Last Updated: 13 June 2026
Effective Date: 26 June 2026
This Privacy Policy explains how Nimbus Intelligence, Inc. ("Nimbus," "we," "us," or "our") collects, uses, discloses, and protects personal information when you visit gonimbus.ai (the "Site"), create an account, or use the Nimbus enterprise AI platform and related services (collectively, the "Services").
This Policy is designed to meet common requirements in the United States, United Kingdom, European Economic Area (EEA), Canada, Australia, and New Zealand. Additional rights or obligations may apply depending on where you live. If local law gives you rights that are not described here, we will honour them to the extent required.
This Policy should be read together with our Terms of Service. Capitalised terms used but not defined here have the meanings given in the Terms.
We do not sell personal information. We do not use personal information for cross-context behavioural advertising.
1. Who we are
Data controller (for account, website, billing, and support data):
Nimbus Intelligence, Inc.
1111B South Governors Avenue
Dover, DE 19904
United States
Privacy contact: [email protected]
Subject line for privacy requests: Privacy Request
When you use the Services on behalf of an organisation, your organisation is generally responsible for the business content you connect to Nimbus (see Section 3).
2. Scope and audience
This Policy applies to:
- visitors to the Site;
- individuals who create or use a Nimbus account (including admins who invite colleagues);
- individuals whose personal information appears in content submitted to the Services by a customer (for example, employee names in CRM records, customer emails in support tickets, or contact details in wiki documents); and
- individuals who communicate with us for sales, support, marketing, or legal purposes.
The Services are not directed to children and are not intended for individuals under 18 (or the age of majority in your jurisdiction).
3. Controller and processor roles
Nimbus wears different hats depending on the data:
| Situation | Our role | Typical examples |
|---|---|---|
| Account, billing, website, and support data | Controller | Your name, work email, login credentials, payment metadata, support tickets you send us |
| Customer Data you or your organisation submits to the Platform | Processor (or service provider under US state law) | CRM records, ERP data, wiki documents, connector payloads, prompts, run outputs containing third-party personal data |
| Usage Data and security logs | Controller | Telemetry, audit logs, IP addresses, device/browser data |
If you connect systems or upload content containing personal information about your employees, customers, or other individuals, your organisation is the controller (or "business" under CCPA) for that content. You are responsible for having a lawful basis to provide it to Nimbus and for configuring access, retention, and approvals appropriately.
Where required, we offer a Data Processing Addendum (DPA) for business and enterprise customers. Contact [email protected] to request one.
4. Personal information we collect
We collect the following categories of personal information, depending on how you interact with us:
4.1 Account and profile information
- Name, work email address, job title, organisation name
- Account credentials (passwords are stored hashed; we do not store plaintext passwords)
- Workspace, role, and permission settings (Owner, Admin, Member, Guest)
- Preferences and notification settings
4.2 Billing and transaction information
- Subscription plan, billing address, tax identifiers where provided
- Payment information processed by our payment processor (we do not store full payment card numbers)
- Invoices, NTU usage, and billing history
4.3 Customer Data and connected-system content
When you or your organisation uses the Services, we process content you submit or authorise us to retrieve, which may include personal information about you or others:
- Prompts, project briefs, configurations, and approvals
- Documents and files synced from wiki or document integrations
- Records pulled from connected SaaS systems (CRM, ERP, support, HR, marketing, engineering tools, etc.)
- Swarm outputs, decision briefs, audit trails, and Decision History / Lifecycle Graph entries
- Connector credentials and OAuth tokens (stored encrypted, tenant-scoped)
4.4 Usage, device, and technical information
- IP address, browser type, device identifiers, operating system
- Log files, diagnostic data, performance metrics, and security events
- Feature usage, run telemetry, and product analytics (Usage Data)
- Cookies and similar technologies (see Section 9)
4.5 Communications and marketing
- Information you provide when contacting sales, support, or legal
- Newsletter or webinar sign-ups
- Records of our correspondence with you
4.6 Sensitive information
The Services are not designed for special categories of sensitive personal information (such as health data under HIPAA, government identifiers, financial account numbers used as primary identifiers, or biometric data). Do not submit such data. If you do, you do so at your own risk and in breach of our Terms.
5. How we collect personal information
We collect personal information:
- Directly from you - when you register, configure workspaces, connect integrations, run projects, approve actions, or contact us;
- From your organisation - when an admin invites you or assigns roles;
- Automatically - through cookies, logs, and telemetry when you use the Site or Services;
- From third parties - payment processors, identity/SSO providers, and systems you connect via OAuth or API credentials; and
- From publicly available sources - only where a feature you enable (such as market sensing) retrieves such data on your instructions.
6. How we use personal information
We use personal information to:
| Purpose | Examples |
|---|---|
| Provide the Services | Authenticate users, run AI departments, land connector data, enforce governance and approvals, maintain Decision History |
| Secure and operate the Platform | Monitor abuse, debug errors, prevent fraud, enforce Terms |
| Bill and administer accounts | Process subscriptions, meter NTU usage, send invoices |
| Communicate with you | Support responses, service notices, security alerts |
| Improve the Services | Analytics, product development, benchmarking (using aggregated or de-identified data where possible) |
| Comply with law | Respond to lawful requests, maintain records, defend legal claims |
| Marketing (with choice) | Send product updates or newsletters where permitted; you may opt out |
6.1 Legal bases (EEA, UK, and similar jurisdictions)
Where GDPR or UK GDPR applies, we rely on the following legal bases:
| Legal basis | Typical use |
|---|---|
| Contract | Providing the Services you or your organisation requested |
| Legitimate interests | Security, fraud prevention, product improvement, B2B marketing to business contacts, enforcing our Terms - balanced against your rights |
| Consent | Optional cookies, certain marketing, where required |
| Legal obligation | Tax, accounting, regulatory, and law-enforcement requests |
You may object to processing based on legitimate interests as described in Section 12.
6.2 AI processing
The Services use artificial intelligence and third-party model providers to generate analyses and recommendations. Personal information in prompts and connected data may be transmitted to infrastructure and AI subprocessors only to deliver the Services, subject to contractual restrictions on use for training shared public models.
We do not use identifiable personal information to train shared public AI models. Business and Enterprise plans may include enhanced data-handling controls. See Section 7 and our Terms for how Customer Data may be used for service improvement.
Automated processing does not produce legal or similarly significant effects about individuals without human review configured by your organisation - write-back and high-impact actions require human-in-the-loop approval where enabled.
7. Customer Data, model training, and business use
This section aligns with our Terms and is important for business customers:
- Customer Data (non-PII business content) may be used to operate, maintain, and improve the Services, including developing and training AI and machine learning models, unless you opt out or your plan provides enhanced controls.
- Personally identifiable information (PII) within Customer Data is not used to train shared public models.
- We do not sell PII and do not share it with third parties for their independent advertising.
- We may anonymise and aggregate information so it no longer identifies an individual; we may use anonymised/aggregated data without restriction.
To opt out of certain uses of Customer Data for model improvement, contact [email protected] or upgrade to a Business or Enterprise plan with enhanced controls, as described on the Site.
8. How we share personal information
We share personal information only as follows:
| Recipient | Why |
|---|---|
| Service providers / subprocessors | Cloud hosting, AI inference, payment processing, email delivery, analytics, customer support tools - under contracts requiring appropriate protection |
| Your organisation | Workspace admins, audit logs, and shared project material according to roles you assign |
| Integrations you authorise | When you enable write-back or outbound actions to third-party systems |
| Professional advisers | Lawyers, accountants, insurers, under confidentiality |
| Corporate transactions | Merger, acquisition, financing, or asset sale, subject to continued protection |
| Law and safety | When required by law, court order, or to protect rights, safety, and integrity of the Services |
We maintain a list of key subprocessors on request and will provide notice of material changes where required by contract or law.
9. Cookies and similar technologies
We use cookies and similar technologies on the Site to:
- keep you signed in;
- remember preferences;
- measure Site performance and usage; and
- protect against abuse.
Where required, we request consent for non-essential cookies. You can control cookies through your browser settings; disabling cookies may limit Site functionality.
We do not use cookies for cross-context behavioural advertising on third-party sites.
10. International data transfers
Nimbus is based in the United States. If you access the Services from the EEA, UK, Canada, Australia, New Zealand, or elsewhere, your personal information may be transferred to, stored in, or processed in the United States and other countries where we or our providers operate.
We implement appropriate safeguards for international transfers, which may include:
- Standard Contractual Clauses (SCCs) approved by the European Commission;
- the UK International Data Transfer Addendum or UK IDTA, as applicable;
- data processing agreements with subprocessors; and
- supplementary measures where required by regulators.
You may request more information about transfer mechanisms by contacting [email protected].
Data residency: Where offered on your plan, we may host certain workspace data in regions such as the United States, European Union, or United Kingdom. Region availability is described on the Site or in your order form.
11. Security
We implement administrative, technical, and organisational measures designed to protect personal information, including:
- TLS encryption in transit;
- encryption at rest for stored credentials and workspace data;
- tenant and workspace isolation;
- role-based access controls and optional SSO;
- logging and monitoring of access and runs;
- contractual opt-outs with AI providers regarding training on your business content.
No method of transmission or storage is completely secure. You are responsible for safeguarding account credentials and configuring governance appropriately.
Report security concerns to [email protected].
12. Retention
We retain personal information only as long as necessary for the purposes described in this Policy, unless a longer period is required by law.
| Data type | Typical retention |
|---|---|
| Account data | While your account is active, plus a reasonable period after closure for backup, dispute, and legal purposes |
| Billing records | As required for tax and accounting laws (often 7 years) |
| Customer Data / run outputs | According to your workspace retention settings (e.g., 7 days to indefinite, depending on plan) |
| Backups | Deleted data may persist in encrypted backups for a limited period before overwrite |
| Anonymised / aggregated data | May be retained indefinitely |
When you delete data or close an account, we delete or anonymise personal information in accordance with this Policy and your contract, subject to legal holds and backup cycles.
13. Your privacy rights
Your rights depend on where you live. We will verify requests before responding. We may decline requests that are unfounded, excessive, or prohibited by law.
To exercise any right: email [email protected] with subject Privacy Request, include your name, organisation (if applicable), and the right you wish to exercise. We aim to respond within 30 days (or the period required by applicable law).
If you are an employee or end user whose data was submitted by your employer, contact your organisation first - they control that Customer Data. We will assist them as processor where required.
13.1 European Economic Area and United Kingdom (GDPR / UK GDPR)
If you are in the EEA or UK, you may have the right to:
- Access - obtain confirmation and a copy of personal information we process about you;
- Rectification - correct inaccurate personal information;
- Erasure - request deletion in certain circumstances;
- Restriction - limit processing in certain circumstances;
- Portability - receive personal information you provided in a structured, machine-readable format where technically feasible;
- Object - object to processing based on legitimate interests or for direct marketing;
- Withdraw consent - where processing is based on consent, without affecting prior lawful processing;
- Automated decision-making - not be subject to solely automated decisions with legal or similarly significant effects, except where permitted by law with safeguards;
- Lodge a complaint with a supervisory authority.
Supervisory authorities (examples):
- EEA: Your local data protection authority - https://edpb.europa.eu/about-edpb/about-edpb/members_en
- UK: Information Commissioner's Office (ICO) - https://ico.org.uk
For EEA/UK inquiries, contact [email protected]. Where required by law, we will designate an EU or UK representative and publish contact details on the Site.
13.2 United States - California (CCPA / CPRA)
If you are a California resident, you may have the right to:
- Know what personal information we collect, use, disclose, and sell or share (we do not sell or share personal information for cross-context behavioural advertising);
- Access specific pieces and categories of personal information;
- Delete personal information, subject to exceptions;
- Correct inaccurate personal information;
- Opt out of sale/share - not applicable as we do not sell or share as defined by CPRA;
- Limit use of sensitive personal information - we do not use sensitive personal information for purposes requiring a "limit" right under CPRA;
- Non-discrimination for exercising privacy rights.
Categories collected (last 12 months): identifiers; commercial information; internet/network activity; professional information; inferences (limited to service personalisation); and Customer Data categories described above when you use the Services.
Business purposes: as in Section 6. Service providers: as in Section 8.
Authorised agents: may submit requests with proof of authorisation.
Shine the Light: we do not disclose personal information to third parties for their direct marketing purposes as defined under California Civil Code § 1798.83.
Other US states (Virginia, Colorado, Connecticut, Utah, Oregon, Texas, and others) may provide similar rights. Contact us to exercise them.
13.3 Canada (PIPEDA and provincial laws)
If you are in Canada, you have rights to access personal information we hold about you, challenge its accuracy, and withdraw consent where processing is consent-based, subject to legal and contractual restrictions.
We are accountable for personal information under our control, including information transferred to service providers. We use contracts to require comparable protection.
Office of the Privacy Commissioner of Canada: https://www.priv.gc.ca
Quebec Law 25 and other provincial privacy laws may provide additional rights. We will comply with applicable provincial requirements.
13.4 Australia (Privacy Act 1988 and APPs)
If you are in Australia, we handle personal information in accordance with the Australian Privacy Principles (APPs).
You may:
- request access to and correction of personal information we hold about you;
- complain to us if you believe we have breached the APPs; and
- complain to the Office of the Australian Information Commissioner (OAIC) - https://www.oaic.gov.au - if not satisfied with our response.
We may disclose personal information to overseas recipients (including the United States). We take reasonable steps to ensure overseas recipients handle information in accordance with the APPs.
13.5 New Zealand (Privacy Act 2020)
If you are in New Zealand, you may request access to and correction of personal information we hold about you.
You may complain to the Office of the Privacy Commissioner - https://www.privacy.org.nz - if you believe we have interfered with your privacy.
Before we disclose personal information to overseas persons or entities, we will comply with New Zealand Privacy Act requirements regarding cross-border disclosure.
14. Marketing communications
We may send product updates, newsletters, or event invitations to business contacts where permitted by law. You may unsubscribe using the link in any marketing email or by contacting [email protected].
Service-related and transactional messages (security alerts, billing, material Terms changes) may still be sent even if you opt out of marketing.
15. Third-party sites and integrations
The Site may link to third-party websites. Connected integrations (Salesforce, Google, Microsoft, etc.) are governed by those providers' privacy policies. We are not responsible for third-party practices outside the Services.
When you authorise an integration, you control the scopes granted in the source system. Review those permissions carefully.
16. Changes to this Policy
We may update this Policy from time to time. We will post the revised Policy on the Site and update the Last Updated date. For material changes, we may provide additional notice (for example, by email or in-product notification).
Continued use of the Services after the effective date constitutes acceptance of the updated Policy, except where prohibited by law.
17. Contact us
Nimbus Intelligence, Inc.
Email: [email protected]
Address: 1111B South Governors Avenue, Dover, DE 19904, USA
Website: gonimbus.ai
For data protection inquiries, DPA requests, or privacy rights requests, email [email protected] with subject Privacy Request.
This Privacy Policy is provided for transparency on the Site. It is not legal advice. Organisations using Nimbus should consult qualified counsel to assess compliance obligations in their jurisdictions and industries.