Privacy Policy for Nexio

Last Updated: July 14, 2025

About This Policy

This privacy policy explains how Nexio processes your information when you use our email automation application on monday.com. Nexio enables rich-text email templates and professional email communication directly from your monday.com workflows, extending beyond monday.com's native plain-text email limitations. If you have questions about this policy, contact us at support@roba-solutions.com

Information We Collect

monday.com Account Information

When you install Nexio, monday.com automatically provides us with certain account and user information as part of their standard app installation process. We receive your account name, account identifier, subscription tier, user count, and the installing user's information including their user ID, email address, full name, server cluster location, and country. This information is used for analytics, user support, and service improvement purposes. We also access your monday.com boards and user data through four specific API permissions (boards:read, users:read, notifications:write, teams:read) that are essential for Nexio's operation.

Email Account Integration

To send emails on your behalf, Nexio requires connection to your Gmail or Microsoft Outlook account through secure OAuth authentication. We store the encrypted authentication tokens in monday.com's secure storage infrastructure, which uses enterprise-grade encryption standards. We never store or have access to your email account passwords. The specific permissions we request from Gmail include only email sending capabilities. For Microsoft Outlook, we connect through Microsoft Graph API (graph.microsoft.com) and request Mail.send and User.read permissions. We do not request or receive access to read your existing emails, contacts, or other personal data beyond what is necessary for sending emails through our application.

Email Templates and Configuration

Nexio stores the email templates you create, including subject lines, message content, formatting preferences, and dynamic variable mappings that connect to your monday.com board data.

Technical Information

Our application, hosted on monday.com's infrastructure, automatically collects basic technical information necessary for operation and security. This includes error logs, performance metrics, and usage patterns that help us maintain service reliability. monday.com's hosting platform provides us with standard monitoring and analytics capabilities that we use solely for application maintenance and improvement.

How We Use Your Information

Nexio processes your information exclusively to provide email automation services within your monday.com workspace. When your workflows trigger email sending, we combine your email templates with live data from your monday.com boards to compose personalized messages, then transmit these through your connected email accounts to the specified recipients.

Information Sharing

Nexio operates as a contained system within monday.com's ecosystem and does not share your personal information with external parties except as necessary for core functionality. Your email sending occurs directly between monday.com's servers and your email provider's APIs, ensuring your communications remain private.

Third-Party API Compliance

Nexio's use of information received from Google APIs adheres to Google's API Services User Data Policy, including the Limited Use requirements. We access Google user data solely to enable email sending functionality as prominently featured in our application. Google user data is never used for advertising, analytics, or any purpose unrelated to Nexio's core email automation functionality.

For Microsoft services, we comply with Microsoft's API Terms of Use and data handling requirements. Our use of Microsoft Graph API is limited exclusively to email sending functionality through Outlook accounts. Microsoft user data is processed solely for this purpose and is never used for advertising, analytics, or any other purpose beyond our core email automation service.

Data Security and Storage

Your information is protected through monday.com's enterprise-grade security infrastructure, which includes encryption in transit and at rest, access controls, and regular security audits. OAuth tokens for your email accounts are stored in monday.com's secure storage system with additional encryption layers. monday.com's hosting platform operates servers in the United States, European Union, and Australia. This global infrastructure ensures reliable service delivery while maintaining security standards across all regions.

Data Retention and Deletion

We retain your information as long as your Nexio installation remains active and you continue using the service. Email templates, and OAuth tokens persist to ensure consistent functionality across your automation workflows.

Upon app uninstallation, we automatically delete all email connection data from our secure storage systems. Template data stored within Monday.com's native storage is completely removed within 10 days of uninstallation.

You may also request deletion of your data at any time while the app is still installed by contacting us at support@roba-solutions.com.

Your Privacy Rights

Depending on your location, you may have specific rights regarding your personal information. These typically include the right to access information we hold about you, correct inaccuracies, request deletion of your data, and withdraw consent for data processing activities that require consent. European Union and United Kingdom residents have additional rights under the General Data Protection Regulation (GDPR), including data portability and the right to object to certain types of processing. California residents have rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information is collected and the right to delete personal information. To exercise any of these rights, contact us at support@roba-solutions.com. We will respond to your request within the timeframe required by applicable law.

International Data Processing

Your information may be processed on servers located outside your home country as part of monday.com's global infrastructure. We ensure appropriate safeguards are in place for international data transfers through monday.com's compliance with relevant data protection frameworks and adequacy decisions.

Changes to This Policy

We may update this privacy policy to reflect changes in our practices, technology, legal requirements, or other factors. We will update the "Last Updated" date above when changes are made. Your continued use of Nexio after policy changes constitutes acceptance of the updated terms. If you disagree with changes, you may discontinue using the service.

Contact Information

For questions about this privacy policy or our data practices, contact us at support@roba-solutions.com. This policy applies specifically to the Nexio application and should be read in conjunction with monday.com's privacy policy, which governs the underlying platform infrastructure and related services