Nexxus Butler Nexxus Butler

Privacy policy

This policy covers Nexxus Butler: the website nexxusbutler.com, the dashboard at app.nexxusbutler.com and our service behind the plugins for WooCommerce and Shopware. Butler advises visitors to a shop in a chat. It suggests better product texts and image descriptions to the shop owner. It also publishes the product data in a form AI assistants can read. This page explains which data we process, where they go and when we delete them.

Who is responsible

The controller is Phillip Kracht, the provider of Nexxus Butler. This applies to everything in this policy except the conversations of visitors in a shop. For questions about privacy, write to hello@nexxusbutler.com.

Address and phone number in the legal notice

The shop’s role

For visitors’ conversations, the shop owner is the controller. We process them on the shop owner’s behalf (Art. 28 GDPR). This policy describes what we do in that role.

If you visit a shop that uses Butler, you will find that shop’s details in its privacy policy.

Website

nexxusbutler.com works without cookies, tracking, analytics or ads. Fonts and files come from our own server.

When you open a page, the server processes your IP address to send you the page. The access log contains no IP addresses. It records only the time, the request, the status, the referring page and the browser details. It is overwritten continuously.

If you use the light and dark switch, your browser keeps your choice in its local storage under “nx_thema”. It stays there until you delete it.

Dashboard for shop owners

You sign in to the dashboard at app.nexxusbutler.com with Nexxus ID, the shared account for all Nexxus products. You need no password. You get a sign-in code by email instead. Without a Nexxus ID account with an email address, you cannot use the dashboard. If you have no account yet when you connect a shop, one is created there.

Nexxus ID is also run by Phillip Kracht. The details are in the privacy policy on nexxus.group.

The dashboard sets two cookies. The first holds your Nexxus ID sign-in. It is valid for 30 days. Scripts on the page cannot read it. The second remembers your language for 365 days. Your choice of light or dark is kept in the browser’s local storage.

Butler stores the identifier of your Nexxus ID account, your role, when your account was created and who invited you. It also stores your last access. Butler does not store your email address.

Butler also stores your shop’s settings: name, offering, web address, language, currency, time zone and plan, plus the tone and form of address of the assistant. In addition, we record how many conversations your shop uses each month and which top-up packs you have bought. These details stay until you delete your account.

Payment does not currently run through a payment service. We write invoices by hand.

The form for connecting a shop protects itself against bots without a captcha. It uses a hidden field and a minimum time. The server checks both for that one request only.

Data from the shop

The WooCommerce plugin sends us the name, description, short text, price, stock status and language of published products. It sends images as an address with alt text, never the image file itself. We store no more than 20 images per product.

It also sends published pages and posts without a password, each with title and text. It does not send the cart, checkout or account pages.

The Shopware plugin sends us the name, description, meta description, price and stock status of active products. It sends no images and no language. As content, it sends active categories with a page layout plus landing pages.

You upload documents yourself: as a PDF or as the address of a web page. Our server then fetches that web page.

The plugins do not read customer accounts or orders.

The data are stored on our server in Germany. For search, a service on the same server calculates numerical vectors, known as embeddings. No outside provider is involved.

For suggested texts, we store the old and the new text. This also applies to suggestions you have discarded. Both texts stay until the product disappears from the shop or you delete your account.

At every full sync, we remove what is no longer in the shop. You can delete the copy of your shop in the plugin. You can delete documents one by one. At the latest, we delete your shop’s data when you delete your account. What remains after that is explained under “Your rights”.

Conversations in a shop

The assistant’s widget stores nothing in your browser: no cookie, nothing in local storage. The identifier of an ongoing conversation is kept only in memory. When the page reloads, it is gone.

The widget loads on every page of the shop. Our server processes your IP address to send you the file. It does not store it. We are responsible for this loading ourselves, not the shop. The basis is our legitimate interest in running and securing the service (Art. 6(1)(f) GDPR).

You do not have to use the assistant. When you ask it something, we store your questions and its answers word for word. We also store the language, the time, which products it recommended and how the conversation ended. We do not store your IP address. There is no identifier for you as a visitor. We build no profile.

A conversation is deleted automatically twelve months after its last message.

In the dashboard, the shop owner sees figures about the conversations, but not their wording. The owner also sees search terms the assistant derives from the questions. This applies to questions without results and to successful conversations.

On the “Visibility” page, the dashboard suggests search terms from successful conversations to the owner as test questions. A search term the owner adopts stays stored as a test question until the owner deletes the account. The twelve-month period therefore does not apply to test questions.

If the owner deletes the account, they get a copy of all of the shop’s conversations word for word, but only if they ask for it. We delete this copy as soon as they have it.

If you add a product to the cart from the chat, that goes straight to the shop, not to us.

The shop owner can store vouchers that the assistant may mention. Nothing about you is stored in the process.

AI at Scaleway

The AI in Butler is the Mistral Medium 3.5 model made by Mistral AI. Among other things, it writes the chat answers, the suggested texts and the image descriptions. It is run by our contract partner Scaleway SAS, 8 rue de la Ville l’Évêque, 75008 Paris, France. Mistral AI, the maker of the model, has no access to the data. Processing currently takes place in a data centre in Paris.

For this, Scaleway receives the question and the conversation so far. It also receives the details needed from the shop: product data plus excerpts from pages and documents. Scaleway also receives the shop’s name, offering and tone, as well as the vouchers. For an image description, Scaleway receives the address of the image. Scaleway fetches the image itself.

The basis is the data processing agreement with Scaleway in its version of 1 June 2024. It is an integral part of our contract with Scaleway. Scaleway’s specific terms for AI services also apply, in their version of 7 April 2026. Under the data processing agreement, Scaleway only transfers personal data outside the EU after informing us explicitly in advance. The exception is a law that prohibits this notice for important reasons of public interest. If that happens, standard contractual clauses apply. The list of subprocessors is at scaleway.com/en/subprocessorlist.

Scaleway does not keep requests or generated answers after processing and does not log them. There is one exception. If Scaleway detects abuse or a request that disrupts the service, Scaleway may keep the content of the requests concerned temporarily. A server error 500 is one example of such a disruption. Scaleway uses the content to find the cause or a security vulnerability. According to Scaleway’s privacy page for this service, the content is then kept for no more than two weeks. Scaleway does not use the data to train or improve the models, nor to improve its service. Neither the maker of the model nor third-party services can access the content. Scaleway stores anonymised usage data without any content for up to six months, such as time, status codes, the number of tokens and chosen settings. Scaleway uses it to monitor operations and improve its service. To speed things up, Scaleway briefly holds technical intermediate values, not the text itself. They are kept separate for each project.

Once a month’s conversations are used up, the assistant answers in economy mode. New conversations are then not sent to Scaleway. Conversations that began earlier are still finished with the model: for no more than two hours after they began and no more than 20 messages. Suggested texts and image descriptions do not depend on the conversation allowance. They still go to Scaleway.

Until the switch to Scaleway on 6 October 2026, the AI in Butler ran at Anthropic using the Claude model. Since then, nothing is sent to Anthropic. The contract partner was Anthropic Ireland, Limited in Ireland. The basis was the data processing agreement with Anthropic, part of its commercial terms for the API. Anthropic passes data on to its own subprocessors, also in the USA. Their list is at trust.anthropic.com/subprocessors. Anthropic does not train models on the data it received up to then. Anthropic deletes inputs and outputs no later than 30 days after receiving them. There are exceptions. If Anthropic’s systems detect a breach of its usage policy, Anthropic keeps the data for up to two years. For a conversation flagged as a breach, Anthropic keeps the assessments of its safety systems for up to seven years. If a law requires it, Anthropic keeps data longer. For research and statistics, Anthropic may use data in anonymised form where the agreement allows it.

Files for AI assistants

The public files are llms.txt, a feed based on Schema.org, markup.json and a merchant profile (haendler.json). They contain the shop’s published product data and services, plus the shop’s name, offering and web address. They contain no conversations and nothing about visitors.

Emails to us

We delete emails sent to hello@nexxusbutler.com once the request is settled. At the latest, we delete them after twelve months. Anything tax law requires us to keep, such as records on invoices, stays for as long as the law requires.

Who receives data

Besides us, these companies receive data. Hetzner Online GmbH runs the data centre in Germany. Our encrypted backups are also stored with Hetzner. For the AI, Scaleway SAS in France receives data, as described above. Until the switch to Scaleway on 6 October 2026, these data went to Anthropic Ireland, Limited in Ireland. Anthropic passes data on to its own subprocessors, also outside the EU, among other places in the USA. Emails sent to hello@nexxusbutler.com are held by Neue Medien Münnich (All-Inkl.com) in Germany.

We do not sell data. We pass data on to no one else.

Backups

We back up the data on our server every day, in encrypted form. The backups are stored with Hetzner.

Each backup is kept for 30 days. Before changes to the database, we also take a snapshot. It stays on the server for no more than seven days.

Legal bases

The basis for the account, the dashboard and the data from the shop is the contract with the shop owner (Art. 6(1)(b) GDPR).

We rely on our legitimate interest (Art. 6(1)(f) GDPR) for running and securing the website and the server. This includes loading the widget in the shops.

When an email to hello@nexxusbutler.com concerns a contract or an account, we answer it on the basis of the contract (Art. 6(1)(b) GDPR). Otherwise the basis is our legitimate interest in answering requests (Art. 6(1)(f) GDPR).

We only use cookies and entries in local storage where they are strictly necessary for a feature you use: sign-in, language plus light or dark (Section 25(2) no. 2 TDDDG). No consent is needed for this.

For visitors’ conversations, the legal basis depends on the shop. We process them on the shop’s behalf.

Butler makes no automated decisions about people and builds no profiles.

We keep invoices because tax law requires it (Art. 6(1)(c) GDPR).

Your rights

You have the right of access, rectification, erasure, restriction of processing and data portability. To use these rights, write to hello@nexxusbutler.com.

If you talked to the assistant in a shop, contact that shop. We help the shop with your request.

To delete your Butler account, write to hello@nexxusbutler.com. On request, you get a copy of all of your shop’s conversations word for word. We delete this copy as soon as you have it. We then delete your shop’s data held by us. There are exceptions. Our backups keep the data for up to 30 days. Scaleway keeps requests only in the one case described under “AI at Scaleway”. Whatever went to Anthropic before the switch on 6 October 2026 is deleted by Anthropic within the periods given in the last paragraph of that section. We keep invoices for as long as tax law requires.

You can complain to a data protection authority. The authority responsible for us is the State Commissioner for Data Protection and Freedom of Information of Mecklenburg-Western Pomerania.

Your right to object

Where we rely on our legitimate interest (Art. 6(1)(f) GDPR), you can object on grounds relating to your particular situation. To do so, write to hello@nexxusbutler.com.

Last updated: 6 October 2026. The German version is authoritative.