Nimply Logo

Data Processing Agreement

Last updated: Sep 11, 2026

This Agreement governs personal data that Nimply processes on your behalf when you use the service. It forms part of our Terms of Service and applies automatically — there is nothing to sign. Where you need a signed copy for your records, or your own DPA on your paper, write to privacy@nimply.io.

Our Privacy Policy covers the personal data we hold about you as our customer. This page covers the personal data you bring with you: your team, and the people in your audience who contact you.

1. Who is who

You are the controller of the personal data you put into Nimply or collect through it: your team members, your audience, and the records the People feature keeps about people who contact you. You decide why it is collected and what happens to it.

Nimply is the processor. We hold and process that data to provide the service, on your instructions, and for no purpose of our own. We do not sell it, we do not share it with other customers, and we do not use it to train AI models.

In this Agreement, “you” means the organisation that holds the Nimply account, and a “person” means an individual whose personal data you process through Nimply. “Applicable law” means the data protection law that binds you, including the UK and EU GDPR and the CCPA where they apply.

2. What we process, and why

Subject matter and duration. Processing lasts for as long as your account is open, plus the deletion period in section 8.

Nature and purpose. Hosting, storing, organising and displaying your content and conversations; publishing what you schedule; delivering and receiving messages through the social platforms you connect; generating drafts with AI at your request; and keeping the relationship records described in the People section of our Privacy Policy.

Categories of person. Your team members and collaborators; and members of your audience who contact you through a connected social account — people who comment on your posts, message you, mention you, or join a group you run.

Categories of personal data.

  • Account data: names, email addresses, roles and login identifiers for the people on your team.
  • Content: posts, captions, media and comments you create or schedule.
  • Conversations: the messages, comments and mentions exchanged between you and your audience on channels where you switched the inbox on.
  • Audience records: the platform account identifier, display name, username, profile link and avatar the platform gives us, plus the tags, notes, lead details, requests and consent records you add yourself.

We do not ask for and do not want special category data — health, beliefs, biometrics, and the rest. Do not put it into Nimply. If a person volunteers it in a message, treat it with the care your own law requires.

3. Your instructions

We process personal data only on your documented instructions. Your use of the product is the instruction: the channels you connect, the inboxes you switch on, the agents you configure, the retention window you set, and the exports and deletions you perform. We also process where a law we are subject to requires it, and we will tell you first unless that law forbids it.

If we believe an instruction breaks applicable law, we will say so rather than carry it out quietly.

You are responsible for having a lawful basis for what you collect, for the notice you give people (see section 9), and for honouring the choices they make.

4. Confidentiality and our people

Access to customer data is limited to the staff who need it to run and support the service, is bound by confidentiality obligations that survive their engagement, and is logged. Support staff access a workspace only to resolve a request or investigate an incident.

5. Security

  • Data is encrypted in transit with TLS and at rest by our hosting and database providers.
  • Platform access tokens are encrypted with a separate application key before they are stored, so a database copy alone does not grant access to your social accounts.
  • Access to production systems requires individual accounts and multi-factor authentication.
  • Every workspace is isolated: queries are scoped to a workspace, and membership and role are checked on every request.
  • Backups are taken by our database provider and restricted to the same team.
  • Changes reach production through review and an automated test suite.

Security is a moving target. We may change a specific measure, but not in a way that materially weakens the protection described here.

6. Sub-processors

We use the providers below to run the service. Each is bound by terms no less protective than this Agreement, and each processes only what its role requires.

  • Amazon Web Services — application hosting, file storage and transactional email (SES).
  • Supabase — database, authentication and file storage.
  • Cloudflare — content delivery, web application hosting and object storage.
  • SendGrid (Twilio) — transactional email, where configured.
  • Google Firebase — mobile push notifications.
  • Stripe — payments and subscription billing.
  • OpenAI, Anthropic and Google — AI generation, only for the content you send to be drafted, summarised or classified. None of these providers may train models on it.

The social platforms you connect — Meta, X, Google, TikTok, Telegram and the rest — are not our sub-processors. They are the source and destination of the data, and they act as controllers in their own right under their own terms.

We will give you notice before adding or replacing a sub-processor, by updating this page and emailing the account owner. If you object on reasonable data protection grounds within thirty days, tell us and we will look for an alternative; where there is none, you may end the affected part of the service.

7. Helping you answer people

The product is the first answer here. You can search, export and delete a person’s record yourself, at any time, without asking us. A deletion removes their record, their platform identities, notes, tags, timeline, consent records and leads; deletes what our AI agents remembered about them; redacts the agent runs that quoted their messages; and asks HubSpot to delete the contact where you synced one.

Where you cannot resolve a request with the product alone, we will help you within a reasonable time and at no charge for a reasonable volume. If a person comes to us directly, we will refer them to you, unless the law requires otherwise.

We will also help you with data protection impact assessments and prior consultations, to the extent the information is ours to give.

8. Retention, return and deletion

You choose how long audience records are kept: between six and thirty-six months, defaulting to twenty-four. Where a platform’s terms require a shorter period, the shorter period wins — YouTube and TikTok identities are held for thirty days unless the person interacts again. A nightly process enforces this without anyone asking.

You can export your data at any time while the account is open. When your account closes, we delete your workspace data within ninety days, except where a law requires us to keep something, in which case we keep only what that law requires and only for as long as it requires.

9. The notice you owe people

When you keep a record about someone who contacted you, most privacy laws expect you to tell them — in particular Article 14 of the UK and EU GDPR, which covers data you did not get from the person directly. Below is a plain-language notice you can adapt and publish. It is a starting point written by us for our own product, not legal advice; have your own adviser check it before you rely on it.

If you contact us on social media

When you comment on our posts, send us a message, mention us or join one of our groups, we keep a record of that conversation so we can answer you and remember what was already said. That record holds the account you contacted us from — your username, display name, profile link and picture as the platform shows them — the messages exchanged with us, and any notes or labels our team adds. If you give us contact details or ask us for something, such as a booking or a quote, we keep that too.

We use it to reply to you, to keep track of what you asked for, and to understand how people engage with us overall. Our lawful basis is our legitimate interest in answering the people who contact us and running our business, or the steps you asked us to take before entering a contract. We do not buy data about you, we do not add information you did not give us, and we do not use it to profile you.

The record comes from the social platform you used to contact us. We keep it for [YOUR RETENTION PERIOD] months after we last heard from you, and some platforms require us to delete their data sooner. Our social media tools are provided by Nimply, who process it on our behalf.

You can ask us for a copy of what we hold, ask us to correct it, ask us to delete it, or object to us keeping it at all — write to [YOUR CONTACT ADDRESS] and we will act on it. You can also complain to your data protection authority.

10. International transfers

Nimply operates from the United Arab Emirates and our providers operate globally, so personal data may be processed outside the country where you or the people in your audience live. Where we move personal data out of the UK or the EEA, we rely on the European Commission’s Standard Contractual Clauses and the UK Addendum, together with the measures in section 5. A copy of the clauses is available on request.

11. Incidents

If we become aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration or unauthorised disclosure of your personal data, we will tell you without undue delay and in any event within seventy-two hours of becoming aware. We will tell you what we know, what we are doing about it, and what we suggest you do — and keep telling you as we learn more. Reporting to a regulator or to the people affected is yours to do, since you hold the relationship with them.

12. Audits

On reasonable written notice, no more than once a year unless a regulator requires otherwise, we will provide the information needed to show we meet this Agreement, and answer a reasonable security questionnaire. Where that is not enough, we will agree a proportionate on-site or remote audit that does not compromise the confidentiality of other customers.

13. Changes and contact

We will update this page when the way we process data changes, and change the date at the top. Material changes are emailed to account owners.

Questions, signed copies, transfer clauses and privacy requests: privacy@nimply.io.