Privacy Policy

Last updated: July 2026

1. Who we are

RBC Group LLC, trading as Nexam, is the controller of personal data processed through nexamclean.com in connection with orders, customer service, marketing and site operation. Controller: RBC Group LLC Registered office: 30 North Gould Street, Suite N, Sheridan, Wyoming 82801, United States Wyoming filing ID: 2025-001839878 Privacy contact: robin@rbcgrp.eu Customer-service contact: support@nexamclean.com RBC Group LLC does not currently appoint a data protection officer because it has not determined that the statutory criteria requiring one are met. This does not affect your right to contact us about privacy matters.

2. Scope

This Policy explains how Nexam collects, uses, discloses, stores and protects personal data when you browse the site, place an order, create an account, contact customer service, subscribe to marketing, submit a review or otherwise interact with Nexam.

3. Personal data we collect

Depending on how you use the site, we may collect: • Identity data: name, title or salutation where supplied. • Contact data: email address, telephone number, billing address and delivery address. • Order data: products, quantities, order number, price, delivery status, returns, refunds and warranty history. • Account data: login identifier, encrypted password information, preferences and account history, where customer accounts are offered. • Payment and transaction data: payment status, method type, payment-provider identifiers, fraud-screening results and limited card metadata such as card brand and last digits. Nexam does not store your complete card number or security code. • Customer-service data: correspondence, forms, photographs or documents you send, complaints and support history. • Review data: rating, review text, display name and verification status where you submit a review. • Marketing data: subscription status, consent records and engagement with communications. • Technical and browsing data: IP address, device and browser information, operating system, timestamps, pages viewed, referral source, identifiers, logs and cookie choices. • Security and fraud data: signals used to protect accounts, payments, the site and other users. We do not intentionally collect special-category data such as health, biometric, political or religious information. Please do not send such information unless it is strictly necessary for a request and we have asked for it.

4. How data is collected

We collect personal data: • directly from you when you order, create an account, contact us, subscribe or submit content; • automatically through site logs and consented cookies or similar technologies; • from payment providers, carriers and service providers involved in an order; • from fraud-prevention and security providers; • from public sources where necessary to protect legal rights or investigate fraud.

5. Purposes, legal bases and retention

We process personal data only where a lawful basis applies. Orders and contract performance : Purpose: process payment, accept and fulfil orders, arrange delivery, provide tracking, handle returns, refunds, warranties and customer service. Data: identity, contact, order, payment-status and support data. Legal basis: performance of a contract and steps requested before entering a contract. Retention: for the active customer relationship and applicable limitation periods; accounting and transaction records may be retained for up to 10 years where required by law. Legal and regulatory obligations : Purpose: accounting, tax, customs, product safety, recall management, consumer-law compliance and responding to lawful authority requests. Data: identity, contact, order, transaction, safety and complaint data. Legal basis: legal obligation. Retention: for the period required by the applicable obligation. Customer service and complaints : Purpose: answer questions, investigate incidents, resolve complaints and improve support. Data: identity, contact, order and correspondence data. Legal basis: contract performance and legitimate interests in providing and improving customer service and defending legal claims. Retention: generally up to three years after the request is closed, or longer where needed for a warranty, dispute or legal obligation. Fraud prevention and security : Purpose: authenticate transactions, prevent fraud, secure the site, investigate abuse and protect legal rights. Data: transaction, device, log, IP, account and fraud-risk data. Legal basis: legitimate interests and, where applicable, legal obligation. Retention: only for as long as necessary for the investigation, risk-control and applicable claim periods. Marketing communications : Purpose: send newsletters, product news or offers where you have requested them. Data: name, email, consent and engagement data. Legal basis: consent, or another basis permitted by the law applicable to existing customers. Retention: until you unsubscribe or withdraw consent, and generally no longer than three years after the last meaningful interaction where a national rule uses that period. Consent records may be retained longer as evidence of compliance. Site analytics and improvement : Purpose: understand site performance, diagnose errors and improve content and user experience. Data: technical, browsing and cookie data. Legal basis: consent for non-essential analytics and legitimate interests for strictly necessary security and diagnostic logs. Retention: according to the relevant tool and cookie settings, subject to data-minimisation and periodic deletion. Anonymous audience measurement exempt from consent: we also measure page usage solely as aggregated statistics (scroll depth, time spent, clicks on key areas), with no identifier and nothing written to your device. Reviews : Purpose: publish and moderate product reviews and indicate verified purchases where applicable. Data: review content, display name, rating and order-verification information. Legal basis: consent or performance of the review service requested by you, and legitimate interests in authentic customer feedback. Retention: while the review remains relevant and published, unless you request removal or a legal reason requires retention. Attribution of sales to advertising : Purpose: attribute a completed purchase to the advertising click that led to it, in order to measure the effectiveness of paid campaigns. Data: the advertising click identifier present in the address of the page at the time of purchase (such as the Google Ads click ID), together with non-identifying campaign parameters, linked to the order. Legal basis: legitimate interest in measuring advertising spend against real transactions. This identifier is not stored on your device and nothing is read from your device for this purpose; it is processed only if you complete a purchase and is not used to follow your browsing or build a profile. Retention: used for attribution for up to 90 days after the purchase (the attribution window); thereafter it remains only as part of the transaction record, subject to the retention periods above.

6. Data required to place an order

Identity, contact, delivery and payment-related information marked as required is necessary to process an order. If you do not provide it, we may be unable to conclude or perform the sales contract. Optional fields are identified as such and are not required for purchase.

7. Recipients of personal data

We disclose personal data only where necessary to: • payment processors and financial institutions; • ecommerce, website-hosting, infrastructure and security providers; • carriers, warehouses, fulfilment and returns providers; • customer-service, email and communications providers; • review, analytics and consent-management providers, where enabled; • professional advisers such as accountants, lawyers and insurers; • public authorities, regulators or courts where legally required; • a buyer, investor or successor in connection with a genuine corporate transaction, subject to appropriate confidentiality and legal safeguards. These recipients act as processors, independent controllers or joint controllers depending on their role. We require service providers processing data on our behalf to use it only under documented instructions, keep it secure and comply with applicable data-protection law.

8. International transfers

RBC Group LLC is established in the United States, and some service providers may process data outside the European Economic Area. Where the GDPR restricts an international transfer, Nexam relies on a lawful transfer mechanism appropriate to the recipient, which may include an adequacy decision, participation in an approved data-privacy framework where applicable, European Commission Standard Contractual Clauses, or another legally recognised safeguard. You may request information about the applicable safeguard by emailing robin@rbcgrp.eu. Commercially sensitive information and information affecting the rights of others may be redacted.

9. Automated decision-making

Payment and fraud-prevention providers may use automated risk signals to approve, authenticate, delay or reject a transaction. Nexam does not intend to make decisions based solely on automated processing that produce legal or similarly significant effects beyond what is necessary to process and secure a transaction. Where applicable law grants rights concerning an automated decision, you may request human review, express your point of view and contest the decision by contacting robin@rbcgrp.eu.

10. Your rights

Subject to the conditions and exceptions in applicable law, you may have the right to: • obtain information about processing; • access your personal data; • correct inaccurate or incomplete data; • request erasure; • request restriction of processing; • receive data in a portable format; • object to processing based on legitimate interests; • object at any time to direct marketing; • withdraw consent at any time, without affecting prior lawful processing; • request safeguards concerning qualifying automated decisions; • lodge a complaint with a competent data-protection authority. To exercise a right, email robin@rbcgrp.eu. We may request proportionate information to verify identity and protect your data. We normally respond within one month where the GDPR applies, subject to permitted extensions for complex or numerous requests. You may lodge a complaint with the supervisory authority in the EU or EEA country where you live, work or believe an infringement occurred.

11. Marketing choices

You can unsubscribe from marketing emails by using the unsubscribe link in the message or contacting robin@rbcgrp.eu. Service messages about an order, safety notice, return or account are not marketing and may continue where necessary.

12. Cookies and similar technologies

The site uses strictly necessary technologies required for functions such as security, cart operation, checkout and consent storage. Other technologies, such as analytics, preference or advertising technologies, are used only where enabled and where the required consent has been obtained. You can accept, reject or manage non-essential technologies through the cookie banner and the permanent Manage cookies control in the site footer. Withdrawing consent does not affect processing that occurred lawfully before withdrawal. More information is provided in the Cookie Policy. Purchase attribution without cookies: if you complete a purchase, the advertising click identifier present in the page address at that moment is associated with your order (legitimate interest, attribution of the sale). It is not stored on your device, nothing is read from your device for this purpose, and it is not used to follow your browsing.

13. Security

We use organisational and technical measures designed to protect personal data against accidental loss, unauthorised access, alteration, disclosure or destruction. Measures may include access controls, encryption in transit, secure payment processing, logging, backups, supplier controls and incident procedures. No online system is completely secure. If a personal-data breach creates a risk requiring notification under applicable law, Nexam will notify the competent authority and affected individuals as required.

14. Children

The site and products are not directed to children. We do not knowingly collect personal data directly from children for marketing or account creation. If you believe a child has supplied data without appropriate authorisation, contact robin@rbcgrp.eu.

15. Third-party links

The site may link to third-party websites. Their privacy practices are governed by their own notices, and Nexam is not responsible for their independent processing.

16. Changes to this Policy

We may update this Policy to reflect changes in law, services or processing. The latest revision date appears at the top. Where a change materially affects your rights or an existing processing purpose, we will provide an appropriate notice and request consent where required.

17. Contact

Privacy requests and questions: robin@rbcgrp.eu Customer-service matters: support@nexamclean.com Postal address: RBC Group LLC 30 North Gould Street, Suite N Sheridan, Wyoming 82801 United States