Privacy Policy

Last updated: 10 August 2026

This Privacy Policy is issued by Nexus Generated FZ-LLC, a free zone limited liability company licensed by the Ras Al Khaimah Economic Zone (RAKEZ), License No. 5034603, with registered address at VUET1700, Compass Building - Al Hulaila, Al Hulaila Industrial Zone-FZ, Ras Al Khaimah, United Arab Emirates ("Nexus Generated", "we", "us").

We operate Odiseo (odiseo.ai), a platform that lets businesses create AI employees that serve their own customers through website chat, live voice, WhatsApp, and email.


1. Scope — when this Policy applies (and when it does not)

This Policy covers personal data for which Nexus Generated is the controller:

  • Visitors of odiseo.ai — including people who interact with our own AI assistant on the site (chat or voice);
  • Client account holders — people who register, administer, or use an Odiseo account on behalf of a business;
  • Prospects — people who contact us, request information, or with whom we communicate about Odiseo.

This Policy does NOT cover visitors of our clients' websites. When a business embeds an Odiseo AI employee on its own site or channels, that business is the controller of its visitors' data and Nexus Generated acts only as a processor on the business's instructions. That processing is governed by our Data Processing Agreement with the client and by the client's own privacy policy, which is the document those visitors should consult.


2. Data we collect

2.1 Visitors of odiseo.ai

  • Conversation data: the content of chat and voice interactions with our AI assistant on odiseo.ai, including any contact details or business information you choose to share during the conversation.
  • Visitor identifier: a server-issued identifier stored in a cookie so that a returning visitor can continue the same conversation. It is generated by our servers and does not contain your name or contact details by itself.
  • Technical and usage data: IP address, browser and device type, pages visited, referral source, approximate location derived from IP (e.g., to select language), and error/diagnostic data.
  • Form data: anything you submit through forms on the site (e.g., contact or sign-up forms).

2.2 Client account holders

  • Account data: name, business email address, company name, role, and authentication data managed through our authentication provider.
  • Billing data: subscription plan, invoices, and payment status. Payments are processed by Stripe; we do not store full card numbers.
  • Configuration and usage data: settings of your workspace, features enabled, and logs of platform usage needed to operate, secure, and bill the service.
  • Support communications: messages you exchange with us for onboarding or support.

2.3 Prospects

  • Contact and communication data: name, business contact details, the content of our exchanges (email, WhatsApp, chat, calls), and where relevant, notes about your business needs and interest level recorded in our CRM.

We do not intentionally collect special categories of personal data (health, beliefs, biometrics, etc.) and ask that you do not share them in conversations with our AI assistant.


3. Purposes of processing

We use personal data to:

  1. Provide the service: run odiseo.ai, answer your questions through the AI assistant, create and manage client accounts, and deliver the features clients subscribe to.
  2. Communicate: respond to inquiries, follow up with prospects, send service and transactional emails, and provide support.
  3. Bill and administer: manage subscriptions, invoicing, and payment collection through Stripe.
  4. Secure and improve the platform: monitor for errors and abuse, enforce spending limits, maintain strict isolation between client workspaces, debug, and improve reliability and product quality.
  5. Comply with law: meet accounting, tax, and regulatory obligations, and respond to lawful requests.

We do not sell personal data. We do not use client data or the content of conversations to train AI models (see Section 5).


4. Legal bases

Under the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021 — PDPL)

We process personal data on the basis of your consent, or without consent where the PDPL permits it — in particular where processing is necessary for a contract to which you are party (e.g., operating your account), necessary to comply with legal obligations, or otherwise falls within the exceptions set out in the PDPL.

Under the GDPR (for data subjects in the European Union / EEA)

  • Contract (Art. 6(1)(b)) — creating and operating client accounts, providing the subscribed service, billing.
  • Consent (Art. 6(1)(a)) — non-essential cookies and analytics, and any marketing communications that require it. Consent can be withdrawn at any time.
  • Legitimate interests (Art. 6(1)(f)) — securing the platform, preventing abuse and fraud, responding to prospect inquiries, and improving the service, balanced against your rights and expectations.
  • Legal obligation (Art. 6(1)(c)) — accounting, tax, and regulatory compliance.

EU representative (Article 27 GDPR). We have assessed Article 27 GDPR and currently rely on the exemption under Article 27(2); we will appoint an EU representative if our processing profile changes.


5. AI processing — what you should know

  • You are talking to an AI. Conversations on odiseo.ai are handled by an AI assistant. This is disclosed in the chat interface at the start of the interaction, consistent with Article 50 of the EU AI Act; voice and WhatsApp are being brought to the same standard.
  • How conversations are processed. To generate responses, conversation content is processed by large language model (LLM) providers acting as our subprocessors (currently Anthropic and Google), and by a voice provider (ElevenLabs) for live voice interactions.
  • No training on your data. We do not use the content of client conversations to train foundation models, and we select providers consistent with that commitment.
  • AI can make mistakes. AI-generated responses may be inaccurate or incomplete. Do not rely on them as professional advice; the assistant is designed not to provide financial, legal, or medical advice.
  • Human escalation. Conversations can be escalated to a human, and you can always contact us directly through the details in Section 12.

6. Cookies

odiseo.ai uses cookies and similar technologies — including the server-issued visitor identifier described in Section 2.1 and analytics cookies. For the full list, purposes, durations, and how to manage them, see our Cookie Policy (separate document).


7. Who we share data with (subprocessor categories)

We share personal data only with service providers that help us run the platform, under contracts that restrict their use of the data. Categories and current providers:

Category Providers
AI / LLM inference Anthropic, Google
Voice ElevenLabs
Messaging & telephony (WhatsApp) Twilio
Payments & billing Stripe
Database Neon (Postgres)
Hosting & delivery Vercel
Authentication Clerk
Caching / queues / background jobs Upstash, Inngest
Error monitoring & observability Sentry, Langfuse
Product analytics PostHog
Transactional email Resend

We may also disclose data where required by law, or in connection with a corporate transaction (merger, acquisition, restructuring), in which case this Policy will continue to apply to the data transferred.


8. International transfers

Nexus Generated is established in the United Arab Emirates, and our service providers operate in other jurisdictions, including the United States. This means personal data may be transferred outside your country.

  • For EU/EEA data subjects, transfers are made under appropriate safeguards required by the GDPR, including Standard Contractual Clauses with our providers where applicable.
  • Under the PDPL, cross-border transfers are made in accordance with the conditions of the PDPL, including contractual protections ensuring an adequate level of protection.

9. Retention

  • We keep personal data only as long as needed for the purposes described in this Policy and to meet legal obligations (e.g., accounting records).
  • Deletion works end-to-end: when data is deleted (on request or per policy), our systems propagate the deletion across conversations, messages, and related records.
  • Default retention: conversations and related data are retained while the account is active and deleted within 30 days after account closure, through the platform's deletion cascade (aligned with GDPR Article 17). The same regime applies to conversations held with our AI assistant on odiseo.ai. Data we must keep longer to meet legal obligations (e.g., accounting and tax records) is retained for the period required by law.

10. Your rights

Subject to the conditions and exceptions of the applicable law (PDPL, and GDPR for EU/EEA data subjects), you have the right to:

  • Access the personal data we hold about you and receive a copy;
  • Rectify inaccurate or incomplete data;
  • Delete your data (right to erasure — our deletion cascade removes conversations and related records end-to-end);
  • Restrict or object to certain processing, including processing based on legitimate interests;
  • Data portability, where processing is based on consent or contract and carried out by automated means;
  • Withdraw consent at any time, without affecting processing already carried out;
  • Not be subject to solely automated decisions that produce legal or similarly significant effects for you (PDPL Article 18; GDPR Article 22). Odiseo is designed around supervised actions: consequential actions are subject to the controls its clients configure, and the platform does not make decisions of that kind about you without a human involved;
  • Complain to a supervisory authority — the UAE Data Office under the PDPL, or your local data protection authority in the EU/EEA.

To exercise any of these rights, contact us at the address in Section 12. We will verify your identity and respond within the timeframe required by applicable law.


11. Security

We apply technical and organizational measures appropriate to the risk, including encryption of data in transit, strict tenant isolation between client workspaces (enforced at the database level), access controls, spending limits per client, and continuous error and abuse monitoring. No system is perfectly secure; if a breach affecting your data occurs, we will notify you and the competent authorities as required by law.


12. Contact

For privacy questions or to exercise your rights:

Nexus Generated FZ-LLC RAKEZ License No. 5034603 VUET1700, Compass Building - Al Hulaila, Al Hulaila Industrial Zone-FZ, Ras Al Khaimah, United Arab Emirates

Email: legal@odiseo.ai

legal@odiseo.ai is our data-protection point of contact. A formal Data Protection Officer is not currently required for our scale of processing; we will reassess as we grow.


13. Children

Odiseo is a business service and odiseo.ai is not directed at children. We do not knowingly collect personal data from children under 16. This 16-year threshold concerns children's personal data; it is distinct from — and serves a different purpose than — the 18-year minimum in our Terms of Service, which is the age required to enter a business contract with us. If you believe a child has provided us personal data, contact us and we will delete it.

14. Changes to this Policy

We may update this Policy as the product or the law evolves. We will post the updated version on odiseo.ai with a new "Last updated" date, and for material changes affecting client account holders we will provide notice through the platform or by email. The English version of this Policy is the binding version; translations are provided for convenience.