Nebusis® Privacy Policy
Protecting your privacy across all business applications
Comprehensive data protection • Transparent practices • Your rights respected
Security by Design
Built-in privacy protections across all 23 applications
Global Compliance
GDPR, HIPAA, ISO standards alignment worldwide
Enterprise Security
AWS infrastructure with end-to-end encryption
Version 1.0
Effective Date: January 31, 2025
Last Updated: January 31, 2025
Questions about this policy?
Contact us through www.nebusis.com
At Nebusis®, we are committed to protecting your privacy and ensuring responsible data management across all our platforms and services. This Privacy Policy outlines how we collect, use, share, retain, and secure information across the Nebusis® Business Suite, NebuBot® platforms, with a particular focus on our primary platform, Nebusis® ComplianceOne, and includes coverage of NebuBot® (www.nebubot.com) and all NebuBot® specialized systems.
Coverage Scope
This policy applies to all Nebusis® applications, NebuBot® platforms, portals, websites, and services. Whether you're using our live ComplianceOne platform, NebuBot® systems, or any of our applications in development, the same privacy protections apply.
Our Privacy Principles
Your trust is essential. We design our services to follow international privacy laws and best practices, including transparency, accountability, purpose limitation, data minimization, and security-by-design.Applications and Coverage
This policy applies to the full suite of Nebusis® software-as-a-service (SaaS) platforms, including all 23 applications in our Business Suite, plus our website and customer portals.
Key Applications Covered:
- Nebusis® ComplianceOne (primary application)
- Nebusis® SmartBooks
- Nebusis® Engage
- Nebusis® CyberWatch
- Nebusis® LegalFlow
- Nebusis® ESG GreenCore
- Nebusis® PeopleCore
- Nebusis® PowerDocs
- Nebusis® PerformanceTracker
- Nebusis® ZappFormZ
- Nebusis® WizSpeek
- Nebusis® ControlCore
- NebuBot® (www.nebubot.com)
- NebuBot® Precision Care System™
- NebuBot® Precision Lab System™
- NebuBot® LIMS Genie™
And additional applications in development
- What We Collect
We collect various types of information depending on how you interact with us:
- User identifiers (names, roles, credentials)
- Organizational data (company name, location, certification status)
- Technical data (IP address, browser, device, telemetry)
- Behavioral data (usage patterns, access logs)
- Compliance content (policies, audit reports, documented procedures)
- Purpose of Data Use
We use your data to:
- Deliver, support, and optimize services like Nebusis® ComplianceOne
- Enable AI-powered compliance automation and reporting
- Customize user experience and interface interactions
- Support legal and regulatory obligations
- Improve product functionality and security
- Manage contracts, accounts, and subscriptions
We only process data for specific, legitimate purposes, based on legal grounds such as consent, performance of contract, or compliance with laws.
- Hosting and Cloud Infrastructure Security
Nebusis® relies on trusted third-party cloud providers such as Amazon Web Services (AWS) for hosting. These providers ensure:
- Encryption of data in transit and at rest
- Physical and digital access control
- Redundancy and availability monitoring
- Independent certification to international security standards (e.g., ISO/IEC 27001)
All data is logically separated, and administrative access is tightly restricted.
- Research and AI Model Development
With client authorization or using de-identified data, Nebusis® may analyze system usage to train AI models, enhance rule engines, and improve products like Nebusis® ComplianceOne, Nebusis® Engage, Nebusis® CyberWatch, and NebuBot® systems including NebuBot® Precision Care System™ and NebuBot® Precision Lab System™.
No identifiable information is ever used for machine learning without explicit permission.
- Industry-Specific Privacy Controls
Nebusis® solutions support regulated environments. For clients in healthcare, finance, government, or defense, we apply additional privacy safeguards aligned with:
- HIPAA
- ISO/IEC 27001
- ISO 42001
- GDPR
- Local regulatory requirements
- Global Data Transfers
Your data may be stored or processed outside your country. Wherever it resides, Nebusis® enforces consistent privacy protections, using appropriate mechanisms such as:
- Standard Contractual Clauses (SCCs)
- Data Processing Agreements (DPAs)
- Vendor audits and risk assessments
- Your Rights
Depending on your jurisdiction, you may have the right to:
- Access your personal or organization-related data
- Request correction of inaccuracies
- Request deletion or restriction of use
- Object to processing or withdraw consent
- Receive your data in a portable format
To submit a request, visit the Contact section of www.nebusis.com.
- Breach Response and Notification
In case of a suspected data breach, Nebusis® activates its incident response plan to:
- Contain the event
- Notify affected parties promptly (as required by law)
- Cooperate with regulatory authorities
- Apply remediation and root cause fixes
Applicant and Personnel Data
If you apply for a job, internship, or business relationship with Nebusis®, we collect application materials, background information, and interview notes solely for evaluation, hiring, or collaboration purposes.
Evaluation Purpose Only
Age Limitations
Nebusis® services are intended for business use by adults. We do not knowingly collect or process information from individuals under the age of 16.
Business Use Only
Cookies and Tracking Technologies
We use cookies and related technologies to:
- Keep users logged in securely
- Monitor application performance
- Understand visitor behavior on Nebusis.com
Users can manage cookie preferences through their browser or by adjusting settings on our website.
Retention and Data Disposal
We keep your data only as long as necessary for:
- Active contracts
- Legal compliance
- Audit trails
- Dispute resolution
Upon contract termination or user request, data may be deleted, anonymized, or returned, based on your preference and legal rights.
Updates to This Policy
We may update this Privacy Policy periodically. When we do, we will:
- Post a notice on www.nebusis.com
- Indicate the effective date at the top of this document
- Where required, provide direct notification through platform banners or messages
Your continued use of Nebusis® services indicates acceptance of the revised terms.
Contact and Inquiries
All questions or requests related to this Privacy Policy should be submitted via the Contact section of www.nebusis.com. This ensures secure and traceable handling by the appropriate team.
Quick Access
For privacy-related inquiries, use our secure contact form: