Privacy Policy
NextiaInvoices is one of the products of the Nextia platform, operated by 1496096 Canada Inc., doing business as Nextia AI (“Nextia”, “we”, “us”). This policy covers your Nextia account and the Nextia platform (account, business, team, billing and the NextiaBusiness mobile app) and, in section 9, what NextiaInvoices collects in addition.
Key points
- NextiaInvoices runs on the Nextia platform. Your account, business and team records are shared across the Nextia products you use.
- Nextia’s databases and file storage are hosted on Microsoft Azure in the Canada Central region.
- Nextia never holds your password: sign-in is handled by Microsoft Entra External ID.
- For your clients’ information, Nextia works on your business’s behalf; your business is accountable to its clients.
- Card data for invoice payments goes to the payment provider your business connects, never to Nextia.
Each Nextia product site publishes the portions of this policy that apply to that product.
1. Who we are
NextiaInvoices is operated by 1496096 Canada Inc., doing business as Nextia AI.
2. Our role: accountable organization or service provider
- For the account data of a business owner and their staff, Nextia is the organization accountable for that information.
- For a business’s own client data — names, invoices, statements and the like — Nextia is a service provider processing that information on the business’s behalf. The business remains accountable to its own clients for it.
If you are a client of a business that uses NextiaInvoices, contact that business first about your information. Questions about your own Nextia account come to us.
Nextia AI’s Privacy Officer is accountable for this policy. Questions, requests and complaints may be sent to privacy@nextia-ai.com.
For account and direct-customer information, Nextia is the accountable organization. For a business’s client information, Nextia acts as a service provider processing information on that business’s behalf.
3. Where your data is stored
- Nextia’s databases (Azure Database for PostgreSQL Flexible Server) and file storage (Azure Blob Storage) are in Microsoft Azure’s Canada Central region.
- Sign-in runs on Microsoft Entra External ID, in a directory created in Canada Central.
- Service providers that process some information outside Canada are listed in section 10.
4. What we collect about you when you sign in
- A stable internal identifier, your primary email address and whether it is verified, your display name, your preferred language and, optionally, a phone number.
- Which sign-in method asserted your account — email and password, Google, Microsoft or Apple — and the email address that provider stated when it was linked.
- Which businesses you belong to, your role in each, and pending invitations sent to your email address.
Your account is keyed on the identity provider’s identifier for you, not on your email address. That is why changing your email does not create a new account.
5. What the Nextia platform does with business information
- Shared clients. A client record entered in one Nextia product is visible in the business’s other Nextia products. It is shared across that business’s products, never across businesses.
- Cross-product insights. The NextiaBusiness home screen combines figures from the business’s Nextia products. Nothing that identifies a customer leaves the business.
- Weekly summary email. Opt-in, and off by default.
- Billing. Nextia subscriptions are billed through Stripe. Nextia stores subscription status and price identifiers, never card numbers.
6. Audit trail and support access
Nextia records consequential actions in an audit trail that stores the identifier and email address of the person who acted. The audit trail is designed to outlive the account: if your account is erased, it is scrubbed, but the audit record of what that account did is kept for the audit retention period.
A Nextia staff member can, with a recorded reason, act inside a business’s account to provide support. Every such session is recorded.
A business owner may request the record of support sessions by emailing privacy@nextia-ai.com.
7. How we protect information
- Every request into a business’s data goes through a permission check tied to that business, and automated tenant-isolation tests fail the build if data can be read across businesses.
- Nextia never holds your password. Authentication is delegated to Microsoft Entra External ID and the identity providers above.
- Third-party connection tokens and payment-provider credentials are encrypted at rest in the product database, and the service refuses to start in a production environment without a real encryption key.
- Our logging rules forbid logging passwords, tokens, sign-in assertions, payment credentials, or client data beyond identifiers.
8. How long we keep information
NextiaInvoices does not currently delete records automatically on a schedule. Automatic deletion runs only in NextiaTax today.
Account data is kept for the life of the account and normally removed within 90 days after a verified closure request. Billing and tax records may be kept for up to six years; support records for up to 24 months; audit and security logs normally for no more than 24 months; and encrypted backups on a rolling cycle of up to 90 days. A legal hold or statutory obligation may require longer retention.
9. What NextiaInvoices collects and why
Your business’s clients
Names, addresses, contact details, custom fields, invoices, credit notes, refunds, statements and payment records. Nextia processes these on behalf of your business; your business is accountable to its own clients for them.
The client portal
Your business can send a client a link that shows that client’s own invoices and statements without a Nextia account. The link works as a key: anyone who holds it can see what it shows.
Documents
Generated PDFs and uploaded files are stored in Azure Blob Storage.
Payments
Where your business connects a payment provider (Stripe, Square or PayPal), card data goes to that provider, never to Nextia. Nextia stores the provider account references and the payment status.
Email delivery
Invoices, receipts and statements are sent by email through Azure Communication Services, and delivery events are recorded.
10. Service providers (sub-processors)
| Provider | What it receives | Where |
|---|---|---|
| Microsoft Azure | Hosting, databases, file storage, message queues, logs | Canada Central |
| Microsoft Entra External ID | Sign-in identity, email address | Canada Central |
| Azure Communication Services | Recipient address and message content for email | Canada Central |
| Cloudflare | DNS | Global |
| Stripe | Payment and subscription data; card data never reaches Nextia | United States / global |
Stripe involves a transfer of personal information to the United States. Payment providers your business chooses to connect for invoice payments (Stripe, Square or PayPal) are governed by those providers’ own terms. Other Nextia products use additional providers, listed in their own sections.
Square and PayPal may process payment information in the United States and other countries where they operate. Information processed outside Canada may be subject to the laws of those jurisdictions.
11. Your rights
You can ask for access to your personal information, have it corrected, and ask for it to be erased, as described below.
- Access and portability. NextiaInvoices lets you export your data. The Nextia platform account itself has no self-service export yet; ask us instead.
- Correction. Edit your information directly in the product.
- Erasure. Request account deletion in the application or by emailing privacy@nextia-ai.com. We verify and complete valid requests within 30 days unless law, security, another person’s rights or a documented legal hold requires preservation. As explained in section 6, necessary audit records may be retained.
These mechanisms differ between Nextia products; the rights section of each product explains what applies there.
Subject to applicable law, you may request access to and correction of your personal information, withdraw consent where processing depends on consent, request deletion, and receive computerized information in a structured, commonly used technological format where the portability right applies. We will explain any lawful refusal or limitation.
Contact our Privacy Officer first. If we do not resolve your concern, you may complain to the Office of the Privacy Commissioner of Canada or, if applicable, the Commission d’accès à l’information du Québec.
12. Cookies
The Nextia apps set no analytics cookies and run no third-party trackers. Only Microsoft Entra’s own sign-in state is stored.
This marketing website uses no analytics or advertising cookies. It stores only essential preferences, such as language and announcement state, in browser storage. The application uses necessary authentication storage supplied by Microsoft Entra.
13. Children
Nextia accounts are for people at least 18 years old. Businesses that enter information about minors are responsible for obtaining any consent required by law and limiting the information collected.
14. Changes to this policy
This policy is effective October 4, 2026. We will post revisions with a new effective date and give notice in the service or by email before a material change takes effect when required by law.