🛡️ Legal Document

Privacy Policy

How we collect, use, and protect your data at Nuanso

Last updated: December 2025

1Introduction

This Privacy Policy explains how Nuanso ("we", "us", or "our") collects, uses, stores, and protects your personal data when you use our marketing analytics platform and related services. Nuanso is a Slack-native marketing analytics tool that delivers daily metric summaries and AI-powered insights to marketing agencies and their clients.

We are committed to protecting your privacy and complying with the General Data Protection Regulation (GDPR), the Belgian Data Protection Act of 30 July 2018, and all other applicable data protection laws.

2Data Controller

The data controller responsible for your personal data is:

Nuanso

Brusselsepoortstraat 134

9000 Gent, Belgium

KBO/BCE: 0714.916.229

Email: hello@nuanso.io

3Data We Collect

We collect and process the following categories of personal data:

3.1 Account Information

When you create an account or connect platforms, we collect:

  • Name and email address
  • Company/organization name
  • Slack workspace information (workspace ID, channel preferences)
  • Authentication tokens for connected platforms (encrypted)
  • Billing and subscription information

3.2 Marketing Platform Data

When you connect your marketing accounts, we access and store performance data from:

Meta Ads (Facebook/Instagram): Campaign performance metrics including spend, impressions, clicks, conversions, CTR, ROAS, and ad creative performance
Google Ads: Campaign performance data including spend, impressions, clicks, conversions, and quality scores
Google Analytics: Website traffic data, user behavior metrics, conversion data, and audience insights
LinkedIn Ads: Campaign performance data, spend, impressions, clicks, conversions, and engagement metrics
TikTok Ads: Campaign performance metrics, spend, impressions, clicks, conversions, and engagement data
Shopify: Store performance data, sales metrics, order data, product performance, and customer analytics

3.3 Onboarding and Context Data

During the onboarding questionnaire, we collect business context including:

  • Industry and business type
  • Marketing goals and KPIs
  • Target audiences and markets
  • Preferred metrics and reporting preferences
  • Notification and briefing schedule preferences

3.4 Usage and Technical Data

  • Log data (IP addresses, browser type, device information)
  • Feature usage and interaction patterns
  • Error logs and performance data
  • Slack interaction data (commands used, messages from our bot)

4How We Use Your Data

4.1 Service Delivery

Legal Basis: Contract Performance

  • Delivering daily marketing briefings via Slack
  • Generating AI-powered insights and recommendations based on your marketing data
  • Displaying performance dashboards and reports
  • Syncing and aggregating data from connected marketing platforms
  • Detecting anomalies and alerting you to significant changes in your metrics

4.2 Service Improvement

Legal Basis: Legitimate Interest

  • Analyzing usage patterns to improve our product
  • Debugging and fixing technical issues
  • Developing new features based on user needs

4.3 Communication

Legal Basis: Legitimate Interest / Consent

  • Sending service-related notifications and updates
  • Responding to support requests
  • Marketing communications (only with your consent)

4.4 Legal Compliance

Legal Basis: Legal Obligation

  • Complying with applicable laws and regulations
  • Responding to lawful requests from authorities
  • Maintaining records required by law

5AI Processing and Automated Decisions

Nuanso uses artificial intelligence (powered by OpenAI) to analyze your marketing data and generate insights and recommendations. This AI processing:

  • Analyzes performance trends and patterns in your connected marketing platforms
  • Generates actionable suggestions for improving campaign performance
  • Creates personalized briefings based on your business context and goals
  • Detects anomalies that may require your attention

Important: These AI-generated insights are recommendations only. They do not result in automated decisions that have legal or similarly significant effects on you. All marketing decisions remain under your control.

6Data Sharing and Third Parties

We do not sell your personal data.

We share data only with the following categories of recipients, as necessary to provide our services:

6.1 Service Providers (Data Processors)

  • Railway: Cloud hosting infrastructure (servers located in the EU/US)
  • PostgreSQL Database: Data storage (hosted via Railway)
  • OpenAI: AI processing for generating insights (data sent to US servers)
  • Slack: Delivery of briefings and notifications

6.2 Platform Integrations

We connect directly with the following platforms to retrieve your marketing data. No third-party intermediaries are used for these integrations:

  • Meta Platforms, Inc. (Facebook Ads, Instagram Ads)
  • Google LLC (Google Ads, Google Analytics)
  • LinkedIn Corporation (LinkedIn Ads)
  • TikTok Inc. (TikTok Ads)
  • Shopify Inc. (Shopify)
  • Slack Technologies, LLC (Slack)

These integrations use OAuth 2.0 authentication. You authorize access directly with each platform, and you can revoke access at any time through your platform settings or your Nuanso dashboard.

7International Data Transfers

Some of our service providers are located outside the European Economic Area (EEA). When we transfer your data outside the EEA, we ensure appropriate safeguards are in place:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • EU-US Data Privacy Framework certification (where applicable)
  • Adequacy decisions by the European Commission (where applicable)

8Data Retention

We retain your data for as long as necessary to provide our services and fulfill the purposes described in this policy:

Account data: Retained while your account is active and for 30 days after deletion request
Marketing platform data: Retained for up to 24 months for trend analysis, unless you request earlier deletion
AI-generated insights: Cached for 24 hours, regenerated when context changes
OAuth tokens: Retained while the connection is active. Deleted immediately upon disconnection
Log data: Retained for 90 days for debugging and security purposes

9Your Rights Under GDPR

Under the GDPR and Belgian data protection law, you have the following rights:

Right of Access: Request a copy of the personal data we hold about you
Right to Rectification: Request correction of inaccurate or incomplete data
Right to Erasure: Request deletion of your personal data ("right to be forgotten")
Right to Restriction: Request limitation of processing in certain circumstances
Right to Data Portability: Receive your data in a structured, machine-readable format
Right to Object: Object to processing based on legitimate interests or direct marketing
Right to Withdraw Consent: Withdraw consent at any time (where processing is based on consent)

To exercise these rights, contact us at hello@nuanso.io. We will respond within 30 days.

10Data Deletion

How to Request Deletion of Your Data

You may request deletion of your personal data at any time by:

  • Sending an email to hello@nuanso.io with the subject "Data Deletion Request"
  • Using the account deletion feature in your Nuanso dashboard
  • Disconnecting your platforms and requesting account closure

Upon receiving a valid deletion request, we will:

  • Delete your account data within 30 days
  • Delete all synced marketing platform data within 14 business days
  • Revoke and delete all OAuth tokens immediately
  • Confirm deletion via email

11Data Security

We implement appropriate technical and organizational measures to protect your personal data:

Encryption: All data is encrypted in transit (TLS 1.2+) and at rest (AES-256)
Access Controls: Strict access controls and authentication requirements
OAuth Security: Tokens are encrypted and stored securely. We never store your platform passwords
Infrastructure: Hosted on secure, SOC 2 compliant cloud infrastructure
Monitoring: Continuous security monitoring and logging
Incident Response: Documented incident response procedures

Data Breach Notification: In the event of a data breach affecting your personal data, we will notify you and the relevant supervisory authority within 72 hours as required by GDPR.

12Cookies and Tracking

Our website and dashboard use cookies and similar technologies:

Essential Cookies: Required for authentication and core functionality (no consent required)
Analytics Cookies: Help us understand how you use our service (with your consent)
Preference Cookies: Remember your settings and preferences

You can manage cookie preferences through our cookie banner or your browser settings.

13Slack Integration Specifics

When you install Nuanso in your Slack workspace:

  • We access only the channels you explicitly configure for receiving briefings
  • We do not read or store messages from your Slack workspace
  • We request only the minimum scopes necessary for delivering notifications
  • You can uninstall the app at any time from your Slack workspace settings
  • Upon uninstallation, all associated data is deleted within 14 business days

14Platform-Specific Data Usage

14.1 Meta (Facebook/Instagram Ads) Data

We use the Meta Marketing API to access your advertising data. Data from Meta is used solely to display your campaign performance in Nuanso dashboards and generate insights. We do not share your Meta data with any third parties except as necessary for AI processing (OpenAI) to generate recommendations. You can disconnect your Meta account and request data deletion at any time.

14.2 Google Data (Google Ads & Google Analytics)

We access Google Ads and Google Analytics data through Google's OAuth APIs. Your use of Google data through Nuanso is limited to displaying your own performance metrics and generating AI-powered insights. We comply with the Google API Services User Data Policy. We do not use Google data for advertising purposes or share it outside the scope of providing Nuanso services.

14.3 LinkedIn Ads Data

We access your LinkedIn Ads data through LinkedIn's Marketing API to display campaign performance metrics. This data is used exclusively within Nuanso to provide insights and is not combined with data from other sources for purposes unrelated to our service.

14.4 TikTok Ads Data

We access your TikTok Ads data through TikTok's Marketing API to display campaign performance metrics. This data is used solely for displaying your advertising performance and generating insights within Nuanso.

14.5 Shopify Data

We access your Shopify store data through Shopify's API to retrieve sales, order, and product performance metrics. This data is used to correlate your advertising performance with actual business outcomes and to generate insights. We do not access customer personal data beyond aggregated analytics. You can disconnect your Shopify store at any time.

14.6 Google API Services Limited Use Disclosure

Nuanso's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically, Nuanso:

  • Only uses Google user data to provide and improve user-facing features that are prominent in our application's user interface
  • Does not transfer Google user data to third parties unless necessary to provide or improve user-facing features, as required by law, or as part of a merger or acquisition with notice to users
  • Does not use Google user data for serving advertisements
  • Does not allow humans to read Google user data unless we have your affirmative consent, it is necessary for security purposes, to comply with applicable law, or our use is limited to internal operations with aggregated and anonymized data

15Children's Privacy

Nuanso is a business-to-business service intended for use by marketing professionals and agencies. We do not knowingly collect personal data from individuals under the age of 16. If we become aware that we have collected data from a child under 16, we will delete it promptly.

16Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by:

  • Posting the updated policy on our website with a new "Last Updated" date
  • Sending an email notification to your registered email address
  • Providing a notification in the Nuanso dashboard or via Slack

Your continued use of Nuanso after changes take effect constitutes acceptance of the updated policy.

17Complaints and Supervisory Authority

If you believe we have not handled your personal data properly, you have the right to lodge a complaint with the Belgian Data Protection Authority:

Gegevensbeschermingsautoriteit (GBA)

Drukpersstraat 35, 1000 Brussels, Belgium

Phone: +32 (0)2 274 48 00

Email: contact@apd-gba.be

Website: www.dataprotectionauthority.be

18Contact Us

For any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us:

✉️
🌐
📄

KBO/BCE

0714.916.229

📍

Location

Gent, Belgium