Legal
Deleting your data
Who to ask depends on how your data got here. If you messaged an estate agency on WhatsApp, the agency holds and controls that conversation and the request goes to them. If you hold a NexusQual login, the request comes to us.
If you messaged an estate agency on WhatsApp
When you message an estate agency's WhatsApp number and an AI assistant replies, that assistant is ours — but the conversation belongs to the agency. In data protection terms the agency is the controller: it decided to use the assistant, it decides what your enquiry is used for, and it decides whether the record is deleted. We are its processor, and we act on its instructions.
So a deletion request is made to the agency you contacted. It has one month to respond.
How to ask
- Contact the agency directly. Use whatever contact details they publish — their website, their office, or a reply in the same WhatsApp conversation. Say that you are asking them to delete the personal data they hold about you, and give them the WhatsApp number you messaged from.
- Or write to us and we will pass it on. Email info@nexusqual.com. We will forward your request to the agency within two working days and confirm to you that we have done so. We cannot decide the outcome ourselves — that is the agency's decision, and we will act on whatever they instruct.
What to include
- The number or account you messaged from, in full international format for a phone number. This is the only thing that identifies your records.
- Which agency you contacted, or the WhatsApp number you sent your message to.
- Roughly when you were in contact, if you remember.
We may ask you to confirm that the number is yours before anything is done with it, so that we are not acting on a request from someone else about you.
Two things worth knowing before you write
The assistant knows you only by the number or account you messaged from. If you have used more than one, we have no way of telling that they belong to the same person — so list every one you have used, and any confirmation you receive will cover only the ones you gave. The same applies across platforms: if we add a channel in future, an account there and a phone number here are two separate records to us, not one person.
If you contacted two agencies, each one is a separate controller of its own record of its own conversation with you. A request to one has no effect on the other's data, and neither we nor the agency you asked can lawfully act on the other's behalf. You would need to ask each agency separately.
What we can do today, and what we cannot
We would rather be exact about this than give an assurance that would not survive contact with the request.
| Request | Position today |
|---|---|
| Delete everything held for one agency | Partly, and we have just found the limit. On the agency’s instruction we run a dedicated deletion process that removes the agency’s configuration, staff and broker records, handoff records and images. On 19 August 2026 we established that this process does not reach the database that holds the conversations and enquiry records themselves, so those rows survive a deletion that reports success. We had previously described this capability as tested and working; that description was based on a test that covered only part of the system, and it was wrong. Extending deletion to cover every store is committed work and is our highest engineering priority. This page will say so plainly until it is done. |
| Delete the records of one individual person, leaving the rest of an agency's data in place | We do not have a way to do this yet. Every deletion capability in the service today operates on a whole agency, not on one member of the public. Building the individual route is committed work and this page will change when it is available, but we are not going to describe it as though it already exists. In the meantime a request about one person is answered by the agency deciding what to do with the data it controls, and we carry out its instruction. |
| Get a copy of the data held about you, or have it corrected | Ask the agency — it is the controller and has to consider your request. We will give it what help we can in finding the records, but we have no automated way of producing or correcting an individual's records, so what it can do today is limited. |
One further point, because it would be misleading to leave it out: when an agency's workspace is deleted, a record of what that agency was billed for is archived for six years so that the account can be substantiated. Those archives are copied from the conversation records and contain phone numbers. Our Privacy Policy sets out where this sits alongside everything else we keep.
Where an agency is no longer our customer, its workspace and the conversations in it will have been deleted. The billing archive described above may still hold the phone number the conversation was billed against, and because there is no longer an agency to instruct us, we do not currently have a route by which we can act on a request about it. Write to us anyway — we will record your request and act on it when the route exists.
If you have a NexusQual client area account
Here we are the controller and you deal with us directly.
- Delete your account from the client area. Sign in at client.nexusqual.com, open your account settings and choose to delete your account. This revokes your sessions, removes the documents you uploaded and anonymises your account record.
- It does not close your agency's workspace. Deleting your own login does not delete your agency's configuration or the conversations held for it — that data belongs to the agency rather than to you personally. If the agency wants its workspace and everything in it deleted, an authorised person should email info@nexusqual.com and we will action it.
- Get your data out first. The client area has an export function. Run it before you delete anything, and ask us for anything the export does not cover.
How we respond
We will acknowledge your request and tell you what we have done with it — whether that is actioning it ourselves, or passing it to the agency that controls the data. Where an agency is the controller, the law gives it one month to respond to you, extendable by two further months for complex requests, and it must tell you if it needs the extension.
If you are not satisfied with how a request has been handled you can complain to the data protection regulator. In the United Kingdom that is the Information Commissioner's Office, at ico.org.uk/make-a-complaint. If the agency you contacted is based elsewhere, the regulator for its location may be the right one.
Contact
Email info@nexusqual.com, or write to NexusQual Technologies Ltd, 71–75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom.