Home · Legal
Privacy Policy
How Nous AI Ltd collects, uses, stores, and protects your personal data when you use our Services.
Nous AI Ltd ("we", "us", or "our") is committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our website, platform, applications, APIs, and other services (collectively "Services"). We act as the data controller when processing personal data for our own business purposes, including: We act as a data processor when processing personal data contained within any documents, files, or other content that you upload, input, or process through our Services. This includes: When we act as Data Controller: We process your personal data under the following legal bases as defined by GDPR: When we act as Data Processor: You remain the data controller. We process this data solely to provide the contracted services as agreed in your Subscription Agreement and in accordance with applicable data protection laws. The legal basis for processing is determined by you, and we process data only as necessary to provide our Services. When we act as Data Controller, we use your personal data for: When we act as Data Processor for client data: We may share your personal data with third-party service providers, but only to carry out the specific services they are performing for us in order to provide our Services and under appropriate data protection agreements. This may include service providers who provide email or electronic communication services, tax, legal and accounting services, payment processing, fraud prevention and detection, web hosting and cloud storage, and artificial intelligence services, which may process your data to help provide our Services. Neither we nor any of our third-party service providers use your personal data to train artificial intelligence models. We may transfer your data outside the UK/EEA only where adequate protections are in place, including Standard Contractual Clauses or adequacy decisions by the UK/EU authorities. We do not sell, rent, or trade your personal data to third parties. Data where we act as Controller: Client Data where we act as Processor: Client data retention is controlled by you as the data controller. As data processor, we follow your instructions regarding retention periods and deletion of your content. Deletion Process: When retention periods expire or upon deletion requests, we securely delete personal data from all our systems, including backups, within a reasonable timeframe not exceeding 90 days, except where retention is required by law. We implement appropriate technical and organisational measures designed to protect your personal data against unauthorised access, disclosure, alteration, and destruction. Our security framework includes encryption of data both in transit and at rest using industry-standard protocols. We maintain strong authentication practices and administrative access controls that limit system access to authorised personnel only. Our platform supports enterprise-grade authentication mechanisms, including Single Sign-On (SSO), enabling clients to integrate access management with their existing identity providers. Our platform architecture incorporates data segregation techniques to ensure customer data remains isolated and separate from other tenants' information. We also provide IP-based access restrictions upon customer request to allow organisations to limit platform access to specific network ranges. For data where we act as Controller: You have the right to access, rectify, erase, restrict processing of, or receive a portable copy of your personal data. You may also object to processing based on legitimate interests or for marketing purposes, and you have rights regarding any automated decision-making or profiling. For client data where we act as Processor: Since you are the data controller for your uploaded content, you should exercise data subject rights directly with us regarding your client data, or contact the relevant data subjects if they request access to data you've uploaded to our platform. To exercise any rights regarding data where we act as controller, please contact us at privacy@nousai.com. We will respond within one month of receiving your request. We use cookies and similar tracking technologies to enhance your experience on our website and services. You can manage your cookie preferences through your browser settings. Our Services are not intended for individuals under the age of 16. We do not knowingly collect personal data from children under 16. If we become aware that we have collected personal data from a child under 16, we will take steps to delete such information promptly. We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify you of any material changes by email. The updated policy will be effective from the date of publication. If you have concerns about how we handle your personal data, please contact us first. If you remain unsatisfied, you have the right to lodge a complaint with the UK's supervisory authority: Information Commissioner's Office (ICO) If you have any questions about this Privacy Policy or our data processing practices, please contact us: Nous AI Ltd1. Data Controller and Data Processor Roles
When We Act as Data Controller
When We Act as Data Processor
2. Legal Basis for Processing
3. How We Use Personal Data
4. Data Sharing and Third Parties
5. Data Retention
6. Data Security
7. Your Rights
8. Cookies and Tracking Technologies
9. Children's Privacy
10. Changes to This Privacy Policy
11. Complaints and Regulatory Authority
Website: ico.org.uk
Telephone: 0303 123 1113
Address: Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF12. Contact Information
71–75 Shelton Street, Covent Garden
London, WC2H 9JQ
United Kingdom
Email: privacy@nousai.com
General Enquiries: info@nousai.com