Privacy Policy

Info Ops LLC, a California limited liability company, doing business as Nenbase.

1. Introduction

Info Ops LLC ("Nenbase," "we," "us") provides a customer relationship management and revenue-attribution platform. This Policy explains what personal information we collect, why, who we share it with, and the rights you have.

There are two very different roles at work here, and the distinction matters. Account Data is about you and your team — the people who sign up for and use Nenbase. For that, we are the controller: we decide why and how it is processed, and this Policy governs it. Customer Data is about your leads, contacts and customers — people whose data you bring into the platform. For that, we are the processor and you are the controller: we process it only on your instructions, and your privacy policy governs it.

If you are an End User — someone who filled out a form, booked a call, or was contacted by a business that uses Nenbase — we are not the company that decides how your data is used. That business is. Contact them directly, or see Section 16 and we will route your request to them. This Policy does not apply to third-party sites or services you connect or link to.

2. Definitions

"Personal Information" is information that identifies, relates to, or could reasonably be linked to an identifiable person. "Controller" is the party that determines the purposes and means of processing. "Processor" is a party that processes personal information on a controller's behalf and on its instructions. "Sub-processor" is a third party we engage to help process data. Account Data, Customer Data, End User, Integration and User carry the meanings given in Section 1 above and in Section 2 of the Terms of Service.

3. Information We Collect

Account Data, collected from you: identity and contact details (name, email, phone, job title, organization, and the account or sub-account you belong to); authentication data (password hashes — we never store passwords in plain text — session tokens and multi-factor settings); billing data (plan, billing address, tax identifiers, transaction history, and the last four digits and brand of your payment method — we never receive or store full card numbers, which go directly to Stripe); support correspondence; usage and device data (pages viewed, features used, actions taken, timestamps, IP address, browser and device type, operating system, referring URL); and integration credentials (OAuth tokens, API keys and webhook secrets, stored encrypted).

Customer Data, processed on your behalf: what this contains is your choice, but typically includes contact details submitted through your forms and funnels; attribution and tracking data such as UTM parameters, referrer, funnel and form identifiers, visitor identifiers, and the sequence of steps a person went through; appointment and call records including bookings, cancellations, no-shows, outcomes, end-of-call verdicts and notes your team enters; message and call content, including SMS and iMessage threads, call metadata, and where you have enabled it, call recordings and transcripts; payment and revenue records; and anything else you or your Integrations push into custom fields.

Do not use Nenbase to collect health information, biometric data, government identifiers, financial account numbers, precise geolocation, or information about children. The Service is not designed or certified for it.

We also receive data from Integrations you connect — contact and opportunity records from GoHighLevel, booking events from Calendly, payment events from Stripe, and message and call events from a connected messaging provider — because you authorized the connection. We do not buy personal information from data brokers, and we do not collect information about you from sources you have not connected or disclosed.

4. How We Use Information

Account Data, as controller, we use to create and administer your account and authenticate you; provide, maintain and support the Service; process payments and collect fees; send service and transactional messages such as security alerts and billing notices, which you cannot opt out of while you have an account; provide customer support; monitor, debug and secure the Service and prevent fraud; understand in aggregate how the Service is used in order to improve it; send marketing about our own products, only with your consent where required and with an opt-out at any time; and comply with law and enforce our Terms.

Customer Data, as processor, we use only to provide the Service as instructed — storing, organizing, deduplicating, enriching with attribution, displaying, and syncing it to Integrations you have connected — to maintain security and integrity, to provide support you request, and as required by law. We do not sell Customer Data, share it with other customers, use it for our own marketing, or use it to train generative AI models for use outside your Account.

We do not make decisions producing legal or similarly significant effects about End Users through solely automated means. The Service computes metrics and attributions; a human in your organization makes the decisions.

5. Data Retention

Account Data is kept for the life of the account, and for 12 months after closure before deletion or anonymization. Customer Data is kept until you delete it or the account terminates; after termination it is exportable for 30 days and deleted within 90 days. Backups expire on their own cycle within 180 days. Billing and tax records are kept for 7 years as required by law. Security and audit logs are kept for 12 months, and support correspondence for 24 months. Call recordings and transcripts are retained for 12 months and then automatically deleted, or sooner if you configure a shorter window or delete them yourself.

We may retain information longer where required by law, or where necessary to establish, exercise or defend legal claims, and only for that purpose.

6. Data Sharing and Disclosure

We do not sell personal information, and we have not sold or shared personal information for cross-context behavioural advertising in the preceding 12 months.

We disclose information to sub-processors who help us run the Service, bound by contract to confidentiality and to process only on our instructions: Supabase, for database, authentication and file storage, handling Account Data and Customer Data; Vercel, for application hosting, CDN and edge delivery, handling usage and device data; Stripe, for payment processing and subscription billing, handling billing data; and Resend, for transactional email delivery, handling name and email address. We use no third-party analytics, advertising, error-monitoring or session-replay services. If we add a sub-processor, we will update this list before it begins processing.

We also disclose data to Integrations you connect, at your direction — see Section 7. We may disclose information if required by law, subpoena or court order, or where we believe in good faith it is necessary to protect our rights or someone's safety; where legally permitted, we will notify you first so you can seek a protective order. If we are involved in a merger, acquisition, financing or sale of assets, information may transfer as part of that transaction, and we will notify you.

7. Third-Party Integrations

Nenbase is built to connect to other tools, currently including GoHighLevel, Calendly, Stripe, Discord, Slack, and connected messaging and voice providers. Connecting one authorizes us to read from and write to that service on your behalf, within the permission scopes you grant. Data sent to a third party is then governed by their privacy policy and terms, not ours, and we do not control what they do with it. You should review each provider's privacy policy before connecting.

You may disconnect an Integration at any time. Disconnecting stops future data flow but does not retrieve or delete data already sent to that provider — you must ask them directly. Where an Integration handles calls or messages, additional law applies to you, including consent to contact, do-not-call rules and call-recording consent. See Section 12.

8. Cookies and Tracking

On our own website and app we use strictly necessary cookies for authentication, session management, security and load balancing, which cannot be disabled because the Service will not work without them, and functional cookies that remember preferences such as theme and selected account. We currently use no third-party analytics service, no advertising cookies, no cross-site tracking, and no advertising pixels.

You can control cookies in your browser settings; blocking strictly necessary cookies will break sign-in. We honour Global Privacy Control signals.

Separately, the Service places identifiers on your forms and funnels in order to attribute a visitor's journey. That tracking happens on your properties, for your purposes, under your privacy policy and cookie notice — not this one. See Section 12.

9. Data Processing and Location

Our infrastructure and primary data storage are located in the United States. Sub-processors may process data elsewhere as described in their own documentation. We process personal information on your documented instructions, to provide the Service, and as required by law. If we believe an instruction violates data protection law, we will inform you.

10. Lawful Basis

Where data protection law requires a lawful basis, we rely on contract for providing the Service, billing and support; legitimate interests for security, fraud prevention and product improvement, balanced against your rights; consent for marketing communications, withdrawable at any time; and legal obligation for tax, accounting and legal retention. For Customer Data, you are responsible for establishing and documenting the lawful basis — see Section 12. Where we rely on legitimate interests, you may object by contacting jonas@nenbase.ai.

11. Data Minimization

We aim to collect only what the Service genuinely needs, keep it only as long as Section 5 provides, and limit internal access to personnel who need it for their role. We ask you to do the same: do not upload data you do not need, do not put sensitive categories into custom fields, and delete records you no longer have a reason to hold. Fields you do not fill are not invented or inferred by us.

12. Customer Responsibilities

If you are a Nenbase customer, this section matters more than any other. As the controller of Customer Data, you are legally responsible for having a lawful basis to collect and process every End User's data and to send it to us; publishing your own privacy policy on your funnels, forms and site, telling End Users what you collect, why, who you share it with including Nenbase as a processor, and how to exercise their rights; obtaining consent to contact before sending marketing SMS, iMessage, email or placing calls, and honouring opt-outs immediately; obtaining call-recording consent from every party in every jurisdiction involved before enabling recording, since many states and countries require all-party consent; providing cookie and tracking notice on your own properties for the attribution tracking the Service performs there; responding to End User rights requests, which we will assist with under Section 16 but which remain your obligation; keeping your account secure and removing Users who should no longer have access; and not uploading sensitive data as described in Section 3.

If you need a Data Processing Addendum, contact jonas@nenbase.ai.

13. Data Breach Notification

We maintain an incident response process. If we become aware of a breach leading to accidental or unlawful destruction, loss, alteration or unauthorized disclosure of or access to personal information, we will notify you without undue delay and in any case within 72 hours of becoming aware, where the breach affects your Account Data or Customer Data. Notice will describe what happened, the categories and approximate number of records affected, likely consequences, steps taken, and steps we recommend you take. We will not delay notice in order to complete our investigation.

Where we are the controller, we will notify supervisory authorities and affected individuals as law requires. Where you are the controller, that duty is yours, and we will give you the information you need to meet it. Report a suspected vulnerability or incident to jonas@nenbase.ai. We will not pursue legal action against good-faith security research that follows coordinated disclosure and does not access or exfiltrate other customers' data.

14. Data Security

We maintain administrative, technical and physical safeguards appropriate to the risk, including encryption in transit and at rest; row-level access control, so data is scoped per client account at the database layer and one account cannot read another's data; encrypted storage of integration tokens and API keys rather than plain text; role-based permissions and least privilege for internal access; audit logging of access and administrative actions; and regular patching and dependency updates.

No system is perfectly secure. We cannot guarantee absolute security, and you share responsibility: use strong unique passwords, enable multi-factor authentication, and revoke access promptly when someone leaves. We do not currently hold SOC 2, ISO 27001 or any equivalent third-party security certification, and we do not claim to.

15. International Transfers

The Service is currently offered to customers in the United States only, and information is stored and processed in the United States. If we begin offering the Service to customers in the European Economic Area, the United Kingdom or Switzerland, we will update this section to describe the transfer safeguards in place before doing so.

16. Your Privacy Rights

Depending on where you live, you may have the right to access a copy of the personal information we hold about you; correct inaccurate or incomplete information; have your information deleted; receive it in a portable, machine-readable format; restrict or object to certain processing; withdraw consent at any time without affecting prior processing; opt out of sale or sharing, which we do not do but the right stands; and not be discriminated against for exercising these rights.

To exercise them, email jonas@nenbase.ai. We will verify your identity before acting, usually by confirming control of the account email, and respond within 30 days, extendable by a further 60 where permitted with notice. There is no fee unless a request is manifestly unfounded or excessive. An authorized agent may submit a request on your behalf with written proof of authorization.

If you are an End User whose data sits in a Nenbase customer's account, we are the processor, not the controller. Contact the business that collected your data. If you contact us instead, we will forward your request to that customer and tell you we have done so, but we cannot decide it ourselves.

17. Privacy Controls

Marketing email carries an unsubscribe link in every message, or you can email jonas@nenbase.ai; transactional and security messages continue regardless. Cookies are controlled in your browser settings, as described in Section 8, and we honour Global Privacy Control. Integrations can be disconnected at any time in the Service. Account deletion can be requested at jonas@nenbase.ai, with retention following Section 5. Data export is available in the Service at any time.

18. Children's Privacy

The Service is a business tool not directed to anyone under 18, and we do not knowingly collect personal information from children. If we learn we have collected information from a child under 13, or under the applicable age of digital consent in your jurisdiction, we will delete it promptly. If you believe a child has provided us information, contact jonas@nenbase.ai. As a customer, you must not use Nenbase to collect information from children.

19. Changes to This Policy

We may update this Policy, and the date above always reflects the current version. For material changes — a new purpose, a new category of recipient, or a reduction in your rights — we will give at least 30 days notice by email to your account address or by prominent notice in the Service before the change takes effect. Where law requires consent, we will obtain it. Prior versions are available on request at jonas@nenbase.ai.

20. Dispute Resolution

If you have a concern about how we handle personal information, contact jonas@nenbase.ai first. We will acknowledge within 5 business days and aim to resolve within 30 days. If we cannot resolve it, disputes are handled as set out in Section 17 of the Terms of Service, subject to your right to complain to a supervisory authority and to any non-waivable right you have under local law to bring a claim in your own courts.

21. Contact Information

Info Ops LLC, 3623 Candor St., Lakewood, CA 90712, United States. Privacy requests and questions, security and incidents, and general support: jonas@nenbase.ai. The Service is currently offered in the United States only; we have not appointed an EU or UK representative or a Data Protection Officer, neither of which is required while that remains true.

22. Jurisdiction-Specific Information

California residents: categories of personal information collected in the past 12 months are identifiers, customer records, commercial information, internet and network activity, professional or employment information, and audio where call recording is enabled. Sources, purposes and recipients are described in Sections 3, 4 and 6. We do not sell personal information and do not share it for cross-context behavioural advertising, and we do not knowingly sell or share the personal information of consumers under 16. California residents have the rights in Section 16, plus the right to limit use of sensitive personal information; we do not use or disclose sensitive personal information beyond the purposes permitted under the CPRA. Under Shine the Light, we make no disclosures to third parties for direct marketing.

Other US states: residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana and other states with comprehensive privacy laws have rights substantially similar to those in Section 16, including the right to appeal a denied request. To appeal, reply to our decision with the word Appeal in the subject line and we will respond within 45 days with a written explanation. Nevada residents may opt out of the sale of covered information; we do not sell it, but you may submit a request to jonas@nenbase.ai.