Thenexi
Sign in Get started
Terms of ServicePrivacy PolicyCookie PolicyAcceptable Use Policy

On this page

  1. 1. Who is responsible
  2. 2. Data we collect
  3. 3. Why we use it (and legal bases)
  4. 4. Promotional emails
  5. 5. Who we share data with (sub-processors)
  6. 6. International transfers
  7. 7. How long we keep data
  8. 8. Security
  9. 9. Your rights
  10. 10. Cookies
  11. 11. Children
  12. 12. Changes

Legal

Privacy Policy

Effective 9 October 2026 · Thenexi is operated by Glofiz, United Arab Emirates

This Privacy Policy explains how Glofiz (“Thenexi”, “we”) collects and uses personal data when you visit thenexi.com, create an account and use the Thenexi platform. It also explains your rights and how to contact us.

1. Who is responsible

Glofiz, United Arab Emirates, operates Thenexi and is the controller of the personal data described in this policy (your account, billing, support and marketing data). Contact: support@thenexi.com.

When you use Thenexi to run websites, forms and mailboxes, the personal data of your visitors, customers and correspondents is processed on your behalf: you are the controller and we are your processor, under section 5 of our Terms of Service. Visitors of websites built with Thenexi should read the privacy notice of that website.

2. Data we collect

  • Account data: name, email address, password (stored only as a secure hash), organization name, team memberships and roles, email-verification status.
  • Consent records: acceptance of our Terms and Privacy Policy (version and date), your promotional-email choice, when and where it was made, and the IP address it was made from.
  • Billing data: plan, subscription status and payment history. Card details are entered directly with Stripe; we never receive or store your full card number.
  • Domain registrant data: the name, organization, address, phone and email you provide to register a domain, stored encrypted and shared with the registrar as required.
  • Content and configuration: websites, revisions, images, AI conversations, domains, form messages, mailbox names and the content you manage through the Service.
  • Integration credentials: WordPress Application Passwords, cPanel API tokens and mailbox passwords you connect. These are encrypted with authenticated encryption, never shown again and never sent to AI providers.
  • Technical and usage data: IP address, browser and device information, request logs, security events, AI usage amounts and audit history of important actions (for example publishing or deleting).
  • Communications: messages you send to support and your email preferences.

3. Why we use it (and legal bases)

PurposeLegal basis (GDPR)
Create and run your account, provide the features you use, process payments, register domains, send verification codes and service emailsPerformance of our contract with you
Keep the Service secure, prevent fraud and abuse, enforce limits, debug and improve reliabilityLegitimate interests (operating a safe, reliable service)
Generate and edit content with AI when you askPerformance of contract
Send product news and promotional offersConsent (opt-in, withdrawable at any time)
Keep accounting, tax and consent records; respond to lawful requestsLegal obligations

4. Promotional emails

We send promotional emails only if you opted in — for example by ticking the optional box at sign-up. You can withdraw consent at any time with the unsubscribe link in every promotional email or in your account settings, without affecting service emails such as security codes, billing notices and important account messages.

5. Who we share data with (sub-processors)

We do not sell your personal data. We share it only with providers that help us run the Service, under contracts that require them to protect it, and only as needed:

ProviderPurpose
RenderApplication servers (API and background jobs)
MongoDB AtlasDatabase hosting
CloudflareWebsite hosting, CDN, DNS, security, object storage and domain registration
StripePayments, subscriptions and invoices
OpenAIAI generation and editing of content you request
BrevoSending service and account emails (and promotional emails if you opted in)
Email hosting providers (e.g. Migadu or our cPanel hosting provider)Hosting mailboxes you create with Thenexi email

We may also disclose data if required by law, to protect rights and safety, or in connection with a merger or acquisition (with notice to you). Services you connect yourself (for example your WordPress site or cPanel host) receive data under their own terms.

6. International transfers

Our providers may process data outside your country, including in the United States and the European Union. Where personal data from the EEA, UK or Switzerland is transferred to countries without an adequacy decision, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses (and the UK addendum) offered by our providers.

7. How long we keep data

  • Account and content data: while your account is active, then 30 days after closure (for export or reactivation) before deletion from active systems; backups expire on their normal cycle.
  • Billing and tax records: as long as required by law (typically up to 7 years).
  • Consent records: for as long as the consent applies plus the period needed to prove it.
  • Security logs: typically up to 12 months. One-time codes expire after 10 minutes and are deleted within days.

8. Security

We use encryption in transit (HTTPS) and at rest for credentials, secure password hashing, role-based access within organizations, isolation between customers, sandboxed previews, audit logs and least-privilege access for our team. No system is perfectly secure; please use a strong unique password and keep verification codes private.

9. Your rights

Depending on where you live (for example under the EU/UK GDPR or the UAE Personal Data Protection Law), you may have the right to: access your data; correct it; delete it; restrict or object to certain processing (including direct marketing, at any time); receive a copy in a portable format; and withdraw consent at any time without affecting earlier processing. To exercise these rights, email support@thenexi.com from your account email. We will respond within the time required by law (usually one month). If you are in the EEA or UK, you can also complain to your local data-protection authority.

10. Cookies

We use only the cookies and similar storage needed to run the Service, plus optional categories you can accept or reject. See our Cookie Policy.

11. Children

Thenexi is not intended for anyone under 18, and we do not knowingly collect their data. If you believe a child has given us personal data, contact us and we will delete it.

12. Changes

We may update this policy. We will post the new version with a new effective date and notify you of material changes in the app or by email.

Questions? Email support@thenexi.com.

Thenexi
Terms of ServicePrivacy PolicyCookie PolicyAcceptable Use Policy

© 2026 Glofiz