NexarBPM Appointment setting
Legal

Privacy policy

Last updated August 2026. This explains what personal data we handle, why, and what you can ask us to do about it.

Who we are

NexarBPM ("we", "us") provides outbound appointment-setting services to business clients. For questions about this policy or about data we hold, email contact@nexarbpm.com.

Three different relationships

We handle personal data in three distinct roles, and your rights differ slightly in each:

You areOur roleWhat we hold
A website visitorControllerAnything you send us through the contact form or by email
A client contactControllerContract, billing and working-relationship details
A prospect we contactedController, alongside our clientBusiness contact details and our correspondence with you

If we contacted you about a client's product

You are reading this most likely because you received an email or LinkedIn message from us on behalf of one of our clients. Here is exactly what that involves.

What we hold

Business contact information only: your name, job title, employer, business email address, public professional profile, and any publicly available signal about your company that made us think their product was relevant to you — a funding round, a job posting, a product launch, a technology your company uses. We also keep the messages we sent you and any reply you sent us.

We do not collect or process special category data, and we do not seek personal information about you outside your professional role.

Where it came from

Publicly available professional sources and licensed business-data providers. Every record is checked by a person before it is used.

Why we're allowed to

Where the UK or EU GDPR applies, we rely on legitimate interests — ours and our client's interest in offering a relevant business product to the person likely to evaluate it, balanced against your interest in not being contacted unnecessarily. We assess that balance per campaign and record the assessment. We only approach people in a professional capacity, about something plausibly relevant to their role, and we stop the moment we're asked to.

Where other rules apply — CAN-SPAM in the United States, CASL in Canada — we work to the stricter of the applicable standards.

How to make it stop

Reply with "unsubscribe", use the opt-out link in any message, or email contact@nexarbpm.com. We action opt-outs the same working day and apply them permanently, across every campaign we run for every client — not just the one that reached you. You never need to ask twice.

Your rights

Depending on where you are, you may have the right to:

  • Ask what personal data we hold about you, and receive a copy
  • Have inaccurate data corrected
  • Have your data erased
  • Object to our processing, including for direct marketing — an objection to marketing is always honoured, without exception or balancing test
  • Ask us to restrict processing while a query is resolved
  • Receive your data in a portable format
  • Complain to your data protection authority

Email us to exercise any of these. We respond within one month. There is no charge. Where a request concerns a campaign run for a client, we'll coordinate with that client so the outcome is applied on both sides.

Retention

DataKept for
Prospect records in an active campaignThe campaign, then returned to the client and deleted from our systems
Correspondence and reply threadsUp to 24 months, so we can evidence what was said if a question arises
Opt-out recordsIndefinitely — we have to keep them to keep honouring them
Website enquiries24 months from last contact
Client contract and billing recordsAs long as required by tax and accounting law

Who else sees it

The client the campaign is run for. Our service providers, under contract and only to do their job — email and sending infrastructure, CRM and sequencing tools, business-data providers, cloud hosting, and analytics. We do not sell personal data, and we do not share it for anyone else's marketing.

Some of these providers are outside your country. Where personal data leaves the UK or EEA we rely on appropriate safeguards, such as Standard Contractual Clauses or an adequacy decision.

Security

Access is limited to the people working your campaign. Accounts require multi-factor authentication, data is encrypted in transit, and access is revoked when someone leaves a project. No system is perfectly secure; if a breach affects you and the law requires notification, we'll tell you and the regulator within the required window.

This website

The site is static. It sets no advertising or tracking cookies and builds no profile of you. Fonts are served by Google Fonts, which receives your IP address as part of delivering them. If we add analytics, we'll use a privacy-preserving tool and update this page before it goes live.

The contact form does not transmit anything on its own — it opens your own email client with the details filled in, so nothing reaches us until you press send.

Changes

If we change this policy we'll update the date at the top. Material changes affecting people we've contacted will be notified directly where we have a way to reach them.

Questions or complaints

Email contact@nexarbpm.com. If you're in the UK you may also complain to the Information Commissioner's Office; if you're in the EEA, to your national supervisory authority.