Compliance
NxCreate's compliance posture and data handling standards
GDPR — General Data Protection Regulation
NxCreate is committed to compliance with the EU General Data Protection Regulation (GDPR) for users in the European Economic Area.
Key commitments:
• Lawful basis for processing is established for all data operations (contract, legitimate interest, or consent)
• Data subject rights (access, erasure, portability, rectification) are honoured within 30 days
• A Data Processing Agreement (DPA) is available on request for business customers
• We maintain records of processing activities as required by Article 30
• Our infrastructure providers operate under EU Standard Contractual Clauses for cross-border transfers
To request a DPA or exercise your GDPR rights, contact [email protected].
Data Residency
By default, user account data and bot logs are stored in EU-based data centres (Frankfurt, Germany). Users on the Business plan may request US-only data residency for specific use cases.
All data in transit is encrypted with TLS 1.2+. Data at rest is encrypted with AES-256. Backups are encrypted and stored in geographically separate regions.
Payment Card & Financial Data
NxCreate does not store, process, or transmit full payment card data. All card payments are handled directly by our PCI-DSS Level 1 compliant payment processor. NxCreate stores only tokenized payment references.
Cryptocurrency payments (USDT) are processed non-custodially — funds go directly to the destination wallet and NxCreate does not hold user funds at any time.
Telegram Platform Compliance
All bots deployed through NxCreate must comply with Telegram's Terms of Service and Bot API usage policies. NxCreate does not facilitate:
• Mass unsolicited messaging or spam
• Bots designed to scrape user data from Telegram
• Impersonation of Telegram or other services
• Distribution of prohibited content
Bots found to violate Telegram's policies will be suspended immediately upon detection or report.
Security Practices
NxCreate maintains a formal security programme that includes:
• Annual third-party penetration testing
• Continuous vulnerability scanning of infrastructure
• Role-based access controls with principle of least privilege
• Multi-factor authentication required for all internal systems
• Incident response plan with defined RTO/RPO targets
• Responsible disclosure programme — [email protected]
Bot execution environments are isolated via containerisation. No bot can access another bot's resources, logs, or secrets.
Subprocessors
NxCreate uses the following categories of subprocessors to deliver the Service:
• Cloud infrastructure (compute, storage, networking)
• Transactional email delivery
• Payment processing
• Uptime monitoring and alerting
• Error tracking and observability
An up-to-date list of named subprocessors is available on request at [email protected]. Business plan customers will be notified of material subprocessor changes 30 days in advance.
Export Controls
NxCreate complies with applicable export control laws and regulations. The Service may not be used by individuals or entities located in countries subject to comprehensive sanctions, or by parties listed on applicable denied-party lists.
Users are responsible for ensuring their use of the Service complies with the laws of their jurisdiction.
Contact & Requests
For compliance enquiries, DPA requests, security disclosures, or regulatory matters:
Email: [email protected]
Security issues: [email protected]
Privacy matters: [email protected]
Telegram: @NxCreate
We aim to respond to all compliance enquiries within 5 business days.
