1. Who We Are and What This Policy Covers
Numidia Analytics LLC (“Numidia,” “we,” “us” or “our”) is a Michigan limited liability company that provides Numidia, a business software platform for analytics, CRM, email campaigns, task management, meeting Planning Sessions and AI features (the “Service”).
This Privacy Policy explains how we collect, use, share and protect personal information when you visit our website, create or use an account, buy a subscription, or contact us, and how we handle personal information that our customers put into the Service. Capitalized terms not defined here have the meanings given in our Terms of Service.
The Service is designed for businesses. This policy does not apply to the privacy practices of our customers, who are responsible for their own handling of the personal information they collect and process using the Service.
2. Our Role: Controller and Processor
Numidia as processor. When our customers use the Service, they decide what data to put into it, such as CRM contacts, uploaded files, connected database results, email campaign recipient lists, tasks, and Planning Session recordings and transcripts (“Customer Data”). For Customer Data, the customer is the controller (or “business”) and Numidia is a processor (or “service provider”) that processes the data only on the customer’s behalf and instructions. If your personal information is in Customer Data, for example because a Numidia customer added you as a CRM contact or sent you an email campaign, please contact that organization to exercise your rights; if you contact us, we will forward your request to them where we can identify them.
Numidia as controller. Numidia is the controller (or “business”) for personal information we process for our own purposes: account and User profile information, billing and subscription information, information about how the Service and our website are used, communications with us, and marketing of our own Service.
3. Information We Collect
Information you give us:
- Account and profile information, such as your name, work email address, organization name, role, password (stored by our authentication provider in hashed form), team membership and preferences.
- Billing information, such as billing contact details, plan and subscription history and tax information. Payment card details are collected and stored by our payment processor, Stripe; we do not store full card numbers.
- Communications, such as support requests, emails, feedback and survey responses.
- Customer Data that you or your organization submit to the Service, as described in Section 2.
Information collected automatically:
- Usage and log information, such as pages and features used, actions taken, timestamps, AI credit consumption, error reports and performance data.
- Device and connection information, such as IP address, browser type and version, operating system, device identifiers, approximate location derived from IP address, and referring URLs.
- Information from cookies, local storage and similar technologies, as described in Section 8.
Information from third parties:
- If you sign in with Google or Microsoft, we receive basic profile information (such as your name and email address) from that provider, as permitted by your settings with them.
- If your organization connects an existing CRM or another Third-Party Service, we receive the records and account identifiers your organization authorizes us to import; this is Customer Data.
- Our payment processor gives us information about payment status and subscription events.
4. Microphone Audio, Recordings and Transcripts
The Service accesses your microphone only when you start a Planning Session recording or another dictation feature and your browser asks for, and you grant, microphone permission. You can stop a recording at any time and revoke microphone permission in your browser settings.
While a recording runs, audio is captured in segments and sent to our servers, where it is transcribed using our AI provider and then used to produce transcripts, summaries, action items, tasks and related records. Recordings, transcripts and the content generated from them are Customer Data, controlled by your organization.
Some browsers offer built-in live captions using the browser’s own speech recognition. Where available, the Service may use that browser feature to show captions while you speak; the browser vendor may process that audio under its own privacy terms.
You can also upload meeting transcript files instead of recording. Before recording or uploading any conversation, your organization must give every participant any legally required notice and obtain any legally required consent, as our Terms and Acceptable Use Policy require.
5. How We Use Information
We use personal information for which we are the controller to:
- create and manage accounts, authenticate Users and provide the Service;
- process payments, manage subscriptions and trials, meter usage and AI credits, and enforce plan limits;
- provide customer support and respond to requests;
- send service, security, billing and legal notices;
- monitor, maintain, secure, debug and improve the Service, including through error monitoring and product analytics;
- detect, prevent and respond to fraud, abuse, security incidents and violations of our Terms and Acceptable Use Policy;
- develop new features, using aggregated or de-identified information where possible;
- send information about our own products and services where permitted by law, with an opt-out in every marketing email; and
- comply with legal obligations and establish, exercise or defend legal claims.
We process Customer Data only to provide, maintain, secure and support the Service for the customer that controls it, as described in our Terms, and as required by law. We do not sell Customer Data and we do not use it for our own marketing.
6. Legal Bases for Processing (EEA, UK and Switzerland)
Where the EU or UK General Data Protection Regulation or similar law applies, we rely on the following legal bases for the processing we do as controller:
- Performance of a contract: to provide the Service, manage accounts and subscriptions, and provide support.
- Legitimate interests: to secure, maintain, analyze and improve the Service, prevent fraud and abuse, communicate with business contacts, and market our Service to business customers, where those interests are not overridden by your rights.
- Legal obligation: to keep financial records, respond to lawful requests and comply with law.
- Consent: for non-essential cookies and similar technologies where consent is required, and for marketing where the law requires consent. You can withdraw consent at any time without affecting processing before withdrawal.
For Customer Data, the legal basis is determined by our customer as controller.
7. AI Processing
AI features of the Service send the relevant Input, such as a question, selected records, a transcript or audio, to an AI model provider listed in Section 10 to generate Output. We send only what the feature needs.
We do not use Customer Data, Input or Output to train or fine-tune third-party foundation models. We use our AI providers’ business API services, under terms that do not permit the provider to use API Input or Output to train its models. Providers may retain Input and Output for a limited period to operate the service and monitor for abuse, according to their terms.
AI Output can be wrong. The Service does not use AI to make decisions that produce legal or similarly significant effects about you.
10. Subprocessors
We use the following third parties to host, operate and support the Service. They may process personal information, including Customer Data, on our behalf. We may update this list as our providers change.
- Supabase: database hosting, authentication and storage of account information and Customer Data. United States.
- Heroku (Salesforce, Inc.): application hosting, background job processing and related infrastructure. United States.
- Stripe: payment processing, subscription billing and the customer billing portal. United States.
- Postmark (ActiveCampaign, LLC): delivery of transactional emails and of email campaigns sent by customers. United States.
- OpenAI: AI model processing for AI features, including audio transcription. United States.
- Anthropic: AI model processing for AI features. United States.
- Nango: managing OAuth authorization and tokens for connections to third-party CRMs that customers choose to connect. United States.
- Sentry (Functional Software, Inc.): error monitoring and performance diagnostics. United States.
- PostHog: product analytics and feature flags. United States.
When you sign in with Google or Microsoft, or connect a Third-Party Service, that provider processes your information under its own privacy terms as an independent party, not as our subprocessor.
11. International Data Transfers
Numidia is based in the United States, and we and our subprocessors process information primarily in the United States. If you are located outside the United States, your information will be transferred to and processed in the United States and other countries whose data protection laws may differ from those where you live.
Where we transfer personal information from the European Economic Area, the United Kingdom or Switzerland, we rely on appropriate safeguards, such as the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum, or on our providers’ certifications under the EU-U.S. Data Privacy Framework and its UK and Swiss extensions where applicable.
12. Data Retention
We keep personal information only as long as we need it for the purposes in this policy:
- Account and profile information: for as long as the account is active, and then for the export and deletion period described below.
- Customer Data: for the customer’s Subscription Term and a 30-day export window after it ends, after which we delete or de-identify it from active systems within a commercially reasonable time; copies in backups are overwritten in the ordinary course of backup rotation. Customers can delete specific Customer Data during the Subscription Term.
- Billing and transaction records: for as long as required by tax, accounting and other legal obligations.
- Logs, error reports and analytics data: for the shorter of the period we need them and our providers’ retention periods.
- Information subject to a legal hold, dispute or investigation: until it is resolved.
13. Security
We use administrative, technical and physical safeguards designed to protect personal information, including:
- a SOC 2 compliance program;
- logical isolation of each customer’s data in its own database schema, enforced with row-level security policies;
- encryption of data in transit using TLS and encryption of data at rest, with additional application-level encryption for stored integration credentials;
- multi-factor authentication options for Users;
- role-based access controls and least-privilege access for our personnel; and
- error monitoring and logging to detect and respond to incidents.
No system is completely secure. If we learn of a security incident affecting your personal information, we will notify you and the relevant authorities where the law requires it. You are responsible for keeping your password secure; tell us immediately at help@numidia.io if you suspect unauthorized access.
14. Your Rights (EEA, UK and Switzerland)
If the GDPR, UK GDPR or Swiss data protection law applies to you, you have the right, subject to legal exceptions, to:
- access the personal information we hold about you and receive a copy;
- correct inaccurate or incomplete information;
- have your information deleted;
- restrict or object to our processing, including processing based on legitimate interests and direct marketing;
- receive your information in a portable format;
- withdraw consent at any time where processing is based on consent; and
- lodge a complaint with your local data protection authority.
To exercise these rights, email help@numidia.io. We will respond within the time the law requires, usually one month, and may need to verify your identity. For Customer Data, we will direct you to, or assist, the customer that controls it.
15. Your Rights (California and Other U.S. States)
If you are a resident of California or another U.S. state with a comprehensive privacy law, you may have the right, subject to legal exceptions, to:
- know the categories and specific pieces of personal information we collect, use and disclose, and the purposes;
- access, correct and delete your personal information;
- receive your information in a portable format;
- opt out of the sale or sharing of personal information, targeted advertising and certain profiling; and
- not be discriminated against for exercising these rights.
We do not sell personal information or share it for cross-context behavioural advertising, and we have not done so in the past 12 months. We do not use or disclose sensitive personal information for purposes that would give rise to a right to limit its use. We do not knowingly sell or share the personal information of anyone under 16.
In the past 12 months we have collected the categories of personal information described in Section 3: identifiers (such as name, email and IP address); commercial information (such as subscription history); internet and network activity; approximate geolocation; audio information (when Users record Planning Sessions); and professional information (such as organization and role). We collect them from the sources and use them for the purposes described in Sections 3 and 5, and disclose them for business purposes to the categories of recipients described in Sections 9 and 10.
To exercise your rights, email help@numidia.io. We will verify your request by matching information you provide with our records. You may use an authorized agent, who must provide proof of authorization. If we deny your request, you may appeal by replying to our decision, and we will respond within the time required by law.
16. If You Receive Email from a Numidia Customer
Our customers use the Service to send email campaigns from their own verified domains. If you receive such an email, the sending organization is responsible for having your contact details and for its use of them. Use the unsubscribe link in the email to stop receiving that organization’s campaigns, and contact that organization to exercise your privacy rights. We process delivery, open and unsubscribe events on the sender’s behalf to operate the Service and to honour unsubscribe requests. If you believe the Service is being used to send you spam, please tell us at help@numidia.io.
17. Children
The Service is intended for business use by adults and is not directed to children. We do not knowingly collect personal information from anyone under 18. If you believe a child has provided us with personal information, contact us at help@numidia.io and we will delete it.
18. Changes to This Policy
We may update this Privacy Policy from time to time. We will post the updated policy with a new “Last updated” date and, for material changes, notify account owners by email or through the Service before the changes take effect.
19. Contact Us
Numidia Analytics LLC is responsible for the personal information it controls. For questions, requests or complaints about this policy or our privacy practices, email help@numidia.io.