Nimble CTO, LLC ("NOS," "we," "us," or "our") respects your privacy. This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information when you use the Nimble Operating System website, platform, software, services, integrations, and related offerings (the "Service").
This policy is designed around recognized privacy principles — transparency, purpose limitation, data minimization, security, accountability, and user control — and accounts for common requirements under the General Data Protection Regulation ("GDPR"), UK GDPR, and the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA").
1. Who we are
The entity responsible for this Privacy Policy is Nimble CTO, LLC (privacy contact email and mailing address to be confirmed before publication). Where we determine how and why personal information is processed — managing accounts, operating our website, communicating with users, administering the Service — we act as a data controller. Where an organization uses NOS to manage its own people and operational data, that organization may act as the data controller and we act as a data processor or service provider.
2. Information we collect
2.1 Account and contact information
Name, business email address, company name, job title or role, account identifiers, authentication information, and support contact details.
2.2 Usage and device information
IP address, browser and device type, operating system, pages viewed, features used, session activity, approximate location derived from IP address, log files, error reports, and performance data.
2.3 Product content and operational data
Content you or your organization submit to the Service — assessments, evidence documents, findings, priorities, decisions, team roles, and other operating data. This content may include personal information if users choose to include it.
2.4 Integration data
If the Service connects to third-party systems (repositories, project management tools, document repositories, data rooms), we process information from those systems only as authorized by you or your organization and only to the extent needed to provide the requested functionality.
2.5 Communications
Information contained in emails, support requests, feedback, demo or sales inquiries, and surveys.
2.6 Payment and billing information
If paid plans apply: billing name and address, subscription plan, payment status, and invoice history. Payment card details are processed by a PCI-compliant third-party payment processor and are not stored by NOS.
2.7 Cookies and similar technologies
We use cookies and similar technologies to keep users signed in, remember preferences, improve performance, analyze usage, and detect fraud or abuse. Where required by law, we provide consent mechanisms or opt-out choices for non-essential cookies.
3. How we use information
| Purpose | Examples | Legal basis where GDPR applies |
|---|---|---|
| Provide the Service | Account access, product functionality, hosting, support | Contract performance |
| Operate and secure the Service | Authentication, monitoring, fraud prevention, incident response | Legitimate interests; legal obligation |
| Improve the Service | Debugging, analytics, feature development | Legitimate interests; consent where required |
| Communicate with users | Service updates, support responses, administrative notices | Contract performance; legitimate interests |
| Sales and marketing | Demo follow-up, product updates | Consent; legitimate interests where permitted |
| Billing and account management | Invoices, subscriptions, tax records | Contract performance; legal obligation |
| Compliance | Legal requests, audits, enforcing terms | Legal obligation; legitimate interests |
| AI-assisted functionality | Summarization, analysis, scoring support | Contract performance; customer instruction |
Where we rely on legitimate interests, we balance those interests against the rights and freedoms of affected individuals.
4. AI and automated processing
NOS may include AI-assisted features such as summarizing documents, supporting assessment scoring, classifying content, and organizing knowledge. Unless otherwise stated in a separate customer agreement: we do not use customer content to train public AI models; we process customer content only to provide, secure, support, and improve the Service; and AI outputs may be inaccurate and should be reviewed before use. If automated decision-making with legal or similarly significant effects is ever introduced, we will provide additional disclosures and rights as required by law.
5. How we share information
We do not sell personal information. We may share information with:
- Service providers — vendors who help us operate the Service (hosting, email delivery, error monitoring, payment processing, AI infrastructure where applicable), authorized to process information only as needed and under contractual protections;
- Your organization — administrators and members of organizations you belong to, based on the permissions your organization configures;
- Integrations — third-party services you or your organization connect;
- Legal and compliance — where necessary to comply with law, respond to lawful requests, protect rights and safety, enforce agreements, or investigate fraud or security incidents; and
- Business transfers — a merger, acquisition, financing, or sale of assets, subject to appropriate protections.
6. Data retention
We retain personal information only as long as reasonably necessary for the purposes described here, unless a longer period is required or permitted by law. Retention depends on the type of information, whether it belongs to an active account, contract requirements, legal and audit obligations, security needs, and backup cycles. Customer content is generally retained for the duration of the customer relationship unless deleted by the customer. Backups may persist for a limited period after deletion before being overwritten.
7. Security
We use reasonable administrative, technical, and organizational safeguards designed to protect personal information — access controls, encryption in transit, encryption at rest where appropriate, authentication controls, logging, least-privilege access, and incident response procedures. No system is completely secure; users and customers are responsible for strong credentials, appropriate access configuration, and the security of their own systems.
8. International data transfers
We may process and store information in the United States or other countries where we or our service providers operate. If personal information is transferred from the European Economic Area, United Kingdom, or Switzerland to a country not recognized as providing an adequate level of protection, we use appropriate safeguards where required, such as Standard Contractual Clauses.
9. Your privacy rights
9.1 GDPR / UK GDPR rights
Where GDPR or UK GDPR applies, you may have the right to access, correct, or delete your personal information; restrict or object to processing; receive a portable copy of your information; withdraw consent where processing is based on consent; and lodge a complaint with a data protection authority.
9.2 California privacy rights
If CCPA/CPRA applies, California residents may have the right to know what personal information is collected, used, disclosed, sold, or shared; to access, delete, and correct personal information; to opt out of the sale or sharing of personal information; to limit the use of sensitive personal information; and not to be discriminated against for exercising privacy rights.
9.3 Exercising rights
To exercise privacy rights, contact us at the privacy contact email (to be confirmed before publication). We may need to verify your identity before fulfilling a request. If your information is controlled by your organization, we may direct you to that organization or process the request per its instructions.
10. California notice at collection
| Category | Examples | Purpose |
|---|---|---|
| Identifiers | Name, email, IP address, account ID | Account management, support, security |
| Commercial information | Subscription plan, billing status | Billing and customer management |
| Internet or network activity | Log data, pages viewed, feature usage | Security, analytics, product improvement |
| Geolocation data | Approximate IP-based location | Security, analytics |
| Professional information | Company, title, role | Account setup, sales, support |
| User-generated content | Documents, evidence, assessments, operating data | Provide the Service |
| Inferences | Product usage trends, feature preferences | Improve the Service |
We do not knowingly sell personal information. If future practices constitute "selling" or "sharing" under California law, we will provide required notices and opt-out mechanisms.
11. Cookies, analytics, and tracking
We may use analytics tools that collect usage, device, and technical data. Where required, we allow users to manage cookie preferences; you can also control cookies through browser settings. Where legally required, we honor recognized opt-out preference signals such as Global Privacy Control.
12. Children's privacy
The Service is intended for business and professional users. It is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If we learn we have, we will take steps to delete it.
13. Organizational use
If you use NOS through an organization, that organization may control account access, permissions, membership, retention, integrations, audit logs, and content deletion. Your organization's policies also apply to your use of the Service.
14. Sensitive information
NOS is not intended to process highly sensitive personal information unless explicitly agreed in writing and configured with appropriate controls. Do not submit Social Security numbers, government identification numbers, financial account credentials, health information, biometric data, children's data, precise geolocation, or passwords and secrets except where the Service explicitly provides for them (your own login credentials).
15. Third-party links and services
The Service may contain links to third-party websites and tools. We are not responsible for the privacy practices of third parties; their own terms and policies govern your use of their services.
16. SMS and text messaging
If you add and verify a mobile phone number, you may choose to opt in to receive text messages from NOS. We use SMS only for the purposes you enable, which are limited to transactional messages: sign-in (two-factor authentication) codes and account and security notifications you turn on in your settings. We do not send marketing or promotional text messages.
Consent to receive texts is not a condition of using the Service. You provide express consent by verifying your number and enabling text messages in your account settings, and we record the date and time of that consent. Message frequency varies based on your activity and settings. Message and data rates may apply. Reply STOP to any message to opt out at any time, or reply HELP for help. Carriers are not liable for delayed or undelivered messages.
Your mobile phone number and your SMS opt-in and consent information are not shared or sold to third parties or affiliates for their marketing purposes. We share your number only with the messaging provider that delivers texts on our behalf, solely to send the messages you requested.
17. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will provide notice as required by law — by updating the version date, posting a notice, or sending an email.
18. Contact us
For privacy questions, requests, or concerns, contact Nimble CTO, LLC (privacy contact email and mailing address to be confirmed before publication). See also the Terms of Use.