Legal

Privacy Policy

NexusQual builds an AI assistant that answers estate agencies' WhatsApp enquiries. That puts us in two different positions at once, and this policy keeps them separate: what we do with our customers' data, and what we do with data belonging to the people who message them.

Version 1.0 Status In force Last updated 14 August 2026 Effective from 14 August 2026

1. Who we are

NexusQual Technologies Ltd is a company registered in England and Wales under company number 17383593, with its registered office at 71–75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom. In this policy, "we", "us" and "NexusQual" mean that company.

We are subject to the UK General Data Protection Regulation and the Data Protection Act 2018. We have not appointed a Data Protection Officer. You can reach us about anything in this policy at info@nexusqual.com.

We sell to estate agencies. Throughout this policy:

An agency
is an estate agency that uses our service. Our customer.
An agency user
is a person at that agency who holds a login to our client area at client.nexusqual.com.
A lead
is a member of the public who sends a message to an agency's WhatsApp number and is answered by the AI assistant.

2. Our two roles

Data protection law distinguishes between the organisation that decides why and how personal data is used — the controller — and an organisation that handles it on the controller's instructions — the processor. We are one or the other depending on whose data it is, and the difference determines who you deal with.

DataControllerOur role
Agency account data
Login details, contact details, consent records, support requests, usage and billing records for our customers.
NexusQual Controller. Sections 3, 8, 9 and 10 of this policy apply directly.
Conversation and lead data
The phone number, messages, images and enquiry details of people who message an agency's WhatsApp number.
The agency that was messaged Processor. We handle it for the agency, on its instructions.
Agency business content
Agency name, assistant persona text, uploaded documents, staff and broker contact details.
The agency Processor.
If you messaged an estate agency

The agency you contacted is the controller of that conversation, not us. It decided to use an AI assistant, it decides what your enquiry is used for, and it decides how long the record is kept. We handle the data for it.

Section 4 explains what is processed. Requests about your data — a copy, a correction, deletion — go to the agency you messaged. Section 10 explains what happens if you send one to us instead.

3. If you hold a NexusQual account

This section covers agency users and people who contact us. Here we are the controller.

What we hold

CategoryWhat it includes
Identity and contactYour email address, and your name where you give it to us.
Sign-in credentialsA hashed version of your password, your two-factor authentication secret, hashed recovery codes, hashed one-time sign-in codes, and identifiers for the sessions you have open.
Account stateWhether your account is active and verified, your interface preference, and the agencies you are attached to.
Consent recordsWhere you grant or withdraw consent for marketing, we record what you consented to, when, how it was captured, which version of our terms applied, and the IP address the action came from. We also keep a suppression list of addresses that have asked not to be contacted.
Support requestsThe subject and content of any support ticket you raise, and our replies.
Uploaded documentsThe file name, size, a content fingerprint, the text extracted from the document, and a record of who uploaded it.
Usage and billingHow many conversations your agency has handled, against what plan, and the records needed to invoice you.
Enquiries to usIf you request early access or contact us through our website, the details you give us in that message.

Why we hold it, and on what legal basis

PurposeLawful basis
Providing the service, operating your account, and supporting youPerformance of our contract with your agency, and our legitimate interest in serving the individual users of a business customer
Keeping accounts secure — authentication, two-factor verification, session management, detecting misuseOur legitimate interest in the security of the service, and our obligation to keep personal data secure
Invoicing, and keeping accounting and company recordsPerformance of our contract, and legal obligations under UK tax and company law
Responding to an enquiry you send usOur legitimate interest in answering people who contact us, and taking steps at your request before entering a contract
Sending product or marketing emailYour consent, which you can withdraw at any time
Keeping a suppression list so a withdrawal keeps workingOur legal obligation to honour a withdrawal of consent

We record marketing consent and withdrawal. We are not currently sending marketing email. If we begin, it will be on the basis of the consent recorded against your account, every message will carry an unsubscribe route, and you can withdraw at any time.

Where we rely on legitimate interests, we have considered whether our interest is overridden by your rights. You can ask us for that assessment.

4. If you messaged an estate agency

When you send a WhatsApp message to an agency that uses NexusQual, the agency's AI assistant answers you. Here the agency is the controller and we are its processor. This section is published so you can see what happens to your message; the agency's own privacy information governs why it was collected.

What is processed

All of this is used for one purpose: to answer your enquiry on the agency's behalf, work out what you are looking for, and pass you to a person at the agency when that is the right next step. It is also counted so we can bill the agency for the conversations it handles.

Please do not send sensitive personal information — passport or identity documents, financial statements, health information — through the WhatsApp conversation. The assistant does not need it, and nothing in the system detects or removes it if you do.

5. Automated replies and profiling

The replies you receive are written by an AI language model, not by a person. Your messages, and the conversation so far, are sent to the model providers listed in section 6 so that a reply can be generated.

The same system builds the enquiry record described in section 4 and uses it to route your enquiry to a particular broker at the agency. That is profiling: attributes are inferred about you from what you write and are then acted on. The assistant does not itself decide whether a property is offered to you — it answers, records what you appear to be looking for, and passes the enquiry to a broker at the agency.

Because the enquiry record is inferred by a language model rather than taken from something you filled in, it can be wrong about you. If you think an agency holds an inaccurate record of what you are looking for or what your circumstances are, tell the agency: it is the controller of that record and has to consider your request. We should be straight about the limit here — the service does not yet provide a way to correct an individual enquiry record, and the agency has no screen of its own in which to do it, so a correction today means the agency asking us and us editing the record by hand.

6. Who we share data with

We do not sell personal data, and we do not use it for advertising. We share it with the service providers below, each of which handles it for us under their terms of service and only to deliver the part of the service described.

ProviderWhat it receivesWhere
Meta Platforms
WhatsApp Business Platform
Every message in both directions, in full, and the phone number it came from. WhatsApp is how messages reach us and how replies reach you; nothing gets to us except through Meta. United States and globally
Fireworks AI Message text and conversation history, to generate replies and build the enquiry record; images sent by leads, read by a vision model; and text extracted from documents the agency has uploaded for the assistant to draw on. United States
Anthropic Configured as an available language model. Depending on how a given request is routed, it may receive the same message text and conversation history as above. United States
Our hosting provider Hosting for the entire service: the databases, uploaded files and server logs described in this policy. Currently a provider in the United States. Moving to Netcup GmbH in Nuremberg, Germany — see section 7.

The agency you messaged does not currently have a screen in which its staff can read the conversations or enquiry records held for it. The Assistant passes a qualified enquiry to one of their brokers over WhatsApp at the time it happens, and everything else is held by us on their behalf. We are building that view for them. Until it exists, an agency asking us to find, produce or correct a record is answered by us doing it by hand.

We are checking whether any component of the platform sends operational telemetry to its own supplier. If any does, we will add it to this table.

We may also disclose personal data to our professional advisers, and where we are required to by law or by a regulator, court or law enforcement authority.

If our business is sold or reorganised, personal data may be transferred as part of it. We would tell agency users before that happened.

7. Where data is held

Our service runs on a single server. As at the effective date of this policy that server is with a hosting provider in the United States. We are moving it to Netcup GmbH in Nuremberg, Germany, and we will update this section when the move completes.

Message content, conversation history and lead-sent images are transmitted to the providers listed in section 6 that are located in the United States. Transferring personal data outside the United Kingdom requires a safeguard recognised under UK data protection law. We do not currently have such a safeguard in place with these providers. Putting one in place with each of them is work we have committed to, and we will update this policy to record them once they are in force.

The agencies that use our service are located in the United Arab Emirates, and the people who message them generally are too. Their staff access their own agency's data from there.

8. How long we keep it

We would rather set this out accurately than round it up into a sentence that sounds tidier than the position is.

WhatHow long
Your NexusQual account record For as long as the account is open. When you delete your account, your sessions are revoked, the documents you uploaded are removed and your account record is anonymised.
Sessions and sign-in tokens Until they expire or are revoked, whichever is sooner. Signing out or changing your password revokes them.
Consent and suppression records Kept for as long as we need to evidence what you consented to. A request not to be contacted is kept even if you close your account, so that the request continues to be honoured.
Conversations, enquiry records, images and handoff records We do not currently apply an automatic deletion schedule to these. They are kept until the agency's workspace is closed, at which point they are deleted. How long this data should be kept is the agency's decision as controller, and we do not yet have a means of enforcing a period automatically. We will state the periods here once agencies can set them.
Records evidencing what an agency was billed for Archived for six years after an agency's workspace is closed. These archives are copied from the conversation records the billing was calculated from, and contain the phone numbers of people who messaged that agency.
A snapshot taken when an agency's workspace is deleted The deletion process records a snapshot of what was removed, which includes conversation content. No period is currently set for it.
Automation engine execution records Removed automatically after 14 days by the automation engine's own default. This is a supplier default rather than a period we have chosen, and it could change.
Administrative audit records 730 days.
Server and application logs Application logs rotate at 10 MB and are kept for 7 days; error logs for 30 days; container output is capped at 10 MB per file, 3 files. These logs can contain the email address of a signed-in user, and deleting your account does not reach them — they age out on the schedule above instead.

9. How we protect it

The measures below are in place. We have described what we actually do rather than making a general claim about standards.

This is a list of the measures we have, not a claim that our security is complete. The measures we do not yet have are set out in the technical measures annex of the agreement we sign with agencies, so that a customer can assess us on the whole picture.

If something goes wrong

If a personal data breach happens that is likely to result in a high risk to you, we will tell you. Where the data affected belongs to an agency's conversations, we tell the agency without undue delay, because it is the controller and the duty to inform the people affected is its own. We will support it in doing that.

10. Your rights

Under UK data protection law you have rights over your personal data: to get a copy of it, to have it corrected, to have it deleted, to restrict or object to how it is used, to receive it in a portable form, and to withdraw consent you have given. Who you exercise them against depends on which of the two roles in section 2 applies.

If you hold a NexusQual account

We are the controller, so bring these to us.

Getting a copy of your data
You can export it yourself from the client area. That export currently covers your account record, the agencies you are attached to, your billing records, and details of the documents you have uploaded. Some records we hold about you are not yet included in it — support tickets, your consent history, your marketing preference and whether two-factor authentication is enabled. Ask us and we will provide those.
Correcting your data
You can edit your own details in the client area. If something you cannot edit is wrong, tell us.
Deleting your account
You can delete your user account from the client area. That revokes your sessions, removes the documents you uploaded and anonymises your account record. It does not close your agency's workspace or delete the conversations held in it — those belong to the agency, not to you personally. If the agency wants its workspace and all data in it deleted, an authorised person at the agency should ask us and we will action it.
Restriction and objection
Contact us and tell us what you want restricted or what you are objecting to.
Withdrawing consent
You can withdraw marketing consent in the client area or by contacting us. We record the withdrawal and add you to a suppression list so it keeps being honoured.

If you messaged an estate agency

The agency you contacted is the controller of that conversation. Your rights are exercised against it, and it decides what happens to the data. Contact the agency directly. It has one month to respond, extendable by two further months for a complex request, and it must tell you if it needs the extra time.

If you contact us instead, we will pass your request to the agency within two working days and help it answer, but we cannot decide the outcome ourselves. There is more detail, including what we need in order to find your records, on our data deletion page.

Two things are worth knowing before you write:

Complaints

If you are unhappy with how we have handled your data, please tell us first so we can put it right. You also have the right to complain to the Information Commissioner's Office, the UK's data protection regulator, at ico.org.uk/make-a-complaint or on 0303 123 1113. If your complaint concerns a conversation with an estate agency, the agency is the controller and the regulator for its location may be the appropriate one.

11. Children

Our service is sold to businesses and is not directed at children. We do not knowingly collect data about children. Because an agency's WhatsApp number is open to anyone who has it, we cannot verify the age of a person who messages one. If you believe a child's data has been sent to an agency using our service, contact the agency or us and we will help get it removed.

12. Changes to this policy

We will update this policy as the service changes, and the version number and date at the top will change with it. We will tell agency users about material changes before they take effect. Where a change affects what happens to conversation data, we will tell the agencies concerned so they can update their own privacy information.

13. Contact and complaints

Email info@nexusqual.com, or write to NexusQual Technologies Ltd, 71–75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom.

If you are contacting us about a WhatsApp conversation with an estate agency, please tell us the WhatsApp number you messaged from and which agency you contacted, so we can pass your request to the right controller.