Privacy policy
Last updated: 29 August 2026
This policy explains how A.K.B.S. ApS (trading as Nexly), Gammel Skovvej 6, 2770 Kastrup, Denmark, CVR 44457415. Contact: help@nexly.dk. collects and processes personal data under the EU General Data Protection Regulation (GDPR) and the Danish Data Protection Act.
1. Data controller
A.K.B.S. ApS is the data controller for personal data about visitors to nexly.dk, merchant users of the Nexly dashboard, and people who book a demo.
For personal data that a merchant's customers submit through a merchant's return portal, the merchant is the data controller and Nexly acts as data processor. See our Data Processing Agreement.
2. What we collect
Depending on how you use Nexly we process:
- Account data: name, work email, password hash, store, role, login timestamps.
- Demo booking data: name, company, email, phone, shop URL, order volume, preferred time, message.
- Return portal data (as processor): order number, customer name, email, shipping address, order lines, return reason, tracking numbers, labels.
- Integration data: Shopify and 3PL API credentials stored encrypted, plus API request metadata.
- Technical data: IP address, browser/device type, log and error data, strictly necessary cookies.
3. Purposes and legal bases
- Delivering the Nexly service and support — performance of a contract (Art. 6(1)(b)).
- Demo bookings and sales follow-up — consent and/or legitimate interest (Art. 6(1)(a)/(f)).
- Security, abuse prevention, logging and service improvement — legitimate interest (Art. 6(1)(f)).
- Bookkeeping and statutory retention — legal obligation (Art. 6(1)(c)).
4. Recipients and sub-processors
We share personal data only with providers that help us run the service: hosting and database infrastructure, Shopify, and the 3PL/carrier a merchant chooses (for example Shipmondo, GLS, PostNord, DAO, Bring, DHL, DPD). A current list is available on the Sub-processors page.
5. Transfers outside the EU/EEA
Data is hosted in the EU where possible. Where a provider processes data outside the EU/EEA, the transfer is covered by the European Commission's Standard Contractual Clauses and supplementary safeguards.
6. Retention
- Return cases: kept while the merchant's account is active and deleted 12 months after the case is closed, unless the merchant sets a shorter period.
- Demo bookings: deleted no later than 24 months after last contact.
- Account data: deleted within 90 days after the account is terminated.
- Accounting records: kept 5 years plus the current year under the Danish Bookkeeping Act.
7. Your rights
You have the right to access, rectification, erasure, restriction, data portability and objection, and to withdraw consent at any time. Write to help@nexly.dk and we respond within one month.
You can complain to Datatilsynet (Carl Jacobsens Vej 35, 2500 Valby, datatilsynet.dk).
8. Security
We use encryption in transit and at rest, row-level access control per store, role-based access, encrypted API credentials, audit logging and least-privilege access for staff. Personal data breaches are reported to Datatilsynet within 72 hours and to affected merchants without undue delay.