Nexis Studio
Privacy Policy
About this policy
This policy explains which personal data we process when you visit nexistudio.dev, send us an enquiry, call our number 01 7800 097, sign up for our app at app.nexistudio.dev, and when you call an office that uses our phone assistant. It is based on the General Data Protection Regulation (Regulation (EU) 2016/679, the GDPR).
We publish this policy in Croatian and English. Both versions have the same content.
If you sign in to our app with Google, the section "Google user data" sets out exactly which data we receive from Google, what we use it for and how to delete it.
Our services are meant for businesses and offices, not for children.
This policy applies from 12 September 2026.
Who the controller is and how to contact us
The controller of your personal data is Luka Djogaš, owner of the sole trader business (obrt) NEXIS STUDIO, obrt za uredske i pomoćne uredske usluge, vl. Luka Djogaš, Buje, Juki 141. An obrt has no separate legal personality, so its owner is the controller. In this policy we call the owner and the obrt together Nexis Studio or "we".
We have not appointed a data protection officer. For any privacy question, write to support@nexistudio.dev.
- Registered name: NEXIS STUDIO, obrt za uredske i pomoćne uredske usluge, vl. Luka Djogaš, Buje, Juki 141
- Owner: Luka Djogaš
- Registered address: Kaštel, Juki 141, Buje
- OIB (Croatian tax identification number): 63105181019
- Email: support@nexistudio.dev
- Phone: 01 7800 097, from abroad +385 1 7800 097 (calls are answered by an AI assistant)
Two roles: when we are the controller and when we process data for an office
We are the controller for data we collect for ourselves: visits to this website, enquiries you send us, calls to our number 01 7800 097, booked introductory calls, data about our clients, including sign-up for the app at app.nexistudio.dev, and our Facebook Page. For these, this policy sets out the purpose, legal basis, recipients and retention periods.
When our phone assistant answers calls for a medical or dental practice, law office or other office that is our client, that office is the controller. We then process the data only on the office's behalf and on its instructions, as a processor. Before the assistant starts answering calls for an office, we sign a data processing agreement with that office.
If you called an office that uses our assistant
If you called a practice or office that uses our phone assistant, that office is the controller of your data. We process the call data (number, recording, transcript, summary, message and booked appointment, which we also add to Google Calendar if the office connected it; see the section "Connecting Google Calendar") only on the office's instructions and in line with the data processing agreement we sign with the office before we start working for it.
The office decides the purpose, legal basis and retention period and tells you about them in its own privacy notice. This also applies if you mention a health or legal matter during the call.
Please send requests for access, correction or deletion to the office you called. If you send them to us, we will pass them on to the office without delay and help it answer you. Tell us which number you called so we can find the right office.
We do not use data from calls to client offices for our own purposes. What our service providers may do with the data is set out in the section "Recipients". To run the assistant we use the providers listed in that section, most of which process data in the USA.
Visiting the website
When you open the website, your browser sends standard technical data. The website is delivered by Cloudflare, which acts as our processor.
There are no analytics scripts, advertising pixels (including the Meta pixel) or other tracking scripts on the website. From technical traffic data, without cookies or scripts, Cloudflare shows us aggregated statistics, for example the number of visits and the countries they come from.
- Data: IP address, browser and device information, the address of the page you open, and the country Cloudflare derives from your IP address.
- Purpose: to show the website and protect it from abuse. If you open the home page without having chosen a language yourself, we redirect you to the Croatian version if you open the site from Croatia, Bosnia and Herzegovina, Serbia or Montenegro, and to the Slovenian version if you open it from Slovenia.
- Legal basis: legitimate interest (Article 6(1)(f) GDPR) in showing the website securely and in the language most likely to suit you.
- Provider: Cloudflare (global network of data centres).
- Retention: our website does not store this data, and the country is used only at the moment of the redirect. Cloudflare keeps technical logs on our behalf, which contain the IP address, for up to 7 days. The aggregated traffic statistics contain no IP addresses.
Enquiry forms
The website has three kinds of forms: the contact form on the home page (Croatian, English and Slovenian versions), the enquiry form about the phone assistant at /hr/asistent/, for the Po mjeri (custom) plan and questions before signing up, and the contact form at /portfolio/. Enquiries are received by Formspree, which forwards them to our mailbox. The Asistent 100 and Asistent 300 plan buttons at /hr/asistent/ lead to sign-up in the app (see the section "Signing up and using the app").
If JavaScript is turned off in your browser, the form is sent directly to formspree.io, where Formspree's own privacy rules and cookies apply.
- Contact form data: name, work email, message and, if you wish, company name.
- Data from the form at /hr/asistent/: name, name of the practice or office, phone number, the plan you are interested in and, if you wish, email.
- Data from the form at /portfolio/: name, email and message.
- Each enquiry also includes a label for the page it was sent from, and Formspree also receives your IP address and browser information.
- Purpose: to answer your enquiry. For the form at /hr/asistent/: to call you, answer questions before you sign up, and agree on the Po mjeri plan.
- Legal basis: steps taken at your request before entering into a contract (Article 6(1)(b)) if you will enter into the contract yourself, for example as a sole trader or as the holder of a private practice. If you send the enquiry on behalf of a company or office, legitimate interest (point (f)) in answering a business enquiry and discussing working together with that company or office. If the enquiry is not about our services, legitimate interest (point (f)) in answering a message you sent us.
- Providers: Formspree (USA), Cloudflare, Google (email for the nexistudio.dev domain).
- Retention: 12 months after the last contact. If the enquiry leads to working together, we keep the data as client data.
Email, WhatsApp and Telegram
You can write to us at support@nexistudio.dev or contact us through the WhatsApp and Telegram buttons on the website. The buttons send no data until you click them. The app then opens, and WhatsApp (Meta) and Telegram process your data under their own privacy rules, as independent controllers.
- Data: email address, phone number or Telegram profile, and anything you write to us.
- Purpose: answering your enquiry, handling privacy requests, and answering questions left open after a call.
- Legal basis: steps before entering into a contract (point (b)) when you write to us about our services as a future contracting party; legitimate interest (point (f)) in answering your message when you write on behalf of a company or office or about something else. We handle requests about your rights to comply with a legal obligation (point (c)).
- Providers: Google (email for the nexistudio.dev domain), WhatsApp (Meta), Telegram.
- Retention: 12 months after the last contact.
Support chat
The home page and the phone assistant page have a "Chat with us" button ("Pišite nam" on the Croatian pages). The chat runs on Crisp, a service of Crisp IM SAS, France. Until you click the button, nothing loads from Crisp and Crisp sets no cookies. Only after the click does your browser load the Crisp chat.
Crisp then sets cookies for the Crisp session in your browser, with names starting with crisp-client/. They link your browser to the conversation so that your messages are not lost when you move to another page. They are described in the section "Cookies".
Basic questions are answered first by an automatic helper that works with Anthropic's Claude language model. At the start of the conversation the chat says that an automatic helper is answering, and one of us can take over the conversation at any time. So that the helper can reply, we send Anthropic your chat messages and the conversation so far. Anthropic acts as our processor and under its commercial terms may not use this data to train its models.
Crisp acts as our processor under Crisp's data processing agreement. According to Crisp, conversations are stored in the Netherlands and plugin data in Germany. Crisp also runs relay servers in the USA, the United Kingdom and Singapore, which do not store conversation content, only connection logs: IP address, time of connection, browser details and the page you connect from.
- Data: the messages you write in the chat, your email address if you leave it, and technical data Crisp collects, such as your IP address and the approximate location derived from it, browser and device details, and the page on which you opened the chat.
- Purpose: answering questions about our services and supporting clients.
- Legal basis: steps before entering into a contract (point (b)) when you ask about our services as a future contracting party; legitimate interest (point (f)) in answering questions and providing support in other cases.
- Providers: Crisp IM SAS (chat), Anthropic Ireland, Limited (the Claude language model for the automatic helper; data is also processed in the USA).
- Retention: we keep our automatic helper's logs for 12 months. We delete conversations in Crisp no later than 12 months after the last message. Under its own rules, Crisp keeps the IP address of a visitor who started a conversation with no time limit, to protect against abuse and spam. Anthropic deletes inputs and outputs within 30 days at the latest, unless it has to keep them longer to enforce its usage policy or because the law requires it.
Calls to our number 01 7800 097
Calls to our number are answered by an AI phone assistant. At the very start of every call it says that it is an AI assistant, that the call is recorded and transcribed so that we can get back to you, and that you can find more information at nexistudio.dev. See the section "AI and call recording" for more.
The assistant knows the number you are calling from so it can offer to call you back on that number. For this reason the number is sent to the language model together with the current date and time.
After the call, we receive a text message on our mobile phone with your name, the reason for your call, the callback number and an urgency flag. If the assistant is not sure it noted the number correctly, the message also contains a link to the recording.
Please do not share health or other sensitive information during the call, as it is not needed for an enquiry about our services. If you share it anyway, it stays in the recording and transcript until the end of the retention period in this section. On request, we will delete it without undue delay.
- Data: the number you call from (unless hidden), time and length of the call, technical call data (for example how the call ended), the call recording, the transcript, and anything you say, for example your name, company, reason for calling, callback number and a time that suits you.
- Data created after the call: a short summary written by AI, plus name, company, reason for calling, callback number and whether it was confirmed, urgency (urgent or routine), preferred time, booked slot, and questions the assistant could not answer.
- Purpose: to answer calls when we cannot pick up ourselves, take a message, answer questions about our services based on information we prepared, flag urgent calls, book an introductory call, and know exactly what you asked for. The recording also lets us check the callback number when the assistant did not understand it with certainty.
- Legal basis: legitimate interest (Article 6(1)(f)). Our interest is to answer every call even when we are busy, and to know exactly who called, why, and which number to call back.
- Providers: Telnyx (number, call control and text messages), Vapi (assistant platform, recordings, transcripts and summaries; it writes the summaries with a language model that Vapi selects), Deepgram (speech to text), OpenAI (language model), ElevenLabs (synthetic voice), Vercel (application), Supabase (database in the EU). Apart from Supabase, all of them process data in the USA.
- Retention: recordings and transcripts 90 days from the call; summaries, data extracted from the call, call records, messages and notices 12 months.
Booking an introductory call
If you wish, the assistant will offer available slots during a call to our number and book a 15-minute introductory call at the time you choose. If the confirmation number is a mobile number, we send you a text message with the date, time and our phone number.
- Data: name, phone number for confirmation, reason for the call, the number you called from, start and end time of the slot.
- Purpose: booking and confirming the slot.
- Legal basis: steps taken at your request before entering into a contract (Article 6(1)(b)) if you will enter into the contract yourself. If you book the call on behalf of a company or office, legitimate interest (point (f)) in discussing working together with that company or office.
- Providers: Vapi, Deepgram, OpenAI, ElevenLabs, Vercel, Supabase, Telnyx (confirmation text message).
- Retention: 12 months.
Text message after a missed call
If the assistant cannot take your call to our number, we may send one text message to the mobile number you called from. It says that we missed your call and will get back to you. The message contains no advertising or offers.
You usually cannot reply to this message because it is sent with a sender name instead of a number. If you want to write to us, use support@nexistudio.dev. If you do not want such messages, you can object (see the section "Right to object"). We then add your number to a list of numbers we no longer send such messages to.
- Data: your number, the text of the message, time sent and delivery status.
- Who receives it: only mobile numbers from Croatia, Slovenia, Bosnia and Herzegovina, Austria, Germany, Switzerland and Italy, at most one message per number per day. We send nothing to a hidden number.
- Purpose: so you know your call was not lost.
- Legal basis: legitimate interest (point (f)) in letting you know we saw your call.
- Providers: Telnyx (USA), Vercel, Supabase.
- Retention: 12 months.
Our clients' data
For each office that uses our assistant, we keep the data needed to run the service. What we process when an office signs up by itself, in the app, is set out in the section "Signing up and using the app".
When a call is forwarded, the phone network also reports the number of the office that forwarded it. We use it only to match the call to the right office, and it is recorded only in technical logs.
- Data: office name, language, the office's public number, the number calls are forwarded to, mobile phone number and email of the owner or contact person, booking link, address for notices, service settings and start date.
- Purpose: providing the service, that is routing calls, call notices and communication with the client.
- Legal basis: performance of a contract (Article 6(1)(b)) when the client is a natural person, for example a sole trader or the holder of a private practice. When the client is a company or other legal person, we process the data of its owner and contact persons on the basis of legitimate interest (point (f)) in communicating with the client about the contract and the service. We keep invoices and other business records to comply with legal obligations (point (c)).
- Providers: Supabase, Vercel, Telnyx, Resend (email).
- Retention: for as long as we work together. When we stop working together, we delete the data needed to run the service, and keep invoices and other business records for as long as tax and accounting rules require or as needed to establish, exercise or defend legal claims.
Signing up and using the app
An office can sign up for the phone assistant by itself, in our app at app.nexistudio.dev: it creates a user account, enters the office's details, adds a card and switches on call forwarding. We are the controller for the account, office and subscription data. For the calls the assistant then answers for the office, the office is the controller and we are the processor (see the section "If you called an office that uses our assistant"). The office accepts the data processing agreement in the app, before we create its assistant.
You create the account with an email address and password or with the "Nastavite s Googleom" (Continue with Google) button. The account is kept by Supabase (Supabase Auth). We do not store your password: the app only passes it on to Supabase, which keeps it in a form from which the password cannot be read. You confirm your email address through a link we send you by email.
The sign-in pages (/start and /login) load Google's sign-in button (Google Identity Services) from accounts.google.com. The button loads as soon as you open the page, so Google already receives your IP address and browser information at that point and may use its own cookies, under its own privacy rules. If you sign in with Google, Google gives us the basic data from your Google account; what it is and how we use it is set out in the section "Google user data".
You enter your card in Stripe's payment form embedded in our page or on Stripe's payment page. The card details go directly to Stripe, where Stripe's privacy rules apply. We do not see or store your card number. From Stripe we store the customer ID, the subscription ID, the subscription status and the date the free trial ends. We sell the subscription, and Stripe processes the payment for us. For part of the processing, for example fraud prevention and meeting legal obligations, Stripe is a controller and processes the data under its own privacy policy.
The free trial covers the first 25 counted calls and lasts at most 30 days. To know when it ends, we count the calls the assistant answers for the office. Calls shorter than 15 seconds, test calls and the call you made to check forwarding do not count.
The app sends you emails through the provider Resend: the links to confirm your address and to set a new password, a summary of every call the assistant answers, a warning when you have used 20 of the 25 free calls and three days before the free trial ends, and a notice if a payment fails. These messages are part of the service and contain no advertising. You can switch off the summaries of individual calls and the daily summary in the app.
- Account data: email address and password or, if you sign in with Google, the data from your Google account listed in the section "Google user data".
- Office data: office name, OIB (see the section "OIB and office check"), the office's phone number (we use it to recognise calls the office forwards to the assistant), the email address for call summaries, the chosen plan, and the time and version of the accepted terms of use and data processing agreement.
- Data the assistant answers from: opening hours, services and prices, questions and answers, address, website, notes, and booking settings and hours. For each office we create an assistant on the Vapi platform and a SIP address through which the assistant receives the office's calls.
- Subscription data: the Stripe customer and subscription IDs, the subscription status, the number of free calls used and the date the free trial ends. We store the text of the messages we send you about calls, the free trial and payments in our database.
- Purpose: creating the account and signing in, setting up and running the office's assistant, charging for the subscription, notices about calls, the free trial and payments, and protecting sign-in from abuse.
- Legal basis: performance of a contract (Article 6(1)(b)) when the client is a natural person, for example a sole trader or the holder of a private practice. When the client is a company or other legal person, we process the data of its owner and contact persons on the basis of legitimate interest (point (f)) in providing the service to the client and communicating with it about the contract. Sign-in security, for example limiting the number of sign-in attempts from the same IP address, is based on legitimate interest (point (f)) in protecting accounts from abuse. We keep invoices for the subscription to comply with a legal obligation (point (c)).
- Providers: Supabase (user accounts and database), Vercel (application), Stripe (payments), Resend (email), Google (sign-in with Google), Vapi (the office's assistant), Telnyx (calls).
- Retention: for as long as we work together. Cancelling the subscription does not delete the account automatically. We delete the account and office data after we stop working together, or earlier if you ask. We keep invoices and other business records for as long as tax and accounting rules require or as needed to establish, exercise or defend legal claims. We delete the text of sent messages after 12 months.
Google user data
This section applies when you sign in to the Nexis Studio app at app.nexistudio.dev with Google (the "Nastavite s Googleom" button, Continue with Google). Sign in with Google is the only way the app receives data from your Google account. Through your Google account we do not ask for access to your Gmail, Google Drive, contacts, calendar or any other Google service. Connecting a calendar for bookings works separately, without your Google account: see the section "Connecting Google Calendar".
When you sign in, Google sends the app a signed ID token with the basic profile of your Google account: your name, your email address and whether Google has verified it, the link to your profile picture and your Google account ID. For a Google Workspace account it also contains the account's domain. We never receive your Google password.
We use this data only to create your account in the app and to sign you in to it securely. Supabase, which keeps our user accounts, checks the ID token, stores the data in your account record and uses your Google account ID to recognise you the next time you sign in. Of this data, the app itself uses only your email address: it shows it in the app and suggests it as the office's contact address when you sign up. If you keep that suggestion, the address is then also office data (see the section "Signing up and using the app").
- Data: name, email address and whether it is verified, profile picture link, Google account ID and, for a Google Workspace account, its domain.
- Purpose: creating your account and signing you in securely, and nothing else.
- What we do not do: we do not use Google user data for advertising, we do not sell it, we do not use it to build profiles or to train AI models, and nobody at Nexis Studio reads it except when you ask us for help with your account, to keep the app secure, or when the law requires it.
- Sharing: only with the providers that run the service for us as processors: Supabase, which keeps user accounts (Supabase Auth), and Vercel, which runs the app. We give it to no one else, except when the law requires us to.
- Storage: in your account record at Supabase. Our database is in the EU; see the section "Transfers outside the EU". The data travels only over encrypted connections.
- Retention: for as long as you have an account. After you delete the account, we delete the account record with the Google data within 30 days.
- Deletion: delete the account in the app ("Obriši račun" on the Poslovanje page), or write to support@nexistudio.dev and we will delete it for you. You can also remove the app's access to your Google account at any time at myaccount.google.com/permissions; that stops Google from confirming your sign-in to us but does not delete the data we already received, so to delete it, delete the account as well.
Nexis Studio's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy (developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.
OIB and office check
When you sign up in the app, you enter the office's OIB (Croatian personal identification number) in the office details step. The OIB is required. If the office is a sole trader (obrt) or a private practice, this is the owner's personal OIB, so it is the owner's personal data. Offices that signed up before this check was introduced add the OIB later in the app.
Using the OIB, we look up the office's registered name, registered address and status in the Croatian court register (Sudski registar, open data) and in the European Commission's VIES system for checking VAT identification numbers. We send these registers only the OIB. If a register finds the office, the app shows you the name and address it found and you confirm that it is your office. We store the registered name and address only if you confirm them; we store the register status and whether the OIB is in the VAT system either way. Sole traders and private practices are not in the court register and are in VIES only if they are VAT registered, so the registers often do not find them. The office then stays unverified, the sign-up continues, and we receive an email notice with the office name, OIB, phone number and email address. The same applies if a register does not answer in time or if the register shows the office in liquidation, in bankruptcy or struck off.
We grant the free trial once per OIB: if an office with the same OIB already had a free trial or a subscription, charging starts at once. In addition, after you enter the card we get the card fingerprint from Stripe. It is a Stripe token that identifies the same card, not the card number. If the same card was already used for another office's free trial, we note it and receive an email notice. Nothing is charged or stopped automatically; a person at Nexis Studio decides on the next steps.
We confirm the office's phone number with the first call that arrives forwarded from that number: the phone network reports the number a call was forwarded from, and we record when such a call first arrived. Forwarding is switched on from the office's own phone line, so such a call confirms that the number belongs to the office. If no such call arrives within 7 days of signing up, we send one reminder by email. If none arrives by the end of the free trial, the subscription ends without a charge and we tell you by email.
- Data: the OIB, the registered name and address you confirmed, the register status, whether the OIB is in the VAT system, how and when it was checked, the card fingerprint from Stripe, and the time of the first forwarded call and of the reminders sent.
- Purpose: issuing invoices, checking that the office really exists, and preventing fraud and abuse of the free trial, so that each office uses it only once.
- Legal basis: for issuing invoices, legal obligation (Article 6(1)(c)) and performance of a contract (point (b)); for checking the office and allowing one free trial per office, legitimate interest (point (f)) in preventing fraud and abuse of the free trial.
- Sources: the court register (Sudski registar, open data), the European Commission's VIES system, Stripe (card fingerprint), the phone network (the number a call was forwarded from).
- Recipients: we pass the OIB, registered name and address to Stripe as the customer's tax ID and billing details. If the OIB is in the VAT system, we send it to Stripe as a VAT identification number (HR plus the OIB), otherwise as an OIB. We send the notices about an unverified office and a reused card to ourselves through the provider Resend.
- Retention: as for other client data. We keep the data needed for invoices for as long as tax and accounting rules require.
Helper for filling in the office details
When you enter the office details in the app, and later when you edit them, you can run the optional "Popunite umjesto mene" (Fill it in for me) helper. The helper reads the office's website and the documents you add, and suggests opening hours, services and prices, the address, questions and answers, and notes. You can accept, edit or reject each item, and you confirm items that differ from your data or may be out of date one by one. Only what you accept goes into the form, and it is saved only when you save the form.
The helper works with a language model from Anthropic. We send Anthropic the office name, the documents you add (PDFs or photos, for example a price list) and their names, and your notes. When the helper reads your website or looks for you online, we also send the office's website, phone number and address. Anthropic runs the web searches and opens the pages with its own web search and web fetch tools. We do not send the rest of the office's existing details: differences between the suggestions and your data are checked in your browser.
We do not store the documents you add: they exist only in the app's memory while the request is processed. We store only data about each run of the helper, without content: the time, the kind of input, the number of tokens (units of text the model processes), the number of searches, the outcome and an error code. Each office can run the helper at most 10 times in 24 hours.
Anthropic acts as our processor. Under Anthropic's commercial terms it may not use this data to train its models. It deletes inputs and outputs within 30 days at the latest, unless it has to keep them longer to enforce its usage policy or because the law requires it.
If the documents or notes contain personal data, for example staff names on a price list, these are also sent to Anthropic and processed in the same way. Add such data only if callers need it to get answers.
- Data: the office name, website, phone number and address, the documents you add and their names, your notes, the search results and pages the helper opens, and the suggestion the helper puts together.
- Purpose: suggesting office details, which the owner reviews and confirms item by item.
- Legal basis: performance of a contract (Article 6(1)(b)), because the office owner runs the helper as part of the service. When the client is a company or other legal person, we process the data of its owner and contact persons on the basis of legitimate interest (point (f)) in providing the service to the client.
- Providers: Anthropic (language model, web search and web fetch), Vercel (application), Supabase (data about helper runs).
- Retention: we do not store the documents or the suggestion; items you accept and save become office details. We delete the data about helper runs after 12 months, like other records. Vercel deletes the technical log of each run, which has no content, within one day at the latest.
Finding the office on Google Maps
An office without a website can look up its listing on Google Maps when it enters the office details in the app. The owner types the office name and town, and we send them to Google through the Places API (Google Maps Platform). Google returns up to five offices with their name, address, phone number, type of office and whether the office has a website. When the owner picks their office, we also ask Google for that office's opening hours and website. We do not ask for reviews or photos.
The owner can accept, edit or reject each item from Google Maps. We store only what the owner accepts and saves, which becomes the office's own data, and Google's place identifier (place ID) of the chosen office, which Google's rules allow us to keep. We never replace an office phone number that is already entered with one from Google. We do not write anything else Google returns to our database: we only pass the search results on to your browser, and we keep the chosen office's details in the app's memory for at most 24 hours, so that looking at the same office again does not go back to Google. For each lookup we store only data without content: the time, the kind of request, the number of results, the outcome and an error code. Each office can run at most 20 searches in 24 hours.
For Google Maps Platform, Google is an independent controller under Google's Controller-Controller Data Protection Terms, which the Google Maps Platform terms of service refer to. For personal data from Europe, those terms name Google Ireland Limited as Google's controller. Google collects data about requests, for example search terms, under its own privacy policy. If the office name contains a person's name, for example "Ordinacija dr. Horvat", Google receives that name too.
- Data: the office name and town you type; the data Google returns (the office's name, address, phone number, type, opening hours and website); Google's place identifier; data about lookups without content.
- Purpose: suggesting office details from Google Maps, which the owner reviews and confirms item by item.
- Legal basis: performance of a contract (Article 6(1)(b)), because the office owner runs the search as part of the service. When the client is a company or other legal person, we process the data of its owner and contact persons on the basis of legitimate interest (point (f)) in providing the service to the client.
- Providers: Google (Google Maps Platform, as an independent controller), Vercel (application), Supabase (place identifier and data about lookups).
- Retention: we do not store data from Google that you do not accept, and the chosen office's details stay in the app's memory for at most 24 hours. We keep accepted data and the place identifier like other office details. We delete the data about lookups after 12 months, like other records.
Connecting Google Calendar
An office that lets the assistant book appointments can connect its Google Calendar in the app. This does not use Sign in with Google and gives us no access to the office's Google account: in Google Calendar's settings the office itself shares one calendar with the address of our service account in Google Cloud, with the permission to make changes to events, and enters the calendar ID in the app, usually its Gmail address. We can then reach only that calendar, and only while it is shared. We store the calendar ID and the time of connection. The office can disconnect the calendar in the app at any time, and stops our access completely by removing the sharing in Google Calendar's settings.
When a caller books an appointment, we read only the busy periods (start and end) from the calendar, not the content of existing events. We add the booked appointment as an event with the caller's name in the title, and the visit type, the callback number and a note that it was booked by phone in the description. The visit type is a neutral label, for example the name of one of the office's services or a word such as "pregled" (check-up) or "kontrola" (follow-up), at most 40 characters; we never record symptoms or the caller's own words. We also store the appointment in our database, with the ID of the event in Google Calendar.
For the office's Google account and calendar the controller is Google (Google Ireland Limited for users in the EU), under the terms the office accepted with Google. We access the calendar on the office's behalf, as its processor, and for the caller's data the office is the controller (see the section "If you called an office that uses our assistant"). We access the calendar without a service account key: on each access the app obtains a short-lived access token from Google that is limited to the calendar.
- Data: the calendar ID and the time of connection; busy periods from the calendar; for each appointment the caller's name, the visit type, the callback number, the start and end of the appointment, and the ID of the event in Google Calendar.
- Purpose: so that the assistant offers only free slots and the booked appointment goes into the calendar the office already uses.
- Legal basis: for the connection data, as for other client data, that is performance of a contract (point (b)) or legitimate interest (point (f)). For the caller's data, the office decides the legal basis as the controller.
- Providers: Google (Google Calendar and Google Cloud), Vercel, Supabase.
- Retention: we keep the connection data like other client data. We delete the appointment from our database after 12 months, like other booking records. The event in Google Calendar stays for as long as the office keeps it.
Outlook, iCloud and other calendars
An office that keeps its appointments in Outlook, Apple iCloud or another calendar can enter its calendar's published link (an ICS link) in the app. For now we accept links from Outlook, iCloud and Google Calendar. We store the link encrypted, we do not write it to technical logs, and the app shows it only in shortened form. We also store the time and outcome of the last check of the link. The office can remove the link in the app at any time.
When a caller books an appointment, we fetch the calendar from the servers of Microsoft, Apple or Google, depending on where the office keeps it, and take only the busy periods (start and end) from it. We do not store the titles, descriptions or attendees of events. We keep the busy periods only in the app's memory, for at most 10 minutes.
We do not write anything to such a calendar. We send the booked appointment to the office as a calendar invitation by email, through the provider Resend, to the office's email address. The invitation contains the caller's name, the visit type, the callback number, the start and end of the appointment and a note that it was booked by phone. We also store the appointment and the email sent in our database.
An office that keeps its appointments on paper, in Excel or without a calendar connects nothing. The assistant then does not book appointments but takes appointment requests, and apart from that choice we process no extra calendar data.
For the caller's data the office is the controller, and we process it as the office's processor (see the section "If you called an office that uses our assistant"). The office keeps its calendar with Microsoft, Apple or Google under the terms it accepted with them.
- Data: the encrypted calendar link and the time and outcome of the last check; busy periods from the calendar; for each appointment the caller's name, the visit type, the callback number, the start and end of the appointment, and the email with the invitation.
- Purpose: so that the assistant offers only free slots and the office gets the booked appointment for the calendar it already uses.
- Legal basis: for the link, as for other client data, that is performance of a contract (point (b)) or legitimate interest (point (f)). For the caller's data, the office decides the legal basis as the controller.
- Providers: Microsoft, Apple or Google (the calendar the office published), Resend (the email with the invitation), Vercel, Supabase.
- Retention: we keep the link until the office removes it or for as long as we work together; busy periods for at most 10 minutes in the app's memory. We delete the appointment and the invitation email from our database after 12 months, like other booking and message records. The invitation in the office's email and calendar stays for as long as the office keeps it.
Technical logs and quality checks
The call application keeps technical logs so we can find and fix errors. They may contain the caller's number, the number called, the office number, numbers we send text messages to, the office name, call, booking, office and subscription identifiers, and error messages. The logs are kept by Vercel (USA), which deletes them automatically within one day. We store event notices that providers send us, for example that a call has ended or a text message was delivered, in our database.
We sometimes listen to recordings or read transcripts of calls to our number to check that the assistant works correctly. For this we may save them on our computer. We delete these copies by hand after the check, and within 90 days from the call at the latest. We do not use calls to client offices for these checks.
For calls to client offices we keep technical logs as a processor, and the office decides the purpose and retention period. The legal basis and periods below apply to our number.
- Legal basis: legitimate interest (point (f)) in a service that works correctly, an assistant that understands callers accurately, and fixing errors quickly.
- Retention: technical logs at Vercel up to one day; event notices in our database 30 days; recordings, transcripts and copies on our computer 90 days from the call.
Facebook Page and ads
We have a Facebook Page called Nexis Studio. When you visit it, Meta Platforms Ireland Limited (Serpentine Avenue, Block J, Dublin 4, Ireland) processes your data under its own privacy rules.
For Page statistics (Page Insights), we and Meta are joint controllers. Meta gives us aggregated statistics about visits to the Page. The legal basis is our legitimate interest (point (f)) in knowing how the Page is used. Under the joint controller addendum published by Meta (Page Insights Controller Addendum), Meta takes primary responsibility for this data, including informing you and handling your rights. You can send a request to Meta or to us, and we will pass it on to Meta.
If we run ads on Meta platforms, we and Meta are joint controllers for choosing the audience that sees the ad, under Meta's controller terms. For the ads we run, we receive only aggregated statistics from Meta. The legal basis for our part of this processing is legitimate interest (point (f)) in presenting our services to businesses and offices. Any consent Meta needs for its own processing, for example for tracking users, is collected by Meta.
If you send us your details through a form in an ad, we are the controller for that data and treat it like an enquiry from our website (see the section "Enquiry forms").
Meta Platforms Ireland transfers data to Meta Platforms, Inc. in the USA under the EU-US Data Privacy Framework (Commission Implementing Decision (EU) 2023/1795 on adequacy) and standard contractual clauses. This transfer is made by Meta, not by us. Meta decides how long it keeps this data.
There is no Meta pixel or other Meta tracking tool on our website.
AI and call recording
Under the EU Artificial Intelligence Act (Regulation (EU) 2024/1689) you have the right to know that you are talking to AI. That is why the assistant says so at the very start of every call and does not present itself as a person. Right after that, it says that the call is recorded and transcribed so that we can get back to you, and that you can find more information at nexistudio.dev.
Recording starts as soon as the assistant answers and cannot be switched off during the call or in advance for a particular number. If you do not want the call recorded, hang up and write to us at support@nexistudio.dev. After the call you can ask us to delete the recording and transcript, or you can object.
For offices that are our clients, we set up the assistant so that at the start of the call it gives the office's name and says that it is an AI assistant and that the call is recorded. We do this before the assistant starts answering calls for the office. In the app the office can change the opening words of the greeting, but it cannot switch this notice off or change it.
In the app the office chooses the assistant's voice from a short list of ElevenLabs preset voices and can switch on office background sound. The voice is still synthesised by ElevenLabs through the Vapi platform, as described below. If you play a voice sample in the app, your browser loads it from ElevenLabs' public address on Google's storage (storage.googleapis.com), so Google and ElevenLabs then receive your IP address.
How the assistant works:
- Your speech is turned into text in real time (Deepgram).
- A language model (OpenAI) writes a reply based on that text and on information we prepared.
- The reply is spoken in a synthetic voice (ElevenLabs).
- The Vapi platform connects all of this, records the call and, after the call, creates a transcript, a short summary and a list of details from the conversation. It writes the summary with a language model that Vapi selects.
Automated decision-making
The assistant answers questions and takes messages, and on our number it also offers available slots and books the slot you choose. Based on what you say, it automatically marks whether the call is urgent or routine and extracts details such as your name, the reason for calling and the callback number. This has no legal effects on you and does not similarly significantly affect you within the meaning of Article 22 GDPR.
A person at Nexis Studio or at the office you called reads the summary and the message and decides on the next steps. The urgency flag only tells that person which calls to look at first.
Recipients
We do not sell your data. It is received by service providers that do the technical part of the work for us, as processors. They may process the data only for us and on our instructions. The exception is Vapi: under its own privacy policy, Vapi may also use call recordings, transcripts and logs to improve its AI models. Under its own terms, Deepgram may keep audio to improve its models unless a setting switches this off.
Deepgram, OpenAI and ElevenLabs work within the Vapi platform, as Vapi's sub-processors. The language model Vapi uses to write call summaries also works within the platform.
Independent controllers are Meta (Facebook, WhatsApp) and Telegram when you use their services, Google when you sign in with Google and when an office looks up its details on Google Maps, Stripe for part of the processing of payment data (for example fraud prevention and meeting legal obligations), and the phone and email providers through which our notices arrive. For Facebook Page statistics and ad audiences, Meta is a joint controller with us (see the section "Facebook Page and ads"). We give data to public authorities only when the law requires us to.
List of providers:
- Cloudflare, Inc. (USA): delivering the website and protecting it from abuse.
- Formspree, Inc. (USA): receiving and storing form enquiries.
- Google (Google Workspace): our mailbox (support@nexistudio.dev).
- Telnyx LLC (USA): Croatian phone number, call control and text messages.
- Vapi Inc. (USA): phone assistant platform, recordings, transcripts and call summaries.
- Deepgram, Inc. (USA): speech to text.
- OpenAI (USA): language model.
- Eleven Labs Inc. (ElevenLabs, USA): synthetic voice.
- Vercel Inc. (USA): the application that handles calls, messages and bookings, the app at app.nexistudio.dev, and technical logs.
- Supabase (database in the EU; contracting party Supabase Pte. Ltd, Singapore): database and user accounts in the app (Supabase Auth).
- Stripe Payments Europe, Limited (Ireland): subscription payments, and the customer's tax ID and billing details (OIB, registered name and address); it also transfers data to Stripe, LLC (USA).
- Plus Five Five, Inc. (Resend, USA): sending emails from the app, including the address confirmation and new password emails that Supabase sends, and appointment invitations to offices that use Outlook, iCloud or another calendar.
- Google (sign-in with Google): Google's sign-in button and verification of the Google account, as an independent controller.
- Anthropic Ireland, Limited (Ireland): the language model, web search and web fetch for the "Popunite umjesto mene" helper, and the Claude language model for the automatic helper in the support chat; data is also processed in the USA.
- Google (the office's Google Calendar and Google Cloud): busy periods and appointments in the calendar the office connected; Google runs the calendar as the controller for the office.
- Google (Google Maps Platform): finding the office on Google Maps (the office name and town), as an independent controller; Google Ireland Limited for personal data from Europe.
- Crisp IM SAS (France): the support chat on the website; conversations are stored in the Netherlands.
Transfers outside the EU
Most of our service providers are in the USA, so your data is also transferred to and processed there. Our database is in the EU, but your data does not stay in the EU.
For these transfers we rely on the safeguards in Chapter V of the GDPR, as listed below. You can ask for a copy or summary of these safeguards at support@nexistudio.dev. The transfer made by Meta is described in the section "Facebook Page and ads".
- Cloudflare, Telnyx and Vercel: certified under the EU-US Data Privacy Framework (Commission Implementing Decision (EU) 2023/1795 on adequacy). Their data processing agreements also contain standard contractual clauses, which apply if the certification stops being valid.
- Vapi and Formspree: standard contractual clauses adopted by the European Commission, which these providers rely on in their terms and data protection documents.
- Deepgram, OpenAI and ElevenLabs: they receive data as Vapi's sub-processors. ElevenLabs (Eleven Labs Inc.) states that it is certified under the EU-US Data Privacy Framework, and its data processing agreement also contains standard contractual clauses. Deepgram and OpenAI rely on standard contractual clauses.
- Supabase: the database is in the EU. If Supabase or its sub-processors access data from outside the EU, for example for support, standard contractual clauses apply.
- Google (Google Workspace): EU-US Data Privacy Framework (Google LLC is certified) and the standard contractual clauses in Google's data processing addendum.
- Stripe: the contracting party is Stripe Payments Europe, Limited in Ireland. Data is also transferred to Stripe, LLC in the USA, which is certified under the EU-US Data Privacy Framework. Stripe's data transfers addendum also contains standard contractual clauses, which apply if the certification stops being valid.
- Resend: the EU-US Data Privacy Framework, which Resend states in its data processing agreement that it complies with, and the standard contractual clauses in that agreement.
- Google (sign-in with Google): the transfer is made by Google as an independent controller, under its own privacy rules. Google LLC is certified under the EU-US Data Privacy Framework.
- Anthropic: the contracting party is Anthropic Ireland, Limited in Ireland, and data is also processed in the USA. Anthropic's data processing agreement contains the standard contractual clauses adopted by the European Commission.
- Google (the office's Google Calendar): Google runs the calendar under the office's terms with Google. Google LLC is certified under the EU-US Data Privacy Framework.
- Google (Google Maps Platform): Google processes the data as an independent controller under its Controller-Controller Data Protection Terms, in which Google Ireland Limited is the controller for personal data from Europe. Google LLC is certified under the EU-US Data Privacy Framework.
- Crisp: the contracting party is Crisp IM SAS in France, and conversations are stored in the Netherlands. Only Crisp's relay servers are outside the EU (USA, United Kingdom, Singapore), and they keep only connection logs. The safeguards in Crisp's data processing agreement apply to these transfers.
How long we keep data
We keep data only for as long as we need it for the purpose we collected it for.
When the period ends, we delete the data from our own systems and from the providers' systems where we can delete it ourselves. We keep it longer only when needed to resolve a specific complaint, request or dispute, or when the law requires it. For calls to client offices, the office decides the retention periods.
Some providers keep part of the data under their own rules: Telnyx keeps call and text message records for as long as it reasonably needs to provide the service, bill for it and meet legal obligations; and ElevenLabs may keep a history of synthesised speech, which can include a phone number the assistant read back to you. Stripe keeps payment data under its own rules and legal obligations. Crisp keeps the IP address of a visitor who started a chat conversation under its own rules, with no time limit.
Periods:
- Recordings and transcripts of calls to our number, including copies saved for quality checks: 90 days from the call.
- Summaries and data extracted from calls, and records of calls, text messages, notices and booked slots: 12 months.
- Event notices that providers send us: 30 days.
- Technical logs at Vercel: up to one day.
- Technical logs at Cloudflare: up to 7 days.
- Form enquiries, including forms in Meta ads, emails, and WhatsApp and Telegram messages: 12 months after the last contact.
- Client data, including the app account and office data: for as long as we work together; after that, invoices and other business records for as long as the law requires or as needed to establish, exercise or defend legal claims.
- Documents added to the "Popunite umjesto mene" helper: we do not store them; Anthropic deletes inputs and outputs within 30 days at the latest.
- Finding the office on Google Maps: the chosen office's details from Google for at most 24 hours in the app's memory; data about lookups for 12 months.
- Calendars connected by ICS link: busy periods for at most 10 minutes in the app's memory; the link until the office removes it or for as long as we work together.
- Support chat: our automatic helper's logs for 12 months; we delete conversations in Crisp no later than 12 months after the last message.
- The lang cookie: 30 days from choosing a language.
- Cookies set by Cloudflare, Supabase and Crisp: see the section "Cookies".
- Facebook Page statistics: under Meta's rules.
Cookies
We use only cookies that are necessary for the website and the app to work or that remember a choice you made yourself. We do not use cookies for analytics or advertising.
These cookies are needed for the service you asked for or keep the website secure, so under Article 43(4) of the Croatian Electronic Communications Act (Zakon o elektroničkim komunikacijama) your consent is not required. That is why the website shows no cookie consent notice. The processing is based on our legitimate interest (point (f)) in a secure website that shows the language you chose.
You can delete or block cookies in your browser settings. The website will then not remember your language choice, and you will not be able to sign in to the app.
If we ever add analytics or advertising cookies, we will ask for your consent first and update this policy.
Cookies the website and the app at app.nexistudio.dev may set:
- lang (Nexis Studio): remembers the language you chose (en, hr or sl) so the website does not redirect you to another language. It is set only when you click a language option or open a link with a language marker. It lasts 30 days and is sent only over a secure (HTTPS) connection.
- __cf_bm (Cloudflare, only if bot protection is switched on): tells people apart from automated traffic. It expires after 30 minutes of inactivity.
- cf_clearance (Cloudflare, only after a security check): records that you passed the check. It lasts as long as the check setting allows, usually 30 minutes.
- cf_chl_rc_i, cf_chl_rc_ni and cf_chl_rc_m (Cloudflare, only during a security check): Cloudflare uses them only to detect errors in the check, not for tracking. Cloudflare does not publish how long they last.
- _cfuvid (Cloudflare, only if request rate limiting is switched on): tells apart visitors who share the same IP address. It lasts until you close the browser.
- sb-aqzmshacfkorvwunzczz-auth-token and cookies starting with that name (Supabase, only on app.nexistudio.dev): they keep you signed in to the app and, during sign-in, hold a one-time code Supabase uses to check that sign-in is completed in the same browser. They are necessary for signing in. They are set only when you create an account or sign in, and deleted when you sign out. They last at most 400 days.
- Google's cookies (Google, on the app's /start and /login pages): Google's sign-in button loads from accounts.google.com, so Google may set or read its own cookies under its own privacy rules. These are Google's cookies, not ours: we do not set or read them.
- Stripe's cookies (Stripe, on the card step in the app): Stripe's payment form loads from js.stripe.com, and Stripe may set its own cookies for fraud prevention and for the form to work, under its own privacy rules. These are Stripe's cookies, not ours.
- crisp-client/ and cookies starting with that name (Crisp, only after you click the chat button): they link your browser to the support chat conversation so that your messages are kept when you move to another page. They are not set before the click. Under Crisp's rules they last 6 months, and the period is renewed when the chat loads again.
Do you have to give us your data?
As a website visitor or caller, you have no legal or contractual obligation to give us personal data. Different rules apply to clients, as set out below. If you do not give us the data, this is what happens:
- Forms: only the marked fields are required. Without them we cannot answer your enquiry or call you.
- Calls: you do not have to give your name or number, and you can hide your number. We may then be unable to call you back. You can hang up at any time and write to support@nexistudio.dev instead.
- Booking: an introductory call needs a name and phone number.
- Clients: the data needed to run the service and issue invoices is required to enter into and perform the contract, and tax rules also require the invoice details, including a business buyer's OIB. Without it we cannot enter into the contract or provide the service. To use the service through the app you need an account and a card entered with Stripe, also for the free trial. When signing up in the app, the office's OIB is also required.
Data we do not get from you directly
We get some data from others:
- If someone else gives your details in a call or enquiry, for example a colleague calling on your behalf, we get them from that person. This is usually a name, phone number and the reason for getting in touch.
- We get the number you call from and technical call data from the phone network, through our provider Telnyx.
- We get aggregated statistics about visits to our Facebook Page and about our ads from Meta.
- If you sign in with Google, we get your name, email address and profile picture from Google. We get the subscription and payment status from Stripe.
- We get the office's registered name, address and status, and whether the OIB is in the VAT system, from the court register and the VIES system, and the card fingerprint from Stripe.
- We get the office details that the "Popunite umjesto mene" helper finds online from public sources, through Anthropic's web search and web fetch.
- We get office details from Google Maps (the name, address, phone number, type of office, opening hours and website) from Google, when the office owner asks for them.
- We get the busy periods from the office's calendar from the servers of Microsoft, Apple or Google, through the link the office published.
Your rights
As a data subject, meaning the person the data relates to, you have the following rights for data where we are the controller:
- Access: you can find out whether we process your data and get a copy.
- Correction: you can ask us to correct inaccurate data or complete incomplete data.
- Deletion: you can ask for deletion, for example when the data is no longer needed or after a successful objection.
- Restriction: you can ask us only to store the data and not use it, for example while we check whether it is accurate.
- Portability: you can receive the data you gave us yourself, which we process by automated means on the basis of a contract or steps before a contract, in a structured, commonly used and machine-readable format.
- Objection: see the next section.
- Withdrawing consent: no processing is currently based on consent. If that changes, you will be able to withdraw consent as easily as you gave it.
Right to object
When we process your data on the basis of legitimate interest (point (f)), you can object at any time on grounds relating to your particular situation. This covers recording and transcribing calls to our number, the text message after a missed call, technical logs, quality checks of the assistant, protecting sign-in to the app from abuse, checking the office and preventing abuse of the free trial, cookies, Facebook Page statistics, and choosing the audience for our ads on Meta platforms.
After an objection we stop that processing, unless we can show compelling legitimate grounds that override your interests, or we need the data to establish, exercise or defend legal claims.
How we act on an objection: for the text message after a missed call, we add your number to a list of numbers we no longer send such messages to. We cannot switch recording off in advance for a particular number, so after an objection to recording we delete the recordings and transcripts of your past calls, and ask you to contact us by email from then on.
Send your objection to support@nexistudio.dev.
How to exercise your rights
Send your request to support@nexistudio.dev or by post to Kaštel, Juki 141, Buje.
- If your request is about a call, give the number you called from and the approximate date and time of the call. This helps us find your data faster.
- We answer without undue delay and within one month at the latest. For complex or numerous requests we can extend this by two further months. We will tell you within the first month and explain why.
- Exercising your rights is free of charge.
- We ask for extra information to confirm your identity only if we have reasonable doubts about the identity of the person making the request. If the request concerns recordings or other call data, we may confirm it by calling or texting the number it relates to, so that we do not give your data to someone who only claims your number.
- For now we handle requests by hand: we search for, export and delete your data in our database and at each provider separately. That is why it matters that you give the number and the date and time of the call.
- If we do not act on your request, we will explain why within one month and tell you about your right to complain to AZOP and to seek a judicial remedy.
- If your request is about a call to an office that is our client, we pass it on to that office without delay.
Complaint to the Croatian data protection authority
If you believe that our processing of your data breaches the GDPR, you have the right to lodge a complaint with a supervisory authority. In Croatia this is the Agencija za zaštitu osobnih podataka (AZOP, the Croatian Personal Data Protection Agency). You can also complain to the supervisory authority in the EU member state where you live or work or where the alleged infringement took place. You also have the right to a judicial remedy.
You are welcome to contact us first, and we will try to resolve the issue.
AZOP contact details:
- Agencija za zaštitu osobnih podataka
- Ulica Metela Ožegovića 16, 10000 Zagreb, Croatia
- Web: www.azop.hr
- Email: azop@azop.hr
- Phone: +385 1 4609 000
Security
No system is completely secure, and we do not claim ours is. If a personal data breach occurs that could put your rights at risk, we will notify AZOP and, where the GDPR requires it, you.
Some of the measures we use:
- The call recording link we send in notices is signed with a secret key, so it cannot be guessed or altered to open a different call. Anyone the link is forwarded to can listen to the recording for as long as the recording exists.
- The website may load only our own scripts and may send forms only to Formspree (Content Security Policy rules). This makes it harder to inject third-party scripts.
- The website has no tracking scripts or advertising pixels.
Changes to this policy
We change this policy when we change how we process data, for example when we add a new service provider. This page always shows the current version with its effective date.
If we want to use your data for a new purpose, we will tell you before we do. We tell clients about important changes by email. You can ask for earlier versions of the policy at support@nexistudio.dev.
This version applies from 12 September 2026.
On 14 September 2026 we added information about signing up for and using the app at app.nexistudio.dev, payments through Stripe, the emails we send through Resend, sign-in with Google, the OIB and office check, the helper for filling in the office details, connecting Google Calendar and choosing the assistant's voice, on 15 September 2026 information about the support chat on the website, on 21 September 2026 information about finding the office on Google Maps and about Outlook, iCloud and other calendars, and on 22 September 2026 the section "Google user data" and a clearer description of connecting Google Calendar.