Legal
Privacy Policy
How Nemexio collects, uses, shares and protects personal data, including our cookie policy and the data processing terms that apply when we handle your customers' data on your behalf.
Last updated: 23 September 2026
1. Who we are
Nemexio Ltd ("Nemexio", "we", "us") operates the Nemexio service.
This policy explains how we handle personal data in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003 (PECR) and, where applicable, the EU GDPR.
For any privacy question or to exercise your rights, contact our privacy team at privacy@nemexio.com or by post to our registered office, marked "Data Protection".
2. Our role: controller and processor
We act as a controller for personal data about our website visitors, account holders, Authorised Users, prospects and suppliers — we decide how and why it is used.
We act as a processor for personal data contained in Customer Data (for example the names and email addresses of your customers, main contractors and their accounts staff, and data synchronised from your accounting software). For that data, our customer (the business using Nemexio) is the controller, and we process it only on their documented instructions. See "Data we process on your behalf" below.
3. Personal data we collect
- Identity and contact data: name, business email, phone number, job title, business name and trading address.
- Account data: login credentials (passwords are stored only in hashed form), social sign-in identifiers from Google or Microsoft, role in the payment chain, preferences and settings.
- Billing data: billing contact, billing address, VAT number and payment history. Card details are collected and stored by our payment processor Stripe; we never see or store full card numbers.
- Usage and technical data: IP address, device and browser type, operating system, pages visited, features used, timestamps, referring URL, and error logs.
- Communications data: messages you send to support, survey responses and feedback.
- Marketing data: your marketing preferences and interactions with our emails.
- Customer Data (as processor): invoice, application and notice details, project references, amounts, dates, Debtor names and contact details, reminder content and delivery status, and accounting records synchronised through Integrations.
We do not intentionally collect special category data (such as health, ethnicity or religious beliefs) or criminal offence data. Please do not include such data in Customer Data.
4. How we collect it
- Directly from you when you register, complete onboarding, add invoices or projects, contact us or subscribe.
- Automatically through cookies and similar technologies when you use our website and app.
- From third parties you connect or authorise: Google or Microsoft (sign-in), Xero, QuickBooks, Sage and FreeAgent (accounting data), and Stripe (payment status).
- From publicly available sources such as Companies House, where relevant to verify a business.
5. Purposes and lawful bases
- To create and manage your Account and provide the Service — performance of a contract (Art. 6(1)(b)).
- To calculate statutory deadlines, generate and send Reminders on your behalf — performance of a contract with our customer; we act as processor for Debtor data.
- To take payments, issue invoices and manage your Subscription — performance of a contract and legal obligation (tax and accounting records, Art. 6(1)(c)).
- To provide customer support and communicate service updates — performance of a contract and legitimate interests.
- To secure the Service, detect and prevent fraud, spam and abuse — legitimate interests (Art. 6(1)(f)) and legal obligation.
- To analyse usage and improve the Service, including creating aggregated, de-identified statistics — legitimate interests.
- To send marketing about our own similar services to existing customers (soft opt-in) or to prospects who have consented — legitimate interests / consent, in line with PECR.
- To comply with legal obligations, respond to lawful requests from authorities, and establish, exercise or defend legal claims — legal obligation and legitimate interests.
- Non-essential cookies — consent.
Where we rely on legitimate interests, we have balanced our interests against your rights and freedoms. You can ask us for more information about this assessment.
6. Data we process on your behalf (Data Processing Terms)
These Data Processing Terms form part of our Terms of Service and apply where we process personal data as processor for you. They meet the requirements of Article 28 UK GDPR.
- Subject matter and duration: provision of the Service for the term of your Subscription plus the post-termination export period.
- Nature and purpose: hosting, storage, synchronisation, calculation of payment deadlines, generation and sending of Reminders, reporting and support.
- Types of personal data: names, business email addresses, phone numbers, job titles, and financial information about invoices and payments linked to identifiable individuals (e.g. sole traders).
- Categories of data subjects: your customers (including private individuals), payers, main contractors, clients, suppliers and their staff; your Authorised Users.
- Instructions: we process personal data only on your documented instructions (including through your configuration of the Service), unless required by law, in which case we will inform you unless legally prohibited.
- Confidentiality: everyone authorised to process the data is bound by confidentiality obligations.
- Security: we implement appropriate technical and organisational measures as described in the Security section.
- Sub-processors: you give general authorisation for us to use the sub-processors listed below. We will notify you of intended changes at least 14 days in advance, giving you the opportunity to object; if you reasonably object and we cannot accommodate it, you may terminate the affected Service. We impose equivalent data protection obligations on each sub-processor and remain liable for them.
- Assistance: we will assist you, taking into account the nature of processing, in responding to data subject requests and in meeting your obligations on security, breach notification, data protection impact assessments and prior consultation.
- Breaches: we will notify you without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting your data, with the information reasonably available to us.
- Deletion or return: at the end of the Service, we will delete or return the personal data at your choice, and delete existing copies unless retention is required by law.
- Audit: we will make available information necessary to demonstrate compliance and allow for audits, which may be satisfied by our providing current security documentation or third-party certifications; on-site audits require 30 days' notice, are limited to once a year and are at your cost.
- International transfers: we will not transfer the data outside the UK unless appropriate safeguards are in place as described below.
As controller, you are responsible for having a lawful basis for processing Debtor data, for providing any required privacy information to your Debtors, and for the lawfulness of your instructions.
7. If you received a reminder through Nemexio
If you received a payment email sent through Nemexio, it was sent on behalf of the business named in the email and in its subject line, which is the controller of your data. That business decided to contact you about an amount it believes is owed for work or services it supplied, usually relying on the performance of its contract with you or its legitimate interests.
If you are a private individual, reminders sent through Nemexio are limited to 3 per invoice, at least 10 days apart, by email only, and never add interest or fees. Nemexio does not negotiate or collect payment. If you dispute the invoice, are in financial difficulty or would prefer to be contacted another way, please contact the business directly using the details in the email.
Please direct questions about the debt, or requests to exercise your data protection rights, to that business. If you contact us, we will pass your request to them promptly and assist them in responding. We will record email delivery events (such as delivered, bounced or opened, where available) to operate the Service.
8. Accounting integrations
When you connect Xero, QuickBooks, Sage or FreeAgent, we receive OAuth access tokens that allow us to read (and, where you enable it, update) the records needed for the Service. We do not receive your password for those services. Tokens are encrypted at rest and you can revoke access at any time from Nemexio or from the provider.
We only request the minimum scopes necessary, we do not sell data obtained through these integrations, and we do not use it to train generalised AI models. Use of data received from third-party APIs complies with the respective provider's developer terms.
10. International transfers
We aim to store Customer Data in the UK or the European Economic Area. Where personal data is transferred to a country without UK adequacy regulations, we use appropriate safeguards such as the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or the UK Extension to the EU-US Data Privacy Framework, together with a transfer risk assessment and supplementary measures where needed. You may request a copy of the relevant safeguards.
11. How long we keep data
- Account data: for the life of your Account and up to 12 months after closure, to handle queries and re-activation.
- Customer Data: for the life of your Subscription, plus a 30-day export period, then deleted from live systems; backup copies are overwritten within a further 35 days.
- Billing and transaction records: 6 years after the end of the financial year to which they relate, as required by UK tax and company law.
- Reminder logs: for the life of the invoice record in your Account, so you have evidence of the communications sent. You can export them at any time; they are erased when you delete your Account.
- Closure record: when you delete your Account we erase all business data, reminder history, connections, team, accountant access and referrals at once. We keep only a minimal record (a one-way hashed reference to your email, the date and version of your reminder authorisation, and the number of reminders sent) for 6 years, the limitation period for claims, as evidence that reminders were sent with your authorisation.
- Support correspondence: 3 years from last contact.
- Marketing data: until you unsubscribe or object, then kept on a suppression list so we do not contact you again.
- Security logs: up to 12 months.
We may keep data longer where required to comply with law, resolve disputes or enforce our agreements.
12. Security
We use appropriate technical and organisational measures to protect personal data, including encryption in transit (TLS) and at rest, hashed passwords, role-based access controls, least-privilege access for staff, logical separation of customer accounts, monitoring and logging, regular backups, vulnerability management, and staff confidentiality and training.
Application data is hosted on the Base44 platform, whose technical infrastructure and physical security are independently audited and hold ISO 27001 and SOC 2 Type II certifications.
No system is completely secure. You are responsible for keeping your credentials safe and for the security of your own devices and networks.
13. Personal data breaches
We maintain an incident response procedure. Where a breach is likely to result in a risk to individuals, we will notify the Information Commissioner's Office within 72 hours of becoming aware of it, and affected individuals without undue delay where the risk is high. Where we act as processor, we notify the relevant customer as described in the Data Processing Terms.
14. Your rights
Subject to conditions and exemptions in the law, you have the right to:
- be informed about how your data is used;
- access your personal data and receive a copy;
- have inaccurate data corrected and incomplete data completed;
- have data erased in certain circumstances;
- restrict processing in certain circumstances;
- data portability — receive data you provided in a structured, machine-readable format;
- object to processing based on legitimate interests, and to object at any time to direct marketing;
- withdraw consent at any time, without affecting processing already carried out;
- not be subject to a decision based solely on automated processing that produces legal or similarly significant effects.
We will respond within one month of receipt, extendable by two further months for complex or numerous requests. We may need to verify your identity. Requests are free unless manifestly unfounded or excessive.
15. Automated calculations
The Service automatically calculates statutory deadlines and labels the legal position of invoices. These are decision-support tools for our customers; they do not by themselves make decisions with legal or similarly significant effects on individuals. Decisions to chase, pause or escalate remain with the business using the Service.
17. Marketing communications
We send business-to-business marketing only where permitted by PECR. Every marketing email includes an unsubscribe link, and you can opt out at any time. Service and transactional messages (such as billing notices, security alerts and changes to terms) are not marketing and will still be sent while you have an Account.
18. Children
The Service is intended for businesses and is not directed at anyone under 18. We do not knowingly collect personal data from children.
19. Third-party websites
Our website may link to third-party websites, such as GOV.UK or accounting providers. We are not responsible for their privacy practices; please read their policies.
20. Changes to this policy
We may update this policy from time to time. We will post the updated version with a new "last updated" date and, where changes are material, notify account holders by email or in the Service before they take effect.
21. Complaints
If you have concerns about our use of your data, please contact us first so we can try to resolve them. You also have the right to complain to the Information Commissioner's Office (ICO), the UK supervisory authority: ico.org.uk, helpline 0303 123 1113, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF. If you are in the EEA, you may contact your local supervisory authority.
22. Contact
Nemexio Ltd. Privacy enquiries: privacy@nemexio.com. General legal enquiries: legal@nemexio.com.