Help Centre Contact Sales
Sign in
Noxtill
Skip to content
PRIVACY

Privacy Policy

Controller and processor roles, data categories, purposes, legal bases, disclosures, retention, privacy rights and international transfers.

Version
1.0
Last updated
October 10, 2026
Reading time
6 min

Noxtill LLC · Privacy Policy · Version 1.0 · noxtill.com/legal/privacy

AT A GLANCE

  • Relationship and roles

    For Noxtill website accounts, direct marketing, billing and support, Noxtill commonly acts as controller/business.

  • Data categories

    Contact and account identity, emails, business profiles, authentication events, subscription metadata, transaction reference IDs, support requests, technical logs, IP/device identifiers, cookie identifiers with…

  • Purposes and lawful basis

    Provide requested services, authenticate users, secure accounts, prevent abuse, bill subscriptions, honor contracts, comply with records laws, communicate service notices, operate support and (where permitted) offer…

  • Sharing and subprocessors

    Disclose only necessary data to actual contracted service providers, processors, authorized integrations, relevant payment service providers, professional advisers and legally required authorities.

  • Retention and rights

    Retain only while necessary for stated purposes and legally mandated records.

  • International transfers and security

    Cross-border processing must use appropriate protections, transfer assessments and contracts where legally required.

Noxtill LLC is an Arizona limited liability company with public business address 4539 N 22ND ST STE R, Phoenix, AZ 85016, United States.

This Privacy Policy describes personal data Noxtill handles as a controller for its website, account administration, sales, support, security, product analytics, billing-related administration, marketing, recruitment and similar business purposes.

For Customer Content processed inside a customer workspace on the customer’s documented instructions—such as end-customer records, staff/payroll data, messages, bookings, documents and transaction records—Noxtill generally acts as a processor/service provider and the customer is the controller/business. Those processor activities are governed by the DPA.

This Policy may apply to website visitors, prospects, customer owners/admins, authorized users, support contacts, event attendees, suppliers, partners and job applicants. Individuals whose data exists only inside a customer’s workspace should ordinarily direct requests first to that customer because Noxtill processes that data on the customer’s instructions.

Depending on the relationship, we may process identity/contact data; business and employment information; account credentials and MFA/security metadata; subscription/transaction references; support communications; device/browser/IP and log data; product usage/feature telemetry; cookie/preferences; sales and marketing engagement; fraud/security indicators; integration metadata; feedback and information voluntarily submitted.

Noxtill should minimize collection and avoid requesting government identifiers, special-category data, precise location or financial-account credentials unless a specific feature or law requires them. Full payment-card details should be handled by the Merchant of Record/payment provider rather than directly stored by Noxtill unless a separately compliant architecture is implemented.

Customer Content may include customer profiles, purchases, orders, products, bookings, loyalty, credit balances, messages, reviews, service requests, staff profiles, attendance, payroll inputs, field-service locations, delivery data, call recordings/transcripts, contracts, signatures, uploaded files, website forms, accounting records, supplier records, inventory, workflows, AI prompts/outputs and related operational data.

The customer determines why this data is processed and is responsible for lawful collection, notice and instructions.

Noxtill may obtain controller data directly from an individual, a customer organization, automated use of the Services, authorized connected providers, Stripe and other payment transaction parties to administer subscriptions, and support or sales interactions.

Where privacy law requires notice for indirectly obtained data, Noxtill should provide it within the required period unless an exemption applies.

AI features may process prompts, conversations, customer records and context that an authorized user chooses or that a configured workflow lawfully makes available. Noxtill should use minimum-necessary context, tool permissions and audit controls.

Recommended Noxtill commitment: Customer Content will not be used to train generalized third-party/foundation models or a generalized Noxtill model unless the customer expressly opts in under a separate clear program. Product improvement using telemetry should be minimized and de-identified/aggregated where feasible.

AI-generated output and material automated decisions are addressed in the AI Transparency Policy. Where law requires meaningful information about automated decision-making/profiling, Noxtill and the customer should provide appropriate explanations and human-review rights.

Noxtill may process message content, sender/recipient identifiers, templates, timestamps, delivery/read/failure status, consent/opt-out evidence, assignment, recordings/transcripts and provider metadata to deliver messaging and voice features.

When the customer controls the communication purpose, Noxtill processes data on the customer’s instructions. Noxtill uses its own controller communications for account notices, security, support, service announcements and its own marketing subject to applicable choices.

Noxtill may use strictly necessary technologies for authentication, security, session continuity and consent records, plus analytics/functional/advertising technologies where enabled. In jurisdictions requiring prior consent, non-essential technologies should remain disabled until valid permission. Applicable universal opt-out signals should be honored where legally required and technically applicable.

Noxtill may share controller data with appropriately contracted service providers, payment processors and financial institutions (including Stripe when used), professional advisers, authorities where legally necessary, and transaction counterparties under appropriate safeguards. Merchant customer data remains subject to the customer’s instructions and applicable DPA.

Noxtill does not sell personal data for money. If an activity constitutes “sale”, “sharing” or targeted advertising under an applicable U.S. state law, Noxtill must provide required opt-out mechanisms and honor applicable universal opt-out signals.

The Subprocessors page must list actual processors used to deliver Customer Content processing, their purpose and processing region where appropriate. Payment/Merchant-of-Record providers, communications platforms or customer-selected third-party apps may act as independent controllers for some data and should not be mislabeled as subprocessors.

Noxtill is based in the United States and may use providers in multiple countries. Where EEA personal data is transferred without an adequacy decision, the DPA should use a valid mechanism such as the European Commission Standard Contractual Clauses and supplementary safeguards where required. UK transfers should use an applicable UK mechanism. Other jurisdictions may require additional contractual or consent safeguards.

Noxtill keeps personal data only as long as needed for the applicable contract, purpose, security, fraud prevention, dispute, tax/accounting, legal or backup requirement.

Recommended product targets, subject to production validation:

  • active Customer Content: subscription term;
  • expired trial or unpaid/suspended workspace: 30-day recovery/export window;
  • rolling backups: up to 90 days;
  • security/audit logs: risk-based period;
  • tax/payment/legal records: legally justified period;
  • marketing suppression: as long as needed to honor the opt-out.

Noxtill uses administrative, technical and organizational safeguards designed to protect data. Public claims must reflect verified controls. Requirements include tenant isolation, role/field-level access, encryption in transit, secure secrets, MFA capability, audit logging, vulnerability management, backups and incident response.

No method is perfectly secure and Noxtill cannot guarantee absolute security.

Depending on jurisdiction, individuals may have rights to access/know, correct, delete, restrict or object, obtain portability, withdraw consent, opt out of sale/sharing/targeted advertising or certain profiling, limit certain sensitive uses, appeal a denial and complain to a regulator.

Requests about Noxtill-controlled data may be sent to privacy@noxtill.com or a privacy request form. For Customer Content, Noxtill may direct the requester to the relevant customer and assist that customer under the DPA.

Where Noxtill is subject to the CCPA or another state privacy law, the Privacy Policy should identify categories collected during the required look-back period, purposes, recipient categories, sensitive-data treatment, retention criteria, request methods, authorized-agent process and legally required opt-out/limit controls.

If Noxtill engages in an activity legally defined as sale/sharing/targeted advertising, it should implement required opt-out and universal opt-out recognition such as GPC where applicable.

Noxtill should not claim CCPA statutory applicability if it does not meet the relevant thresholds; it may voluntarily extend similar rights while clearly distinguishing statutory status.

Where applicable, Noxtill should identify controller/representative/DPO information if legally required, lawful bases, legitimate interests, transfers, retention, rights and supervisory-authority complaint routes.

Consent must be as easy to withdraw as to give. Applicable rights may include access, rectification, erasure, restriction, portability and objection, plus safeguards for certain solely automated decisions with legal or similarly significant effects.

Where PIPEDA or substantially similar law applies, Noxtill should support meaningful consent, accountability, access/correction, safeguards, appropriate purposes and breach obligations.

Country addenda should be activated according to actual market entry and counsel review. A U.S.-based contract does not override non-waivable local rights.

Noxtill is business software and is not directed to children. Customers must not use Noxtill to collect children’s data in violation of COPPA or other child-privacy laws.

Noxtill maintains incident-response procedures. If an incident triggers contractual or statutory notification duties, Noxtill should notify affected customers and/or authorities as required by applicable law and the DPA.

Noxtill should archive material versions. New processing purposes should be communicated before the new processing begins where required. If consent is the legal basis and the change exceeds the original permission, fresh consent should be obtained.

Privacy/data rights: privacy@noxtill.comSupport: support@noxtill.comNoxtill LLC, 4539 N 22ND ST STE R, Phoenix, AZ 85016, United States

Questions about this document: support@noxtill.com · Privacy: privacy@noxtill.com · Noxtill LLC, 4539 N 22nd St, Ste R, Phoenix, AZ 85016, United States.

Related documents