Skip to content
Nod
IntegrationsPricingPartners
ESEN
Log inGet started
OperationsCRM and pipelineEach contact, with its next step.Lead generationForms and landings that connect.Products and paymentsFrom the sale to the payment follow-up.Student PortalPrograms, resources and progress.AI ChatCheck your business data.
Nod AI Conversation inboxHistory, context and human control.
PlaybookYour offer, your criteria and your rules.SimulatorTest the conversation before approving.AI ManagementDecide when your team intervenes.AutomationsRespond to messages and comments.
IntegrationsStripeProducts, payments and subscriptions.Google CalendarCalls and calendar connected.Meta AdsCheck campaign performance.Calendly and Cal.comReservations associated with each contact. Security and privacy
See all features Let's talk about your business
Operations Nod AI
Features

Operations

CRM and pipelineEach contact, with its next step.Lead generationForms and landings that connect.Products and paymentsFrom the sale to the payment follow-up.Student PortalPrograms, resources and progress.AI ChatCheck your business data.

Nod AI

Conversation inboxHistory, context and human control.
PlaybookYour offer, your criteria and your rules.SimulatorTest the conversation before approving.AI ManagementDecide when your team intervenes.AutomationsRespond to messages and comments.
See all features
Integrations Pricing Partners Contact Log in
Legal and data

Privacy Policy

Last updated · 09/25/2026

Legal NoticePrivacy PolicyCookie PolicyTerms of ServiceData Processing Agreement (DPA)SubprocessorsGoogle API DisclosureData DeletionAcceptable Use PolicyCancellation and Refund PolicyAffiliate Terms

This Privacy Policy explains how WANDA LABS S.L. (“Nod”, “we”) processes personal data when you visit https://thenodai.com, when you contract or use the Nod platform on https://app.thenodai.com, when you participate in our affiliate program and when you connect the platform with third-party services such as Google, Meta, Calendly, Cal.com, Fathom, Commas or Stripe.

We have written it so that it is understood. If something is not clear, write to us at hello@thenodai.com.

Index

  • Who is responsible
  • To whom this policy applies and in what role we process the data
  • What data we process
  • What do we use them for and on what legal basis
  • Data obtained from third-party services that you connect
  • Google user data
  • Meta Platform Data
  • Who we share data with
  • International transfers
  • How long do we keep data
  • How we protect data
  • Your rights
  • Automated decisions and profiling
  • Minors
  • Commercial communications
  • Cookies
  • Data Deletion
  • Changes to this policy
  • Contact

1. Who is responsible

  • Responsible: WANDA LABS S.L.
  • NIF: B70618970
  • Address: Plaça Can Portabella 8, 08030, Barcelona
  • Contact email for privacy: hello@thenodai.com
  • General mail: hello@thenodai.com
  • Data Protection Officer: we have not currently designated a DPO. The internal Nod team, under the responsibility of WANDA LABS S.L., responds to privacy requests at hello@thenodai.com. This team does not act as a DPO.

2. To whom this policy applies and in what role we process the data

Nod is a software platform for training, consulting and service businesses. Each business that hires Nod (a "Client") has its own space, separate from the rest, where it manages its leads, its clients and students, its sales, its calls and its content.

We process personal data in two different roles:

a) As data controllers, for data from:

  • People who visit our website.
  • The Clients and the people who represent them: the contractor, the account owner and the members of their team who use the Platform.
  • Affiliates who enroll in our program.
  • People who write to us or request information.

b) As data processors, for the data that each Client enters, imports or receives in their space on the Platform about their own leads, clients, students and contacts. In that case, the data controller is the Client, who decides what data is stored and for what purpose, and Nod processes it solely on behalf of the Client, following its instructions, to provide the service. This relationship is regulated in our Data Processing Agreement (https://thenodai.com/data-processing-agreement).

If you are a lead, client or student of a business that uses Nod, the person responsible for your data is that business. To exercise your rights or resolve any questions, contact him. If you don't know how to contact him, write to us and we will help you send him your request.

3. What data we process

3.1 Website Visitors

  • Technical navigation data necessary to serve the website, such as the IP address, the browser and the pages visited, in the technical logs of the hosting provider.
  • The data you provide if you write to us: name, email and content of the message.
  • The cookies described in the Cookies Policy.

3.2 Clients and users of the Platform

  • Registration data: business name, account address, owner's name and email, contracted plan.
  • Account details: name, email, profile image, role and permissions of each user. Passwords are managed by our authentication provider and are stored so that no one can read them.
  • Billing information: name or company name, tax data that the Client enters and the subscription payment history. The charge is made by Stripe: Nod does not receive or store the complete card data.
  • Usage and technical data: records of activity necessary to provide, protect and maintain the service, such as automated jobs executed and their errors.
  • Communications: the messages you exchange with our support.

3.3 Affiliates

  • Name and email.
  • The businesses that have registered from your link and the commissions generated.
  • Your collection account identifier at Stripe. Identity and banking data are collected and managed directly by Stripe during account registration.

3.4 Data that Clients save on the Platform (as processors)

Depending on what each Client decides to use, it may include:

  • Identification and contact data of your leads, clients and students: name, email, telephone number and origin.
  • Tags, notes, stages of the business process and responses to forms, with their scores.
  • Sales, payment plans, subscriptions and receipts.
  • Scheduled calls, with the invited person and, if using Fathom, the link to the recording, summary and tasks.
  • Progress on training programs, support tickets and their attachments.
  • In the onboarding process, the name, identification document number and date of acceptance of the contract, and the copy of the accepted contract.
  • Records of sending emails and unsubscribes from commercial communications.
  • Data imported from the integrations that the Client connects (see section 5).

The Client is responsible for having a legal basis to process this data and for informing the interested parties.

4. What we use the data for and on what legal basis

PurposeDataLegal basis (GDPR)
Create and manage your account and provide you with the contracted serviceRegistration, account, useExecution of the contract (art. 6.1.b)
Collect subscription, issue invoices and comply with accounting and tax obligationsBillingExecution of the contract (art. 6.1.b) and legal obligation (art. 6.1.c)
Connect and operate the integrations you activateIntegrations data (section 5)Execution of the contract (art. 6.1.b), at your request
Send necessary service communications: account access, password recovery, payment notices, relevant changesAccountExecution of the contract (art. 6.1.b)
Respond to your queries and support requestsCommunicationsExecution of the contract (art. 6.1.b) or legitimate interest in responding (art. 6.1.f)
Maintain security, prevent fraud and abuse, and resolve incidentsUse and techniquesLegitimate interest (art. 6.1.f)
Manage the affiliate program and pay commissionsAffiliatesExecution of the contract (art. 6.1.b) and legal obligation (art. 6.1.c)
Send you commercial information about NodContactConsent (art. 6.1.a) or, if you are already a Client, legitimate interest in similar products (art. 21.2 LSSI-CE)
Formulate, exercise or defend claimsThe necessary onesLegitimate interest (art. 6.1.f)
Process the data that Clients save in their spaceSection 3.4On behalf of the Client, who is responsible (art. 28 GDPR)

We do not sell personal data. We do not use any Client's data, nor the data that its clients or students generate, nor the data from integrations, for advertising, to create our own commercial profiles or to train our own or third-party artificial intelligence models.

5. Data obtained from third-party services that you connect

Integrations are only activated when the owner or an administrator of a Client expressly decides so from the Integrations section of the Platform. We only ask for the permissions necessary for each feature. Keys and access tokens are stored encrypted with AES-256-GCM, used exclusively for the described function and never displayed again. Customer may disconnect any integration at any time. By disconnecting it we instantly delete your access credentials.

ServicePermissions we requestWhat data do we obtain?What do we use them for?
Google Calendar and Google Meetcalendar.events, openid, emailGoogle account email address; the events that the Platform createsCreate in the user's calendar the event of the calls that are scheduled in Nod, with their Google Meet link and invitation to the client; update or delete it if it changes or is canceled
Goal (Meta Ads)ads_read, business_managementOf the chosen advertising account: identifier, name, currency and status; campaigns, sets and ads (id, name, status, goal, budget and thumbnail); Daily metrics per ad (spend, impressions, clicks, shares, share value, and video views)Show the Client themselves the performance of their ads within their space. Read only
Calendlyusers:read, scheduled_events:read, scheduled_events:writeCalendly User; of each reservation, type of event, hours, status, link and name and email of the person bookingShow reservations on the Client's calendar and associate them with the contact; cancel a reservation or mark an absence when the user requests it
Cal.comPROFILE_READ, BOOKING_READProfile; of each reservation, title, hours, status, link and name and email of the person booking and the hostShow reservations on the Client's calendar and associate them with the contact
FathomAPI key provided by the ClientOf each recording: link, title, hours, guests, summary and tasksSave the link, summary and tasks of the call in the person's file. We do not obtain or save the full transcript or video
CommasAPI key provided by the ClientTransactions, refunds and subscriptions, with name and email of the buyer and productRecord the Customer's sales and subscriptions and provide access to what was purchased
Stripe (Customer account)Notice signing key and optionally secret keyCollections, refunds and subscriptions, with name and email of the customer and productRecord the Customer's income and, if requested, publish their products and payment links to their Stripe account
Resend (Customer account)API key provided by the ClientNoneSend the Client's emails from their own domain
SlackWebhook address provided by the ClientNoneSend notices to the channel that the Client indicates

Data from these services is only visible to the Customer who connected them and to users on their computer with permission. Each of these services also processes your data in accordance with their own privacy policies, which we recommend that you consult.

5 bis. voice cloning

This function deals with the recording you provide, the voice model created, the texts you want to convert into audio and the generated audios, exclusively to provide the cloning and voice generation that you request. The voice can identify and imitate a person and requires special care. The feature is not intended to uniquely identify a person through biometric recognition.

The creation and use of the voice will require the explicit consent of its owner. It may be withdrawn at any time, without affecting the legality of the previous treatment, and the deletion of the recording and the voice model may be requested. You can exercise these rights by writing to hello@thenodai.com; In the voice management of the account, you will also be informed how to do it from your settings.

If voice is part of the data that a Client provides for their business, that Client will be the data controller and Nod will act as processor following their instructions. When Nod determines the purposes and means of its own processing, it will act as responsible, in accordance with this policy. The intended supplier for cloning and generation is ElevenLabs Inc., as processor or subprocessor as applicable. Your intervention will be subject to the processing agreement applicable to providing the function.

The processing may involve transfers outside the European Economic Area. The ElevenLabs DPA contemplates standard contractual clauses and other applicable mechanisms; To provide the service, the contract, locations and effective guarantees will be verified. Exclusive residence in the European Union is not offered as a condition of this role. You can consult the ElevenLabs DPA and the list of Nod subprocessors.

The planned preservation of the recording and the model is linked to the active function. The withdrawal of consent, the deletion of the voice, the end of the subscription that enables it or the deletion of the account must result in the cessation of its use and its deletion in Nod and in the provider. The provision of the function requires validating the effective procedure and deadlines, including backups and legal exceptions. An immediate automatic deletion already available is not announced. The texts and audios generated will be subject to the general deadlines applicable to Client data and deletion requests.

The recording and the model will not be used to train general AI models or for purposes other than the requested service. Only necessary providers subject to applicable processing obligations will have access, including authorized subprocessors of the provider.

6. Google user data

This section specifically describes how we access, use, store and share Google user data. You have more details in https://thenodai.com/google-api-disclosure.

Google Workspace data and AI/ML models

The use and transfer of information received from Google APIs comply with the Google API Services User Data Policy, including Limited Use requirements. Google data is only used to create and delete calendar events you schedule on Nod. We do not use raw, aggregated or derived Google user data to develop, improve or train general AI or machine learning models, nor do we transfer it to third-party AI services.

  • What data we access: when you connect your Google account, we access your Google email address, through permissions openid and email, and the ability to create, modify and delete events on your calendar, using the permission https://www.googleapis.com/auth/calendar.events.
  • How we use them: only to create in your Google Calendar the event for each call you schedule in Nod, with its Google Meet link and the invitation to your client, and to update or delete it when you change or cancel it in Nod. Your Google Mail is used only to show you which account is connected. We do not read, analyze or save the rest of the events on your calendar.
  • How we store them: we store your AES-256-GCM-encrypted Google Account access token, and the event ID and Meet link of each call created from Nod, on servers located in the European Union.
  • Who we share them with: we do not share Google user data with third parties, except with the infrastructure providers that host the Platform, to the extent strictly necessary to provide the service, when required by law or with your express consent.
  • Limited use: Nod's use and transfer to any other application of information received from Google APIs is in compliance with the Google API Services User Data Policy, including limited use requirements. Specifically: (a) we only use this data to offer or improve user-visible functions on the Platform; (b) we do not transfer them to third parties except as permitted by that policy; (c) we do not use them for advertising, including personalized, interest-based or retargeting advertising; (d) we do not sell them; (e) we do not use them to determine creditworthiness or for lending purposes; (f) no one reads them except with your express consent, when necessary for security reasons, to comply with the law or in aggregated and anonymized form for internal operations; and (g) we do not use them to develop, improve or train generalized artificial intelligence or machine learning models.
  • Conservation and disposal: we keep the token as long as the integration is connected. By disconnecting it from Nod we eliminate the token instantly. You can also remove access at any time from https://myaccount.google.com/permissions. To also delete associated data, follow the instructions from https://thenodai.com/data-deletion.

7. Meta Platform Data

  • What data we obtain: When a user connects Meta Ads using the Facebook for Business login, we get read-only access to the ad account they choose, with the data described in section 5.
  • What we use them for: exclusively to show that Client, within their own space on the Platform, the performance of their campaigns and advertisements.
  • What we don't do: we do not create, modify, pause or delete ads, campaigns or budgets. We do not sell, license or transfer the data from the Meta Platform. We do not use them for advertising, to create profiles or to offer services to third parties. We do not share them with other Clients. We comply with the Meta Platform Terms and Meta Developer Policies.
  • Storage and security: the access token is saved encrypted with AES-256-GCM, and the imported data is saved in the Client space, separate from the rest.
  • Conservation and disposal: we retain this data as long as the integration is connected and the Customer's account is active. You can disconnect the integration from Nod or remove access from your Meta business portfolio settings. To request the deletion of data already imported, follow the instructions of https://thenodai.com/data-deletion. We delete it within a maximum period of 30 days and we confirm it to you.

8. Who we share the data with

We only share personal data with:

  • Suppliers who help us provide the service (subprocessors), with whom we have contracts that require them to process the data only following our instructions and with appropriate security measures: application hosting, database and file storage, payment processing and email sending. The updated list is at https://thenodai.com/subprocessors.
  • Third-party services that you connect, to the extent that the integration requires it and following your instructions (section 5).
  • Authorities, judges and courts, when there is a legal obligation.
  • A possible buyer or successor, in the event of a merger, acquisition or sale of assets, with the guarantees required by regulations and prior notice.

9. International transfers

We prioritize providers and regions in the European Union: the Platform's database and files are hosted in the European Union and the application is served from the Frankfurt region (Germany).

Some of our suppliers, or their parent companies, are based in the United States or other countries outside the European Economic Area, and may access data to provide their services, for example for support or sending mail. In these cases, transfers are covered by an adequacy decision of the European Commission, such as the EU-US Data Privacy Framework. for certified companies, or in the standard contractual clauses approved by the European Commission, together with complementary measures where appropriate. You can request more information at hello@thenodai.com.

10. How long do we retain data

DataConservation period
Client account and space detailsWhile the contract is in force
Space from a Customer whose subscription has ended or has not been paidIt is kept frozen for 90 days to allow reactivation. After this period, or sooner if the Client requests it, it is deleted within a maximum of 30 days.
Invoices and accounting data6 years from the last entry, in accordance with article 30 of the Commercial Code; longer only when required by a specific obligation or the defense of claims
Integrations CredentialsUntil the integration is disconnected, at which point they are instantly deleted
Data imported from integrationsWhile the account is active, or until the Client requests its deletion, which is done in a maximum of 30 days
Automatic job logs30 days
Record of cancellations of commercial communicationsAs long as necessary to respect the withdrawal
Affiliate dataWhile participating in the program and, thereafter, during the legal deadlines applicable to payments made
Contact and support queries and messagesUp to one year from the closing of the consultation, unless conservation is necessary due to a claim
BackupsDeleted data can remain in backup copies for up to 30 days, until overwritten, protected and without active use

When the term expires, the data is deleted or anonymized. They can be kept blocked during the statute of limitations of possible legal liabilities.

11. How we protect data

We apply technical and organizational measures appropriate to the risk, including:

  • Isolation by Client: each query to the database is filtered by the Client to which it belongs and, in addition, the database applies security policies at the row level.
  • Encryption: encrypted communications using HTTPS/TLS; integrations credentials encrypted with AES-256-GCM; passwords managed by a specialized authentication provider, which never stores them in the clear.
  • Access control: roles and permissions by area within each Client; Users only access what their role allows, and students only access their portal.
  • Private files: private documents are only served via signed temporary links.
  • Notice verification: notifications we receive from Stripe, Commas and Fathom are verified by your signature before being processed.
  • Link Protection: email unsubscribe links are signed and download vouchers are stored so that they cannot be reconstructed.
  • Least privilege: we only ask third-party services for the necessary permissions.
  • Incident management: in the event of a security breach, we will act in accordance with articles 33 and 34 of the GDPR and will notify the supervisory authority and, where applicable, the affected parties and the Clients.

12. Your rights

The internal Nod team, under the responsibility of WANDA LABS S.L., attends to these requests at hello@thenodai.com. Indicate “Privacy” in the subject. This channel does not imply the appointment of a data protection officer. The legal response time is different from the indicative time of general support.

You can exercise at any time, free of charge, the rights of:

  • Access: know what data we process about you.
  • Correction: correct inaccurate or incomplete data.
  • Deletion: ask us to delete your data.
  • Opposition: oppose certain treatments.
  • Limitation: request that we suspend treatment in certain cases.
  • Portability: receive your data in a structured and commonly used format.
  • Withdraw your consent when the treatment is based on it, without affecting the legality of the previous treatment.

To exercise them, write to hello@thenodai.com indicating the right you want to exercise. If we have reasonable doubts about your identity, we may ask you for additional information to confirm it. We will respond within one month of receipt. When the complexity or number of requests justifies it, the deadline may be extended up to two additional months; We will inform you of the extension and its reasons within the first month.

If you consider that we have not processed your data correctly, you can file a claim with the Spanish Data Protection Agency (https://www.aepd.es), C/ Jorge Juan, 6, 28001 Madrid.

If you are a lead, client or student of a business that uses Nod, remember that the person responsible for your data is that business (section 2).

13. Automated decisions and profiling

Nod does not make decisions based solely on automated processing that produce legal effects on individuals or similarly significantly affect them.

The Platform allows Customers to configure features such as response scoring on their forms or automation rules. These functions are defined and used by each Client, as responsible, to organize their own commercial activity. It is the Client's responsibility to inform the interested parties of this and guarantee its use in accordance with the regulations.

14. Minors

Nod is a professional service aimed at companies and professionals over 18 years of age. We do not knowingly collect data from minors under 14 years of age as controllers. Clients who use the Platform with students or minor clients are responsible for obtaining, when applicable, the consent of their parents or legal guardians, in accordance with article 7 of Organic Law 3/2018 (LOPDGDD).

15. Commercial communications

We will only send you commercial information about Nod if you have given us your consent or, if you are already a Client, about products or services similar to those contracted, in accordance with article 21 of the LSSI-CE. You can unsubscribe at any time with the link included in each communication or by writing to hello@thenodai.com.

The communications that Clients send to their own contacts from the Platform are the responsibility of each Client. The Platform includes an unsubscribe link in commercial communications and respects registered unsubscribes.

16. Cookies

We use cookies and similar technologies as explained in the Cookie Policy (https://thenodai.com/cookie-policy).

17. Data deletion

You can learn how to disconnect integrations, withdraw access granted to Nod, and request deletion of your data at https://thenodai.com/data-deletion.

18. Changes to this policy

We may update this policy to reflect changes to the Platform, the law, or our practices. We will publish the updated version with its date. If the changes are relevant, we will notify Clients by email or within the Platform with reasonable advance notice.

19. Contact

For any questions about this policy or your data: hello@thenodai.com · WANDA LABS S.L. · Plaça Can Portabella 8, 08030, Barcelona.

Nod AI · intended scope of treatment

The treatment of the complement is subject to the effective suppliers and contracts. The planned processing includes authorized messages from Instagram, identity of the interlocutors, contact details, playbook instructions, documents provided, simulations and execution records to provide the requested commercial assistance. The Client determines the purpose and legal basis regarding its contacts; WANDA LABS S.L. acts as manager following your instructions. Nod's account and billing management has its own purposes as the person responsible.

Minimization, access control, and the retention periods in this policy will apply. Inference providers, their locations and transfer guarantees must be identified in the list of subprocessors to provide the processing. It is not assumed that the data is processed exclusively in the European Union. The proposal does not authorize using Client data to train general models or clone voices without authorization.

U.S. residents

WANDA LABS S.L. is a Spanish company. This policy retains the protections of the GDPR and applicable Spanish law; rights under U.S. law apply in addition where the requirements of that law are met. The English version does not mean that data is hosted in the United States. Purposes, data categories, recipients, retention, and transfers are described in the preceding sections.

Depending on your state of residence, the processing involved, and applicable law, you may have rights to access, correct, delete, or obtain a portable copy of your personal information; to opt out of its sale, certain advertising uses, or certain profiling-based decisions; and to limit certain processing of sensitive information. These rights are subject to applicable legal exceptions. We will not discriminate against you in violation of law for exercising them.

To exercise a right, email hello@thenodai.com with your request and state of residence. We will verify identity and, where applicable, an authorized agent’s authority in a proportionate manner. We will follow the deadlines required by applicable law. If we deny a request, we will explain the reason and any applicable complaint or appeal options. Where the law provides an internal appeal, email the same address with the subject “Privacy appeal”; we will respond within the statutory deadline and identify the relevant authority where required.

If your data belongs to a business using Nod and we process it on that business’s instructions, the business is responsible for deciding on your request. You may contact it directly or email us so we can route the request in accordance with our obligations as a processor.

Nod

Your business.
One place.

Product

OperationsNod AIFeaturesIntegrationsPricingSecurity

Company

ContactPartnershello@thenodai.com+34 691 33 84 18

Legal

Legal NoticePrivacy PolicyCookie PolicyTerms of ServiceAcceptable Use PolicyCancellation and Refund Policy

Data

Data Processing Agreement (DPA)SubprocessorsGoogle API DisclosureData DeletionAffiliate Terms
ESEN
© 2026 Nod. All rights reserved.Designed for businesses that move forward.