Legal

Privacy Policy

This policy explains what personal information NexBroad Technologies Inc. collects, why we hold it, who else touches it, and how long we keep it. It covers our website at nexbroad.com and the NexBroad Reach platform at reach.nexbroad.com.

Effective
7 September 2026
Last updated
7 September 2026

1.Who we are

NexBroad Technologies Inc. is a Canadian corporation. We build custom software, and we operate NexBroad Reach, a platform organisations use to send SMS, MMS and voice broadcasts to people who have agreed to hear from them.

Who those people are depends on the organisation sending. They may be customers, patients, students, parents, members, donors, residents, volunteers, contractors, applicants or an organisation’s own team. This policy treats none of those groups differently and none of them is a closed list. What decides whether a message may be sent is consent, not the label on the relationship.

Two very different groups appear in this policy, and the difference matters. Customers are the organisations that hold a NexBroad Reach account, whether they are companies, clinics, schools, charities, associations or public bodies. Recipients are the people those organisations message. If you received a text or a call and came here looking for answers, read section 11 first.

For a customer’s own account information we decide what is collected and why, so the responsibility is ours. For the contact lists and message content a customer loads into the platform, we act on that customer’s instructions and hold the data on their behalf. They decide who gets messaged and what the message says. We decide nothing about it, and we do not use it for our own purposes.

2.What we collect

Account and registration

Your name, work email address, mobile number, company name and country. We keep a hash of your password, never the password itself. Registration requires you to confirm a code sent to your email and a second code sent to your phone, and we record that both checks passed.

Consent evidence

When you accept our terms at signup we store the exact wording you were shown, the version number of that wording, the time you accepted it, the page you accepted it on, and the IP address the acceptance came from. Carriers and regulators can ask us to produce this record years later, so it is written once and never edited.

Business profile

Before an account can send to its own audience, we collect the legal business name, the business registration number, the registered address, the company website, a named authorised contact, sample message content, and a description of how the business collects consent from the people it messages. Parts of this profile are filed with the messaging registries and carriers that approve business traffic. That filing is the only way a business can send legitimate SMS in North America, and it is described in section 5.

Customer content

Contact records our customers upload or create, including names, phone numbers and any custom fields they choose to add. Message and script content, delivery receipts, inbound replies, opt-out records, and call metadata such as start time, duration and outcome. We do not record call audio.

Payments

Credit purchases are processed by a third-party payment processor certified to the PCI DSS standard. Card numbers go to that processor directly and never reach our servers. What we store is the amount, the date, the card brand and last four digits, and a ledger entry for the credits the purchase bought.

Technical and audit

IP address, browser and device information, pages visited and timestamps. We also keep an audit trail of administrative actions, including every occasion on which a member of our own staff opens a customer account for support or investigation.

Cookies and tracking

Our marketing website runs no advertising cookies and no third party analytics. We do not build advertising profiles, we do not share anything with ad networks, and there is no tracking pixel following you off this site. The application stores a session token in your browser so that you stay signed in and so that we can end a session when you log out. That is the whole of it.

Because we run nothing that tracks you across sites, a Do Not Track signal from your browser has nothing here to switch off. We have said that rather than staying silent on it, since silence is what usually means the opposite.

Our email provider records whether a service email was delivered or bounced, which is how we find out that somebody’s verification code never arrived. We do not use that data for marketing.

3.Why we collect it

  • To operate the platform: deliver messages and calls, show delivery results honestly including failures, and keep your data separated from every other customer's.
  • To verify that an account belongs to a real organisation and a reachable person, which is the first defence against the fraud and abuse that messaging platforms attract.
  • To meet carrier and registry requirements, which include producing consent evidence on request and demonstrating that opt-outs are honoured.
  • To screen content automatically before it is sent, so that traffic which would put an entire brand at risk is stopped rather than delivered.
  • To bill accurately, to answer support requests, and to send you service notices such as verification codes, receipts and security alerts.
  • To comply with Canadian and applicable foreign law, and to establish or defend legal claims.

Service notices are not marketing. Verification codes, security alerts, receipts, outage notices and changes to this policy keep coming for as long as your account is open, because an account holder we cannot reach is an account holder we cannot protect. If we ever want to send you marketing, we will ask separately, the unsubscribe link will work within a few days at most, and withdrawing that consent will not cost you anything in the product.

4.Mobile information

This clause exists because it is the question we are asked most often, and because carriers require it to be stated plainly.

No mobile information will be sold or shared with third parties for promotional or marketing purposes.

Phone numbers and the consent records attached to them are not sold, rented, traded or licensed. They are not shared with any third party except the service providers listed in the next section, who use them only to deliver the service on our instructions. Text messaging originator opt-in data and consent are never shared with anyone for any other purpose.

5.Who else handles your data

Running the platform takes more than our own servers, so a small number of specialist service providers handle personal information on our behalf. Each is bound by contract to use the data only to provide its service to us, on our instructions, and none of them is permitted to use it for their own purposes. Below is the complete set of purposes for which any provider ever touches your data.

  • Message and call delivery, phone number provisioning, and the carrier and registry filings that allow business traffic to run in North America.
  • Transactional email such as verification codes, password resets and service notices.
  • Payment processing for credit purchases.
  • Application hosting, database, job queue, and file storage for uploads such as contact imports.
  • Automated screening of message content and classification of inbound replies.

We do not publish the names of these providers here, because the list changes as our infrastructure changes and a stale list is worse than an accurate description of what is actually done with your data. If you need the current list for a vendor review or a privacy assessment of your own, write to us at hello@nexbroad.com and we will provide it.

Beyond those purposes we share personal information in only three situations. When a customer instructs us to, for example by exporting their own data. When the law requires it, including a valid court order, subpoena or regulatory demand, and we will tell the affected customer unless we are prohibited from doing so. And in the event of a merger, acquisition or sale of assets, in which case the acquirer inherits this policy and you will be notified before your data moves under different control.

That set of purposes is narrow on purpose, and it is a commitment rather than a snapshot. If we ever need a provider for a purpose not listed above, we update this page before that provider starts, and we email account holders when the change is material. We do not sell personal information to anyone, and we do not disclose it to data brokers, ad networks or list vendors in any form.

6.Where your data is held

Our application and database run on infrastructure in North America. Message delivery, email and payment providers operate in Canada, the United States and other countries where they maintain facilities. This means personal information may be stored or processed outside the province or country where you live.

You should know what that implies. While data is in another country it is subject to that country’s laws, including lawful access by its courts and government authorities. We contract for protection comparable to what Canadian law requires, but no contract overrides a foreign court order.

7.How long we keep it

Retention is not a single number, because different records answer to different obligations. The schedule below is what we apply.

RecordRetention
Account and profile recordsFor as long as the account is open, then 90 days after closure unless a longer period below applies
Consent and opt-in evidence5 years from the date it was collected
Message content, delivery receipts and call metadata13 months
Opt-out recordsKept indefinitely. We cannot honour an opt-out we have deleted
Provider webhook payloads and diagnostic logs90 days
Audit logs of administrative access7 years
Billing, invoicing and tax records7 years, as Canadian tax law requires

Closing an account does not erase compliance evidence. Consent records, opt-out records and audit logs survive deletion of the account they belong to, because their entire purpose is to answer a question that gets asked after the fact. Everything else is deleted or irreversibly anonymised on the schedule above.

8.Automated processing

Two parts of the platform make decisions without a person involved, and we would rather describe them than let you discover them.

  • Message content is screened automatically before it is sent, in layers, the last of which is a language model. A send can be blocked or held on that basis. Repeated blocks contribute to an automated risk signal against an account.
  • Inbound replies are classified automatically so that opt-outs are applied immediately and so that replies can be routed. A misclassified reply never causes a message to be sent; the worst case is that a reply is filed in the wrong place.
  • Signup and sending behaviour is scored automatically for fraud and abuse, and a strong enough signal suspends an account before a person looks at it.

None of this profiles the recipients of your messages, and none of it is used for advertising. Where an automated decision affects your account, you can ask for it to be reviewed by a person, and you can ask us what triggered it. Write to us and we will look. We will not always disclose the exact threshold, because publishing the number tells the people we are trying to stop precisely where to sit.

9.Your rights

Under Canadian privacy law you can ask us for a copy of the personal information we hold about you, ask us to correct it if it is wrong, ask us to delete it, and withdraw a consent you previously gave. Write to hello@nexbroad.com with enough detail for us to find the records, and we will respond within 30 days.

Two honest limits. We will not act on a request until we are reasonably satisfied you are who you say you are, because handing someone else’s data to a convincing stranger is the failure this policy exists to prevent. And where a record is held under a legal or carrier retention requirement, we will restrict its use rather than delete it, and we will tell you which requirement applies.

If our answer does not satisfy you, you may complain to the Office of the Privacy Commissioner of Canada, or to your provincial privacy regulator.

10.Where you live changes the detail

The rights in the previous section are what we give everybody, because running one standard is simpler than running five and it is the higher one anyway. Some places add specifics, and these are the ones that apply to us.

Canada

Our baseline is the federal Personal Information Protection and Electronic Documents Act, and the provincial statutes that stand in its place in Alberta, British Columbia and Quebec. Quebec adds rights to data portability and to be informed about automated decisions, which section 8 describes. If we serve Quebec residents in French, we will do it in French. Complaints can go to the Office of the Privacy Commissioner of Canada or to your provincial commissioner, and you do not have to come through us first.

United States

If you are a California resident, you may ask what categories of personal information we collected about you, why, and who received it, and you may ask us to delete or correct it. We do not sell personal information and we do not share it for cross context behavioural advertising, so there is nothing for you to opt out of on that front, and we will not treat you differently for asking any of this. Residents of other states with comparable laws get the same answers; we do not maintain a different standard per state.

United Kingdom and European Economic Area

We are not established in the United Kingdom or the European Economic Area and we do not target the service there. If you are there and your information reaches us anyway, you have rights of access, correction, erasure, restriction, portability and objection, and transfers to Canada rely on the adequacy recognition Canada holds for commercial organisations. Write to us and we will handle the request on the same 30 day clock.

Whichever of these applies to you, the address is the same one in section 16. We have not built a separate portal, because a portal is mostly a way of making a request harder to make.

11.If you received a message from a NexBroad Reach customer

We are not the sender. An organisation used our platform to reach you, and that organisation chose your number, wrote the message and holds the consent record for it.

  • Reply STOP to any message to stop further messages from that sender. The block is applied by our system the moment we receive the reply, and it does not depend on the sender acting on it.
  • Reply HELP to any message and you will receive the sender's identity and contact details.
  • If you want to know who has your number, or you want your number removed entirely, email us with the number that contacted you and the approximate date. We will identify the customer responsible and pass your request to them, and we will tell you that we have done so.
  • If an organisation is messaging people who never agreed to hear from it, tell us. Sending without valid consent is a breach of our terms and we act on it.

12.How we protect it

Data is encrypted in transit and at rest. Access inside the company runs on defined roles rather than shared logins, and staff access to a customer account is logged with the person, the time and the reason. Signup requires both an email check and a phone check, which raises the cost of creating accounts in bulk.

No system is perfect, and we will not pretend otherwise. If a breach creates a real risk of significant harm, we will notify affected customers and the Privacy Commissioner as Canadian law requires, and we will tell you what happened rather than what we wish had happened.

We will never ask you for a password

We do not ask for your password, your card number or a verification code by email, by text or on a phone call, and no member of our staff has a reason to. Anyone who does is not us, whatever the message looks like. Forward it to hello@nexbroad.com and then delete it.

13.Other websites

Our site and the platform link out to places we do not run, including documentation, payment pages and the websites our customers put in their own messages. Once you follow one of those links you are on somebody else’s property under somebody else’s policy, and this one no longer covers you. We are not responsible for what those sites collect, and a link is not an endorsement of how they behave.

14.Children

NexBroad Reach is a business tool. It is not directed at children and we do not knowingly collect personal information from anyone under 18. If you believe a child’s information has reached us, contact us and we will delete it.

15.Changes to this policy

When this policy changes we update the effective date at the top. If a change materially affects how we handle your personal information, we will email account holders before it takes effect. Previous versions are available on request, and the consent record attached to your account always shows the exact wording you accepted.

16.Contact

Privacy questions, access requests and complaints go to hello@nexbroad.com, addressed to the Privacy Officer, NexBroad Technologies Inc. We answer privacy mail ourselves rather than routing it to a ticket queue.