Legal
Privacy Policy
Last updated: 29 August 2026
1. Who we are
CorpAi (“we”, “us”) operates the Operational Intelligence Platform at nexoracorpai.com and related applications. This policy explains how we handle personal data and organisational content you entrust to us.
2. Data we collect
We may collect:
- Account data — name, email, phone, company, role, and authentication details.
- Workspace content — messages, tasks, commitments, CRM records, and configurations you create or connect.
- Channel metadata — WhatsApp and email connection status, delivery receipts, and integration settings.
- Usage and device data — product analytics, IP address, browser type, and security logs needed to operate the service.
3. How we use data
We process data to provide the platform, operate the Proprietary Intelligence Engine on authorised conversations, improve reliability and security, communicate about the service, and meet legal obligations. We do not sell customer message content. We do not use your conversation data to train third-party models for unrelated purposes.
4. Google user data
CorpAi integrates with Gmail so a business’s inbound and outbound customer emails appear alongside their WhatsApp conversations in one place.
When you connect a Gmail account, CorpAi requests read-only access to your mailbox (the gmail.readonly scope) via Google OAuth. We use this access only to:
- Detect new messages in the connected mailbox and copy the sender, subject, and body of customer-facing emails into your organisation’s CorpAi workspace as CRM conversation records.
- At your organisation’s discretion, generate an advisory summary of a message’s likely intent using an AI model. This is a suggestion only — it is never used to send, delete, or modify anything in your Gmail account, and it never acts on a conversation without a person choosing to.
CorpAi’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We do not use Gmail data for advertising.
- We do not allow humans to read Gmail data except with your explicit consent, to comply with applicable law, to investigate abuse, or with your explicit permission for support.
- We do not transfer Gmail data to third parties except as necessary to provide the CorpAi features you requested (for example, our cloud hosting and AI providers, under contract), to comply with applicable law, or as part of a merger or acquisition subject to this policy.
- We do not use Gmail data to train generalised or third-party AI/ML models.
You can revoke CorpAi’s access to your Gmail account at any time from your CorpAi mail connection settings, or directly from your Google Account permissions. Revoking access stops future syncing; previously synced conversation records remain in your workspace, under this policy’s normal retention rules, until you delete them.
5. Sharing
We share data with sub-processors who help us run the service (hosting, authentication, messaging, email delivery), and when required by law. See our Data Processing Agreement for the current sub-processor list.
6. Retention & security
We retain data for as long as your organisation maintains an account and as needed for backups, dispute resolution, and legal compliance. We use encryption in transit and at rest, role-based access controls, and audit logging. More detail is available on our Security page.
7. Your rights
Depending on applicable law, you may request access, correction, deletion, or export of personal data, and you may object to or restrict certain processing. Organisation admins control workspace content. Contact contact@nexoracorpai.com for privacy requests.
8. Contact
Questions about this policy: contact@nexoracorpai.com. General inquiries: Contact us.