Draft for review by counsel — not yet in effect.
Privacy Policy
This policy explains what personal data Nymbrink handles, why, where it is kept, and the rights you have. Nymbrink is operated by No Hustle, Inc., a Delaware corporation (USA). Questions go to privacy@nymbrink.com.
Who is responsible
For the people who sign up and for visitors to our public pages, No Hustle, Inc. is the controller. For the data a business customer puts into its account — its team members, the agents it watches, its rules and decisions — the customer is the controller and we act as its processor under the Data Processing Addendum.
What we collect
- Account data: your email address, your company’s name, and your role in the account.
- What you put in: the agents you watch, your rules, approvals and notes, and where alerts should go (email addresses, Slack or Teams addresses, webhook addresses).
- Service records: when checks ran and what they found, stamps issued, alerts sent, and sign-in events.
- Public passports: the public declarations we fetch. These may name the company answerable for an agent and a contact address it chose to publish.
We do not use advertising trackers, and we do not sell personal data.
Why we use it, and the legal basis
- To provide the service you signed up for: performance of a contract (GDPR Art. 6(1)(b)).
- To keep the service secure, prevent abuse and keep records of what we observed: our legitimate interests (Art. 6(1)(f)).
- To keep billing and tax records: legal obligation (Art. 6(1)(c)).
- To fetch and record public passports: our legitimate interest in providing an independent record of what was published, balanced by fetching only public addresses, at low frequency, and identifying ourselves.
No customer data is used to train AI models.
Where it is kept
Our database and application run in the European Union (Frankfurt, Germany). Email delivery uses a provider in the United States, which receives the recipient address and the message. The full list is on the subprocessors page. Transfers outside the EU and EEA rely on the European Commission’s Standard Contractual Clauses or the EU-US Data Privacy Framework where the provider is certified.
No Hustle, Inc. is itself a US company. Where our staff access data from outside the EU, the same safeguards apply.
Who sees it
Only the members of your company account see what you put in. Other customers never see which agents you watch or what you decided. Nymbrink’s public pages show only public passports and what Nymbrink observed about them — never who asked to watch.
How long we keep it
Account data and what you put in are kept while your account is open and deleted when it closes, apart from what we must keep by law. Records of what we observed, and stamps, are kept for up to seven years so that they can serve as evidence. Personal data inside them is limited to what the public passport itself contained.
Your rights
If you are in the EU, EEA or UK you may ask to access, correct, delete or export your personal data, to restrict or object to how we use it, and to withdraw any consent you gave. Write to privacy@nymbrink.com; we answer within one month. You may also complain to your local data protection authority.
If your request concerns data a business customer put into its account, we will pass it to that customer and help it respond.
Cookies
We use only the cookies needed to keep you signed in. We do not use cookies for advertising or cross-site tracking.
Security
How we protect data is described on the security page.
Changes
We will announce material changes to this policy by email and on this page at least 30 days before they take effect.