Privacy Policy

Nimble Operating System · Version 2026-07-15 · Effective 2026-07-15

Nimble CTO, LLC ("NOS," "we," "us," or "our") respects your privacy. This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information when you use the Nimble Operating System website, platform, software, services, integrations, and related offerings (the "Service").

This policy is designed around recognized privacy principles — transparency, purpose limitation, data minimization, security, accountability, and user control — and accounts for common requirements under the General Data Protection Regulation ("GDPR"), UK GDPR, and the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA").

1. Who we are

The entity responsible for this Privacy Policy is Nimble CTO, LLC (privacy contact email and mailing address to be confirmed before publication). Where we determine how and why personal information is processed — managing accounts, operating our website, communicating with users, administering the Service — we act as a data controller. Where an organization uses NOS to manage its own people and operational data, that organization may act as the data controller and we act as a data processor or service provider.

2. Information we collect

2.1 Account and contact information

Name, business email address, company name, job title or role, account identifiers, authentication information, and support contact details.

2.2 Usage and device information

IP address, browser and device type, operating system, pages viewed, features used, session activity, approximate location derived from IP address, log files, error reports, and performance data.

2.3 Product content and operational data

Content you or your organization submit to the Service — assessments, evidence documents, findings, priorities, decisions, team roles, and other operating data. This content may include personal information if users choose to include it.

2.4 Integration data

If the Service connects to third-party systems (repositories, project management tools, document repositories, data rooms), we process information from those systems only as authorized by you or your organization and only to the extent needed to provide the requested functionality.

2.5 Communications

Information contained in emails, support requests, feedback, demo or sales inquiries, and surveys.

2.6 Payment and billing information

If paid plans apply: billing name and address, subscription plan, payment status, and invoice history. Payment card details are processed by a PCI-compliant third-party payment processor and are not stored by NOS.

2.7 Cookies and similar technologies

We use cookies and similar technologies to keep users signed in, remember preferences, improve performance, analyze usage, and detect fraud or abuse. Where required by law, we provide consent mechanisms or opt-out choices for non-essential cookies.

3. How we use information

PurposeExamplesLegal basis where GDPR applies
Provide the ServiceAccount access, product functionality, hosting, supportContract performance
Operate and secure the ServiceAuthentication, monitoring, fraud prevention, incident responseLegitimate interests; legal obligation
Improve the ServiceDebugging, analytics, feature developmentLegitimate interests; consent where required
Communicate with usersService updates, support responses, administrative noticesContract performance; legitimate interests
Sales and marketingDemo follow-up, product updatesConsent; legitimate interests where permitted
Billing and account managementInvoices, subscriptions, tax recordsContract performance; legal obligation
ComplianceLegal requests, audits, enforcing termsLegal obligation; legitimate interests
AI-assisted functionalitySummarization, analysis, scoring supportContract performance; customer instruction

Where we rely on legitimate interests, we balance those interests against the rights and freedoms of affected individuals.

4. AI and automated processing

NOS may include AI-assisted features such as summarizing documents, supporting assessment scoring, classifying content, and organizing knowledge. Unless otherwise stated in a separate customer agreement: we do not use customer content to train public AI models; we process customer content only to provide, secure, support, and improve the Service; and AI outputs may be inaccurate and should be reviewed before use. If automated decision-making with legal or similarly significant effects is ever introduced, we will provide additional disclosures and rights as required by law.

5. How we share information

We do not sell personal information. We may share information with:

  • Service providers — vendors who help us operate the Service (hosting, email delivery, error monitoring, payment processing, AI infrastructure where applicable), authorized to process information only as needed and under contractual protections;
  • Your organization — administrators and members of organizations you belong to, based on the permissions your organization configures;
  • Integrations — third-party services you or your organization connect;
  • Legal and compliance — where necessary to comply with law, respond to lawful requests, protect rights and safety, enforce agreements, or investigate fraud or security incidents; and
  • Business transfers — a merger, acquisition, financing, or sale of assets, subject to appropriate protections.

6. Data retention

We retain personal information only as long as reasonably necessary for the purposes described here, unless a longer period is required or permitted by law. Retention depends on the type of information, whether it belongs to an active account, contract requirements, legal and audit obligations, security needs, and backup cycles. Customer content is generally retained for the duration of the customer relationship unless deleted by the customer. Backups may persist for a limited period after deletion before being overwritten.

7. Security

We use reasonable administrative, technical, and organizational safeguards designed to protect personal information — access controls, encryption in transit, encryption at rest where appropriate, authentication controls, logging, least-privilege access, and incident response procedures. No system is completely secure; users and customers are responsible for strong credentials, appropriate access configuration, and the security of their own systems.

8. International data transfers

We may process and store information in the United States or other countries where we or our service providers operate. If personal information is transferred from the European Economic Area, United Kingdom, or Switzerland to a country not recognized as providing an adequate level of protection, we use appropriate safeguards where required, such as Standard Contractual Clauses.

9. Your privacy rights

9.1 GDPR / UK GDPR rights

Where GDPR or UK GDPR applies, you may have the right to access, correct, or delete your personal information; restrict or object to processing; receive a portable copy of your information; withdraw consent where processing is based on consent; and lodge a complaint with a data protection authority.

9.2 California privacy rights

If CCPA/CPRA applies, California residents may have the right to know what personal information is collected, used, disclosed, sold, or shared; to access, delete, and correct personal information; to opt out of the sale or sharing of personal information; to limit the use of sensitive personal information; and not to be discriminated against for exercising privacy rights.

9.3 Exercising rights

To exercise privacy rights, contact us at the privacy contact email (to be confirmed before publication). We may need to verify your identity before fulfilling a request. If your information is controlled by your organization, we may direct you to that organization or process the request per its instructions.

10. California notice at collection

CategoryExamplesPurpose
IdentifiersName, email, IP address, account IDAccount management, support, security
Commercial informationSubscription plan, billing statusBilling and customer management
Internet or network activityLog data, pages viewed, feature usageSecurity, analytics, product improvement
Geolocation dataApproximate IP-based locationSecurity, analytics
Professional informationCompany, title, roleAccount setup, sales, support
User-generated contentDocuments, evidence, assessments, operating dataProvide the Service
InferencesProduct usage trends, feature preferencesImprove the Service

We do not knowingly sell personal information. If future practices constitute "selling" or "sharing" under California law, we will provide required notices and opt-out mechanisms.

11. Cookies, analytics, and tracking

We may use analytics tools that collect usage, device, and technical data. Where required, we allow users to manage cookie preferences; you can also control cookies through browser settings. Where legally required, we honor recognized opt-out preference signals such as Global Privacy Control.

12. Children's privacy

The Service is intended for business and professional users. It is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If we learn we have, we will take steps to delete it.

13. Organizational use

If you use NOS through an organization, that organization may control account access, permissions, membership, retention, integrations, audit logs, and content deletion. Your organization's policies also apply to your use of the Service.

14. Sensitive information

NOS is not intended to process highly sensitive personal information unless explicitly agreed in writing and configured with appropriate controls. Do not submit Social Security numbers, government identification numbers, financial account credentials, health information, biometric data, children's data, precise geolocation, or passwords and secrets except where the Service explicitly provides for them (your own login credentials).

15. Third-party links and services

The Service may contain links to third-party websites and tools. We are not responsible for the privacy practices of third parties; their own terms and policies govern your use of their services.

16. SMS and text messaging

If you add and verify a mobile phone number, you may choose to opt in to receive text messages from NOS. We use SMS only for the purposes you enable, which are limited to transactional messages: sign-in (two-factor authentication) codes and account and security notifications you turn on in your settings. We do not send marketing or promotional text messages.

Consent to receive texts is not a condition of using the Service. You provide express consent by verifying your number and enabling text messages in your account settings, and we record the date and time of that consent. Message frequency varies based on your activity and settings. Message and data rates may apply. Reply STOP to any message to opt out at any time, or reply HELP for help. Carriers are not liable for delayed or undelivered messages.

Your mobile phone number and your SMS opt-in and consent information are not shared or sold to third parties or affiliates for their marketing purposes. We share your number only with the messaging provider that delivers texts on our behalf, solely to send the messages you requested.

17. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. If we make material changes, we will provide notice as required by law — by updating the version date, posting a notice, or sending an email.

18. Contact us

For privacy questions, requests, or concerns, contact Nimble CTO, LLC (privacy contact email and mailing address to be confirmed before publication). See also the Terms of Use.

Home · Terms of Use · Privacy Policy