1. Data controller
Identity: Stefany Alejandra Cesar Funes
Tax ID (NIE): Z1026100Y
Address: Calle Murta 19, Paterna, Valencia, Spain.
General email: info@nexolicit.com
Service-specific channel: privacidad@nexolicit.com
Service website: nexolicit.com
Stefany Alejandra Cesar Funes acts as controller with regard to the website, accounts, company profile, subscriptions, matching, alerts, user support, and its own commercial activities. When it provides professional services on behalf of a client and processes data according to their instructions, the role and conditions will be governed by the contract and, where applicable, by a data processing agreement.
2. Privacy contact
No Data Protection Officer has been appointed because it has not been determined that appointment is mandatory for this activity. Questions and the exercise of rights are handled via privacidad@nexolicit.com. If circumstances make appointment mandatory, this policy will be updated with the relevant contact details.
3. Who this applies to
This policy applies to visitors, people who create or manage an account, users invited by a company, contacts requesting information, blog subscribers, paying customers, and representatives or professionals whose data is shared in a commercial relationship with NexoLicit.
The service is aimed primarily at companies, self-employed professionals (autónomos) and professionals. A business account may contain data from multiple people. The company that invites users must inform them and ensure it has a valid basis to share their data.
4. Categories of data
- Identification and contact: first name, last name, email, phone, role, company, language and preferences.
- Account and security: identifier, password hash, authentication, sessions, access events and recovery. To prevent duplicate free trials, the normalized email, domain, company, optional tax ID, IP and device are converted into pseudonymized HMAC fingerprints; those signals are not stored in plain text in the anti-fraud record.
- Company profile: legal name, tax ID (NIF), trade name, website, sector, CPV, territories, invoicing ranges and headcount, capabilities, technologies, experience, accreditations, restrictions, amounts and preferences.
- Product usage: searches, filters, alerts, favorites, exclusions, notes, assignments, corrections, interactions with recommendations and configuration.
- Contracting and billing: plan, period, tax address, invoices, payment status, transaction identifiers and support. Full card details are processed by Stripe and are not stored in NexoLicit.
- Support and communications: messages, incidents, files the user provides and communication logs.
- Experience analytics: URL, referrer, IP address, browser, device, resolution, page dimensions and interactions such as clicks, scrolling, pointer movement, resizing and navigation, used to create heatmaps and masked session replays. Microsoft Clarity only loads after analytics consent and uses strict masking. This implementation does not use the identify API or send names, email addresses, company names, tax IDs or form contents.
- Marketing, measurement and attribution: consent, source, date, channel, campaign, URL and page visited, referrer, standard visit or registration events, cookie identifiers such as
_fbpand, where applicable,_fbc, IP, browser, device and preferences. NexoLicit does not send through Meta Pixel the person’s name, email, company, tax ID or fields entered in the registration form. - Data from public sources: information from notices, files, contracting or granting authorities, awarded entities or beneficiaries and professional contacts published by official portals, limited to what is necessary to inform about procurement and public aid and subject to the reuse restrictions applicable to personal data.
- Interactions with AI: queries, documents or fragments sent, answers, rating, corrections and metadata needed for security and improvement. The user will be warned not to enter unnecessary personal data, secrets or unauthorized information.
5. Purposes, legal bases and retention
| Processing | Purpose | Legal basis | Indicative retention |
|---|---|---|---|
| Website and forms | Handle inquiries, display content and maintain security. | Consent or pre-contractual measures; legitimate interest in security. | Inquiry: up to 24 months; if it leads to a relationship, during that period and within liability timeframes. |
| Registration and account | Create, authenticate and manage the account and its users. | Performance of the contract or pre-contractual measures. | While it is active and up to 5 years after closure for liability purposes; blocked data when applicable. |
| Trial abuse prevention | Prevent multiple free trials, resolve matches and enable manual review. | Legitimate interest in preventing fraud and protecting the service, using minimized and pseudonymized signals. | Up to 24 months from the request, unless additional retention is needed for claims or fraud. |
| Profile and matching | Personalize results, apply filters and generate explained affinity. | Performance of the requested service. | While the account is active; deletion or anonymization after closure and during the operational recovery period. |
| Alerts and operational communications | Send opportunities, security, billing and essential changes. | Contractual performance and, where applicable, a legal obligation. | During the relationship; delivery logs according to need and security. |
| Trial and subscription | Manage access, renewals, cancellations, payments and taxes. | Contract and legal obligations. | Invoices and commercial documentation: up to 6 years, without prejudice to tax deadlines or other applicable periods. |
| Email marketing | Send updates, promotions and associated services. | Consent; exceptionally, prior relationship for similar own services when permitted by the LSSI and always with easy opt-out. | Up to withdrawal or objection; evidence of consent and suppression list entries during the period necessary to demonstrate compliance. |
| Contextual commercial recommendations (feature not active) | If enabled in the future, show a help option related to a technical need in the tender, separate from the organic result. | This processing is not currently performed. Before activation, the applicable legal basis will be documented and communicated and appropriate controls will be provided. | No preferences or events are currently retained for this purpose. Any future retention period will be disclosed before activation. |
| Non-essential analytics and user experience | Measure usage, detect friction and improve conversion through Google Analytics 4 and Microsoft Clarity heatmaps and masked session replays. | Consent for cookies or equivalent technologies, withdrawable at any time through the panel. | According to the cookie inventory and provider configuration. Microsoft normally retains session replays for 30 days and click and heatmap data for up to 9 months. |
| Advertising measurement and attribution | Measure visits and completed registrations, attribute campaigns and evaluate advertising performance through Google Ads and Meta Pixel. | Consent for marketing cookies or equivalent technologies. Advertising measurement remains blocked until consent is given. | According to the cookie inventory and provider configuration. |
| Support | Resolve incidents, prevent abuse and maintain evidence. | Contract and legitimate interest in security and defense. | Up to 5 years when liability may exist; minor incidents, shorter period. |
| AI | Extract, classify, summarize and assist the user. | Service performance; consent when an optional function requires it. | NexoLicit retains queries, answers and metadata while they are necessary to provide, protect and audit the function, applying minimization. The provider’s technical retention is subject to the configuration and contract of its API. Its use for training other models is not authorized unless express information and a valid basis are provided. |
| Public sources | Aggregate, normalize and link procurement and public-aid information. | Legitimate interest in providing a business information service and lawful reuse of public information, subject to the specific limitations applicable to personal data. | During its informational and historical usefulness, with update, rectification, restriction and objection mechanisms where applicable. |
6. Profiling, matching and automated decisions
NexoLicit may evaluate affinity between the company profile and an opportunity using rules, statistical models or AI. It may use activity, CPV, territory, amounts, capabilities, stated experience, exclusions and interactions with results.
The output is an indicative recommendation. By itself, it does not produce legal effects or determine eligibility for or award of public aid, solvency, price, submission or a tender award. The user must review the official source and, as applicable, the tender documents, regulatory terms and call. Where feasible, the interface will show the main factors, missing data, confidence and correction paths.
No special categories of data will be used for profiling opportunities. The user can disable learning based on interactions and request intervention or review regarding errors that affect the service.
7. Commercial communications
The marketing checkbox in registration will be separate, optional and not pre-ticked. Creating an account or enjoying the trial will not depend on accepting it. Consent will cover exclusively the channels and categories described in the text shown to the user.
Each promotional email will include a simple and free opt-out method. Withdrawal does not affect communications necessary for security, account, billing or requested alerts. NexoLicit will maintain a minimal suppression list so it does not contact anyone who has objected.
8. Source of data
Data is obtained directly from the user, from the company that invites them, from their interactions and from technical providers. Tender and public-aid information comes from platforms, bulletins, national or regional systems and other public portals through permitted interfaces, downloads or reuse mechanisms. Each listing must identify the source and link to the original.
If a public source contains personal or professional contact data, it will be processed only where there is a valid purpose and legal basis and with the applicable minimization and reuse limitations. Where the source restricts reuse to specific purposes—as is the case for certain personal data published in public-aid systems—it will not be incorporated for commercial purposes and may be excluded, anonymized or restricted. Requests for rectification, restriction or objection will be checked against the source; the official document will not be changed, but the index may be corrected, display restricted or the competent authority notified.
9. Recipients and processors
Personal data is not sold. Only the necessary providers may access it, subject to a contract and protective measures, as well as public administrations, courts or authorities when a legal obligation exists.
| Provider or category | Data processed | Purpose |
|---|---|---|
| Vercel | IP, headers and requests to the website | Frontend hosting, CDN and delivery security. |
| Cloudflare | DNS, IP and technical metadata | DNS, connectivity, protection and availability. |
| hCaptcha | Challenge response, IP and necessary technical metadata | Automation detection and protection of registration and recovery. |
| Infrastructure and PostgreSQL contracted by the owner | Account, profile, usage, tenders, public aid and technical logs | API, database, backups and service operation. |
| Stripe | Billing, customer and transaction data | Checkout, subscriptions, invoicing and fraud prevention. NexoLicit does not store the complete card number. |
| Resend | Name, email and transactional content | Account messages, security, alerts and service. |
| Klaviyo | Name, email, consent, preferences and interaction | Activation communications and marketing when a legal basis exists. |
| Microsoft Ireland Operations Limited | Online identifier, IP address, browser, device, URL, referrer and navigation interactions, only after analytics consent and with strict masking | Microsoft Clarity: heatmaps, masked session replays, friction diagnostics and website improvement. Advertising storage remains denied and personalized identification is not used. See the Microsoft Privacy Statement. |
| Meta Platforms Ireland Limited | Online identifiers, IP, browser, device, URL, referrer, campaign and standard visit or registration events | Advertising measurement, campaign attribution, reporting and audience features through Meta Business Tools, only after marketing consent. |
| OpenAI | Matching profile query and summarized opportunity fields | Contextual search and explanation of results. The context is minimized and secrets must not be sent. |
Additional information about processors, sub-processors and guarantees may be requested by writing to privacidad@nexolicit.com.
10. International transfers
Some technology providers, in particular Vercel, Stripe, Klaviyo, Google Ireland Limited, Microsoft Ireland Operations Limited and Microsoft Corporation, Meta Platforms Ireland Limited, OpenAI or their sub-processors, may process data from the United States or other countries. When processing leaves the European Economic Area, an adequacy decision, a valid adherence to the EU-U.S. Data Privacy Framework where applicable, standard contractual clauses, or another safeguard under Chapter V of the GDPR is required, together with additional measures when necessary.
Information about the safeguard applicable to each provider may be requested at privacidad@nexolicit.com.
11. Security
Risk-proportionate measures will be applied: encryption in transit, robust passwords and secure hashing, MFA for sensitive functions, environment segregation, least-privilege, audit logs, backups, updates, vulnerability management, provider controls, abuse prevention and incident response.
The user is responsible for safeguarding credentials, controlling guests and reporting suspicious access. No system is completely infallible; incidents will be handled according to the plan and applicable notification obligations.
12. Rights
The person may request access, rectification, deletion, restriction, objection, portability when applicable and withdrawal of consent. They may also object at any time to marketing and raise observations about profiling.
Requests must be sent to privacidad@nexolicit.com, indicating the right and the information needed to locate the data. Proof of identity may be requested if there are reasonable doubts about identity. Responses will be provided within the legal timeframe, informing of any extension.
They may also file a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos). It is recommended to contact NexoLicit first in order to try to resolve the matter.
13. Minors and intended use
The service is intended for professionals and is not designed for children under fourteen years of age. Accounts must not be created on behalf of minors, and minors’ data must not be entered in profiles, documents or queries unless there is legitimate need, authorization and specific controls.
14. Opt-out, blocking, backups and anonymization
When closing an account, access will be disabled and, where applicable, an export period will be offered. Data will be deleted or anonymized after the recovery period, unless there is an obligation to retain data, to defend claims, to address fraud or non-payments. Backup copies are overwritten according to their cycle, with a standard maximum ordinary period of 90 days, unless legally required exceptional retention applies.
Blocked data will not be used for ordinary purposes. Anonymization will be irreversible and will be verified to prevent reasonable re-identification.
15. Changes and version
The policy may be updated due to product changes, providers or regulations. Material changes will be communicated through reasonable means and, if they require new consent, the affected function will remain disabled until it is obtained. The version and date will remain visible.
16. Contact
Privacy and rights: privacidad@nexolicit.com
General contact: info@nexolicit.com
Controller: Stefany Alejandra Cesar Funes, Calle Murta 19, Paterna, Valencia, Spain.