Privacy Policy
Last updated
Draft - needs lawyer review. This document describes how Nomisly actually works but has not yet been reviewed by a lawyer for the operating entity and each jurisdiction.
Who we are
Nomisly (operated by its founder, India; legal entity details to be added) provides lead response, messaging, booking and follow-up software ("the Service"). For data our customers process about their own customers (end users), our customer is the controller and Nomisly is the processor; see the DPA. For our website visitors and account holders, Nomisly is the controller.
What we collect
Account data: name, e-mail, business name, role, password hash or sign-in identity (Google/Microsoft), two-step verification settings.
Customer content: leads, conversations, bookings, documents and knowledge that customers upload or connect. We process it only to provide the Service.
Usage and technical data: log records (with contact data redacted), device and browser information, IP address for security and rate limiting.
Website analytics: Cloudflare Web Analytics (cookieless, aggregated). With consent only: Google Analytics (pages visited, device and approximate location, set through cookies) and advertising cookies on content pages.
Community posts: the name, optional e-mail, business type and text you send on the community page or with the in-app Feedback button. The name and text are shown once approved; the e-mail is used only to tell you about a reply and is never shown. We keep a one-way hash of your IP address (not the address) to stop spam and duplicate votes. Ask us to remove a post at any time.
Why we use it (legal bases)
To provide and secure the Service (contract; legitimate interests in security).
To bill and meet tax obligations (legal obligation).
To improve the product using aggregated, de-identified usage (legitimate interests).
Marketing e-mails to account holders only with consent, with one-click unsubscribe.
AI processing
The Service uses AI models to draft replies, qualify leads and answer from the customer's own knowledge. Depending on the customer's settings, text is sent to the AI provider the customer chooses (for example Anthropic, OpenAI, Google or OpenRouter) under their API terms. We do not use customer content to train our own models. Customers can connect their own AI provider keys.
Where data is stored and who we share it with
Data is stored with the sub-processors listed on the sub-processors page, which may be outside your country. Where required we rely on appropriate safeguards such as Standard Contractual Clauses.
We never sell personal data.
How long we keep it
Account and customer content: for the life of the account. When a trial or paid plan ends, the workspace moves to the free plan and its data is kept. When a customer closes the account, we delete it after notice, unless the customer exports it first or law requires longer retention.
Security audit records: up to 400 days. Backups: up to 14 days.
Your rights
Depending on where you live (for example the EU/UK GDPR, India's DPDP Act 2023, Brazil's LGPD, the UAE PDPL or the California CCPA/CPRA), you may have rights to access, correct, delete or port your data, withdraw consent, object to processing and complain to a regulator. End users of our customers should contact the business they interacted with; we will help that business respond.
Contact: privacy@nomisly.com. We answer within 30 days.
Security
Encryption in transit and at rest for secrets, per-tenant database isolation with row-level security, two-step verification, least-privilege access and an append-only audit log. See the Security page.
Children
The Service is for businesses and is not directed at children.
Changes
We will post changes here with a new date and notify account holders of material changes.