Legal
NitroStack Privacy Policy
Effective Date: August 17, 2026
Last Updated: August 17, 2026
Nitrostack Inc. ("NitroStack," "we," "us," or "our") respects your privacy and is committed to protecting Personal Data processed through our websites, applications, platforms, products, and services.
This Privacy Policy explains how NitroStack collects, uses, discloses, retains, and otherwise processes Personal Data in connection with the NitroStack platform, including NitroStack Studio, NitroStack Cloud (NitroCloud), NitroChat, NitroStack Composer, our websites, documentation, developer resources, and related services (collectively, the "Services").
Nitrostack Inc. is a Delaware corporation.
Registered Office:
16192 Coastal Highway
Lewes, Delaware 19958
United States
Business/Mailing Address:
14 NE 1st Avenue
Miami, FL 33132
United States
For privacy-related questions or requests, contact:
For general legal matters:
1. Scope of This Privacy Policy
This Privacy Policy applies to Personal Data that NitroStack processes:
- when you visit or interact with NitroStack websites;
- when you create or use a NitroStack account;
- when you use NitroStack Studio;
- when you use NitroStack Cloud or NitroCloud;
- when you use NitroChat;
- when you use NitroStack Composer;
- when you communicate with NitroStack or request support;
- when you participate in NitroStack events, programs, or other activities that link to this Privacy Policy; and
- when you otherwise interact with NitroStack in connection with the Services.
This Privacy Policy does not replace or supersede a Data Processing Addendum ("DPA") or other agreement governing NitroStack's processing of Personal Data on behalf of a business customer.
Where NitroStack processes Personal Data contained in Customer Data solely on behalf of a customer and according to that customer's instructions, the applicable customer agreement and DPA govern that processing. In those circumstances, the customer is generally responsible for determining the purposes and means of processing, while NitroStack acts as a service provider or processor, as applicable under applicable law.
Where NitroStack processes information for its own business purposes—for example, account administration, billing, security, service operation, support, or certain analytics—NitroStack may act as an independent controller or business, as applicable under applicable law.
2. Definitions
For purposes of this Privacy Policy:
"Personal Data"
"Personal Data" means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked to an identified or identifiable individual, or any equivalent term under applicable privacy law.
"Customer Data"
"Customer Data" means information, content, materials, data, configurations, code, prompts, files, records, credentials, conversations, workflows, or other information submitted to, stored in, transmitted through, or processed by the Services on behalf of a customer.
Customer Data may contain Personal Data.
"Usage Data"
"Usage Data" means information concerning the use, operation, performance, configuration, and interaction with the Services, including certain technical and operational information.
"Services"
"Services" means NitroStack's products and services covered by the applicable NitroStack Terms of Service or customer agreement, including NitroStack Studio, NitroStack Cloud/NitroCloud, NitroChat, and NitroStack Composer.
3. Information We Collect
The information NitroStack collects depends on how you interact with the Services.
We seek to collect only information reasonably necessary for the purposes described in this Privacy Policy.
3.1 Account and Registration Information
When you create or manage a NitroStack account, we may collect information such as:
- name;
- email address;
- organization or company name;
- account credentials;
- role or account information;
- account preferences;
- authentication information;
- organization membership and administrative information; and
- other information you provide when creating or managing an account.
If you use NitroStack as part of an organization, your organization's administrators may control or manage your access to the Services.
3.2 Billing and Transaction Information
If you purchase or subscribe to paid Services, we may collect information necessary to administer the commercial relationship, including:
- billing contact information;
- billing address;
- subscription information;
- plan information;
- usage and consumption information;
- invoices;
- transaction information;
- payment status; and
- other information necessary for billing and account administration.
Payment card information may be processed by third-party payment providers where applicable. NitroStack does not need to receive or retain complete payment-card information where such information is processed directly by the applicable payment provider.
4. Customer Data and Content
Because NitroStack is a developer and AI infrastructure platform, customers may submit or process a broad range of information through the Services.
Depending on how a customer configures and uses NitroStack, Customer Data may include:
- source code;
- application code;
- files and documents;
- prompts and instructions;
- AI conversations;
- AI-generated outputs;
- MCP servers;
- MCP tools;
- MCP resources;
- workflows;
- agent configurations;
- database information;
- API responses;
- application configurations;
- personal information;
- credentials;
- API keys;
- OAuth tokens;
- information from connected systems; and
- other application or configuration data.
Customers determine what information they submit to the Services.
NitroStack does not intentionally determine the purposes for which customers use Customer Data. Except as otherwise provided in the applicable agreement, NitroStack processes Customer Data primarily to provide, maintain, secure, support, and operate the Services in accordance with the customer's instructions.
Customers are responsible for ensuring that they have the legal rights, permissions, authorizations, and lawful bases required to submit and process Customer Data through the Services.
5. Information Collected Automatically
When you access or use the Services, NitroStack may automatically collect certain technical and operational information.
This may include:
- IP address;
- browser type;
- operating system;
- device information;
- approximate location derived from technical information where applicable;
- timestamps;
- access information;
- authentication events;
- session information;
- referring and exit pages;
- service interaction information;
- deployment and system information;
- error information;
- performance information;
- security events;
- usage information;
- resource consumption information; and
- other technical information reasonably necessary to operate and secure the Services.
We may combine automatically collected information with information associated with your account or organization.
6. Logs and Operational Information
NitroStack generates technical and operational logs as part of operating, securing, monitoring, and troubleshooting the Services.
Our current standard operational log retention period is 14 days, subject to:
- security requirements;
- legal obligations;
- incident investigation;
- backup processes;
- contractual requirements; and
- other circumstances where longer retention is reasonably necessary.
Certain information may be retained separately from standard operational logs where required for legitimate business, legal, security, billing, or compliance purposes.
7. Information Relating to Prompts, Conversations, and AI Outputs
NitroStack provides AI-powered functionality, including functionality that may process prompts, instructions, conversations, files, and other inputs to generate AI outputs.
Depending on the particular Service, configuration, and feature, information submitted for AI processing may be transmitted through NitroStack's AI infrastructure to the applicable model provider.
NitroStack's current AI infrastructure uses OpenRouter and may use other model providers or model-routing services in the future.
The model or provider used may depend on the model selected or configured by the user or customer.
Because the precise storage behavior of prompts and AI outputs can vary by product configuration and feature, NitroStack does not represent in this Privacy Policy that all prompts or outputs are either permanently stored or universally deleted immediately after processing.
Instead, applicable storage and retention practices may depend on the Service, feature, configuration, and technical implementation.
Where a feature provides conversation history, stored content may remain available to the relevant account or organization until deleted in accordance with the applicable Service functionality.
8. AI Model Providers
When you use AI functionality, NitroStack may transmit the inputs necessary to process your request to the applicable AI model provider.
For example, if a user selects a particular model, NitroStack may route the applicable request through OpenRouter or another applicable provider to the selected model.
The information transmitted may include the content necessary to generate the requested output, including prompts, instructions, and other data intentionally included in the request.
Important:
AI model providers are independent third parties.
Their handling of inputs and outputs may be subject to their own:
- privacy policies;
- terms;
- data-retention practices;
- security practices;
- model-training practices; and
- applicable contractual or technical configurations.
NitroStack does not represent that every third-party model provider has identical data-retention or model-training practices.
Accordingly, customers should review the applicable provider's terms and data practices when selecting a model or configuring AI functionality.
NitroStack may modify or add supported model providers as the Services evolve.
9. Customer Data Is Not Used to Train Generalized AI Models
NitroStack does not use Customer Data to train generalized artificial intelligence or machine-learning models.
This includes Customer Data such as:
- customer source code;
- customer documents;
- customer prompts;
- customer conversations;
- customer AI outputs;
- customer workflows;
- customer MCP configurations; and
- other Customer Content.
This restriction does not prevent NitroStack from processing Customer Data as necessary to provide the Services or from transmitting information necessary to a model provider when a customer invokes AI functionality.
It also does not prevent NitroStack from using properly aggregated or anonymized information that does not identify a customer, user, or individual, as described below.
10. Aggregated and Anonymized Information
NitroStack may create, derive, collect, and use aggregated, statistical, or appropriately anonymized information concerning the use and performance of the Services.
Such information may include:
- aggregate usage statistics;
- aggregate performance metrics;
- error rates;
- feature usage;
- system performance;
- reliability information;
- aggregate resource consumption;
- service trends; and
- similar operational metrics.
NitroStack may use such information to:
- operate the Services;
- monitor performance;
- diagnose problems;
- improve reliability;
- improve features;
- understand product usage;
- conduct analytics;
- improve the user experience; and
- develop or improve NitroStack's products and services.
NitroStack will not use Customer Data as a substitute for properly aggregated or anonymized information under this section.
11. How We Use Personal Data
Depending on the circumstances, NitroStack may process Personal Data for the following purposes:
11.1 Providing the Services
We process Personal Data as necessary to:
- create and administer accounts;
- authenticate users;
- provide access to Services;
- operate deployments;
- provide AI functionality;
- provide NitroChat functionality;
- process requests;
- facilitate integrations;
- provide customer support; and
- perform other activities necessary to provide the Services.
11.2 Account Administration
We may process Personal Data to:
- manage accounts;
- manage organizations;
- administer user roles;
- maintain account security;
- communicate with account administrators; and
- manage subscriptions and access.
11.3 Billing and Payments
We process information necessary to:
- calculate usage;
- administer subscriptions;
- process invoices;
- collect payments;
- identify payment issues; and
- maintain transaction records.
11.4 Security
We may process Personal Data and Usage Data to:
- authenticate users;
- detect suspicious activity;
- investigate security incidents;
- prevent abuse;
- protect accounts;
- protect infrastructure;
- investigate unauthorized access;
- enforce security controls; and
- protect NitroStack, customers, users, and third parties.
11.5 Service Operation and Improvement
We may process information to:
- monitor system performance;
- troubleshoot errors;
- diagnose technical issues;
- maintain infrastructure;
- improve reliability;
- understand feature usage;
- improve Services; and
- develop new functionality.
11.6 Communications
We may use Personal Data to communicate with you about:
- account activity;
- security matters;
- service changes;
- billing;
- support;
- operational notices;
- product-related information; and
- other communications reasonably related to the Services.
11.7 Legal and Compliance Purposes
We may process Personal Data to:
- comply with applicable laws;
- respond to lawful requests;
- respond to court orders, subpoenas, or other legal processes;
- establish, exercise, or defend legal claims;
- enforce agreements;
- investigate suspected violations;
- prevent fraud or abuse; and
- protect rights, property, safety, and security.
12. Legal Bases for Processing in the EEA and United Kingdom
Where applicable data protection laws require a lawful basis for processing, NitroStack may rely on one or more of the following:
Performance of a Contract
We may process Personal Data where necessary to enter into or perform a contract with you or your organization, including providing the Services.
Legitimate Interests
We may process Personal Data where necessary for our legitimate interests, provided those interests are not overridden by your rights and interests.
Our legitimate interests may include:
- operating and improving the Services;
- maintaining security;
- preventing fraud and abuse;
- providing customer support;
- administering accounts;
- communicating with customers;
- protecting our business and legal interests; and
- understanding aggregate Service usage.
Legal Obligation
We may process Personal Data where necessary to comply with legal or regulatory obligations.
Consent
Where applicable law requires consent, NitroStack may process Personal Data based on your consent.
Where processing is based on consent, you may withdraw consent as permitted by applicable law.
Withdrawal of consent does not affect the lawfulness of processing performed before withdrawal.
13. How We Share Personal Data
NitroStack may disclose Personal Data in the following circumstances.
13.1 Service Providers and Subprocessors
We may disclose Personal Data to third-party service providers that provide infrastructure or services necessary to operate NitroStack.
These may include providers supporting:
- cloud infrastructure;
- database infrastructure;
- AI/model processing;
- security;
- monitoring;
- communications;
- payments;
- technical operations; and
- other services necessary to operate the Services.
NitroStack currently uses infrastructure including Amazon Web Services (AWS) and MongoDB, and uses OpenRouter for AI model routing.
The actual providers used may change as the Services evolve.
Where required by applicable law, NitroStack will impose appropriate contractual obligations on service providers processing Personal Data on its behalf.
14. AI Model Providers
As described above, when you use AI functionality, NitroStack may transmit applicable inputs to the model provider necessary to process your request.
The relevant provider may process the transmitted information according to its own terms and privacy practices.
NitroStack does not control all practices of third-party model providers.
Customers should therefore consider the applicable model provider's policies before submitting confidential, sensitive, regulated, or personal information to an AI model.
15. Business Transfers
NitroStack may disclose Personal Data in connection with:
- a merger;
- acquisition;
- financing;
- restructuring;
- reorganization;
- sale of assets;
- bankruptcy;
- dissolution; or
- other corporate transaction.
Where required by applicable law, NitroStack will provide appropriate notice or obtain required consent.
16. Legal Requirements and Protection of Rights
NitroStack may disclose Personal Data when reasonably necessary to:
- comply with applicable law;
- respond to lawful government requests;
- comply with judicial proceedings;
- respond to subpoenas or court orders;
- enforce our agreements;
- investigate fraud;
- prevent security threats;
- protect NitroStack;
- protect customers;
- protect users; or
- protect the safety, rights, or property of any person.
We may also preserve information where reasonably necessary for these purposes.
17. Publicly Shared Content
Certain NitroStack functionality may allow users or organizations to make content publicly accessible.
Examples may include:
- publicly accessible deployments;
- public MCP servers;
- public applications;
- public URLs;
- shared configurations;
- publicly accessible NitroChat experiences; or
- other features that explicitly provide public-sharing functionality.
If you intentionally make content public, information contained in that content may be accessible to third parties.
You should not publish Personal Data, confidential information, credentials, API keys, authentication tokens, or other sensitive information through a public-sharing feature.
NitroStack is not responsible for information that a customer or user intentionally makes publicly accessible through the Services.
18. Organizations and Administrative Access
Where NitroStack is used by or on behalf of an organization, the organization's administrators may have the ability to:
- manage users;
- manage roles and permissions;
- control access;
- manage organization settings;
- administer subscriptions;
- access organization-controlled content or information; and
- remove or suspend user access.
If you use NitroStack through an organization, the organization may control your account and certain information associated with your use of the Services.
Questions concerning organization-controlled accounts should generally be directed to the relevant organization administrator.
19. Third-Party Integrations and Connected Systems
NitroStack enables customers to connect external systems, applications, databases, APIs, MCP servers, tools, and other services.
Customers may provide NitroStack with:
- API keys;
- OAuth tokens;
- credentials;
- access tokens;
- configuration information; or
- other authorization information.
Customers are responsible for:
- having the authority to connect the relevant system;
- obtaining required permissions;
- configuring appropriate access;
- complying with third-party terms;
- maintaining appropriate authorization;
- revoking credentials when necessary; and
- ensuring that connected systems are used lawfully.
Third-party systems are not controlled by NitroStack.
Their availability, security, privacy practices, functionality, and data handling may be governed by their own terms and policies.
NitroStack is not responsible for the independent privacy or security practices of third-party services.
20. International Data Transfers
NitroStack is a United States company and currently hosts its primary Services infrastructure in the AWS us-east-2 region in the United States.
Accordingly, Personal Data may be processed in the United States and in other countries where NitroStack or its service providers operate.
NitroStack does not currently provide a general geographic data-residency guarantee unless expressly agreed in writing with a customer.
Where applicable data protection law requires a lawful mechanism for transferring Personal Data across borders, NitroStack will use an applicable transfer mechanism, which may include:
- an adequacy decision;
- Standard Contractual Clauses;
- applicable contractual safeguards;
- other legally recognized transfer mechanisms; or
- another mechanism permitted by applicable law.
21. Data Retention
NitroStack retains Personal Data and other information only for as long as reasonably necessary for the purposes described in this Privacy Policy, including:
- providing Services;
- maintaining accounts;
- fulfilling contractual obligations;
- maintaining security;
- resolving disputes;
- enforcing agreements;
- complying with legal obligations;
- maintaining financial and business records;
- preventing fraud or abuse; and
- maintaining appropriate business records.
Current retention practices
NitroStack currently retains standard operational logs for approximately 14 days.
Certain account, Customer Data, configuration, billing, or other information may currently be retained for an extended or indefinite period while an account or customer relationship remains active, subject to applicable law and product functionality.
NitroStack may retain certain information after account termination where reasonably necessary for:
- legal obligations;
- dispute resolution;
- security;
- fraud prevention;
- accounting;
- compliance;
- backup and disaster recovery; or
- other legitimate business purposes.
22. Deletion
NitroStack uses different forms of deletion depending on the type of information and Service functionality.
Soft Deletion
Soft deletion may involve marking information as deleted and removing it from normal user visibility while retaining it temporarily in underlying systems.
Hard Deletion
Hard deletion involves permanently deleting information from the applicable production systems, subject to applicable backup, legal, security, or other legitimate retention requirements.
When an account is terminated or a customer requests deletion, NitroStack intends to delete applicable Customer Data within a reasonable period, subject to:
- applicable law;
- contractual requirements;
- legitimate security requirements;
- backup systems;
- legal holds; and
- other legitimate retention requirements.
Where a customer agreement or DPA establishes a specific deletion period, that agreement will control.
23. Security
NitroStack maintains technical and organizational safeguards designed to protect Personal Data and Customer Data against unauthorized access, loss, misuse, alteration, or disclosure.
Depending on the applicable Service, NitroStack's security architecture may include:
- encryption in transit;
- encryption at rest;
- authentication;
- OAuth;
- API keys;
- JWT-based security mechanisms;
- role-based access controls;
- access controls;
- monitoring;
- logging;
- security controls; and
- other administrative, technical, and organizational safeguards.
No method of transmission, storage, or security technology can guarantee absolute security.
Accordingly, NitroStack does not guarantee that Personal Data or Customer Data will be completely immune from unauthorized access, loss, misuse, or security incidents.
Customers are responsible for maintaining the confidentiality of their credentials and for configuring appropriate security controls within their own applications and connected systems.
24. Data Breach and Security Incidents
If NitroStack determines that a security incident has occurred that requires notification under applicable law or contractual obligations, NitroStack will take reasonable steps to investigate, contain, remediate, and notify affected parties as required by applicable law and applicable customer agreements.
Where NitroStack acts as a processor for a customer, notification and cooperation obligations will be governed by the applicable DPA or customer agreement.
25. Your Privacy Rights
Depending on where you live and applicable law, you may have rights concerning your Personal Data.
These rights may include:
- the right to know or access Personal Data;
- the right to request correction;
- the right to request deletion;
- the right to restrict processing;
- the right to object to certain processing;
- the right to data portability;
- the right to withdraw consent where processing is based on consent;
- the right to request information about processing;
- the right to lodge a complaint with a supervisory authority; and
- rights concerning automated decision-making or profiling where applicable.
Not every right applies in every jurisdiction or in every circumstance.
NitroStack may need to verify your identity before completing certain requests.
26. European Economic Area and United Kingdom Rights
If you are located in the European Economic Area or United Kingdom, you may have rights under applicable data protection laws including:
- access;
- rectification;
- erasure;
- restriction;
- objection;
- data portability;
- withdrawal of consent;
- objection to certain direct marketing; and
- rights relating to automated decision-making and profiling where applicable.
You may also have the right to lodge a complaint with the relevant data protection supervisory authority.
Where NitroStack processes Personal Data on behalf of a NitroStack customer, requests concerning that Customer Data may need to be directed to the relevant customer, which generally determines the purposes and means of processing.
NitroStack will provide reasonable assistance to customers where required under applicable law and the applicable DPA.
27. California Privacy Rights
If you are a California resident and applicable California privacy law applies to NitroStack's processing, you may have rights including, as applicable:
- the right to know what categories of Personal Information are collected;
- the right to access Personal Information;
- the right to request deletion;
- the right to request correction;
- the right to know categories of recipients and purposes of disclosure;
- the right to opt out of certain sales or sharing of Personal Information;
- the right to limit certain uses of Sensitive Personal Information where applicable;
- the right to non-discrimination for exercising privacy rights; and
- other rights provided by applicable California law.
NitroStack does not sell Personal Data for monetary consideration.
NitroStack does not intend to use Personal Data for cross-context behavioral advertising.
To exercise applicable California privacy rights, contact:
NitroStack may request information reasonably necessary to verify your identity and the legitimacy of your request.
Where permitted by law, an authorized agent may submit a request on your behalf.
28. Other U.S. State Privacy Laws
Residents of other U.S. states may have additional rights under applicable state privacy laws.
Depending on the applicable jurisdiction, these may include rights relating to:
- access;
- correction;
- deletion;
- portability;
- objection;
- opting out of certain processing;
- profiling;
- targeted advertising; and
- other legally protected interests.
NitroStack will process requests in accordance with the law applicable to the individual and the relevant processing activity.
29. India
Where applicable, NitroStack processes Personal Data relating to individuals in India in accordance with applicable Indian data protection and privacy laws.
Where the Digital Personal Data Protection Act, 2023 and applicable rules apply to NitroStack's processing, NitroStack will provide applicable notices and honor applicable rights and obligations as required by law.
Where NitroStack processes Personal Data on behalf of a customer, the relevant customer may be responsible for determining the purposes and means of processing and fulfilling obligations applicable to that customer.
30. Other Jurisdictions
NitroStack intends to operate globally and may process Personal Data of individuals in jurisdictions with different privacy laws.
Where applicable local law provides rights or protections that differ from those described in this Privacy Policy, NitroStack will comply with applicable legal requirements to the extent they apply to NitroStack's processing.
Nothing in this Privacy Policy is intended to limit rights that cannot lawfully be limited under applicable law.
31. Cookies and Similar Technologies
NitroStack may use cookies, local storage, session technologies, and similar technologies to:
- maintain sessions;
- authenticate users;
- remember preferences;
- secure accounts;
- understand use of the Services;
- measure performance;
- diagnose problems; and
- improve the Services.
Some technologies may be strictly necessary for the operation of the Services.
Where applicable law requires consent for non-essential cookies or similar technologies, NitroStack will request consent through appropriate mechanisms.
You may be able to control cookies through your browser or device settings. Disabling certain technologies may affect the functionality of the Services.
32. Analytics and Operational Monitoring
NitroStack may use internal and operational analytics to understand:
- service performance;
- reliability;
- errors;
- usage;
- feature adoption;
- infrastructure performance; and
- aggregate product trends.
We may use infrastructure and monitoring systems to operate and secure the Services.
Where information is aggregated or anonymized such that it no longer reasonably identifies an individual or customer, it may be used for legitimate business purposes consistent with this Privacy Policy.
33. Marketing Communications
NitroStack may send service-related communications that are necessary to operate an account or provide the Services.
Where permitted by applicable law, NitroStack may also send marketing communications concerning NitroStack products, events, or services.
You may unsubscribe from marketing communications by using the unsubscribe mechanism provided in the communication or by contacting NitroStack.
Unsubscribing from marketing communications does not prevent NitroStack from sending essential transactional, security, legal, or service-related communications.
34. Children's Privacy
The Services are designed for developers, businesses, organizations, and enterprise users.
The Services are not intended for individuals under 18 years of age.
NitroStack does not knowingly seek to collect Personal Data from children under 18 through the Services.
If you believe a child has provided Personal Data to NitroStack, please contact:
If NitroStack becomes aware that it has collected Personal Data from a child in circumstances where applicable law requires deletion, NitroStack will take appropriate steps to delete the information.
35. Automated Decision-Making and Profiling
NitroStack provides AI and automation infrastructure.
NitroStack does not intend to make decisions about individuals based solely on automated processing that produce legal or similarly significant effects on individuals for its own independent purposes.
Customers may use NitroStack to build applications that perform automated processing or decision-making.
Where a customer uses NitroStack for such purposes, the customer is responsible for determining whether applicable laws impose additional requirements and for configuring and operating its application accordingly.
36. Sensitive and Regulated Information
NitroStack is a general-purpose developer and AI infrastructure platform.
Customers should not submit highly sensitive or regulated information unless:
- the customer has determined that NitroStack is appropriate for the intended processing;
- the customer has satisfied applicable legal requirements;
- appropriate contractual arrangements are in place where required; and
- the customer has implemented appropriate safeguards.
Customers remain responsible for determining whether their intended use involves:
- special categories of Personal Data;
- health information;
- financial information;
- children's information;
- employment information;
- government identifiers;
- biometric information;
- regulated information; or
- other specially protected data.
Where applicable law or a separate customer agreement imposes additional requirements, those requirements will govern.
37. Intellectual Property and Customer Content
Nothing in this Privacy Policy transfers ownership of Customer Data or Customer Content to NitroStack.
Ownership and licensing of Customer Data and other content are governed by the applicable NitroStack Terms of Service or customer agreement.
NitroStack receives only the rights necessary to process information for the purposes described in the applicable agreement and this Privacy Policy.
38. Third-Party Websites and Services
The Services may contain links to or integrations with third-party websites, applications, APIs, services, or platforms.
NitroStack does not control the privacy practices of independent third parties.
Your interaction with third-party services may be governed by their own:
- privacy policies;
- terms;
- security practices; and
- data-processing practices.
You should review applicable third-party documentation before using those services.
39. Changes to This Privacy Policy
NitroStack may update this Privacy Policy from time to time.
Changes may be necessary because of:
- changes to the Services;
- changes to technology;
- changes to applicable law;
- changes to our business practices;
- changes to third-party providers; or
- other legitimate business reasons.
When we make material changes, we may provide notice through the Services, by email, or through other appropriate means where required by applicable law.
The "Last Updated" date at the top of this Privacy Policy indicates when it was most recently revised.
We will not materially expand the purposes for which we process Personal Data without providing any notice required by applicable law.
40. Contact Us
If you have questions about this Privacy Policy, our privacy practices, or the processing of Personal Data, contact us at:
Nitrostack Inc.
16192 Coastal Highway
Lewes, Delaware 19958
United States
Privacy: privacy@nitrostack.ai
Legal: legal@nitrostack.ai
For requests concerning Customer Data processed by NitroStack on behalf of a NitroStack customer, we may direct you to the relevant customer or organization administrator where that customer is the controller or business responsible for the processing.
41. Data Protection Addendum
Where NitroStack processes Personal Data on behalf of a customer as a processor or service provider, the parties may enter into or become subject to NitroStack's Data Processing Addendum.
The DPA governs matters including, as applicable:
- roles of the parties;
- processing instructions;
- confidentiality;
- security;
- subprocessors;
- international transfers;
- data subject requests;
- deletion and return of Customer Data;
- regulatory cooperation; and
- other processor obligations required by applicable law.
Where the DPA applies, it forms part of the agreement between NitroStack and the applicable customer.
If there is a conflict between this Privacy Policy and a DPA concerning NitroStack's processing of Customer Data on behalf of a customer, the DPA will control to the extent of that conflict.
42. Controller and Processor Roles
NitroStack may operate in different privacy roles depending on the processing activity.
NitroStack as Controller / Business
NitroStack generally acts as a controller or business when determining the purposes of processing information such as:
- account information;
- billing information;
- support communications;
- website usage information;
- security information;
- service-generated operational information; and
- certain analytics.
NitroStack as Processor / Service Provider
NitroStack generally acts as a processor or service provider when processing Personal Data contained in Customer Data on behalf of a customer according to the customer's instructions.
The applicable customer agreement and DPA determine the specific allocation of responsibilities.
43. No Absolute Security or Privacy Guarantee
Although NitroStack takes reasonable measures designed to protect information, no online service, cloud infrastructure, database, transmission method, or security control can guarantee absolute security.
You acknowledge that:
- internet transmissions may involve risks;
- third-party services may experience security incidents;
- connected systems may be outside NitroStack's control;
- customers are responsible for securing their own accounts and systems; and
- AI model providers and other third parties may have independent security and privacy practices.
NitroStack's security obligations are limited to those expressly stated in the applicable agreement, DPA, or other binding contractual commitment.
44. Severability of Privacy Rights
Nothing in this Privacy Policy is intended to:
- waive a right that cannot legally be waived;
- restrict a statutory privacy right;
- prevent an individual from exercising a legally protected right; or
- reduce NitroStack's obligations under applicable mandatory privacy laws.
Where a provision of this Privacy Policy conflicts with a mandatory requirement of applicable law, the mandatory legal requirement will apply to the extent of the conflict.
45. Governing Documents
This Privacy Policy should be read together with the other applicable NitroStack agreements, including:
- NitroStack Terms of Service;
- NitroStack Data Processing Addendum;
- applicable order forms or enterprise agreements; and
- applicable third-party service terms.
Where a customer has entered into a negotiated agreement with NitroStack, that agreement may establish additional privacy, security, processing, or data-handling obligations.
End of Privacy Policy
Nitrostack Inc.
16192 Coastal Highway
Lewes, Delaware 19958
United States
Privacy: privacy@nitrostack.ai
Legal: legal@nitrostack.ai