Back

Compliance

NxCreate's compliance posture and data handling standards

GDPR — General Data Protection Regulation

NxCreate is committed to compliance with the EU General Data Protection Regulation (GDPR) for users in the European Economic Area. Key commitments: • Lawful basis for processing is established for all data operations (contract, legitimate interest, or consent) • Data subject rights (access, erasure, portability, rectification) are honoured within 30 days • A Data Processing Agreement (DPA) is available on request for business customers • We maintain records of processing activities as required by Article 30 • Our infrastructure providers operate under EU Standard Contractual Clauses for cross-border transfers To request a DPA or exercise your GDPR rights, contact [email protected].

Data Residency

By default, user account data and bot logs are stored in EU-based data centres (Frankfurt, Germany). Users on the Business plan may request US-only data residency for specific use cases. All data in transit is encrypted with TLS 1.2+. Data at rest is encrypted with AES-256. Backups are encrypted and stored in geographically separate regions.

Payment Card & Financial Data

NxCreate does not store, process, or transmit full payment card data. All card payments are handled directly by our PCI-DSS Level 1 compliant payment processor. NxCreate stores only tokenized payment references. Cryptocurrency payments (USDT) are processed non-custodially — funds go directly to the destination wallet and NxCreate does not hold user funds at any time.

Telegram Platform Compliance

All bots deployed through NxCreate must comply with Telegram's Terms of Service and Bot API usage policies. NxCreate does not facilitate: • Mass unsolicited messaging or spam • Bots designed to scrape user data from Telegram • Impersonation of Telegram or other services • Distribution of prohibited content Bots found to violate Telegram's policies will be suspended immediately upon detection or report.

Security Practices

NxCreate maintains a formal security programme that includes: • Annual third-party penetration testing • Continuous vulnerability scanning of infrastructure • Role-based access controls with principle of least privilege • Multi-factor authentication required for all internal systems • Incident response plan with defined RTO/RPO targets • Responsible disclosure programme — [email protected] Bot execution environments are isolated via containerisation. No bot can access another bot's resources, logs, or secrets.

Subprocessors

NxCreate uses the following categories of subprocessors to deliver the Service: • Cloud infrastructure (compute, storage, networking) • Transactional email delivery • Payment processing • Uptime monitoring and alerting • Error tracking and observability An up-to-date list of named subprocessors is available on request at [email protected]. Business plan customers will be notified of material subprocessor changes 30 days in advance.

Export Controls

NxCreate complies with applicable export control laws and regulations. The Service may not be used by individuals or entities located in countries subject to comprehensive sanctions, or by parties listed on applicable denied-party lists. Users are responsible for ensuring their use of the Service complies with the laws of their jurisdiction.

Contact & Requests

For compliance enquiries, DPA requests, security disclosures, or regulatory matters: Email: [email protected] Security issues: [email protected] Privacy matters: [email protected] Telegram: @NxCreate We aim to respond to all compliance enquiries within 5 business days.