Privacy Policy
Last updated 2026-08-12 · Effective 2026-08-12
This policy explains how nexistxt (“we”, “us”) handles personal data in connection with the nexistxt messaging platform. It is written to meet the Digital Personal Data Protection Act, 2023 (“DPDP Act”), the Information Technology Act, 2000 and the rules made under them.
1The two roles, and why the distinction matters
We handle personal data in two distinct capacities, and your rights differ depending on which applies.
As a Data Fiduciary — for the account data of our own customers: the names, work emails, phone numbers and billing details of the businesses that sign up to use the platform. We decide why and how that data is processed.
As a Data Processor — for the recipient data our customers upload: the mobile numbers they send messages to. We process those numbers only on our customer’s documented instructions. The customer is the Data Fiduciary for that data and is responsible for having a lawful basis to send to it. If you received a message from us and want it to stop, see section 9.
2What we collect
Account data. Company name, contact name, work email, mobile number, GSTIN where provided, and the password hash for your login. We never store your password itself.
Compliance data. Your DLT entity ID, registered sender IDs and approved content templates, because Indian regulation requires us to verify these before transmitting.
Recipient data. Mobile numbers you upload, the message content you send, and the delivery outcome the operator returns. Uploaded numbers are stored so that campaigns can be sent and reported on.
Transaction data. Wallet balance, payments, invoices and the ledger of every debit and credit. Card and bank details are handled by our payment provider and are never stored on our systems.
Technical data. IP address, browser type, timestamps and API request logs, kept for security and abuse investigation.
3Why we process it
- To provide the service you have signed up for — sending messages, reporting on them, and billing you.
- To meet legal obligations under TRAI regulations, including DLT verification and retention of transmission records.
- To prevent fraud, abuse and unsolicited commercial communication.
- To notify you about your account: low balance, failed payments, service incidents.
We do not sell personal data. We do not use recipient data uploaded by one customer for any purpose connected to another customer, and we do not use it to build marketing lists of our own.
4Consent and lawful basis
For account data, we rely on your consent given at sign-up and on the necessity of processing to perform our contract with you. Where the DPDP Act permits processing for a legitimate use — such as complying with a legal obligation — we rely on that.
For recipient data, consent is the customer’s responsibility. By uploading numbers you confirm that you have a lawful basis to contact them and that the traffic complies with your DLT registration. We enforce template matching, but we cannot verify the provenance of a list.
5Who we share it with
Telecom operators and aggregators, to deliver your messages. This is inherent to the service — a message cannot be sent without passing the recipient number to a carrier.
Payment providers, to process wallet top-ups.
Regulators and law enforcement, where we are legally required to disclose.
Infrastructure providers, for hosting and monitoring, under contracts that restrict them to processing on our instructions.
6Where it is stored
Platform data is stored on servers located in India. Where a sub-processor operates outside India, we transfer data only to countries not restricted by the Central Government under section 16 of the DPDP Act, and under contractual safeguards.
7How long we keep it
- Message and delivery records: retained as required by TRAI regulations, and no longer than necessary thereafter.
- Uploaded contact lists: retained while your account is active. You can delete a list at any time and we remove it.
- Financial records: retained for eight years, as required by tax and companies legislation.
- Account data: erased on closure of your account, except where retention is legally required.
8Security
Passwords are hashed and never recoverable. Credentials for payment and carrier integrations are encrypted at rest with authenticated encryption. Access to production data is restricted and logged. Traffic to the platform is served over TLS.
No system is perfectly secure. If a personal data breach occurs, we will notify the Data Protection Board of India and each affected Data Principal, as required by section 8(6) of the DPDP Act.
9Your rights
If you are our customer, you may ask us to:
- confirm what personal data of yours we process, and give you a summary of it;
- correct anything inaccurate or incomplete, or complete anything missing;
- erase personal data that is no longer needed for the purpose it was collected;
- nominate another person to exercise these rights if you die or become incapacitated;
- withdraw consent, which we will act on as easily as it was given.
If you received a message and did not want it: the sender is our customer, not us, and we cannot make decisions about their list on their behalf. Reply STOP to the message where a stop facility is offered, register with the National Customer Preference Register at 1909 or on the DND app, and write to our grievance officer at available on request. We will add your number to our platform-wide suppression list and pass the complaint to the sender.
10Children
The platform is for business use and is not directed at children. We do not knowingly process the personal data of anyone under eighteen, and we do not undertake tracking, behavioural monitoring or targeted advertising directed at children.
11Cookies
We use a single session cookie to keep you signed in, and local storage for your interface preferences such as light or dark theme. We do not use advertising or cross-site tracking cookies. Blocking the session cookie will prevent you from signing in.
12Grievances
Our Grievance Officer, appointed under the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 and section 13 of the DPDP Act, is:
available on request
available on request
available on request
We acknowledge complaints within 24 hours and resolve them within 15 days. If you are not satisfied with our response, you may complain to the Data Protection Board of India.
13Changes
We will post any change on this page and update the date above. Where a change materially affects how we handle your data, we will notify you by email before it takes effect.
Questions about this document: support@nexistxt.com