Privacy Policy
Last updated: June 2026
1. Who we are
Rexium AI, Lda ("Rexium", "we", "our", "us") is a company incorporated in Portugal (Sociedade por Quotas), NIPC 519476239, with registered office at Travessa do Candal, 21, 4535-324 Paços de Brandão, Santa Maria da Feira, Portugal. We operate the Rexium platform at rexium.ai — including the dashboard, the embeddable AI chat widget, hosted storefronts, the email/audience tools, the invoicing module, and the associated APIs (together, the "Service").
For any privacy matter you can reach us at hello@rexium.ai. We do not currently operate a separate data-protection mailbox — hello@rexium.ai reaches the people responsible for it.
2. Our role: controller vs. processor
Rexium is a B2B platform. Whether we are a "controller" or a "processor" under the GDPR depends on whose data is involved:
- Our customers' account data — we are the controller. When you sign up and run a business on Rexium, we determine how your account, login, billing and usage data are processed.
- Your end-users' data — we are the processor. The personal data your store shoppers, chat visitors and email contacts generate is processed by us strictly on your instructions, to operate the Service for you. You are the controller of that data and are responsible for having a lawful basis, your own privacy notice, and the necessary consents (see our Terms / data-processing terms).
If you interacted with a business that uses Rexium (e.g. a chat widget, an online store, or a newsletter), that business is the controller of your data — please contact them directly to exercise your rights. We will assist them as their processor.
3. Information we collect
Depending on which modules you use, this includes:
- Account data: name, email, password (hashed by our auth provider), organization name, role, and (for the Billing module / Studio partners) legal name, tax ID (NIF/NIPC) and address you enter.
- Business content: knowledge-base documents, product catalogues, pages, media and settings you upload to run your store / chatbot / campaigns.
- Chat data: messages exchanged between your visitors and the AI, plus visitor metadata (page, referrer, device, approximate country).
- Commerce data: for stores in sales mode — orders, buyer name, email, billing/shipping address, order contents and amounts. Card details are handled by Stripe; we never see or store full card numbers.
- Audience (Reach) data: contacts, email addresses, tags, consent state and engagement (opens/clicks) for the campaigns you send.
- Invoicing data: for the Billing module — customer fiscal details and documents needed to issue invoices under Portuguese law.
- Payment metadata: subscription, plan, and payment status from Stripe (no card numbers).
- Usage & logs: feature usage, counts, response times, and technical logs used to run and secure the Service.
4. How we use it & lawful bases
- To provide, operate and secure the Service (performance of contract).
- To process subscriptions and payments (performance of contract; legal obligation for invoicing/accounting).
- To power AI features on your content — chat answers, product/listing generation, campaign suggestions (performance of contract; on your instructions as processor for end-user data).
- To send service emails — invitations, escalation alerts, billing and security notices (legitimate interest / performance of contract).
- To improve the Service through aggregated, anonymized analytics (legitimate interest).
- To comply with legal and tax obligations (legal obligation).
We do not sell personal data, and we do not use your data or your end-users' data for advertising.
5. AI processing
AI features send the relevant content (e.g. a conversation, a product description, a campaign draft) to our AI providers (Anthropic and Google) to generate a response. This content is processed to serve your request and is not used to train the providers' foundation models under our API terms. Enterprise customers may bring their own AI keys (BYOK), in which case the provider relationship is theirs.
6. Subprocessors
We rely on the following processors to run the Service:
- Google Cloud / Firebase — hosting, database (Firestore), authentication, storage, and serverless functions (EU and US regions).
- Anthropic — Claude models for AI responses and generation (US).
- Google Generative AI — embeddings used for search/retrieval (US).
- Stripe — payment processing and merchant payouts (Stripe Connect). See Stripe's Privacy Policy.
- Amazon Web Services (SES) — transactional and campaign email delivery.
- Cloudflare — Turnstile anti-spam for forms.
We may update this list as the Service evolves; material changes are announced as described in section 13.
7. International transfers
Some subprocessors are located outside the EEA (e.g. in the United States). Where personal data is transferred internationally, it is covered by appropriate safeguards such as the European Commission's Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework.
8. Data isolation & multi-tenancy
Each business account (organization) is logically isolated. Your data — content, conversations, orders, contacts and settings — is stored separately and is not accessible to other accounts. We use Google Cloud Firestore with strict security rules to enforce this isolation at the database layer.
9. Data retention
We retain your data for as long as your account is active. When you close your account, associated data is deleted within 30 days, except where we must keep records to meet legal obligations — most notably invoicing and accounting records, which Portuguese law requires us (and merchants) to retain for up to 10 years.
10. Your rights (GDPR)
If you are in the EEA you have the right to access, rectify, erase, port, and restrict or object to the processing of your personal data. To exercise these rights regarding data for which Rexium is the controller, contact hello@rexium.ai. If your request concerns data held by a business that uses Rexium, contact that business (the controller); we will support them as processor. You may also lodge a complaint with the Portuguese supervisory authority (CNPD) or your local authority.
11. Cookies & local storage
The dashboard uses essential cookies for authentication and session management. The embeddable chat widget stores a visitor identifier in the browser to keep a conversation continuous. Hosted storefronts use essential cookies for cart/session and, where required, a consent banner before any non-essential storage. We do not use advertising or cross-site tracking cookies.
12. Security
We apply industry-standard measures: encryption in transit (TLS) and at rest, role-based access control, tenant isolation enforced in the database, secrets held in a managed secret store, and audit logging of sensitive actions. No method of transmission or storage is perfectly secure, but we work to protect your data and to notify you of incidents as required by law.
13. Changes to this policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by email or via a notice in the dashboard. Continued use of the Service after changes take effect constitutes acceptance.
14. Contact
Rexium AI, Lda — Travessa do Candal, 21, 4535-324 Paços de Brandão, Portugal · NIPC 519476239 · Email: hello@rexium.ai.