Noxtill LLC is an Arizona limited liability company with public business address 4539 N 22ND ST STE R, Phoenix, AZ 85016, United States.
This Privacy Policy describes personal data Noxtill handles as a controller for its website, account administration, sales, support, security, product analytics, billing-related administration, marketing, recruitment and similar business purposes.
For Customer Content processed inside a customer workspace on the customer’s documented instructions—such as end-customer records, staff/payroll data, messages, bookings, documents and transaction records—Noxtill generally acts as a processor/service provider and the customer is the controller/business. Those processor activities are governed by the DPA.
This Policy may apply to website visitors, prospects, customer owners/admins, authorized users, support contacts, event attendees, suppliers, partners and job applicants. Individuals whose data exists only inside a customer’s workspace should ordinarily direct requests first to that customer because Noxtill processes that data on the customer’s instructions.
Depending on the relationship, we may process identity/contact data; business and employment information; account credentials and MFA/security metadata; subscription/transaction references; support communications; device/browser/IP and log data; product usage/feature telemetry; cookie/preferences; sales and marketing engagement; fraud/security indicators; integration metadata; feedback and information voluntarily submitted.
Noxtill should minimize collection and avoid requesting government identifiers, special-category data, precise location or financial-account credentials unless a specific feature or law requires them. Full payment-card details should be handled by the Merchant of Record/payment provider rather than directly stored by Noxtill unless a separately compliant architecture is implemented.
Customer Content may include customer profiles, purchases, orders, products, bookings, loyalty, credit balances, messages, reviews, service requests, staff profiles, attendance, payroll inputs, field-service locations, delivery data, call recordings/transcripts, contracts, signatures, uploaded files, website forms, accounting records, supplier records, inventory, workflows, AI prompts/outputs and related operational data.
The customer determines why this data is processed and is responsible for lawful collection, notice and instructions.
Noxtill may obtain controller data directly from an individual, a customer organization, automated use of the Services, authorized connected providers, Stripe and other payment transaction parties to administer subscriptions, and support or sales interactions.
Where privacy law requires notice for indirectly obtained data, Noxtill should provide it within the required period unless an exemption applies.
Where GDPR/UK GDPR or similar laws require a legal basis, purposes may rely on:
- performance of a contract for account/service delivery;
- legitimate interests for security, fraud prevention, reliability and ordinary B2B administration where not overridden;
- legal obligation for tax, sanctions, law-enforcement or regulatory duties;
- consent for optional marketing, cookies or other processing where consent is required; and
- another lawful basis available under applicable law.
Purposes include providing accounts/services, authenticating users, processing instructions, administering subscriptions, securing infrastructure, preventing abuse, support, service notices, improving reliability/usability, analytics, recordkeeping, enforcing agreements and legal compliance.
AI features may process prompts, conversations, customer records and context that an authorized user chooses or that a configured workflow lawfully makes available. Noxtill should use minimum-necessary context, tool permissions and audit controls.
Recommended Noxtill commitment: Customer Content will not be used to train generalized third-party/foundation models or a generalized Noxtill model unless the customer expressly opts in under a separate clear program. Product improvement using telemetry should be minimized and de-identified/aggregated where feasible.
AI-generated output and material automated decisions are addressed in the AI Transparency Policy. Where law requires meaningful information about automated decision-making/profiling, Noxtill and the customer should provide appropriate explanations and human-review rights.
Noxtill may process message content, sender/recipient identifiers, templates, timestamps, delivery/read/failure status, consent/opt-out evidence, assignment, recordings/transcripts and provider metadata to deliver messaging and voice features.
When the customer controls the communication purpose, Noxtill processes data on the customer’s instructions. Noxtill uses its own controller communications for account notices, security, support, service announcements and its own marketing subject to applicable choices.
The Subprocessors page must list actual processors used to deliver Customer Content processing, their purpose and processing region where appropriate. Payment/Merchant-of-Record providers, communications platforms or customer-selected third-party apps may act as independent controllers for some data and should not be mislabeled as subprocessors.
Noxtill is based in the United States and may use providers in multiple countries. Where EEA personal data is transferred without an adequacy decision, the DPA should use a valid mechanism such as the European Commission Standard Contractual Clauses and supplementary safeguards where required. UK transfers should use an applicable UK mechanism. Other jurisdictions may require additional contractual or consent safeguards.
Noxtill keeps personal data only as long as needed for the applicable contract, purpose, security, fraud prevention, dispute, tax/accounting, legal or backup requirement.
Recommended product targets, subject to production validation:
- active Customer Content: subscription term;
- expired trial or unpaid/suspended workspace: 30-day recovery/export window;
- rolling backups: up to 90 days;
- security/audit logs: risk-based period;
- tax/payment/legal records: legally justified period;
- marketing suppression: as long as needed to honor the opt-out.
Noxtill uses administrative, technical and organizational safeguards designed to protect data. Public claims must reflect verified controls. Requirements include tenant isolation, role/field-level access, encryption in transit, secure secrets, MFA capability, audit logging, vulnerability management, backups and incident response.
No method is perfectly secure and Noxtill cannot guarantee absolute security.
Depending on jurisdiction, individuals may have rights to access/know, correct, delete, restrict or object, obtain portability, withdraw consent, opt out of sale/sharing/targeted advertising or certain profiling, limit certain sensitive uses, appeal a denial and complain to a regulator.
Requests about Noxtill-controlled data may be sent to privacy@noxtill.com or a privacy request form. For Customer Content, Noxtill may direct the requester to the relevant customer and assist that customer under the DPA.
Where Noxtill is subject to the CCPA or another state privacy law, the Privacy Policy should identify categories collected during the required look-back period, purposes, recipient categories, sensitive-data treatment, retention criteria, request methods, authorized-agent process and legally required opt-out/limit controls.
If Noxtill engages in an activity legally defined as sale/sharing/targeted advertising, it should implement required opt-out and universal opt-out recognition such as GPC where applicable.
Noxtill should not claim CCPA statutory applicability if it does not meet the relevant thresholds; it may voluntarily extend similar rights while clearly distinguishing statutory status.
Where applicable, Noxtill should identify controller/representative/DPO information if legally required, lawful bases, legitimate interests, transfers, retention, rights and supervisory-authority complaint routes.
Consent must be as easy to withdraw as to give. Applicable rights may include access, rectification, erasure, restriction, portability and objection, plus safeguards for certain solely automated decisions with legal or similarly significant effects.
Where PIPEDA or substantially similar law applies, Noxtill should support meaningful consent, accountability, access/correction, safeguards, appropriate purposes and breach obligations.
Country addenda should be activated according to actual market entry and counsel review. A U.S.-based contract does not override non-waivable local rights.
Noxtill is business software and is not directed to children. Customers must not use Noxtill to collect children’s data in violation of COPPA or other child-privacy laws.
Noxtill maintains incident-response procedures. If an incident triggers contractual or statutory notification duties, Noxtill should notify affected customers and/or authorities as required by applicable law and the DPA.
Noxtill should archive material versions. New processing purposes should be communicated before the new processing begins where required. If consent is the legal basis and the change exceeds the original permission, fresh consent should be obtained.
Privacy/data rights: privacy@noxtill.comSupport: support@noxtill.comNoxtill LLC, 4539 N 22ND ST STE R, Phoenix, AZ 85016, United States
