1. Data controller
Identity: Stefany Alejandra Cesar Funes
Tax ID (NIE): Z1026100Y
Address: Calle Murta 19, Paterna, Valencia, Spain.
General email: info@nexolicit.com
Service-specific channel: privacidad@nexolicit.com
Service website: nexolicit.com
Stefany Alejandra Cesar Funes acts as controller with regard to the website, accounts, company profile, subscriptions, matching, alerts, user support, and its own commercial activities. When it provides professional services on behalf of a client and processes data according to their instructions, the role and conditions will be governed by the contract and, where applicable, by a data processing agreement.
2. Privacy contact
No Data Protection Officer has been appointed because it has not been determined that appointment is mandatory for this activity. Questions and the exercise of rights are handled via privacidad@nexolicit.com. If circumstances make appointment mandatory, this policy will be updated with the relevant contact details.
3. Who this applies to
This policy applies to visitors, people who create or manage an account, users invited by a company, contacts requesting information, blog subscribers, paying customers, and representatives or professionals whose data is shared in a commercial relationship with NexoLicit.
The service is aimed primarily at companies, self-employed professionals (autónomos) and professionals. A business account may contain data from multiple people. The company that invites users must inform them and ensure it has a valid basis to share their data.
4. Categories of data
- Identification and contact: first name, last name, email, phone, role, company, language and preferences.
- Account and security: identifier, password hash, authentication, sessions, IP, device, access events, recovery and anti-fraud controls.
- Company profile: legal name, tax ID (NIF), trade name, website, sector, CPV, territories, invoicing ranges and headcount, capabilities, technologies, experience, accreditations, restrictions, amounts and preferences.
- Product usage: searches, filters, alerts, favorites, exclusions, notes, assignments, corrections, interactions with recommendations and configuration.
- Contracting and billing: plan, period, tax address, invoices, payment status, transaction identifiers and support. Full card details are processed by Stripe and are not stored in NexoLicit.
- Support and communications: messages, incidents, files the user provides and communication logs.
- Marketing: consent, source, date, channel, preferences, opens or clicks when legally enabled and consent exists for the necessary technologies.
- Data from public sources: information from notices, files/expedientes, contracting authorities, awardees, representatives or professional contacts published by official portals, limited to what is necessary to inform about contracting.
- Interactions with AI: queries, documents or fragments sent, answers, rating, corrections and metadata needed for security and improvement. The user will be warned not to enter unnecessary personal data, secrets or unauthorized information.
5. Purposes, legal bases and retention
| Processing | Purpose | Legal basis | Indicative retention |
|---|---|---|---|
| Website and forms | Handle inquiries, display content and maintain security. | Consent or pre-contractual measures; legitimate interest in security. | Inquiry: up to 24 months; if it leads to a relationship, during that period and within liability timeframes. |
| Registration and account | Create, authenticate and manage the account and its users. | Performance of the contract or pre-contractual measures. | While it is active and up to 5 years after closure for liability purposes; blocked data when applicable. |
| Profile and matching | Personalize results, apply filters and generate explained affinity. | Performance of the requested service. | While the account is active; deletion or anonymization after closure and during the operational recovery period. |
| Alerts and operational communications | Send opportunities, security, billing and essential changes. | Contractual performance and, where applicable, a legal obligation. | During the relationship; delivery logs according to need and security. |
| Trial and subscription | Manage access, renewals, cancellations, payments and taxes. | Contract and legal obligations. | Invoices and commercial documentation: up to 6 years, without prejudice to tax deadlines or other applicable periods. |
| Email marketing | Send updates, promotions and associated services. | Consent; exceptionally, prior relationship for similar own services when permitted by the LSSI and always with easy opt-out. | Up to withdrawal or objection; evidence of consent and suppression list entries during the period necessary to demonstrate compliance. |
| Commercial recommendations in the app | Show related own services connected with an opportunity, clearly differentiated from the technical result. | Legitimate interest in offering related own services, balanced against the user’s rights; objection at any time. | Preference while the account exists; analytical events in minimized format. |
| Non-essential analytics | Measure usage and improve conversion. | Cookie consent or equivalent technologies. | According to the cookie inventory and provider configuration. |
| Support | Resolve incidents, prevent abuse and maintain evidence. | Contract and legitimate interest in security and defense. | Up to 5 years when liability may exist; minor incidents, shorter period. |
| AI | Extract, classify, summarize and assist the user. | Service performance; consent when an optional function requires it. | NexoLicit retains queries, answers and metadata while they are necessary to provide, protect and audit the function, applying minimization. The provider’s technical retention is subject to the configuration and contract of its API. Its use for training other models is not authorized unless express information and a valid basis are provided. |
| Public sources | Aggregate, normalize and link contracting information. | Legitimate interest in providing a business information service and lawful reuse of public information. | During their information/historical usefulness, with update, rectification and objection mechanisms where applicable. |
6. Profiling, matching and automated decisions
NexoLicit may evaluate affinity between the company profile and an opportunity using rules, statistical models or AI. It may use activity, CPV, territory, amounts, capabilities, stated experience, exclusions and interactions with results.
The output is an indicative recommendation. By itself, it does not produce legal effects nor does it determine eligibility, solvency, price, presentation or award. The user must review the official source and the tender documents (pliegos). Where feasible, the interface will show the main factors, missing data, confidence and correction paths.
No special categories of data will be used for profiling opportunities. The user can disable learning based on interactions and request intervention or review regarding errors that affect the service.
7. Commercial communications
The marketing checkbox in registration will be separate, optional and not pre-ticked. Creating an account or enjoying the trial will not depend on accepting it. Consent will cover exclusively the channels and categories described in the text shown to the user.
Each promotional email will include a simple and free opt-out method. Withdrawal does not affect communications necessary for security, account, billing or requested alerts. NexoLicit will maintain a minimal suppression list so it does not contact anyone who has objected.
8. Source of data
Data is obtained directly from the user, from the company that invites them, from their interactions and from technical providers. Information about tenders comes from public platforms and bulletins, interfaces, downloads or reuse mechanisms that are allowed. Each listing must identify the source and link to the original.
If a public source contains professional contact details, they will only be processed in the informational context of contracting. Requests for rectification will be checked against the source; the official document will not be changed, but the index may be corrected, the display may be limited, or the relevant authority may be notified.
9. Recipients and processors
Personal data is not sold. Only the necessary providers may access it, subject to a contract and protective measures, as well as public administrations, courts or authorities when a legal obligation exists.
| Provider or category | Data processed | Purpose |
|---|---|---|
| Vercel | IP, headers and requests to the website | Frontend hosting, CDN and delivery security. |
| Cloudflare | DNS, IP and technical metadata | DNS, connectivity, protection and availability. |
| Infrastructure and PostgreSQL contracted by the owner | Account, profile, usage, tenders and technical logs | API, database, backups and service operation. |
| Stripe | Billing, customer and transaction data | Checkout, subscriptions, invoicing and fraud prevention. NexoLicit does not store the complete card number. |
| Resend | Name, email and transactional content | Account messages, security, alerts and service. |
| Klaviyo | Name, email, consent, preferences and interaction | Activation communications and marketing when a legal basis exists. |
| OpenAI | Matching profile query and summarized opportunity fields | Contextual search and explanation of results. The context is minimized and secrets must not be sent. |
Additional information about processors, sub-processors and guarantees may be requested by writing to privacidad@nexolicit.com.
10. International transfers
Some technology providers, in particular Vercel, Stripe, Klaviyo, OpenAI or their sub-processors, may process data from the United States or other countries. When processing leaves the European Economic Area, an adequacy decision, a valid adherence to the EU-U.S. Data Privacy Framework where applicable, standard contractual clauses, or another safeguard under Chapter V of the GDPR is required, together with additional measures when necessary.
Information about the safeguard applicable to each provider may be requested at privacidad@nexolicit.com.
11. Security
Risk-proportionate measures will be applied: encryption in transit, robust passwords and secure hashing, MFA for sensitive functions, environment segregation, least-privilege, audit logs, backups, updates, vulnerability management, provider controls, abuse prevention and incident response.
The user is responsible for safeguarding credentials, controlling guests and reporting suspicious access. No system is completely infallible; incidents will be handled according to the plan and applicable notification obligations.
12. Rights
The person may request access, rectification, deletion, restriction, objection, portability when applicable and withdrawal of consent. They may also object at any time to marketing and raise observations about profiling.
Requests must be sent to privacidad@nexolicit.com, indicating the right and the information needed to locate the data. Proof of identity may be requested if there are reasonable doubts about identity. Responses will be provided within the legal timeframe, informing of any extension.
They may also file a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos). It is recommended to contact NexoLicit first in order to try to resolve the matter.
13. Minors and intended use
The service is intended for professionals and is not designed for children under fourteen years of age. Accounts must not be created on behalf of minors, and minors’ data must not be entered in profiles, documents or queries unless there is legitimate need, authorization and specific controls.
14. Opt-out, blocking, backups and anonymization
When closing an account, access will be disabled and, where applicable, an export period will be offered. Data will be deleted or anonymized after the recovery period, unless there is an obligation to retain data, to defend claims, to address fraud or non-payments. Backup copies are overwritten according to their cycle, with a standard maximum ordinary period of 90 days, unless legally required exceptional retention applies.
Blocked data will not be used for ordinary purposes. Anonymization will be irreversible and will be verified to prevent reasonable re-identification.
15. Changes and version
The policy may be updated due to product changes, providers or regulations. Material changes will be communicated through reasonable means and, if they require new consent, the affected function will remain disabled until it is obtained. The version and date will remain visible.
16. Contact
Privacy and rights: privacidad@nexolicit.com
General contact: info@nexolicit.com
Controller: Stefany Alejandra Cesar Funes, Calle Murta 19, Paterna, Valencia, Spain.