Privacy Policy
Key points:
- One Nextia account works across the Nextia apps. Your account, business and team records are shared across the apps your business uses.
- Nextia’s databases and file storage are hosted on Microsoft Azure in the Canada Central region.
- Nextia never holds your password: sign-in is handled by Microsoft Entra External ID.
- For a business’s own customers and clients, Nextia processes information on that business’s behalf — the business is accountable for it.
- Some service providers involve transfers to the United States. They are named in the service-provider section below.
1. Who we are and what this policy covers
Nextia is operated by 1496096 Canada Inc., doing business as Nextia AI (“Nextia”, “we”, “us”). This policy covers your Nextia account and the Nextia platform — your account, business record, team and roles, subscriptions and billing, shared clients and cross-product insights — and the additional information handled by each Nextia app. Each product site publishes the portions that apply to that product.
2. Our role: accountable organization or service provider
- For the account data of a business owner and their staff, Nextia is the organization accountable for that information.
- For a business’s own customer data — for example a person who books an appointment, a client who receives an invoice, or a vendor on a receipt — Nextia is a service provider processing that information on the business’s behalf. The business remains accountable for it, so questions about it should go to that business first.
Nextia AI’s Privacy Officer is accountable for this policy. Questions, requests and complaints may be sent to privacy@nextia-ai.com.
3. Where your data is stored
- Nextia’s databases (Azure Database for PostgreSQL Flexible Server) and file storage (Azure Blob Storage) are in Microsoft Azure’s Canada Central region.
- Sign-in runs on Microsoft Entra External ID, in a directory created in Canada Central.
- Nextia’s own configuration does not replicate your data outside Canada. Third-party services that a business chooses to connect are different, and are named in the service-provider section.
Document reading (Azure AI Document Intelligence) runs in Microsoft Azure’s Canada Central region. The AI assistant and AI categorization use Azure OpenAI through a resource in Canada Central, where the service’s stored data stays; Microsoft’s Global deployment type may process prompts and responses in other Azure regions.
4. What we collect about you when you sign in
- A stable internal identifier, your primary email address and whether it is verified, your display name, your preferred language and, optionally, a phone number.
- Which sign-in method asserted your account (email and password, Google, Microsoft or Apple), and the email address that provider gave us when the sign-in method was linked.
- Which businesses you belong to, your role in each, and pending invitations sent to your email address.
Your account is keyed to your sign-in identity, not your email address. That is why changing your email address does not create a new account.
5. How the Nextia platform uses information
- Shared clients. A client record entered in one Nextia app is visible in the business’s other Nextia apps. A business’s clients are shared across that business’s Nextia apps — not across businesses.
- Cross-product insights. The NextiaBusiness home aggregates figures from the business’s Nextia apps. Nothing customer-identifying leaves the business.
- Weekly summary email. This email is opt-in and off by default.
- Billing. Subscriptions are billed through Stripe. Nextia stores subscription status and price identifiers, never card numbers.
6. The audit trail, and support access to your account
Nextia records the identifier and email address of the person who performed each consequential action. This audit trail is designed to outlive the account: if you ask us to erase your account, your account is scrubbed, but the audit record of what the account did is kept for the audit retention period (see “How long we keep information”).
A Nextia staff member can, with a recorded reason, act inside a business account — for example to help with a support request. Every such session is recorded. A business owner may request the record of support sessions by emailing privacy@nextia-ai.com.
7. How long we keep information
- In NextiaTax, an automated daily process deletes audit-log entries older than 365 days (the default setting), and permanently removes documents, transactions and assistant conversations that were deleted and have passed the soft-delete retention window.
- The other Nextia apps do not yet run an equivalent automated deletion process. Nextia does not promise automatic deletion across all apps.
Deleted NextiaTax documents, transactions and assistant conversations remain recoverable for 30 days before permanent deletion. Tax and billing records that Nextia must retain for legal, accounting or dispute purposes may be kept for up to six years. Audit and security logs are kept only as long as needed for security, accountability and legal obligations, normally no more than 24 months.
8. Your rights: access, correction and deletion
These rights are implemented differently in each Nextia app today:
- Access and portability. In NextiaTax you can export your own data as a file, and a separate accountant export package is available. NextiaInvoices has a data export. NextiaBooking and the Nextia platform do not yet offer a self-service export; ask the privacy contact.
- Deletion. You may request deletion of your account. We verify and complete valid requests within 30 days unless law, security, another person’s rights or a documented legal hold requires us to preserve specific information.
- Correction. You can correct your information by editing it in the app.
How to delete your Nextia account across all three apps: Delete your Nextia account.
For any request that the apps do not handle directly, contact the Privacy Officer. We respond to access and correction requests within 30 days, subject to any extension or exception permitted by applicable law.
9. How we protect information
- Every request for a business’s data passes a permission check tied to that business. Each app has a tenant-isolation test suite that fails the build if data can be read across businesses.
- Nextia never holds passwords: authentication is delegated to Microsoft Entra External ID and the identity providers (Google, Microsoft, Apple, or email and password).
- Tokens for connected calendars and meeting providers, and payment-provider credentials, are encrypted at rest. The apps refuse to start in a production environment without a real encryption key.
- Nextia’s logging rules forbid logging passwords, tokens, authentication assertions, payment credentials, or client data beyond identifiers.
11. NextiaTax — what it collects in addition
- Receipts and financial documents. Uploaded files are stored in Azure Blob Storage; extracted transactions, vendors and categories are stored in the database. These are among the most sensitive records Nextia holds.
- Automated reading of documents. Uploaded documents are sent to Microsoft Azure AI services (Azure Document Intelligence and, when enabled, Azure OpenAI) under Nextia’s Azure subscription so their details can be extracted. When the assistant is enabled, conversation content is sent to the same services. Microsoft states in its Azure Direct Models privacy documentation that prompts, outputs, embeddings and training data are not available to OpenAI or other customers and are not used to improve provider models.
- Bank connections. If bank feeds are enabled and a business connects one, Plaid is the provider and holds the banking credentials; Nextia receives transactions, not credentials. Plaid’s end-user privacy policy is available at plaid.com/legal/end-user-privacy-policy.
- Receipts by email. A business may forward receipts to a Nextia address. Messages are received through Cloudflare Email Routing and passed to Nextia. Anything in a forwarded message is processed, including whatever else was in the email thread.
- WhatsApp. WhatsApp messaging is not enabled at launch. Before enabling it, we will disclose the information sent to Meta and add the consent and opt-out controls required for that channel.
- Retention. People may need tax records years later, for example for a reassessment. See “How long we keep information”.
12. NextiaInvoices — what it collects in addition
- A business’s clients. Names, addresses, contact details, custom fields, invoices, credit notes, refunds, statements and payment records. Nextia processes these on behalf of the business, which is accountable to its own clients: clients should contact the business first.
- The client portal. A business can send a client a link that shows that client’s invoices, quotations, receipts, statements and related payment status without a Nextia account. The link works like a key: anyone who holds it can see those records. The business can revoke the link from NextiaInvoices.
- Documents produced. Generated PDFs and uploaded files are stored in Azure Blob Storage.
- Payments. Where a business uses a payment provider, card data goes to that provider, never to Nextia; Nextia stores provider references and payment status.
- Email delivery. Invoices, receipts and statements are sent through Azure Communication Services, and delivery events are recorded.
13. NextiaBooking — what it collects in addition
NextiaBooking collects information from members of the public who book with a business and have no Nextia account.
- The public booking page. Anyone can book without an account. A booking collects your name, email address and phone number, your answers to the questions the business added to its booking form, and any files the form asks for. The business chooses those questions and is accountable for asking only what it needs.
- Confirmations and reminders. Transactional confirmations, changes, cancellations and appointment reminders are sent by email through Azure Communication Services. The business controls reminder settings. A recipient may ask the business to stop optional reminders; essential service messages may still be sent. SMS and WhatsApp reminders are not enabled at launch.
- Calendar connections. When a staff member connects Google Calendar or Microsoft Outlook (Microsoft Graph), Nextia reads busy times and creates events. Nextia requests read access to calendars and access to events for Google, and read/write calendar access with offline access for Microsoft. The access token is stored encrypted and can be revoked by disconnecting the calendar in NextiaBooking or from the provider’s own security settings.
- Meeting links. Google Meet and Microsoft Teams links are created through the connected calendar. Zoom is a separate connection with its own authorization.
- Waitlists and group sessions. A booking can affect the availability other people see, but nothing that identifies a customer is shown on the public booking page.
- Payments and deposits. Booking does not process customer deposits or payments at launch. If this feature is enabled later, payment-card data will go directly to the business’s payment provider and not to Nextia, and this policy will be updated before launch.
14. Service providers (sub-processors)
Nextia uses these service providers. Providers marked “if connected” only receive information when a business chooses to connect them.
| Provider | What it receives | Where |
|---|---|---|
| Microsoft Azure | Hosting, databases, file storage, message queues, logs | Canada Central |
| Microsoft Entra External ID | Sign-in identity and email address | Canada Central |
| Azure Communication Services | Recipient address and message content for email | Canada Central |
| Azure AI Document Intelligence (NextiaTax) | Uploaded documents | Canada Central |
| Azure OpenAI (NextiaTax) | Document content; assistant conversations when enabled | Canada Central (resource and stored data); prompts may be processed in other Azure regions |
| Cloudflare | DNS; email routing for forwarded receipts (NextiaTax) | Global |
| Google (if connected) | Calendar busy times and events (NextiaBooking) | Google’s regions |
| Microsoft Graph (if connected) | Calendar busy times and events (NextiaBooking) | Microsoft’s regions |
| Zoom (if connected) | Meeting creation, updates and deletion (NextiaBooking) | Zoom’s regions |
| Stripe | Subscription and payment data; card data never reaches Nextia | United States / global |
| Plaid (if connected) | Bank connection; holds banking credentials (NextiaTax) | United States / global |
| Meta — WhatsApp Business (if enabled) | Phone number and message content | United States / global |
Stripe is used for subscriptions and may process information in the United States or other countries. Plaid and Meta are listed for transparency but their bank-feed and WhatsApp features are not enabled at launch. When information is processed outside Canada it may be subject to the laws of that jurisdiction. We assess providers and use contractual and technical safeguards appropriate to the information.
15. Changes to this policy and contact
- This policy is effective October 4, 2026. We will post revisions with a new effective date and give notice in the service or by email before a material change takes effect when required by law.
- Send questions or complaints first to privacy@nextia-ai.com. If we do not resolve your concern, you may complain to the Office of the Privacy Commissioner of Canada or, if applicable, the Commission d’accès à l’information du Québec.
- Nextia AI is operated by 1496096 Canada Inc. Privacy requests and requests for a current mailing address may be sent to the Privacy Officer at privacy@nextia-ai.com.