Security and privacy

Your business.
Your own space.

Understand who can access information, how connections are protected, and where you can exercise your rights.

Access according to responsibility

One space per business.
One access for each person.

The data of each business is logically separated. Team and student portal permissions define what information each person needs to work.

Your workspace

Team

Access to authorized areas according to their roles and permissions.

Students and clients

Access to their portal and the contents that correspond to them.

Other businesses

Independent spaces, separated by the business identifier.

Explanatory diagram of the access model.
Protection on every connection

What protects the information.

The measures are applied at different points of the service: the account, credentials, documents and connections with other tools.

Encrypted credentials

Integration accesses are saved encrypted with AES-256-GCM. Communications with the platform use HTTPS and passwords are managed by the authentication provider.

Permits by area

Each team member works with assigned permissions. Review those accesses when their responsibilities change or they stop collaborating with your business.

Private documents

Private files are served through signed temporary links. Share documents only with the people who should receive them.

Verified notices

Events received from Stripe, Commas, and Fathom are verified by their signature before being processed. A connected integration does not equal unlimited access.

Connections you control

You connect the services you need and you can withdraw your authorization. Disconnecting prevents new synchronizations; Deletion of already imported data is requested separately.

Location and providers

The Operations database is hosted in the European Union. Some providers may process data outside the EEA: see their functions and applicable guarantees in the list of subprocessors.

Your data, your requests

A clear channel
for privacy.

WANDA LABS S.L. handles requests through the internal Nod team. There is no designated data protection officer.

Contact privacy

If you have an account at Nod

Write to hello@thenodai.com indicating which right you want to exercise. We will only ask for additional identity information when necessary. The general response period is one month, with the legally provided extensions.

If you are a student or client of another business

That business decides what it uses your data for. You can address him; If we receive your request, we will help you process it as data processors.

If you want to delete information

Disconnecting an integration, canceling a subscription, and deleting data are different actions. Check the steps and retention periods before requesting closure.

How to request deletion
Scope of Nod AI

Assistance does not replace
your oversight.

The use of Nod AI requires identifying effective providers, authorized connections and treatment conditions. It does not imply that all data is processed exclusively in the European Union.

The intended processing includes authorized conversations, instructions and business documentation. The client must have a legal basis to use that data and review business instructions. Its use to train general models or clone voices without authorization is not authorized.

See each condition in detail.