Skip to main content

Draft for early-access review

Privacy Notice

Last updated: July 20, 2026. This is a working draft, not a representation that a finalized operating entity, production service, or complete legal program is already in place. It must be reviewed and adopted before launch.

1. Current scope

This draft describes the public Nimble Suites website and its early-access request form. Product demonstrations are illustrative. Broader product data practices will require a deployment-specific notice, signed terms, and legal review before customer use.

2. Information submitted for access review

The access form may collect the following information that you provide:

  • Name and business email address
  • Company name and role
  • Team size and region
  • An optional description of the workflow you want to evaluate
  • Consent to receive a response about the request

The implementation also uses a request identifier to make retries safe. It does not intentionally persist raw bot-verification tokens or raw IP addresses in the access-request table.

3. Purpose

Submitted information is used to review early-access interest, respond to the requester, prevent duplicate submissions, protect the form from abuse, and maintain an operational record of the request. It must not be used for unrelated marketing without an appropriate notice and lawful basis.

4. Service providers in the proposed implementation

When configured, the form uses Neon for durable request storage, Resend for transactional notifications, Upstash for distributed rate limiting, and Cloudflare Turnstile for bot verification. Hosting and request logs may be processed by Vercel. Each provider processes information under its own terms and configuration. Production use is blocked until the required accounts, secrets, regions, retention choices, and agreements are approved.

5. Retention and deletion

A final retention schedule has not yet been adopted. Access-request records should be retained only for the review and follow-up period, then deleted or de-identified under the approved schedule. Deletion or access requests can be sent to the contact address below; identity may need to be verified.

6. Security and data minimization

The current code validates and bounds submitted fields, checks the request origin, verifies Turnstile server-side, applies distributed rate limits, uses idempotent database writes, and redacts raw verification material from persistence. These are technical controls, not a certification or guarantee that every risk has been eliminated.

7. International and regulatory considerations

The product is intended to support scoped US and European pilots, but no particular data-residency, transfer, GDPR, or sectoral-compliance outcome is promised by this draft. Those obligations depend on the selected deployment, contracts, subprocessors, customer role, and completed legal assessment.

8. Changes

This draft may change as the service, entity structure, vendors, and legal requirements are finalized. A production notice should identify its effective date and the responsible legal entity.

9. Contact

Privacy and data questions may be sent to sales@nimblesuites.com.