, stored in, and processed in the United States, where data protection laws may differ from those of your country of residence.
We take appropriate safeguards to ensure your personal information remains protected in accordance with this Privacy Policy when transferred internationally, including:
- Standard Contractual Clauses (SCCs): For transfers from the EEA, UK, and Switzerland, we utilize European Commission-approved Standard Contractual Clauses
- Contractual Protections: We ensure that our third-party service providers maintain adequate data protection standards through contractual obligations
- Technical Safeguards: All data in transit is encrypted using current industry-standard transport security regardless of the country of origin
By using the Service, you understand and consent to the transfer, storage, and processing of your information in the United States and other countries where our service providers operate.
16. Data Breach Notification
In the event of a data breach affecting your personal information, we will take the following steps in compliance with the New York SHIELD Act and other applicable breach notification laws:
Notification to Affected Individuals
We will notify affected individuals in the most expedient time possible and without unreasonable delay, consistent with the legitimate needs of law enforcement and any measures necessary to determine the scope of the breach and restore the integrity of our data systems. Notification may be provided via email, conspicuous posting on our website, or other methods as required by applicable law.
Notification to Regulators
Where required by law, we will notify the appropriate regulatory authorities, including:
- New York: The New York State Attorney General, the New York Department of State Division of Consumer Protection, and the New York State Division of State Police (per the SHIELD Act, when more than 5,000 New York residents are affected)
- California: The California Attorney General (when more than 500 California residents are affected, per California Civil Code Section 1798.82)
- European Union: The relevant supervisory authority within 72 hours of becoming aware of the breach (per GDPR Article 33), where the breach is likely to result in a risk to the rights and freedoms of data subjects
- Other Jurisdictions: Applicable state attorneys general and regulatory bodies as required by their respective breach notification laws
Notification Content
Breach notifications will include, to the extent known:
- A description of the nature of the breach
- The categories and approximate number of individuals affected
- The categories of personal information involved
- Steps we are taking to address the breach and mitigate potential harm
- Recommendations for affected individuals to protect themselves
- Contact information for further inquiries
17. Email Communications
In compliance with the CAN-SPAM Act (15 U.S.C. Section 7701 et seq.), we adhere to the following practices:
Transactional Emails
We send transactional emails that are necessary for the operation of the Service, including account verification, password resets, processing completion notifications, subscription confirmations, invoice receipts, and security alerts. These emails are not subject to marketing opt-out because they are essential to providing the Service.
Marketing Emails
With your consent, we may send marketing emails about new features, product updates, promotions, and company news. Every marketing email will:
- Clearly identify NEXOS as the sender
- Include a valid physical mailing address
- Contain a clear and conspicuous unsubscribe mechanism
- Honor unsubscribe requests within 10 business days
- Not use deceptive subject lines or misleading header information
Email Ingestion
If you use our email ingestion feature, emails forwarded to your designated store email address are processed by AWS SES. We extract attachments (invoices and receipts) from these emails for scanning. The email body content and metadata (sender, subject, timestamp) are used solely for processing and are discarded after attachments are successfully extracted. We do not read, analyze, or store the content of forwarded emails beyond what is necessary for attachment extraction.
18. SMS Communications
Where your organization enables SMS features, NEXOS sends and receives transactional text messages. SMS is used for: (a) receipt capture, when you text a photo of a receipt or invoice to a NEXOS phone number assigned to your location; (b) scheduling, such as shift-assignment notifications and two-way confirmations where employees reply to confirm or decline a shift; and (c) approval and alert workflows, such as spend-approval requests and operational alerts. By providing a mobile number or opting in to these features, you consent to receive related SMS messages from NEXOS.
Use Case
All SMS messages are transactional and limited to the workflows above — for example, receipt confirmations ("Got it! Processing your receipt..."), extraction confirmation prompts ("Reply Y to confirm or N to discard"), shift confirmations ("Reply YES to accept this shift"), approval requests, and standard HELP/STOP keyword responses. We do not send marketing or promotional content via SMS.
Frequency, Cost, and Carrier Notice
- Frequency: Varies based on your usage. Typically 2-4 messages per receipt submission.
- Cost: Message and data rates may apply. NEXOS does not charge you for SMS, but your wireless carrier may.
- Carriers are not liable for delayed or undelivered messages.
Opt-Out and Help
- Reply STOP to any message to unsubscribe immediately. Other accepted opt-out keywords: UNSUBSCRIBE, CANCEL, END, QUIT.
- Reply HELP at any time for support contact information.
- Opt-out is honored automatically per CTIA guidelines.
No Third-Party Sharing
Your mobile number will not be sold, rented, shared, or used for any purpose other than the NEXOS SMS receipt-capture flow described above. We do not share mobile numbers with third parties for their marketing purposes.
19. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, the Service, or applicable law. When we make changes, we will:
- Post the updated Privacy Policy on this page with a revised "Last updated" date
- For material changes, provide additional notice via email to the address associated with your account or through a prominent notice within the Service
- Where required by applicable law (such as the GDPR), obtain your consent to material changes in how we process your personal data
Your continued use of the Service after the effective date of any changes to this Privacy Policy constitutes your acceptance of the updated policy. We encourage you to review this Privacy Policy periodically.
20. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us using the information below:
NEXOS
Titan Innovations LLC
PO Box 1121
Ronkonkoma, NY 11779
Privacy Inquiries: privacy@nexosscan.com
Legal Department: legal@nexosscan.com
General Inquiries: hello@nexosscan.com
For GDPR-related requests or to exercise your rights under the CCPA/CPRA, please email privacy@nexosscan.com with the subject line "Data Subject Request" and we will respond within the applicable timeframe required by law.