NexusProps NexusProps

Privacy Policy

Last updated: May 16, 2026.

1. Data controller identification

Controller: Álvaro Mauricio Hernandorena Núñez.

Trade name: NexusProps.

Registered address: 18 de Julio 683, Maldonado, Department of Maldonado, Uruguay.

General contact: support@nexusprops.com.

Privacy contact / data protection officer: privacy@nexusprops.com.

Legal contact: legal@nexusprops.com.

Hereinafter referred to as “NexusProps”, “we” or “the controller”.

2. Executive summary

NexusProps is a real-estate CRM offered as a SaaS product. We process personal data of three categories of data subjects:

  1. CRM users: real-estate agents, brokers, and administrative staff of real-estate agencies who log into the platform.
  2. CRM contacts: end clients (buyers, sellers, tenants, owners) whose data is uploaded by our users to manage the real-estate commercial relationship.
  3. Website visitors to www.nexusprops.com.

Our main legal bases are performance of a contract with the real-estate agency that contracts our service, and explicit consent when OAuth permissions are granted to connect external accounts (Google, Microsoft, etc.).

Limited Use: When a user connects a Google account to NexusProps, our use and transfer of information received from Google APIs is governed by the Google API Services User Data Policy, including the Limited Use requirements. See section 6 for details.

3. Information we collect

3.1. Account and usage data (CRM users)

  • Name, email, phone number, profile picture.
  • Access credentials, stored in encrypted form and never in plaintext.
  • Real-estate agency they belong to, assigned role.
  • Technical logs: IP address, user agent, access timestamps, actions performed in the platform.

3.2. Data uploaded by the user (contacts, properties, deals)

  • Contact data: name, email, phone, real-estate preferences, interaction history.
  • Property data: address, characteristics, photos, associated documents.
  • Commercial operation data (deals): amounts, commissions, contracts, notes.

The user acts as primary controller of this data with respect to the data subjects; NexusProps acts as data processor providing the service.

3.3. Email integration data (Email Pro)

When a user chooses to connect a mailbox to NexusProps (via OAuth Google, OAuth Microsoft, or IMAP/SMTP with their own credentials), we collect:

  • Authorization tokens or SMTP/IMAP credentials, stored in encrypted form.
  • Message metadata: sender, recipients, subject, date, thread and message identifiers, labels/folders, read/unread state, presence of attachments.
  • Message bodies: HTML and plain text, only under the terms described in section 6.
  • Attachments: file name, MIME type, size and content, downloaded on demand under the storage policies in section 9.

3.4. Public website data

  • Contact-form data voluntarily submitted by the visitor.
  • Technical cookies required for site operation. We do not use advertising cookies or third-party profiling.

4. Purposes of processing

We process personal data for the following purposes:

  • Provide the contracted CRM service: contact, property and deal management; calendar; internal communications.
  • Synchronize user email with the CRM so that the user can send and receive messages from the platform, link them to contacts/properties/deals, and maintain a unified commercial record.
  • Authenticate and authorize access to the platform.
  • Detect and prevent abuse, fraud or unauthorized use.
  • Comply with legal, tax and contractual obligations.
  • Improve the service through aggregated, anonymized usage metrics.
  • Communicate with the user on operational matters (service notices, changes to terms, security alerts).

We do not use personal data to train general AI models or for personalized advertising. The CRM’s AI features (suggestions, transcriptions, assistant) process data only to return a response to the user invoking them, and the providers we use (OpenAI, Anthropic, Groq, etc.) operate under agreements prohibiting model training on submitted data.

5. Legal basis

In accordance with Uruguay’s Law No. 18.331 on Personal Data Protection and equivalent applicable regulations:

  • Performance of the contract with the real-estate agency client, for all essential CRM operations.
  • Explicit consent of the data subject for specific integrations:
    • Google OAuth connection → consent given through the official Google consent screen.
    • Microsoft OAuth connection → consent given through the official Microsoft consent screen.
    • SMTP/IMAP credentials → manifest consent when entered into the platform.
  • Legitimate interest for security, fraud prevention and service improvement.
  • Legal obligation for retention of tax and accounting records.

OAuth consent can be revoked at any time (see section 11).

6. Google API Services and Limited Use

NexusProps integrates with Google APIs (Gmail API + OAuth 2.0) when a user chooses to connect their Google Workspace or personal Gmail account.

6.1. Requested scopes

Scope Description for the end user
openid, email, profile Identify you on return from the OAuth flow: name, picture, email address.
https://www.googleapis.com/auth/gmail.send Send emails on your behalf from the CRM (compose, reply, forward).
https://www.googleapis.com/auth/gmail.metadata Read only the metadata of your emails (sender, recipients, subject, date, labels). We do not access message bodies through this permission.

We do not request the scopes gmail.readonly, gmail.modify or https://mail.google.com/. This means that, through Google OAuth, NexusProps cannot read message bodies, modify messages, delete messages, or access your Drive, Calendar, Contacts or other Google services.

6.2. Optional message body access via IMAP

If you want NexusProps to display the full body of your messages inside the integrated CRM mail client, you may optionally provide a Google App Password generated at account.google.com/apppasswords. With this credential, NexusProps opens a secure connection to Google's mail server to download the bodies of messages you select.

  • The App Password is stored in encrypted form.
  • This integration is optional; if you do not activate it, NexusProps only shows metadata via OAuth.
  • You can revoke the App Password at any time from your Google account.

6.3. Limited Use disclosure (Google API Services User Data Policy)

NexusProps adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • We do not use Google user data to train, fine-tune, or evaluate generalized AI or machine learning models.
  • We do not transfer Google user data to third parties except to the sub-processors strictly necessary to provide the requested functionality (see section 10), under confidentiality agreements.
  • We do not use Google user data for advertising or personalized marketing.
  • We do not allow human access to Google user data, except in the following limited cases:
    • With the user’s explicit and specific consent.
    • When necessary for security reasons (for instance, abuse investigation).
    • When necessary to comply with applicable law.
    • When data has been aggregated and anonymized for internal operational maintenance.

6.4. Real-time notifications

To keep the inbox synchronized in real time, NexusProps receives change notifications from Gmail through Google's official notification system. These notifications contain only a technical identifier used to query updates via the API; they do not carry message content itself.

7. Microsoft 365 / Microsoft Graph services

NexusProps integrates with Microsoft Graph when a user connects a Microsoft 365, Outlook.com or Exchange Online account.

7.1. Requested permissions

Permission Description
openid, email, profile, User.Read Identify you: name, picture, email address.
Mail.Read Read your mailbox messages to display them in the CRM client.
Mail.Send Send messages on your behalf from the CRM.
Mail.ReadWrite Mark messages as read, move between folders, archive, delete (actions you perform from the CRM).
offline_access Refresh your access token to keep synchronization without prompting login every hour.

7.2. Real-time notifications

To keep real-time synchronization, NexusProps uses Microsoft Graph's official notification system. Notifications carry only change identifiers; content is fetched through subsequent authenticated queries.

7.3. Limited Use applicability

NexusProps applies to data obtained via Microsoft Graph the same restrictions Google requires under Limited Use: no generalized AI training, no transfer to third parties beyond necessary sub-processors, no advertising use, restricted human access. This policy is voluntary with respect to Microsoft (which has no formal Limited Use equivalent) but we consider it best practice.

8. Generic IMAP/SMTP (other providers)

For providers other than Google or Microsoft (Apple iCloud, Yahoo, ProtonMail, Hostinger, GoDaddy, Antel, Dattatec, custom domains, etc.), NexusProps uses the standard IMAP and SMTP protocols with in-transit encryption, using the credentials you upload to the platform.

  • Credentials are stored in encrypted form.
  • SMTP send is routed through a secure relay service that does not persist your credentials beyond the time needed to deliver the message.

9. Data storage

9.1. Infrastructure

Data type Storage At-rest encryption In-transit encryption
Structured data (users, contacts, properties, deals, email metadata and small messages, integration tokens) Managed database in a recognized cloud provider (United States) Yes TLS
Files (property photos, email attachments and large messages) Global CDN storage with per-agency segregation Yes TLS
Backups Automated daily backups managed by the database provider Yes n/a

Additionally, sensitive credentials (integration tokens, App Passwords, third-party provider secrets) are encrypted at the application level with industry-standard methods before being persisted, using a master key kept outside the database.

9.2. Data retention

Data type Retention period
User account data While the account is active + 30 days after cancellation, unless legally required otherwise.
Contact, property and deal data uploaded by the user Under user control; retained until the user deletes them or the agency is canceled.
Synchronized email metadata While the mailbox remains connected to the CRM.
Email bodies linked to CRM entities Permanent, as part of the commercial record, until the user explicitly deletes them.
Email bodies not linked to CRM entities Temporary cache depending on plan tier: between 7 days (Starter) and permanent (Enterprise).
Cached attachments Between 3 and 30 days depending on plan, unless explicitly downloaded and persisted.
Technical and access logs 90 days, unless a security investigation is in progress.
Tax and accounting records Statutory periods applicable in Uruguay (5 to 10 years as appropriate).

9.3. Deletion upon OAuth revocation

When a user revokes OAuth permission (from NexusProps or directly from Google/Microsoft):

  1. Immediate: refresh token is deleted from our database.
  2. Immediate: synchronization with the external account ceases.
  3. CRM-linked emails (associated with a contact, property or deal): retained as part of the commercial record, unless the user explicitly requests deletion.
  4. Emails not linked to CRM: scheduled for purge 30 days after revocation; during that window the user may reconnect and restore them. The UI also offers a “Delete all unlinked now” button for immediate total removal.

10. Data sharing / Sub-processors

NexusProps does not sell, rent or trade personal data. We share data exclusively with the following sub-processors, necessary to operate the service, under confidentiality and security agreements:

Sub-processor Function Physical location Data shared
Cloud hosting provider (Digital Ocean) Service infrastructure hosting United States Service information, encrypted
Cloudflare, Inc. CDN, storage and public site hosting Global Encrypted files, public site content
Google LLC (Gmail API + OAuth) and Google Cloud OAuth connection with Google accounts and cloud services supporting email integrations United States OAuth tokens, message metadata; SMTP credentials in flight (non-persisted)
Microsoft Corporation (Graph API + OAuth) Only when the user connects a Microsoft account United States / EU OAuth tokens, metadata and message bodies
Stripe, Inc. Subscription billing United States / EU Name, email, card data (Stripe is data controller for payment data)
MercadoPago Uruguay S.A. Subscription billing (alternative to Stripe) Uruguay Name, email, payment data
AI providers (OpenAI, Anthropic, Groq, Google AI, xAI, DeepSeek, Z.AI, Stability AI) Specific AI features invoked by the user United States Only the specific content the user submits to the AI feature per call (not bulk data)
Resend System transactional notifications (welcome, password reset) United States Name, email, notification content

All sub-processors are contractually bound to protection standards equivalent to those of this policy. We do not transfer data to other third parties without your consent or legal requirement.

11. Your rights

11.1. ARCO and equivalent rights

As data subject you have the right to:

  • Access the personal data we process about you.
  • Rectify inaccurate or incomplete data.
  • Cancel / Erase data when no longer necessary or when you withdraw consent.
  • Object to processing, in cases provided by law.
  • Portability: request a copy of your data in a structured, machine-readable format.
  • Restriction: ask us to restrict processing while a controversy is resolved.
  • Withdraw consent at any time (does not affect prior processing based on previously valid consent).

How to exercise these rights: email privacy@nexusprops.com identifying yourself sufficiently. We respond within the applicable legal period (10 business days in Uruguay, 30 days under GDPR).

11.2. How to revoke OAuth access

See section 9.3 for what happens to data after revocation.

11.3. Supervisory authority

You have the right to lodge a complaint with the competent supervisory authority:

12. International transfers

Some sub-processors (Digital Ocean, Cloudflare, Google, Microsoft, Stripe, AI providers) process data on servers located outside Uruguay, mainly in the United States and the European Union.

Transfers take place under the safeguards provided by applicable regulation:

  • Standard Contractual Clauses approved by the European Commission where applicable.
  • Sub-processor adherence to recognized frameworks (EU-US Data Privacy Framework, where applicable).
  • Specific Data Processing Agreements (DPA) with each sub-processor.

By using NexusProps you acknowledge and consent to these transfers under the terms described.

13. Cookies and similar technologies

NexusProps uses:

  • Strictly necessary cookies for platform operation (session, CSRF, language and theme preference).
  • Internal analytics cookies (aggregated, anonymized measurements) to understand feature usage. We do not use third-party advertising tracking cookies for profiling purposes.
  • Browser localStorage to save user visual preferences.

We do not use Google Analytics, Facebook Pixel or similar inside the CRM application. On the public website (www.nexusprops.com) we may use aggregated measurements; please refer to the site-specific notice if we publish a separate one.

14. Security

We apply reasonable technical and organizational measures aligned with industry standards:

  • In-transit encryption (TLS) on all connections.
  • At-rest encryption in databases and file storage.
  • Additional application-level encryption, with industry-standard methods, for sensitive credentials and tokens.
  • Session-token authentication with expiration.
  • Role-based access control within each agency.
  • Audit logs for critical actions.
  • Automated daily backups.
  • Network firewalls on exposed servers.
  • Administrative management with strict access controls.

No system is 100% impenetrable. If we detect an incident affecting your personal data, we will notify you within applicable legal periods (72 hours under GDPR, equivalent in Uruguay).

15. Minors

NexusProps is a B2B service aimed at real-estate professionals. It is not directed to minors and we do not knowingly collect data from individuals under 18. If we learn that a minor has provided data without parental authorization, we will delete it.

16. Changes to this policy

We may update this policy to reflect legal, operational or product changes. Versions are identified by the “Last updated” date at the top of the document.

  • Minor changes (corrections, clarifications): immediate publication.
  • Substantive changes (new purposes, new sub-processors, modification of OAuth scopes): user notification by email and prominent in-app notice at least 15 days in advance whenever operationally feasible. Continued use after that date implies acceptance.

Version history available upon request to legal@nexusprops.com.

17. Applicable legal framework

This policy is drafted in accordance with:

  • Uruguay: Law No. 18.331 on Personal Data Protection and Habeas Data Action, and Regulatory Decree 414/009.
  • Argentina (where Argentine subjects are involved): Law No. 25.326 on Personal Data Protection.
  • Brazil (where Brazilian subjects are involved): Lei Geral de Proteção de Dados — LGPD (Law No. 13.709/2018).
  • Mexico (where Mexican subjects are involved): Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP).
  • European Union / EEA (where EU subjects are involved): General Data Protection Regulation (GDPR) 2016/679.
  • Chile: Law No. 19.628 on Protection of Private Life.

In case of conflict between frameworks, the most protective of the data subject prevails.

18. Contact

Subject Email
Privacy / exercise of ARCO rights / DPO privacy@nexusprops.com
Legal / contracts legal@nexusprops.com
Technical support support@nexusprops.com

Postal address:

Álvaro Mauricio Hernandorena Núñez

18 de Julio 683

Maldonado, Department of Maldonado, Uruguay