Skip to content

Legal

Privacy Policy

How nox.markets collects, uses, retains, and shares personal data for website visitors and B2B workspace customers, including model routing and rights requests.

Last updated: 16 September 2026
Controller / operator: NOX AETERNA GROUP LLC, a Wyoming limited liability company, trading as nox.markets, 5830 E 2nd St, Ste 7000 #34506, Casper, WY 82609, USA
Applicable law: US federal and state privacy laws, including the CCPA/CPRA where it applies, plus the laws of the State of Wyoming
Privacy contact: antonott@nox.markets
Notices: 5830 E 2nd St, Ste 7000 #34506, Casper, WY 82609, USA

This Privacy Policy explains how nox.markets handles personal data. The Service is English-only and billed in USD. It is a B2B marketplace of tools, agents, workflows, and packs for business customers. The Service is provided by a United States company and is not directed at customers or individuals in the European Union or the European Economic Area.

We do not sell or share personal information as those terms are defined under the CPRA. We do not use customer workspace content to train models.


1. Who we are

nox.markets is operated by NOX AETERNA GROUP LLC. We provide a catalog and application that businesses use to run named operational jobs (for example invoice assembly or bill coding) in hosted, connected, or self-hosted deployment models.

If you are an employee or contractor of a Customer workspace, your employer (the Customer) is typically the controller of workspace content. We are the processor. Direct rights requests about that content should go to the Customer; we will notify them (see Section 9).

If you visit nox.markets without a workspace, submit a marketing or demo form, or are billed as a buyer, we are the controller of that personal data.


2. Categories of personal data

We map stored data to the same classes used on /security and in the DPA.

ClassWhat it isStored on our infrastructure?
account_dataWork email, display name, hashed password or IdP subject, billing email, Stripe customer id, company name, plan tierYes
workspace_configProduct mappings, schedules, approval matrices, templates, price lists typed into a hosted toolYes
connector_secretsOAuth refresh tokens, API keys Customer pastes, BYOK model keysYes, encrypted as secrets (not application-DB plaintext)
run_payloadInput document, prompt context, and model/tool output of a single runYes, unless zero-retention is on or deployment is self-hosted
run_metadataRun id, product slug, timestamps, status, credits consumed, SHA-256 of payload, actorYes (including under zero-retention)
audit_eventWho, what, when, IP, object idYes
support_dataTickets and screenshots Customer sendsYes
telemetry_self_hostedLicense check, version, heartbeat. No documents, tokens, or promptsYes (license service only)
Website / marketingIP address, user-agent, pages viewed, form fields (name, work email, company, role, company size, inquiry type), demo notes Customer types, /fit answers and ROI calculator inputs sent with an email address, UTM campaign parametersYes, as needed to operate the site and respond

Payment cards. Checkout takes no payment yet. Once it does, Stripe, Inc. processes card payments as our payment processor; NOX AETERNA GROUP LLC remains the seller. We never store the card number (PAN) or CVV, only Stripe’s cus_* / sub_* identifiers and the last four digits for display.

What we do not store. Full exports of Customer’s QuickBooks, HubSpot, mailbox, or drive, except objects a product pulled for a named run. Bank login passwords (Plaid, when connected, holds credentials; we receive tokens and balances the product is configured to read). Biometric data. Children’s data. PHI/ePHI until a BAA is in force (Planned, not offered until 2027-06-30; Acceptable Use forbids ePHI until then). Fine-tuned model weights derived from Customer documents. A second copy of invoice/bill/quote PDFs after Customer’s retention window, other than encrypted backups that age out on the same clock.

Sources. Directly from you; from Google, if you sign in with Google; from systems you connect; from our payment processor once checkout takes payment; from security and error logs; from cookies and similar technologies as described in the Cookie Policy.


We process personal data to:

  1. Provide the contract — create the workspace, authenticate users, run products, meter credits, bill, support, and honor export/deletion. Basis: performance of our contract with Customer, and our role as a service provider under US state privacy law.
  2. Secure the Service — authentication logs, fraud and abuse detection, tenant isolation, incident response. Basis: our interest in securing a multi-tenant B2B service; contract where the processing is inherent to providing the Service.
  3. Comply with law — tax invoices (7 years), responding to lawful process. Basis: legal obligation.
  4. Communicate as controller — respond to /contact, /demo, and DPA request forms; send transactional mail (receipts, invites, security notices). Basis: contract, or our interest in answering the request. We do not send marketing email or a newsletter. Besides transactional mail, we only send a message you asked for, such as your /fit shortlist.
  5. Cookies. Launch position: no non-essential cookies on the authenticated app. Strictly necessary cookies only (session, CSRF, guest cart, workspace selection). Consent is used only if we later add a non-essential cookie (see Cookie Policy).

We do not process Customer Content to “improve our AI,” train models, or build profiles of other customers.


4. Model subprocessors

Some tools, agents, workflows, and packs call a model. When they do, we send the minimum retrieved context the product needs, plus our system instructions, and we receive a completion. We do not send connector_secrets, Stripe identifiers, or other tenants’ data.

Deterministic steps (posting a bill that already has a GL code, sending a template email, writing a CSV) do not call a model.

Training. Customer data is not used to train nox.markets models or, by contract, provider foundation models we route to. We execute zero-data-retention / no-training API terms where the endpoint offers them. If an endpoint cannot be put on no-training terms, we do not route Customer data to it. Providers may retain a limited slice for abuse monitoring even under zero-retention programs. That exception is real; we do not hide it. No product in this build calls a model yet; each provider’s no-training terms will be linked here before one does.

Named model processors (OpenAI, LLC; Anthropic, PBC; Google LLC for Vertex AI) and all other subprocessors live on /legal/subprocessors. Below Scale, we choose the vendor; the list still names them. Scale and Enterprise may use BYOK; data then also sits under Customer’s agreement with that provider. We refuse keys we cannot verify are not set to train on API data.


5. Retention

Retention is a workspace setting with a ceiling by tier. Audit retention is not payload retention.

ArtifactStarterGrowthScaleEnterprise
run_payload default30 days30 days90 days90 days
run_payload maximum30 days365 days365 days365 days, or 0 days (zero-retention)
run_metadata30 days12 months36 months36 months, or term + 12 months by MSA
audit_event30 days12 months36 months36 months, or term + 12 months by MSA
connector_secretsUntil disconnect + 24 hourssamesamesame
account_data / workspace_configAccount life + 30 dayssamesameMSA may extend for legal hold
Encrypted backups35-day rolling35-day rolling35-day rolling35-day rolling, or customer-managed
support_data24 months24 months24 months24 months
Billing records (tax)7 years7 years7 years7 years
Infra logs (non-audit)90 days90 days90 days90 days

Deletion. A workspace admin can delete a run (payload + metadata) in the UI; deletion is queued immediately and applied to primary storage within 24 hours. Backup copies age out with the 35-day backup clock and are not scrubbed on demand.

Account closure. Customer may export configuration and run history for 30 days, then primary delete; backups expire by day 65 (30 + 35). Legal hold on Enterprise pauses deletion for named objects.

Self-hosted. Customer data does not enter production; license telemetry follows account life.

Website inquiries and waitlist. Inquiries sent through our website forms (/contact, /demo, /fit, the ROI calculator) are deleted from our database 24 months after their last update. Checkout waitlist entries are deleted 24 months after sign-up. Copies in notification emails or chat channels follow the retention settings of those tools. You can ask us to delete your data earlier (see Section 9).

Website logs. Our web server logs each request with IP address, requested URL, user agent, and time. The logs rotate daily and are deleted after 14 rotations, so no entry is older than 15 days. The usage events of the /fit wizard contain no IP address and no cookie.


6. Recipients and subprocessors

We disclose personal data to:

  • Service providers listed at /legal/subprocessors: Hetzner Online GmbH hosts the Service and Zoho Corporation B.V. hosts our email. Payment, model, and notification providers are listed there with their status and receive nothing until they are in use.
  • Customer’s connected systems, when Customer authorizes a connected product (those vendors are Customer’s processors).
  • Professional advisers under confidentiality (counsel, accountants) as needed.
  • Authorities when law requires.

No advertising network. No third-party marketing pixel on authenticated app routes. If a marketing-site analytics vendor is added, it will be listed on /legal/subprocessors the day it ships.

Our staff have no standing access to run_payload. Break-glass is ticketed, ≤ 4 hours, hardware MFA, logged.


7. Where data is processed

The Service is hosted by Hetzner Online GmbH in a data center in Nuremberg, Germany, on every tier. We do not offer another processing region. Email we exchange with you is hosted by Zoho Corporation B.V. in its EU data centers.


8. CPRA / US state privacy (service provider)

We do not sell or share personal information as defined in the CPRA (including for cross-context behavioral advertising). We act as a service provider / contractor for Customer workspace personal information. We do not combine that information with other customers’ information to train or to profile, except as needed to provide the Service to that Customer.

We honor the service-provider restriction: we will not retain, use, or disclose Customer personal information for any purpose other than the business purposes specified in the contract, including not for our own commercial purposes except as permitted for providing the Service, security, and legal compliance.

To exercise California or other US state rights as a website visitor (access, delete, correct, opt-out of sale/share — noting we do not sell or share), contact the privacy mailbox above. We will verify the request. An authorized agent may submit a request for you. We ask the agent for your signed permission and may ask you to confirm your identity with us directly, unless the agent holds a valid power of attorney.

If you are a data subject of a Customer workspace, see Section 9. We cannot treat a workspace export as a consumer request against another company’s controller file without that controller’s instruction.

We do not use or disclose sensitive personal information to infer characteristics, and we do not seek that data. Acceptable Use forbids several sensitive classes.

Appeals. If we decline to act on your request, you can appeal by writing to the privacy contact above with the subject “Privacy appeal”. We decide within 45 days and explain the outcome in writing. If we deny the appeal, you can contact your state attorney general.


9. Rights (access, delete, export)

If you are a Customer user (controller’s workforce or Customer’s own customers appearing in invoices/tickets): we notify the Customer (controller) within 5 business days of a request that hits us directly and do not respond on the controller’s behalf except to redirect you to the Customer. The Customer may use account export and deletion tools. We provide manual assistance within 15 business days on Scale and Enterprise, 30 business days on Starter and Growth.

If you are a website visitor or a buyer whose data we control: depending on the law that applies to you (for example the CCPA/CPRA for California residents), you may request access to, correction of, deletion of, or a copy of your personal data, and you may withdraw consent where processing was based on consent.

Export formats for workspace data: JSON/CSV and original files where we still hold them.


10. Children

The Service is not directed at children under 16. We do not knowingly collect their personal data. If we learn we have, we will delete it from primary storage on the deletion clock in Section 5 and notify the workspace owner if it arrived via a Customer workspace.


11. Changes

We may update this Policy. Material changes will be emailed to the workspace owner at least 30 days in advance where required. The “Last updated” date will change. Continued use after the effective date constitutes notice of the update, except where law requires consent or an opt-in.


12. Additional controller details

Automated decision-making. We do not make legal or similarly significant decisions about individuals as a controller using solely automated processing. Products that draft or propose operational actions are tools Customer operates; Customer is the operator and, where law requires a human, must not disable required approval (see Acceptable Use).

Do Not Track. The app does not respond to DNT as a substitute for our Cookie Policy; we do not run advertising trackers on /dashboard.

Employment data. Our employee and contractor data is out of scope of this customer-facing policy except as needed to say that production access is limited, background-checked where lawful, and logged.

Compliance status. CCPA/CPRA compliance is an operational legal program, not a certification. SOC 2 Type I is Planned for 2027-05-31. SOC 2 Type II is Planned for 2027-12-15. ISO/IEC 27001 is Planned for 2028-09-30. HIPAA BAA is Planned / not offered until 2027-06-30. Current table: /trust.