Legal
This policy explains what personal information NexBroad Technologies Inc. collects, why we hold it, who else touches it, and how long we keep it. It covers our website at nexbroad.com and the NexBroad Reach platform at reach.nexbroad.com.
NexBroad Technologies Inc. is a Canadian corporation. We build custom software, and we operate NexBroad Reach, a platform organisations use to send SMS, MMS and voice broadcasts to people who have agreed to hear from them.
Who those people are depends on the organisation sending. They may be customers, patients, students, parents, members, donors, residents, volunteers, contractors, applicants or an organisation’s own team. This policy treats none of those groups differently and none of them is a closed list. What decides whether a message may be sent is consent, not the label on the relationship.
Two very different groups appear in this policy, and the difference matters. Customers are the organisations that hold a NexBroad Reach account, whether they are companies, clinics, schools, charities, associations or public bodies. Recipients are the people those organisations message. If you received a text or a call and came here looking for answers, read section 11 first.
For a customer’s own account information we decide what is collected and why, so the responsibility is ours. For the contact lists and message content a customer loads into the platform, we act on that customer’s instructions and hold the data on their behalf. They decide who gets messaged and what the message says. We decide nothing about it, and we do not use it for our own purposes.
Your name, work email address, mobile number, company name and country. We keep a hash of your password, never the password itself. Registration requires you to confirm a code sent to your email and a second code sent to your phone, and we record that both checks passed.
When you accept our terms at signup we store the exact wording you were shown, the version number of that wording, the time you accepted it, the page you accepted it on, and the IP address the acceptance came from. Carriers and regulators can ask us to produce this record years later, so it is written once and never edited.
Before an account can send to its own audience, we collect the legal business name, the business registration number, the registered address, the company website, a named authorised contact, sample message content, and a description of how the business collects consent from the people it messages. Parts of this profile are filed with the messaging registries and carriers that approve business traffic. That filing is the only way a business can send legitimate SMS in North America, and it is described in section 5.
Contact records our customers upload or create, including names, phone numbers and any custom fields they choose to add. Message and script content, delivery receipts, inbound replies, opt-out records, and call metadata such as start time, duration and outcome. We do not record call audio.
Credit purchases are processed by a third-party payment processor certified to the PCI DSS standard. Card numbers go to that processor directly and never reach our servers. What we store is the amount, the date, the card brand and last four digits, and a ledger entry for the credits the purchase bought.
IP address, browser and device information, pages visited and timestamps. We also keep an audit trail of administrative actions, including every occasion on which a member of our own staff opens a customer account for support or investigation.
Our marketing website runs no advertising cookies and no third party analytics. We do not build advertising profiles, we do not share anything with ad networks, and there is no tracking pixel following you off this site. The application stores a session token in your browser so that you stay signed in and so that we can end a session when you log out. That is the whole of it.
Because we run nothing that tracks you across sites, a Do Not Track signal from your browser has nothing here to switch off. We have said that rather than staying silent on it, since silence is what usually means the opposite.
Our email provider records whether a service email was delivered or bounced, which is how we find out that somebody’s verification code never arrived. We do not use that data for marketing.
Service notices are not marketing. Verification codes, security alerts, receipts, outage notices and changes to this policy keep coming for as long as your account is open, because an account holder we cannot reach is an account holder we cannot protect. If we ever want to send you marketing, we will ask separately, the unsubscribe link will work within a few days at most, and withdrawing that consent will not cost you anything in the product.
This clause exists because it is the question we are asked most often, and because carriers require it to be stated plainly.
No mobile information will be sold or shared with third parties for promotional or marketing purposes.
Phone numbers and the consent records attached to them are not sold, rented, traded or licensed. They are not shared with any third party except the service providers listed in the next section, who use them only to deliver the service on our instructions. Text messaging originator opt-in data and consent are never shared with anyone for any other purpose.
Our application and database run on infrastructure in North America. Message delivery, email and payment providers operate in Canada, the United States and other countries where they maintain facilities. This means personal information may be stored or processed outside the province or country where you live.
You should know what that implies. While data is in another country it is subject to that country’s laws, including lawful access by its courts and government authorities. We contract for protection comparable to what Canadian law requires, but no contract overrides a foreign court order.
Retention is not a single number, because different records answer to different obligations. The schedule below is what we apply.
| Record | Retention |
|---|---|
| Account and profile records | For as long as the account is open, then 90 days after closure unless a longer period below applies |
| Consent and opt-in evidence | 5 years from the date it was collected |
| Message content, delivery receipts and call metadata | 13 months |
| Opt-out records | Kept indefinitely. We cannot honour an opt-out we have deleted |
| Provider webhook payloads and diagnostic logs | 90 days |
| Audit logs of administrative access | 7 years |
| Billing, invoicing and tax records | 7 years, as Canadian tax law requires |
Closing an account does not erase compliance evidence. Consent records, opt-out records and audit logs survive deletion of the account they belong to, because their entire purpose is to answer a question that gets asked after the fact. Everything else is deleted or irreversibly anonymised on the schedule above.
Two parts of the platform make decisions without a person involved, and we would rather describe them than let you discover them.
None of this profiles the recipients of your messages, and none of it is used for advertising. Where an automated decision affects your account, you can ask for it to be reviewed by a person, and you can ask us what triggered it. Write to us and we will look. We will not always disclose the exact threshold, because publishing the number tells the people we are trying to stop precisely where to sit.
Under Canadian privacy law you can ask us for a copy of the personal information we hold about you, ask us to correct it if it is wrong, ask us to delete it, and withdraw a consent you previously gave. Write to hello@nexbroad.com with enough detail for us to find the records, and we will respond within 30 days.
Two honest limits. We will not act on a request until we are reasonably satisfied you are who you say you are, because handing someone else’s data to a convincing stranger is the failure this policy exists to prevent. And where a record is held under a legal or carrier retention requirement, we will restrict its use rather than delete it, and we will tell you which requirement applies.
If our answer does not satisfy you, you may complain to the Office of the Privacy Commissioner of Canada, or to your provincial privacy regulator.
The rights in the previous section are what we give everybody, because running one standard is simpler than running five and it is the higher one anyway. Some places add specifics, and these are the ones that apply to us.
Our baseline is the federal Personal Information Protection and Electronic Documents Act, and the provincial statutes that stand in its place in Alberta, British Columbia and Quebec. Quebec adds rights to data portability and to be informed about automated decisions, which section 8 describes. If we serve Quebec residents in French, we will do it in French. Complaints can go to the Office of the Privacy Commissioner of Canada or to your provincial commissioner, and you do not have to come through us first.
If you are a California resident, you may ask what categories of personal information we collected about you, why, and who received it, and you may ask us to delete or correct it. We do not sell personal information and we do not share it for cross context behavioural advertising, so there is nothing for you to opt out of on that front, and we will not treat you differently for asking any of this. Residents of other states with comparable laws get the same answers; we do not maintain a different standard per state.
We are not established in the United Kingdom or the European Economic Area and we do not target the service there. If you are there and your information reaches us anyway, you have rights of access, correction, erasure, restriction, portability and objection, and transfers to Canada rely on the adequacy recognition Canada holds for commercial organisations. Write to us and we will handle the request on the same 30 day clock.
Whichever of these applies to you, the address is the same one in section 16. We have not built a separate portal, because a portal is mostly a way of making a request harder to make.
We are not the sender. An organisation used our platform to reach you, and that organisation chose your number, wrote the message and holds the consent record for it.
Data is encrypted in transit and at rest. Access inside the company runs on defined roles rather than shared logins, and staff access to a customer account is logged with the person, the time and the reason. Signup requires both an email check and a phone check, which raises the cost of creating accounts in bulk.
No system is perfect, and we will not pretend otherwise. If a breach creates a real risk of significant harm, we will notify affected customers and the Privacy Commissioner as Canadian law requires, and we will tell you what happened rather than what we wish had happened.
We do not ask for your password, your card number or a verification code by email, by text or on a phone call, and no member of our staff has a reason to. Anyone who does is not us, whatever the message looks like. Forward it to hello@nexbroad.com and then delete it.
Our site and the platform link out to places we do not run, including documentation, payment pages and the websites our customers put in their own messages. Once you follow one of those links you are on somebody else’s property under somebody else’s policy, and this one no longer covers you. We are not responsible for what those sites collect, and a link is not an endorsement of how they behave.
NexBroad Reach is a business tool. It is not directed at children and we do not knowingly collect personal information from anyone under 18. If you believe a child’s information has reached us, contact us and we will delete it.
When this policy changes we update the effective date at the top. If a change materially affects how we handle your personal information, we will email account holders before it takes effect. Previous versions are available on request, and the consent record attached to your account always shows the exact wording you accepted.
Privacy questions, access requests and complaints go to hello@nexbroad.com, addressed to the Privacy Officer, NexBroad Technologies Inc. We answer privacy mail ourselves rather than routing it to a ticket queue.