Nex Dot Data Processing Corp.
Operating as NexDotWorks and NexDot AI Chat
Effective Date: May 22, 2026 · Last Updated: May 25, 2026
1. Who We Are
This Privacy Policy applies to Nex Dot Data Processing Corp. (“we”, “us”, “our”), a corporation operating under the trade names NexDotWorks and NexDot AI Chat, based in Ontario, Canada.
We provide the following services to businesses (“Clients”):
- Website development — custom WordPress websites built for trades and service businesses in Ontario
- NexDot AI Chat — a done-for-you AI chatbot service that installs on a Client’s website to answer visitor questions, capture leads, and send real-time notifications to the Client
- NexDot AI Chat E-Commerce Product Finder — an add-on that connects the chatbot to a Client’s Shopify or WooCommerce catalog to provide conversational product recommendations
- AI Strategy & Automation — consulting and implementation services to help businesses identify, plan, and deploy AI-powered workflows and automation solutions
- Database Architecture — design, build, and optimization of database systems for business applications
- IT Security Audit — assessment of a Client’s IT infrastructure, systems, and practices to identify security vulnerabilities and provide remediation recommendations
- Hosting & Infrastructure — setup, configuration, and management of hosting environments and server infrastructure for Client applications and websites
Where our services involve deploying a chat widget on a Client’s website, that widget may interact with the Client’s website visitors (“End Users”).
Contact:
Nex Dot Data Processing Corp.
Email: info@nexdotworks.com
Website: nexdotworks.com
2. Scope of This Policy
This policy explains:
- What personal information we collect when you visit nexdotworks.com or contact us directly
- How we handle personal information of End Users (visitors to Client websites) when Clients use the NexDot AI Chat service
- Your rights under Canadian privacy law
This policy does not govern how our Clients use the information they receive through the chatbot service. Each Client is an independent data controller and is responsible for their own privacy practices and disclosures to their website visitors.
3. Information We Collect
3.1 When You Visit nexdotworks.com or Contact Us
| Data | How Collected | Purpose |
|---|---|---|
| Name | Contact form, email | Respond to your inquiry |
| Email address | Contact form, email | Respond to your inquiry; send service information if requested |
| Phone number | Contact form (optional) | Respond to your inquiry |
| Message content | Contact form, email | Understand and respond to your inquiry |
| IP address, browser type, pages visited | Automatically (server logs / analytics) | Website security and performance analytics |
We do not use tracking cookies or third-party advertising pixels on nexdotworks.com.
3.2 When You Use the NexDot AI Chat Widget (End Users on Client Websites)
When you interact with a NexDot AI Chat widget embedded on a Client’s website, the following information may be collected on behalf of that Client:
| Data | Source | Purpose |
|---|---|---|
| Conversation messages (text) | Your input in the chat widget | Generate AI responses; maintain conversation continuity within the session |
| Name | Lead capture form (if you choose to submit) | Delivered to the Client as a lead notification |
| Email address | Lead capture form (if you choose to submit) | Delivered to the Client; used to send the Client a lead notification email |
| Phone number | Lead capture form (optional) | Delivered to the Client as part of the lead notification |
| Page URL at time of conversation | Browser metadata | Provide context in the Client’s lead notification |
| Session ID (randomly generated) | System-generated | Maintain conversation continuity; not linked to your identity |
We act as a data processor for this information. The Client whose website you are visiting is the data controller and is responsible for informing you about how your data is used, obtaining any required consent, and responding to privacy requests. Please refer to the Client’s own privacy policy for details.
3.3 When You Send an Instagram Direct Message to a Client Connected to NexDot AI Chat
Some Clients connect their Instagram Business or Creator account to NexDot AI Chat so that direct messages sent to the Client’s Instagram account are answered by our AI assistant on the Client’s behalf. When you send an Instagram direct message to a Client whose account is connected to our service, the following information is processed on behalf of that Client:
| Data | Source | Purpose |
|---|---|---|
| Message text you send | Meta Platforms webhook | Generate AI response on behalf of the Client |
| Instagram-scoped sender ID (IGSID) | Meta Platforms webhook | Identify your conversation thread; deliver the AI reply back to you |
| Conversation history (within the same thread) | Our database | Maintain conversational context so the AI can respond coherently |
| Timestamp and message ID | Meta Platforms webhook | Order messages and prevent duplicate processing |
We do not request, store, or access your Instagram profile information beyond what is required to deliver the AI reply (sender ID and message content). We do not access your follower lists, your other conversations, your profile photo, your media, or any other data from your Instagram account.
The Client whose Instagram account you contacted is the data controller for this interaction. We act as a data processor on the Client’s behalf, pursuant to the Client’s agreement with us. The Client is responsible for informing their Instagram audience that an AI assistant may respond to direct messages.
Instagram direct message data is subject to the retention schedule in Section 6 and the sharing terms in Section 5 (in particular, Section 5.1 regarding Anthropic and the new Section 5.5 regarding Meta Platforms).
4. How We Use Personal Information
We use the information we collect to:
- Respond to inquiries and provide the services you or your business has requested
- Deliver the NexDot AI Chat service to Clients (including generating AI responses and sending lead notifications)
- Maintain and improve the security, reliability, and performance of our systems
- Comply with legal obligations
We do not:
- Sell personal information to any third party
- Use End User conversation data to train AI models
- Use End User data for marketing purposes unrelated to the Client’s service
- Share personal information with third parties except as described in Section 5
5. How We Share Personal Information
5.1 Anthropic PBC (AI Response Generation)
To generate AI responses in the chat widget, conversation messages are transmitted to the API of Anthropic PBC (San Francisco, California, USA). Anthropic processes these messages solely to generate a response and does not retain them for training purposes under their API terms. By using the chat widget on a Client’s website, you acknowledge that your conversation messages are transmitted to a service located in the United States.
For more information, see Anthropic’s Privacy Policy at: anthropic.com/legal/privacy
5.2 Hosting Infrastructure
Our services run on servers provided by IONOS, located in the United States. This means personal information may be stored outside Canada. We take reasonable steps to ensure that data transferred outside Canada receives comparable protection.
5.3 Legal Requirements
We may disclose personal information if required to do so by law, court order, or government authority, or where we believe disclosure is necessary to protect our rights, the rights of others, or the safety of any person.
5.5 Meta Platforms, Inc. (Instagram Direct Message Integration)
Where a Client has connected their Instagram Business or Creator account to our service, we receive direct message events from, and send replies through, the Meta Graph API operated by Meta Platforms, Inc. (Menlo Park, California, USA). The Instagram-scoped sender ID and the text content of messages exchanged in the connected conversation are transmitted between our servers and Meta’s servers in order to deliver the AI reply to you.
Meta is the operator of Instagram and is the source of the personal information we receive in this flow. Meta’s handling of your Instagram account data is governed by Meta’s own policies, not by us.
For more information, see Meta’s Privacy Policy at: facebook.com/privacy/policy
5.4 Business Transfers
In the event of a merger, acquisition, or sale of substantially all of our assets, personal information may be transferred as part of that transaction. We will provide notice before personal information becomes subject to a materially different privacy policy.
We do not share personal information with any other third parties.
6. Data Retention
| Data Type | Retention Period |
|---|---|
| nexdotworks.com contact form submissions | 24 months from date of submission, then deleted |
| End User conversation messages (website widget) | 12 months from date of conversation, then permanently deleted |
| Instagram direct message content and sender ID | 12 months from date of message, then permanently deleted. Deleted within 30 days if the Client disconnects their Instagram account or you request deletion (see Section 8). |
| End User lead data (name, email, phone) | 24 months from date of capture, or until the Client or End User requests deletion |
| Data after Client contract termination | 60 days from termination date, then permanently deleted |
| Server logs (IP, access logs) | 90 days, then deleted |
You may request earlier deletion at any time — see Section 8.
7. Security
We implement reasonable technical and organizational safeguards to protect personal information, including:
- HTTPS encryption for all data in transit
- SSH key-based authentication for server access
- API keys and credentials stored as environment variables, not in source code
- Database not exposed to the public internet
- Access to stored personal information restricted to authorized personnel
No method of transmission or storage is 100% secure. In the event of a data breach affecting personal information, we will notify affected parties and, where required, the Office of the Privacy Commissioner of Canada, in accordance with applicable law.
8. Your Rights
Under Canadian privacy law (PIPEDA and applicable provincial legislation), you have the right to:
- Access the personal information we hold about you
- Correct inaccurate personal information
- Request deletion of your personal information, subject to our legal obligations
- Withdraw consent to certain uses of your personal information
To exercise any of these rights, contact us at:
Email: info@nexdotworks.com
Subject line: “Privacy Request”
We will respond within 30 days of receiving your request.
Note for End Users of Client chatbots: If your request relates to information collected through a chatbot on a Client’s website, we will forward your request to the relevant Client within 5 business days. The Client, as the data controller, is responsible for responding to your request.
Quebec residents: If you are located in Quebec, you have additional rights under Quebec Law 25 (Act Respecting the Protection of Personal Information in the Private Sector), including the right to be informed of any automated decision-making affecting you and to request human review of such decisions. Contact us at the address above.
9. Children’s Privacy
Our services are not directed to individuals under the age of 16. We do not knowingly collect personal information from children under 16. If you believe we have inadvertently collected such information, please contact us at info@nexdotworks.com and we will delete it promptly.
10. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last Updated” date at the top of this page and, where appropriate, notify affected parties. Your continued use of our website or services after changes are posted constitutes your acceptance of the updated policy.
11. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact:
Nex Dot Data Processing Corp.
Email: info@nexdotworks.com
If you are not satisfied with our response, you may contact the Office of the Privacy Commissioner of Canada:
Website: priv.gc.ca
Toll-free: 1-800-282-1376
© 2026 Nex Dot Data Processing Corp. All rights reserved.