PRIVACY & DATA POLICY

How Nimble handles data across websites, products and services.

This policy describes how Nimble Technology may collect, use, store, process, share and protect information when you use our website, products, software, marketing, development, automation and related services.

Last updated: 24 September 2026Website · Products · Services

PRIVACY AT A GLANCE

Product and service data may be stored where required to provide the service.

We may process customer-authorised access to business platforms and accounts.

Third-party platforms apply their own terms, policies and privacy practices.

Sensitive credentials should be shared only when genuinely necessary and through an approved secure method.

AI and automation may involve third-party processors depending on the configured service.

Retention depends on the service, contract, legal requirement and operational need.

ON THIS PAGE

Overview

01 · OVERVIEW

This policy covers more than the public website.

Nimble Technology may operate websites, software products, SaaS platforms, digital marketing services, development projects, business automation, integrations, AI-assisted systems and related technology services.

Website visitors and people who submit project enquiries.

Customers and authorised users of Nimble products and software.

Customers who engage Nimble for development, automation, UI/UX, marketing or technology services.

Employees, contractors, candidates and other people who interact with Nimble in a professional capacity.

02 · SCOPE

Our role can differ depending on the service.

Privacy responsibilities depend on why information is being processed and who determines its purpose.

Nimble's own business data

For website enquiries, account administration, billing, hiring and similar activities, Nimble may determine why and how certain personal information is processed.

Customer-controlled data

For some products, hosted software or development services, a customer may determine the purpose of end-user or business data and Nimble may process that information to provide the contracted service.

PRODUCT-SPECIFIC POLICIES MAY ALSO APPLY

Products that process specialised categories of data—particularly healthcare, student, employee, financial or regulated information— may require additional privacy notices, contracts, data-processing terms, permissions or safeguards.

03 · INFORMATION

Information we may collect or process

Identity & business details

Name, phone number, email, job role, city, organisation, business information, account details and related contact information.

Project & requirement data

Project briefs, business processes, workflows, specifications, documents, media, feedback, technical requirements and communications.

Product data

Information created, uploaded, imported, transmitted, generated or stored while using Nimble software or hosted products.

Technical information

IP address, browser or device information, timestamps, logs, identifiers, session information, security events and diagnostic information.

04 · PRODUCT DATA

Our products may store customer and operational data.

Data storage is often necessary for software to work. The type of information depends on the product and the features enabled by the customer.

ConversiaX

Depending on enabled features, the platform may process business account details, contacts, conversation data, WhatsApp-related information, templates, campaigns, automation configuration, bookings, analytics, team information and operational records.

Skoler

During testing or future operation, Skoler may process school, administrator, teacher, student, parent, admission, attendance, fee, communication and related school-management information.

Arovia

During testing or future operation, Arovia may process clinic, doctor, staff, appointment, patient, clinical, prescription, billing, follow-up and related healthcare workflow information.

HEALTHCARE AND STUDENT DATA NEED ADDITIONAL CARE

The exact data model, legal basis, consent requirements, role of the customer, security controls and retention rules for Arovia and Skoler should be documented in product-specific policies and customer agreements before wider production use.

05 · ACCOUNT ACCESS

Social accounts, advertising accounts and credentials

Some services require authorised access to third-party business accounts.

We may request authorised access to Meta Business Manager, Facebook, Instagram, Google Ads, Google Analytics, Google Business Profile, YouTube, hosting, domains, CRM platforms, email systems, website administration or similar services when necessary for the agreed work.

Wherever possible, customers should provide official role-based, partner, admin, delegated or OAuth access rather than sharing their primary account password.

If credentials must temporarily be provided, they should be shared through an approved secure channel, access should be limited to authorised personnel and passwords should be changed or access revoked when no longer required.

Customers remain responsible for ensuring that they have authority to provide Nimble access to the relevant account, data and intellectual property.

DO NOT SEND PASSWORDS THROUGH GENERAL CONTACT FORMS

General website forms are not intended for passwords, OTPs, API secret keys, private keys, banking credentials or other high-risk secrets.

06 · DIGITAL MARKETING

Data used while managing marketing campaigns

When Nimble provides digital marketing, campaign management, advertising, social-media management, lead generation or related services, we may process information required to configure, operate, optimise and report on those activities.

Advertising account IDs, page or business IDs, pixels, conversion events, campaign settings, audiences and authorised customer data.

Leads, campaign enquiries, conversion data and performance reports.

Creative assets, videos, photographs, logos, copy and brand materials supplied by the customer.

Analytics and attribution information made available through advertising or analytics platforms.

07 · THIRD-PARTY PLATFORMS

Meta, Google and other platforms operate under their own policies.

When services depend on third-party platforms, both Nimble and the customer may be required to follow the current rules of those platforms.

Advertising platforms

Meta, Google and other advertising platforms independently control ad review, eligibility, data-use restrictions, audience rules, account restrictions, suspensions, billing and policy enforcement.

Platform policies change

Customers should understand that external platform terms, APIs, features, pricing, limits and policies may change without Nimble controlling those changes.

Nimble may assist with compliance and implementation, but use of an external platform remains subject to that platform's applicable terms, privacy documentation, advertising rules, developer policies and technical requirements.

08 · AI & AUTOMATION

AI-enabled features may process prompts, files and operational context.

AI-assisted features may process text, documents, images, website content, customer instructions, workflow data or other context required to perform the requested function.

Depending on the implementation, information may be sent to a third-party AI, cloud or automation provider.

Data retention and model-training practices vary between providers, products and account types. Applicable provider terms should be reviewed for the exact configuration being used.

Customers should avoid submitting unnecessary confidential, regulated or highly sensitive information to AI features unless the relevant implementation and contract are appropriate for that use.

09 · DEVELOPMENT PROJECTS

Software development can involve access to customer systems and data.

Development environments

Development may involve source code, APIs, staging systems, databases, repositories, environment variables, logs, test data and customer-provided content.

Secrets & keys

API keys, SSH keys, database credentials and similar secrets should be provided only when necessary and handled with restricted access.

Wherever practical, development and testing should use non-production or appropriately minimised data. Access to production systems should be limited to what is necessary for the agreed work.

10 · PEOPLE DATA

Employees, contractors and applicants

If you apply to work with Nimble, join the company, provide services as a contractor or otherwise work with us professionally, Nimble may process information needed for recruitment, onboarding, identity verification, attendance, payroll, performance, access management, communication, legal compliance and employment administration.

Contact details, resume, qualifications and employment history.

Government or tax-related information where legitimately required.

Bank details required for salary or authorised payments.

Attendance, leave, role, access, work-related records and company system usage where appropriate.

11 · PAYMENTS

Payment and billing information

Billing records

Nimble may retain invoices, transaction references, payment status, billing contact details, tax-related information and accounting records where required.

Payment processors

Where online payment providers or banks are used, payment credentials may be processed directly by those providers under their own terms and privacy practices.

CARD AND BANKING CREDENTIALS

General Nimble website forms should not be used to send card numbers, CVV codes, banking passwords, UPI PINs or similar authentication secrets.

12 · COOKIES

Cookies, analytics, pixels and similar technologies

Nimble websites or products may use cookies, browser storage, analytics scripts, advertising pixels, session technologies or similar tools for functionality, authentication, security, preferences, measurement, attribution, troubleshooting and product improvement.

Essential technologies

Some storage may be necessary for login sessions, security, preferences or other essential product functionality.

Analytics & marketing

Analytics or advertising technologies may collect usage, attribution, campaign or device information where enabled and permitted.

13 · DATA SHARING

When information may be shared

With hosting, cloud, database, communication, analytics, AI, automation, payment, security and other technology providers used to operate the relevant service.

With authorised employees, contractors or service providers who require the information to perform legitimate work.

With Meta, Google, WhatsApp or another third-party platform where the customer has requested or authorised an integration or campaign.

Where necessary to comply with law, legal process, regulatory obligations, enforce agreements, protect security or investigate suspected misuse.

In connection with a legitimate business restructuring, acquisition, financing or transfer, subject to applicable legal requirements.

Nimble does not intend to sell personal information merely as a standalone business of trading personal data.

14 · DATA LOCATION

Cloud services may process information in different locations.

Technology providers, cloud infrastructure, APIs and third-party platforms may operate servers or support teams in India or other countries. As a result, information may be stored or processed outside the user's immediate location, subject to applicable law and the provider's contractual and security arrangements.

15 · RETENTION

Information is retained according to purpose, service and legal requirements.

Account and product data may remain while an account or service is active.

Project information may remain for the duration of development, support, warranty, maintenance or an ongoing commercial relationship.

Accounting and transaction records may be retained where required for tax, audit, legal or business-record obligations.

Security logs and backups may have separate technical retention periods.

When data is no longer required, it may be deleted, anonymised, archived or otherwise handled according to legal, contractual and operational requirements.

16 · SECURITY

We aim to use safeguards appropriate to the information and service.

Access control

Access should be limited according to role, purpose and operational need.

Infrastructure

Hosting and services may use platform-supported encryption, authentication, logging, backup and security controls.

Credential handling

Privileged credentials, secrets and API keys should be restricted and rotated or revoked when access is no longer required.

No internet-connected system can be guaranteed completely secure. Users and customers also have responsibilities such as protecting passwords, enabling available security features and promptly reporting suspected compromise.

17 · YOUR RIGHTS

You may have rights relating to your personal data.

Rights depend on the applicable law, the nature of the information and Nimble's role in the processing.

Information & access

Request information about personal data associated with you and how it is processed where applicable.

Correction

Request correction or completion of inaccurate information.

Deletion

Request erasure where there is no continuing lawful or legitimate reason to retain the data.

Consent & communications

Withdraw consent where processing relies on consent, or ask to stop optional marketing communications.

Grievance

Raise a privacy concern or grievance relating to Nimble's handling of your personal data.

Account controls

Where a product provides settings for profile, permissions, exports or deletion, those controls may also be used.

18 · CHILDREN & MINORS

Some products may involve data relating to children, but access should be controlled by authorised adults and organisations.

The public Nimble Technology website is not intended as a general consumer service for children. Education products such as Skoler may, however, process information relating to students as part of a service provided to an authorised school or organisation.

Product-specific requirements for parental or guardian consent, school authority, age verification, data minimisation and legal compliance should be implemented where required by applicable law.

19 · RELATED TERMS

Copyright, refunds, development ownership and advertising guarantees belong in separate commercial terms.

These topics can involve data, but their primary rules should be defined in Nimble's Terms & Conditions, proposals, invoices or service agreements.

Copyright & ownership

Ownership of source code, designs, creatives, domain assets, customer-supplied material, licences, third-party software and final deliverables should be defined in the applicable project agreement or Terms & Conditions.

Payments & refunds

Deposits, milestones, recurring subscriptions, cancellation, non-refundable work, refunds and payment disputes should be governed by the relevant commercial terms rather than this Privacy Policy.

Development terms

Scope, revisions, acceptance, warranty, support, source-code transfer, third-party costs and change requests should be covered by the project or service terms.

Advertising policies

Ad approval, campaign performance, account suspension, platform limits and policy decisions are ultimately subject to third-party advertising platforms and should not be treated as guaranteed by Nimble.
Read Terms & Conditions

20 · CHANGES

This policy will evolve with the company, products and integrations.

Check the updated date

This document should be reviewed whenever Nimble launches a materially different product, introduces new tracking, advertising, payment, AI or data-processing technology, or changes how personal information is handled.

21 · PRIVACY CONTACT

Contact us about your information.

Privacy request or grievance

Use our Contact page and clearly mention that your request relates to privacy, access, correction, deletion, consent or another data-protection matter.

Contact Nimble

YOUR DATA

Have a question about your data or account access?

Contact Nimble and explain which website, product, service or project your privacy request relates to.

Contact us