NexlyFlow
Security
Where your data lives, how it is protected, and who processes it.
Last updated: 10 September 2026
NexlyFlow is a B2B outreach and conversation platform operated by NexlyFlow Pte. Ltd. (UEN 202632611H). This page describes how we protect your data. Enterprise customers can request our Data Processing Agreement and a completed security questionnaire from info@nexlyflow.com.
Where your data lives
- Hosting: dedicated virtual servers operated by Hostinger, located in Malaysia. Data is not replicated outside this region except to the sub-processors listed below.
- Backups: full database and file backups run daily and are kept for 10 days, stored in the same Malaysian data centre.
- Isolation: every customer workspace is a separate tenant. All queries are scoped by tenant ID; there is no shared contact data between customers.
Encryption
- All traffic between your browser, our servers and third-party APIs uses TLS 1.2 or higher (HTTPS only, HSTS enabled).
- Mailbox (SMTP/IMAP) credentials are encrypted at rest with a server-side key that is never stored in the database.
- WhatsApp access tokens are stored encrypted and are never exposed to the browser.
Access control
- Three workspace roles: Owner (everything, including billing), Admin (everything except billing) and Agent (inbox and contacts by default; the Owner decides what else).
- Sign-in by one-time email code or Google Workspace; passwords are optional and never stored in plain text.
- Campaign launches can require Owner/Admin approval; the Owner can revoke launch rights per member.
- Platform staff access to customer workspaces is role-restricted and logged.
Audit and transparency
- Every sign-in, permission change, launch approval, brand-voice change and data export is recorded in the workspace Security log, visible to the Owner on the Account page.
- Outbound messages keep a per-recipient delivery and consent trail (opt-outs, bounces, suppressions).
Your data, your control
- Export: contacts and campaigns can be downloaded as CSV at any time.
- Deletion: Owners can request workspace deletion; data is removed after a grace period. Individual contacts can be erased on request (PDPA / GDPR right to erasure), including from shared lead data.
- Retention: we keep workspace data for as long as the workspace is active; deleted workspaces are purged from production and rotate out of backups on the backup retention schedule.
AI
- AI features (email drafting, reply suggestions, the WhatsApp concierge) are powered by OpenAI’s API. Under OpenAI’s API terms, data sent through the API is not used to train OpenAI models.
- Only the content needed for the specific task is sent (the conversation, the contact’s public company details, your Knowledge Base entries and your brand-voice rules). Mailbox credentials and payment data are never sent to AI providers.
- Automatic replies can be switched off, set to suggestion-only, or limited to out-of-hours by the Owner.
Sub-processors
| Provider | Purpose | Data | Location |
|---|---|---|---|
| Hostinger | Server hosting and backups | All workspace data | Malaysia |
| Meta Platforms (WhatsApp Cloud API) | WhatsApp message delivery | Phone numbers, message content | Global (Meta infrastructure) |
| OpenAI | AI drafting and concierge | Conversation text, Knowledge Base, brand voice | United States |
| Stripe | Payments | Billing contact, card data (held by Stripe only) | Global |
| Optional sign-in | Email address, name | Global |
Operations
- Sending is rate-limited per mailbox and per workspace, with automatic pausing on bounce spikes to protect your sender reputation.
- An emergency stop halts all outbound sending for a workspace or the whole platform within one minute.
- Servers are monitored continuously; security updates are applied on a regular schedule.
Support and incident response
- Enterprise support: response within 4 business hours on business days (GMT+8).
- If we become aware of a security incident affecting your data, we will notify the workspace Owner without undue delay and no later than 72 hours after confirmation, with what happened, what data was involved and what we are doing about it.
Compliance
- We operate under Singapore’s Personal Data Protection Act (PDPA) and support customers’ obligations under the EU/UK GDPR and Malaysia’s PDPA.
- Outbound messaging follows the Singapore Spam Control Act and Do Not Call provisions; every email carries a working unsubscribe link and every WhatsApp contact carries a recorded lawful basis.
- We do not currently hold SOC 2 or ISO 27001 certification. We will share our internal security practices and answer questionnaires on request.
Questions: info@nexlyflow.com
NexlyFlow