Legal
Privacy Policy
NexusQual builds an AI assistant that answers estate agencies' WhatsApp enquiries. That puts us in two different positions at once, and this policy keeps them separate: what we do with our customers' data, and what we do with data belonging to the people who message them.
1. Who we are
NexusQual Technologies Ltd is a company registered in England and Wales under company number 17383593, with its registered office at 71–75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom. In this policy, "we", "us" and "NexusQual" mean that company.
We are subject to the UK General Data Protection Regulation and the Data Protection Act 2018. We have not appointed a Data Protection Officer. You can reach us about anything in this policy at info@nexusqual.com.
We sell to estate agencies. Throughout this policy:
- An agency
- is an estate agency that uses our service. Our customer.
- An agency user
- is a person at that agency who holds a login to our client area at client.nexusqual.com.
- A lead
- is a member of the public who sends a message to an agency's WhatsApp number and is answered by the AI assistant.
2. Our two roles
Data protection law distinguishes between the organisation that decides why and how personal data is used — the controller — and an organisation that handles it on the controller's instructions — the processor. We are one or the other depending on whose data it is, and the difference determines who you deal with.
| Data | Controller | Our role |
|---|---|---|
| Agency account data Login details, contact details, consent records, support requests, usage and billing records for our customers. |
NexusQual | Controller. Sections 3, 8, 9 and 10 of this policy apply directly. |
| Conversation and lead data The phone number, messages, images and enquiry details of people who message an agency's WhatsApp number. |
The agency that was messaged | Processor. We handle it for the agency, on its instructions. |
| Agency business content Agency name, assistant persona text, uploaded documents, staff and broker contact details. |
The agency | Processor. |
The agency you contacted is the controller of that conversation, not us. It decided to use an AI assistant, it decides what your enquiry is used for, and it decides how long the record is kept. We handle the data for it.
Section 4 explains what is processed. Requests about your data — a copy, a correction, deletion — go to the agency you messaged. Section 10 explains what happens if you send one to us instead.
3. If you hold a NexusQual account
This section covers agency users and people who contact us. Here we are the controller.
What we hold
| Category | What it includes |
|---|---|
| Identity and contact | Your email address, and your name where you give it to us. |
| Sign-in credentials | A hashed version of your password, your two-factor authentication secret, hashed recovery codes, hashed one-time sign-in codes, and identifiers for the sessions you have open. |
| Account state | Whether your account is active and verified, your interface preference, and the agencies you are attached to. |
| Consent records | Where you grant or withdraw consent for marketing, we record what you consented to, when, how it was captured, which version of our terms applied, and the IP address the action came from. We also keep a suppression list of addresses that have asked not to be contacted. |
| Support requests | The subject and content of any support ticket you raise, and our replies. |
| Uploaded documents | The file name, size, a content fingerprint, the text extracted from the document, and a record of who uploaded it. |
| Usage and billing | How many conversations your agency has handled, against what plan, and the records needed to invoice you. |
| Enquiries to us | If you request early access or contact us through our website, the details you give us in that message. |
Why we hold it, and on what legal basis
| Purpose | Lawful basis |
|---|---|
| Providing the service, operating your account, and supporting you | Performance of our contract with your agency, and our legitimate interest in serving the individual users of a business customer |
| Keeping accounts secure — authentication, two-factor verification, session management, detecting misuse | Our legitimate interest in the security of the service, and our obligation to keep personal data secure |
| Invoicing, and keeping accounting and company records | Performance of our contract, and legal obligations under UK tax and company law |
| Responding to an enquiry you send us | Our legitimate interest in answering people who contact us, and taking steps at your request before entering a contract |
| Sending product or marketing email | Your consent, which you can withdraw at any time |
| Keeping a suppression list so a withdrawal keeps working | Our legal obligation to honour a withdrawal of consent |
We record marketing consent and withdrawal. We are not currently sending marketing email. If we begin, it will be on the basis of the consent recorded against your account, every message will carry an unsubscribe route, and you can withdraw at any time.
Where we rely on legitimate interests, we have considered whether our interest is overridden by your rights. You can ask us for that assessment.
4. If you messaged an estate agency
When you send a WhatsApp message to an agency that uses NexusQual, the agency's AI assistant answers you. Here the agency is the controller and we are its processor. This section is published so you can see what happens to your message; the agency's own privacy information governs why it was collected.
What is processed
- Your WhatsApp phone number. This is the only thing that identifies you to the system.
- The full text of your messages and of the assistant's replies, with timestamps, message counts and delivery status.
- Any photographs you send. Images are read by an automated vision model so the assistant can respond to them.
- An enquiry record. Your contact name if you give it, and details of what you are looking for — budget range, area, number of bedrooms, property type, how soon you want to move, whether you are financing, whether you have asked about visas, and the language you write in. These are worked out from what you write rather than collected on a form.
- A written summary of your conversation, generated automatically.
- A handoff record when the assistant passes you to a human broker.
All of this is used for one purpose: to answer your enquiry on the agency's behalf, work out what you are looking for, and pass you to a person at the agency when that is the right next step. It is also counted so we can bill the agency for the conversations it handles.
Please do not send sensitive personal information — passport or identity documents, financial statements, health information — through the WhatsApp conversation. The assistant does not need it, and nothing in the system detects or removes it if you do.
5. Automated replies and profiling
The replies you receive are written by an AI language model, not by a person. Your messages, and the conversation so far, are sent to the model providers listed in section 6 so that a reply can be generated.
The same system builds the enquiry record described in section 4 and uses it to route your enquiry to a particular broker at the agency. That is profiling: attributes are inferred about you from what you write and are then acted on. The assistant does not itself decide whether a property is offered to you — it answers, records what you appear to be looking for, and passes the enquiry to a broker at the agency.
Because the enquiry record is inferred by a language model rather than taken from something you filled in, it can be wrong about you. If you think an agency holds an inaccurate record of what you are looking for or what your circumstances are, tell the agency: it is the controller of that record and has to consider your request. We should be straight about the limit here — the service does not yet provide a way to correct an individual enquiry record, and the agency has no screen of its own in which to do it, so a correction today means the agency asking us and us editing the record by hand.
6. Who we share data with
We do not sell personal data, and we do not use it for advertising. We share it with the service providers below, each of which handles it for us under their terms of service and only to deliver the part of the service described.
| Provider | What it receives | Where |
|---|---|---|
| Meta Platforms WhatsApp Business Platform |
Every message in both directions, in full, and the phone number it came from. WhatsApp is how messages reach us and how replies reach you; nothing gets to us except through Meta. | United States and globally |
| Fireworks AI | Message text and conversation history, to generate replies and build the enquiry record; images sent by leads, read by a vision model; and text extracted from documents the agency has uploaded for the assistant to draw on. | United States |
| Anthropic | Configured as an available language model. Depending on how a given request is routed, it may receive the same message text and conversation history as above. | United States |
| Our hosting provider | Hosting for the entire service: the databases, uploaded files and server logs described in this policy. | Currently a provider in the United States. Moving to Netcup GmbH in Nuremberg, Germany — see section 7. |
The agency you messaged does not currently have a screen in which its staff can read the conversations or enquiry records held for it. The Assistant passes a qualified enquiry to one of their brokers over WhatsApp at the time it happens, and everything else is held by us on their behalf. We are building that view for them. Until it exists, an agency asking us to find, produce or correct a record is answered by us doing it by hand.
We are checking whether any component of the platform sends operational telemetry to its own supplier. If any does, we will add it to this table.
We may also disclose personal data to our professional advisers, and where we are required to by law or by a regulator, court or law enforcement authority.
If our business is sold or reorganised, personal data may be transferred as part of it. We would tell agency users before that happened.
7. Where data is held
Our service runs on a single server. As at the effective date of this policy that server is with a hosting provider in the United States. We are moving it to Netcup GmbH in Nuremberg, Germany, and we will update this section when the move completes.
Message content, conversation history and lead-sent images are transmitted to the providers listed in section 6 that are located in the United States. Transferring personal data outside the United Kingdom requires a safeguard recognised under UK data protection law. We do not currently have such a safeguard in place with these providers. Putting one in place with each of them is work we have committed to, and we will update this policy to record them once they are in force.
The agencies that use our service are located in the United Arab Emirates, and the people who message them generally are too. Their staff access their own agency's data from there.
8. How long we keep it
We would rather set this out accurately than round it up into a sentence that sounds tidier than the position is.
| What | How long |
|---|---|
| Your NexusQual account record | For as long as the account is open. When you delete your account, your sessions are revoked, the documents you uploaded are removed and your account record is anonymised. |
| Sessions and sign-in tokens | Until they expire or are revoked, whichever is sooner. Signing out or changing your password revokes them. |
| Consent and suppression records | Kept for as long as we need to evidence what you consented to. A request not to be contacted is kept even if you close your account, so that the request continues to be honoured. |
| Conversations, enquiry records, images and handoff records | We do not currently apply an automatic deletion schedule to these. They are kept until the agency's workspace is closed, at which point they are deleted. How long this data should be kept is the agency's decision as controller, and we do not yet have a means of enforcing a period automatically. We will state the periods here once agencies can set them. |
| Records evidencing what an agency was billed for | Archived for six years after an agency's workspace is closed. These archives are copied from the conversation records the billing was calculated from, and contain the phone numbers of people who messaged that agency. |
| A snapshot taken when an agency's workspace is deleted | The deletion process records a snapshot of what was removed, which includes conversation content. No period is currently set for it. |
| Automation engine execution records | Removed automatically after 14 days by the automation engine's own default. This is a supplier default rather than a period we have chosen, and it could change. |
| Administrative audit records | 730 days. |
| Server and application logs | Application logs rotate at 10 MB and are kept for 7 days; error logs for 30 days; container output is capped at 10 MB per file, 3 files. These logs can contain the email address of a signed-in user, and deleting your account does not reach them — they age out on the schedule above instead. |
9. How we protect it
The measures below are in place. We have described what we actually do rather than making a general claim about standards.
This is a list of the measures we have, not a claim that our security is complete. The measures we do not yet have are set out in the technical measures annex of the agreement we sign with agencies, so that a customer can assess us on the whole picture.
- Everything we serve publicly is served over HTTPS, with certificates managed automatically. No part of the application is exposed to the internet directly — all traffic goes through a reverse proxy, and the internal service endpoints are blocked from public access.
- Each agency's data is separated at the database level by row-level security, so a request made in the context of one agency cannot read another's records. The application connects using a restricted database role rather than an administrative one. One configuration table is readable across agencies by design, because an incoming phone number has to be matched to an agency before that separation can be applied; it holds agency settings, not conversations.
- Passwords and recovery codes are stored using argon2 hashing and cannot be recovered by us or by anyone who obtains the database.
- A two-factor secret has to be stored in a form the system can use to check your codes, so it is not hashed. We treat it with the same care as a password.
- Two-factor authentication is available on client area accounts and is in use.
- Incoming WhatsApp messages are checked against a cryptographic signature before we process them, so we do not act on messages that did not come from Meta.
- Stored service credentials are encrypted. Our cache enforces per-service access control with the default account disabled.
- Deleting an agency workspace runs through a dedicated, restricted database role rather than the application's own.
- An automated check runs every ten minutes covering service health, configuration drift, and whether internal endpoints have become publicly reachable. It raises an alert when any of those change.
If something goes wrong
If a personal data breach happens that is likely to result in a high risk to you, we will tell you. Where the data affected belongs to an agency's conversations, we tell the agency without undue delay, because it is the controller and the duty to inform the people affected is its own. We will support it in doing that.
10. Your rights
Under UK data protection law you have rights over your personal data: to get a copy of it, to have it corrected, to have it deleted, to restrict or object to how it is used, to receive it in a portable form, and to withdraw consent you have given. Who you exercise them against depends on which of the two roles in section 2 applies.
If you hold a NexusQual account
We are the controller, so bring these to us.
- Getting a copy of your data
- You can export it yourself from the client area. That export currently covers your account record, the agencies you are attached to, your billing records, and details of the documents you have uploaded. Some records we hold about you are not yet included in it — support tickets, your consent history, your marketing preference and whether two-factor authentication is enabled. Ask us and we will provide those.
- Correcting your data
- You can edit your own details in the client area. If something you cannot edit is wrong, tell us.
- Deleting your account
- You can delete your user account from the client area. That revokes your sessions, removes the documents you uploaded and anonymises your account record. It does not close your agency's workspace or delete the conversations held in it — those belong to the agency, not to you personally. If the agency wants its workspace and all data in it deleted, an authorised person at the agency should ask us and we will action it.
- Restriction and objection
- Contact us and tell us what you want restricted or what you are objecting to.
- Withdrawing consent
- You can withdraw marketing consent in the client area or by contacting us. We record the withdrawal and add you to a suppression list so it keeps being honoured.
If you messaged an estate agency
The agency you contacted is the controller of that conversation. Your rights are exercised against it, and it decides what happens to the data. Contact the agency directly. It has one month to respond, extendable by two further months for a complex request, and it must tell you if it needs the extra time.
If you contact us instead, we will pass your request to the agency within two working days and help it answer, but we cannot decide the outcome ourselves. There is more detail, including what we need in order to find your records, on our data deletion page.
Two things are worth knowing before you write:
- We can find your data only by the WhatsApp number you used. If you have messaged from more than one number, we have no way of knowing those numbers belong to the same person, so tell the agency each number you used.
- Each agency holds its own separate records. If you contacted two agencies, each is a separate controller of its own copy, and a request to one has no effect on the other. You would need to ask each of them.
- If the agency you messaged is no longer our customer, its workspace and the conversations in it will have been deleted — but the billing archive described in section 8 may still hold the phone number the conversation was billed against, and we do not currently have a route by which we can act on a request about it. If that applies to you, write to us anyway so that your request is recorded.
Complaints
If you are unhappy with how we have handled your data, please tell us first so we can put it right. You also have the right to complain to the Information Commissioner's Office, the UK's data protection regulator, at ico.org.uk/make-a-complaint or on 0303 123 1113. If your complaint concerns a conversation with an estate agency, the agency is the controller and the regulator for its location may be the appropriate one.
11. Children
Our service is sold to businesses and is not directed at children. We do not knowingly collect data about children. Because an agency's WhatsApp number is open to anyone who has it, we cannot verify the age of a person who messages one. If you believe a child's data has been sent to an agency using our service, contact the agency or us and we will help get it removed.
12. Changes to this policy
We will update this policy as the service changes, and the version number and date at the top will change with it. We will tell agency users about material changes before they take effect. Where a change affects what happens to conversation data, we will tell the agencies concerned so they can update their own privacy information.
13. Contact and complaints
Email info@nexusqual.com, or write to NexusQual Technologies Ltd, 71–75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom.
If you are contacting us about a WhatsApp conversation with an estate agency, please tell us the WhatsApp number you messaged from and which agency you contacted, so we can pass your request to the right controller.