NEXUMRISE
  • Home
  • Services
  • SMS campaigns
  • FAQ
  • Contacts
  • Get a quote

Legal

Privacy Policy

Last updated: August 25, 2026

1. Who we are

[LEGAL ENTITY NAME, e.g. "Nexum LLC"], registered in [COUNTRY / JURISDICTION] under registration number [REGISTRATION NUMBER], with its registered office at [FULL REGISTERED BUSINESS ADDRESS] ("Nexum", "we", "us", "our"), is the data controller responsible for the personal data described in this Privacy Policy. We provide information technology services and digital solutions for businesses, including a communication platform (operated under the "Nexum Rise" product) and related software, integration and support services (together, the "Service"). This Policy applies to nexum-rise.com and to the Nexum Rise dashboard and API.

2. Scope of this Policy

This Policy explains how we collect, use, share and protect personal data of two categories of individuals: (a) our direct Customers and their authorized users (people who register an account and use the Service), and (b) end recipients whose contact details our Customers submit to the Service in order to receive communications on the Customer's behalf (e.g. recipients of SMS, Viber or RCS messages sent by a Customer). Where we process end-recipient data on a Customer's instructions, we act as a data processor for that data and the Customer acts as the data controller; our processor obligations are set out in Section 9 and in a Data Processing Agreement available on request.

3. Personal data we collect

  • Account and billing data — name, email address, phone number, company name, billing address and payment metadata (see Section 6) that you provide when registering, placing an order, or contacting support.
  • Service usage data — information generated by your use of the Service, including API calls, campaign configuration, delivery and read reports, error logs and support tickets.
  • Recipient contact data submitted by Customers — phone numbers, names or other identifiers a Customer uploads to send messages through the Service, and delivery-status metadata associated with those messages. We do not use this data for our own marketing purposes.
  • Technical data — IP address, browser and device type, and similar information collected automatically via cookies and server logs, used for security, analytics and service reliability.

4. Legal basis for processing (GDPR)

Where the UK/EU General Data Protection Regulation applies, we rely on the following legal bases:

  • Performance of a contract — to create and manage your Account, deliver the Service, and process payments.
  • Legitimate interests — to maintain the security and reliability of the Service, prevent fraud and abuse, and improve our products, balanced against your rights and interests.
  • Legal obligation — to comply with tax, accounting, anti-fraud and other applicable regulatory requirements.
  • Consent — where required by law for specific processing, such as certain marketing communications or non-essential cookies, which you can withdraw at any time.

5. How we use personal data

We use personal data to: provide, operate and maintain the Service; process transactions and send related communications (e.g. invoices, service notices); authenticate accounts and secure the platform; provide customer support; monitor, troubleshoot and improve the Service; detect and prevent fraud, abuse and violations of our Terms of Use; and comply with legal and regulatory obligations, including those imposed on us by payment processors and telecommunications carriers.

6. Payment data

When you make a payment, your payment details are collected and processed directly by our payment processors — Stripe, PayPal, Przelewy24 and PayU — under their own privacy policies and security standards (including PCI DSS for card data). We do not store full card numbers or payment credentials on our own servers. We receive limited transaction metadata from these processors (such as payment status, amount, and a masked reference) to reconcile orders, provide receipts, issue refunds, and prevent fraud.

7. Cookies and similar technologies

We use strictly necessary cookies to operate the website and Service (e.g. session and security cookies), and, where applicable, analytics cookies to understand site usage. Non-essential cookies are only set with your consent, which you can manage through our cookie banner or your browser settings. See our [Cookie Policy / cookie banner] for details.

8. Sharing of personal data

We do not sell personal data. We share personal data only with:

  • Payment processors (Stripe, PayPal, Przelewy24, PayU) to process payments and refunds;
  • Telecommunications carriers and messaging aggregators, solely to deliver messages a Customer has instructed us to send;
  • Hosting, infrastructure and IT service providers who process data on our behalf under written data processing agreements;
  • Professional advisers and authorities, where necessary to comply with a legal obligation, enforce our Terms of Use, or protect our rights, safety, or property, or those of our Customers or the public.

Where personal data is transferred outside the European Economic Area, we rely on adequacy decisions, Standard Contractual Clauses, or other safeguards recognized under applicable data protection law.

9. Our role as a data processor

For recipient contact data that a Customer submits to send messages through the Service, we process that data solely on the Customer's documented instructions, for the purpose of delivering the Customer's communications and providing delivery reporting. We do not use recipient data for our own marketing and do not combine it with data from other Customers. Customers remain responsible for having a valid legal basis (such as consent or another lawful basis under applicable anti-spam and data protection law) for contacting their own recipients.

10. Data security

We apply technical and organizational measures appropriate to the sensitivity of the data we process, including encryption of traffic in transit, access controls, two-factor authentication for accounts, and regular review of our security practices. No system is completely secure; if we become aware of a breach affecting your personal data, we will notify you and any applicable authority as required by law.

11. Data retention

We retain personal data for as long as your Account is active or as needed to provide the Service, plus any additional period required to comply with legal, tax, accounting or dispute-resolution obligations. Recipient contact data submitted by a Customer is retained for as long as instructed by that Customer, or deleted/anonymized within [X days] of Account closure, whichever is earlier, subject to legally required retention periods (e.g. transaction records for tax purposes).

12. Your rights

Subject to applicable law (including the GDPR for individuals in the European Economic Area and the UK), you may have the right to: access the personal data we hold about you; request correction of inaccurate data; request erasure of your data; restrict or object to certain processing; request data portability; and withdraw consent at any time where processing is based on consent. To exercise these rights, contact us at info@nexum-rise.com. If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority (in the EEA) or with [LOCAL DATA PROTECTION AUTHORITY, e.g. UODO in Poland].

If you are an end recipient who received a message sent through the Service by one of our Customers and wish to exercise a data-subject right, please contact that Customer directly, as they are the data controller for that communication; we will assist our Customer in responding to your request as required by applicable law.

13. Children's privacy

The Service is intended for business use and is not directed at individuals under the age of 18. We do not knowingly collect personal data from children.

14. Changes to this Policy

We may update this Policy from time to time to reflect changes in our practices or legal requirements. We will post the updated Policy on this page with a revised "Last updated" date and, for material changes, provide additional notice by email or through the dashboard.

15. Contact us

Questions about this Privacy Policy, or requests to exercise your data protection rights, can be sent to info@nexum-rise.com or by post to [FULL REGISTERED BUSINESS ADDRESS]. [If applicable: "Our Data Protection Officer can be reached at [DPO EMAIL]."]

← Back to home

NEXUMRISE
HomeServicesSMS campaignsContactsTerms of UsePrivacy Policyinfo@nexum-rise.com

© NEXUM RISE. All rights reserved.