Nialli™ legal
Nialli Privacy Policy
Last Updated: July 24, 2026
Nialli Inc. ("Nialli," "we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, retain, and protect personal data in connection with our websites, portals, and digital properties (collectively, the "Sites"), and sets out your rights and choices.
This Privacy Policy should be read together with our Cookie Policy (https://www.nialli.com/legal/cookie-policy), our Data Processing Addendum (https://www.nialli.com/legal/dpa ), our Subprocessors List (https://www.nialli.com/legal/subprocessors) , and our Terms of Use (https://www.nialli.com/legal/terms-of-use), all of which form part of Nialli’s legal framework related to the Sites.
Nialli’s Roles
Nialli acts in different roles depending on context:
- Nialli as Controller: We act as a data controller when you visit or interact with the Sites; submit forms; download content; request demos; communicate with us; register for events; or when we collect professional contact information from public or third-party sources.
- Nialli as Processor/Service Provider: We act as a processor or service provider when our enterprise customers use Nialli products or cloud services and provide or store data for their own business purposes ("Customer Data"). In those cases, the customer is the controller, and our Data Processing Addendum (“DPA)” governs that processing: https://www.nialli.com/legal/dpa.
- Nialli as Controller (B2B datasets): We also act as a controller when we collect or process business contact information from public or third-party enterprise data sources for legitimate B2B sales and marketing purposes.
Key Definitions
"Personal Data" means any information relating to an identified or identifiable natural person. "Customer Data" means information submitted to or collected through Nialli enterprise services on behalf of a Nialli customer. "Controller" means an entity that determines the purposes and means of processing. "Processor" or "Service Provider" means an entity that processes personal data on behalf of a controller.
By using the Sites, you agree to this Privacy Policy. If you do not agree, please do not use the Sites. If your data is processed by Nialli on behalf of a Nialli enterprise customer, please contact that customer regarding your data rights.
1. Scope
Covered by this Policy
- Nialli.com and any subdomain or related web property displaying this Policy;
- Event registration pages and content download experiences;
- Marketing pages and pre-sales experiences;
- Chat tools, scheduling, and contact forms hosted on the Sites.
Not Covered by this Policy
- Nialli product software, Nialli Console, device firmware, or cloud services governed by separate agreements;
- Customer Data processed under a DPA;
- Third-party websites that link to or are linked from the Sites.
2. Information We Collect
2.1 Information You Provide Directly
- Contact and professional details: name, email address, phone number, job title, company name, industry, and geographic region;
- Form submissions: contact us, demo requests, pricing inquiries, content downloads, event registrations, and support requests;
- Chat interactions and meeting scheduling;
- Account or portal credentials (if applicable);
- Preferences, consent records, and communication opt-in/opt-out choices;
- Conversation data: free-text messages, questions, and information you share when interacting with the HubSpot AI Customer Agent on the Site. Conversation transcripts are processed by HubSpot on Nialli’s behalf and subject to HubSpot’s privacy and AI terms.
- Testimonials or case study participation (with your consent);
- Survey responses and feedback.
2.2 Information Collected Automatically
When you visit the Sites, we automatically collect:
- IP address and approximate geographic location derived from it;
- Device and browser type, operating system, screen resolution;
- Pages viewed, time on page, scroll depth, clicks, and navigation paths;
- Session duration, entry/exit pages, and referring URLs;
- UTM parameters and campaign attribution data;
- Cookie identifiers and advertising identifiers;
- Heatmap and interaction data (via tools such as Hotjar and Microsoft Clarity);
- Diagnostic and security log events.
2.3 Information from Third-Party Sources
- Authorized Nialli distributors, dealers, and resellers;
- Event platform operators;
- Public and professional directories (e.g., LinkedIn);
- B2B data enrichment and contact intelligence providers; and
- HubSpot Breeze Intelligence: an AI-powered data enrichment service that automatically researches and updates company and contact records in our CRM using third-party data sources. This means that if you are in our CRM, Breeze Intelligence may automatically append or update firmographic data (company size, industry, technology stack, revenue estimates) and contact data (job title, location) without you directly providing that information. See Section 16 for more detail on how this automated enrichment works and your rights in relation to it.
We use this data to update records, personalize communications, identify prospective customers, and enhance advertising relevance, consistent with applicable law.
2.4 Sensitive Personal Data
Nialli does not intentionally collect sensitive personal data (such as health information, racial or ethnic origin, political opinions, religious beliefs, or biometric data) through the Sites. Please do not submit such information through the Sites.
2.5 Children’s Data
The Sites are not directed to children under 16 years of age. We do not knowingly collect personal data from children under 16. If you believe we have inadvertently collected such data, please contact PrivacyOfficer@nialli.com so that we can promptly delete it.
3. How We Use Personal Data
3.1 Communications and Relationship Management
We use Personal Data to respond to your inquiries, schedule demos and meetings, deliver transactional and administrative notices, provide customer support, and maintain our relationship with you.
3.2 Providing and Operating the Sites
We use Personal Data to respond to create and manageaccounts, authenticate users, deliver features, secure access, perform technical operations, and provide the experiences you request. Customer Data processed through Nialli services is handled under the applicable DPA and customer instructions.
3.3 Improving the Sites and Services
We use Personal Data to respond to analyze usage patterns, performance metrics, feedback, and telemetry to improve features, content, design, and user experience.
3.4 Marketing and Advertising
We use Personal Data to respond to send marketing communications (where lawful and, where required, with your consent); personalize Site content and emails based on your interests; conduct retargeting campaigns; build custom, look-alike, and suppression audiences; measure attribution, conversion, and campaign performance. You can opt out at any time (see Section 8).
3.5 Security and Compliance
We use Personal Data to respond to detect, prevent, and investigate fraud, abuse, security incidents, and policy violations; enforce our Terms of Use; complyi with legal obligations and lawful requests; protect Nialli’s rights and the rights of others.
3.6 With Your Consent
We use Personal Data to respond to for any additional purposes that we describe when obtaining your consent. You may withdraw consent at any time; withdrawal does not affect the lawfulness of processing before withdrawal.
4. Legal Bases for Processing (EEA and UK)
Where Nialli processes personal data of individuals in the European Economic Area (EEA) or United Kingdom (UK), we rely on the following legal bases:
| Processing Purpose | Legal Basis (EEA/UK) |
|---|---|
| Responding to inquiries and providing services | Contract performance; Legitimate interests |
| Sending marketing communications (email) | Consent (EU/UK); Legitimate interests (elsewhere, where permitted) |
| Analytics and site performance measurement | Consent (EU/UK); Legitimate interests (elsewhere) |
| Advertising, retargeting, and audience building | Consent (EU/UK); Legitimate interests (elsewhere, with opt-out) |
| Account provisioning and authentication | Contract performance |
| Security, fraud prevention, and incident response | Legitimate interests; Legal obligation |
| Compliance with legal requirements | Legal obligation |
| Testimonials and case studies | Consent |
Where we rely on legitimate interests, we have balanced those interests against your rights and interests and determined that legitimate interests are not overridden. You may object to processing based on legitimate interests at any time (see Section 8).
5. How We Share Personal Data
5.1 Service Providers (Processors)
We share personal data with trusted service providers that process data on our behalf, including providers of CRM and marketing automation, analytics, advertising, cloud infrastructure and hosting, cybersecurity, support tools, and event platforms. These providers are contractually required to process data only on our documented instructions and to apply appropriate security measures. See our Subprocessors List: https://www.nialli.com/legal/subprocessors.
5.2 Channel and Business Partners
We may share data with authorized Nialli distributors, dealers, resellers, co-marketing partners, and event co-sponsors, where appropriate transparency and controls are in place.
5.3 Advertising Platforms
We may share hashed identifiers (e.g., hashed email addresses) with advertising platforms (Google, Meta, LinkedIn, Microsoft, and others) to enable retargeting, custom/look-alike audience building, suppression, and measurement, in compliance with platform policies and applicable law. We do not sell personal data.
5.4 Corporate Transactions
In the event of a merger, acquisition, restructuring, asset sale, or similar transaction, personal data may be transferred to the relevant successor entity, subject to the commitments in this Privacy Policy.
5.5 Legal and Safety Disclosures
We may disclose personal data to law enforcement, regulatory authorities, courts, or government bodies where required by applicable law, or to protect Nialli’s rights, property, or safety, or the rights, property, or safety of others. Where legally permitted, we will make reasonable efforts to notify you and challenge requests that appear to be unlawful or overbroad and to limit any disclosure to the minimum required. See also Section 14.
5.6 Aggregated and De-Identified Data
We may create, use, and share aggregated, anonymized, or de-identified data for research, product improvement, marketing analytics, and reporting. We will not attempt to re-identify such data where prohibited by applicable law.
6. International Data Transfers
Nialli is headquartered in Calgary, Alberta, Canada. Personal data collected through the Sites may be transferred to, processed, and stored in Canada, the United States, or other countries where our service providers operate. When we transfer personal data from the European Economic Area (the “EEA”), the United Kingdom (the “UK”), or Switzerland to countries without an adequacy decision, we rely on:
- EU Standard Contractual Clauses (2021 SCCs), incorporated by reference into our DPA;
- UK International Data Transfer Addendum to the EU SCCs;
- Swiss FDPIC-specific modifications where required;
- Supplementary technical and organizational measures where appropriate.
We will cooperate on transfer risk assessments as required. For more details on international transfer mechanisms, see our DPA: https://www.nialli.com/legal/dpa.
7. How We Store and Protect Personal Data
7.1 Security Measures
Nialli maintains administrative, technical, and physical safeguards designed to protect personal data against unauthorized access, disclosure, alteration, or destruction, including:
- Encryption of data in transit (TLS) and at rest where appropriate;
- Role-based access controls and multi-factor authentication;
- Centralized monitoring, logging, and anomaly detection;
- Secure software development practices and vulnerability management;
- Vendor due diligence and contractual security requirements;
- Business continuity and disaster recovery planning;
- Employee training and confidentiality obligations.
Nialli’s Information Security Management System is ISO 27001:2022 certified.
No transmission or storage system is completely secure. If you believe your personal data has been compromised, please contact PrivacyOfficer@nialli.com promptly.
7.2 Data Retention
We retain personal data only for as long as necessary to fulfill the purposes described in this Policy and to meet our legal, contractual, and business obligations. Typical retention periods:
| Data Category | Typical Retention Period |
|---|---|
| Marketing contacts and preferences | Until opt-out or inactivity; generally 24–36 months |
| Analytics and behavioral data | Per tool configuration; generally 14–26 months |
| Support and service records | 2–3 years from last interaction, unless subject to legal hold |
| Account/portal data | Duration of services plus limited backup/archive windows |
| Event registration data | 12–24 months following the event |
| Customer Data (processor role) | As instructed by Customer; per DPA |
| Legal/compliance records | As required by or advisable under applicable law (may exceed above periods) |
After retention periods expire, we will securely delete or anonymize personal data, unless retention is required by or advisable under applicable law.
8. Your Privacy Rights and Choices
Depending on your location, you may have the following rights with respect to your personal data:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate or incomplete personal data.
- Deletion: Request deletion of your personal data, subject to applicable legal exceptions.
- Restriction/Objection: Object to or request restriction of certain processing, including processing based on legitimate interests or direct marketing.
- Portability: Request your personal data in a structured, machine-readable format (EEA/UK).
- Withdraw Consent: Withdraw consent at any time for processing based on consent; withdrawal does not affect prior processing.
- Opt Out of Targeted Advertising/“Sharing”: Opt out of interest-based advertising and cross-context behavioral advertising (see Section 9 for California-specific rights).
- Non-Discrimination: Exercise your rights without discriminatory treatment.
- Lodge a Complaint: Lodge a complaint with a supervisory authority (EEA/UK).
How to Exercise Your Rights
To exercise your rights contact: PrivacyOfficer@nialli.com. Please describe your request clearly, including your name, contact information, and the nature of your request. We may need to verify your identity before fulfilling your request. We will respond consistent with applicable law and timelines (e.g., within 30 days for GDPR; 45 days for CCPA).
If your personal data is processed on behalf of a Nialli enterprise customer: Please contact that customer directly regarding your data rights. Nialli will assist the customer as required under the DPA.
Right to appeal: If Nialli does not fulfill a request, you may appeal by contacting PrivacyOfficer@nialli.com and indicating that you wish to appeal the decision.
9. California Privacy Rights (CPRA)
If you are a California resident, you have rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA):
- Right to Know: The categories and specific pieces of personal information we collect, use, disclose, and “share.”
- Right to Deletion: Request deletion of personal information we have collected, subject to exceptions.
- Right to Correction: Request correction of inaccurate personal information.
- Right to Opt-Out of “Sharing”: Opt out of the “sharing” of personal information for cross-context behavioral advertising.
- Right to Limit Use of Sensitive Personal Information: Nialli does not use sensitive personal information for purposes that require a right to limit under CCPA/CPRA.
- Right to Non-Discrimination: You will not be discriminated against for exercising your CCPA/CPRA rights.
To exercise your rights, submit a request to: Email PrivacyOfficer@nialli.com or use the contact information in Section 16. We will verify your identity before processing the request. Authorized agents may submit requests on your behalf but we require proof of authorization.
Right to Appeal: If we do not take action on your request, you may appeal by emailing PrivacyOfficer@nialli.com. We will respond within 60 days.
California Privacy Rights Notice for Personnel/B2B Contacts: California residents whose data is processed solely in the B2B context may have different rights. Contact PrivacyOfficer@nialli.com for details.
10. Cookies and Similar Technologies
We use cookies, pixels, tags, scripts, and local storage for essential functionality, analytics, personalization, advertising, and attribution. Our Cookie Policy provides full details:
Cookie Policy: https://www.nialli.com/legal/cookie-policy
When you first visit nialli.com, you will see a cookie consent banner allowing you to accept all cookies, reject non-essential cookies, or manage your preferences by category. If you are in the EU, EEA, UK, or Switzerland, the banner defaults to opt-in: no non-essential cookies will be set unless you grant consent, consistent with Google Consent Mode v2 requirements.
You can manage, update, or withdraw your cookie preferences at any time by:
- Using our cookie preference controls on the Site (where available);
- Clearing your browser cookies to trigger the consent banner again;
- Adjusting browser or device settings;
- Using industry opt-out tools at aboutads.info/choices, optout.networkadvertising.org, or youronlinechoices.eu; or
- Emailing PrivacyOfficer@nialli.com.
11. Third-Party Integrations
We use and embed tools from third-party providers whose own privacy policies govern their collection and use of data. Key integrations include:
- Google Analytics and Google Ads: Website analytics, ad performance, and remarketing.
- Google reCAPTCHA: Bot and fraud prevention for form submissions. Subject to Google’s Privacy Policy and Terms of Service.
- HubSpot: CRM, marketing automation, forms, live chat, and AI Customer Agent. The HubSpot AI Customer Agent is an AI-powered conversational assistant deployed on nialli.com. It processes conversation transcripts in real time to respond to visitor enquiries. Conversation data is transmitted to and stored by HubSpot; see Section 16 and our Subprocessors list for details.
- Hotjar and Microsoft Clarity: Behavioral analytics, heatmaps, and session recordings.
- LinkedIn, Meta, Microsoft Advertising, X (Twitter): Advertising measurement and audience targeting.
- Wistia: Video hosting and playback analytics.
- OnceHub/ScheduleOnce: Demo and meeting scheduling.
For ad choices, use your account settings on each platform, or industry tools such as NAI (networkadvertising.org), DAA (aboutads.info), or YourOnlineChoices (youronlinechoices.eu).
12. Do Not Track and Global Privacy Control
Our Sites do not currently respond to browser-level “Do Not Track” (DNT) signals. However, we make reasonable efforts to respect recognized Global Privacy Control (GPC) signals where technically feasible, consistent with applicable law.
You can control cookies and advertising preferences through our cookie banner, browser settings, and the opt-out mechanisms described in Sections 8 and 10.
13. Subprocessors
Our Subprocessors List identifies the third-party service providers that process personal data collected through nialli.com: https://www.nialli.com/legal/subprocessors. This list is updated when material changes are made.
Nialli uses HubSpot as a key processor. HubSpot may use its own subprocessors; HubSpot’s subprocessor list is published by HubSpot directly.
14. Government and Law Enforcement Requests
If Nialli receives a legally binding request for disclosure of personal data from law enforcement, regulators, or government authorities, we will, to the extent permitted by law:
- Notify you of the request (unless prohibited from doing so);
- Limit disclosure to what is legally required;
- Challenge requests that appear unlawful, overbroad, or disproportionate.
We will comply with court orders and legal requirements as applicable.
15. Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes in our practices, technologies, legal requirements, or for other operational reasons. We will post the updated version with a revised “Last Updated” date. Where changes are material, we will provide additional notice where required by applicable law (e.g., by posting a prominent notice on the Sites or sending a direct communication).
Your continued use of the Sites after the updated Privacy Policy is posted constitutes acceptance of the updated terms. We encourage you to review this Policy periodically.
16. Automated Processing, AI, and Profiling
16.1 How Nialli Uses Automated Processing and AI
Nialli and its service providers may use automated processing, machine learning, and artificial intelligence ("AI") technologies in connection with the Sites and services. Current and anticipated uses include:
- Behavioural analytics and segmentation: automated analysis of how visitors interact with the Sites to identify patterns, group audiences, and personalize content or advertising (e.g., via HubSpot, Google Analytics, Hotjar, and Microsoft Clarity);
- Marketing automation: automated scoring, sequencing, and routing of communications based on engagement signals, contact attributes, and inferred interests;
- Fraud and bot detection: automated analysis of form submissions, traffic patterns, and behavioural signals to identify and block malicious or non-human activity (e.g., via Google reCAPTCHA and Cloudflare);
- AI-assisted and AI-agent features: Nialli uses HubSpot Breeze, a suite of AI-powered tools, across its Sites and CRM platform. Active Breeze components and their functions include: (i) Breeze Customer Agent – an AI-powered chat assistant on nialli.com that responds to visitor enquiries in real time (the chat widget identifies itself as an AI); (ii) Breeze Copilot – an AI assistant embedded in HubSpot that helps Nialli’s team draft emails, summarise contact records, and suggest next actions, operating on CRM data; (iii) Breeze Intelligence – an AI data enrichment service that automatically researches and updates company and contact records using third-party data sources, including firmographic and contact data from external providers (see Section 2.3); (iv) Breeze Content Agent – AI-assisted drafting of blog posts, landing pages, and marketing content by Nialli’s team (does not process visitor personal data directly); (v) Breeze Social Agent – AI-assisted scheduling and publishing of social media content (does not process visitor personal data directly); (vi) Breeze Prospecting Agent – AI-assisted research on prospects and drafting of outreach communications, drawing on CRM data and publicly available sources. Where Breeze tools interact with your personal data, this is disclosed in the relevant subsection of Section 16 and our Subprocessors list;
- Security monitoring: automated detection of anomalous access patterns, potential security incidents, and policy violations.
16.2 Profiling and Automated Decision-Making
Some of the automated processing described above constitutes “profiling” as defined under the GDPR and UK GDPR – that is, automated processing of personal data used to evaluate, analyse, or predict aspects of your behaviour, interests, or characteristics.
Nialli does not currently make solely automated decisions that produce legal or similarly significant effects on individuals. If this changes, we will update this section, provide appropriate notice, and implement the safeguards required by applicable law.
If you are in the EEA or UK, you have the right to: (a) obtain information about any profiling Nialli conducts on your personal data; (b) request human review of any automated decision that produces a legal or similarly significant effect on you; and (c) object to profiling for direct marketing purposes. To exercise these rights, contact PrivacyOfficer@nialli.com.
16.3 AI and Personal Data – Our Commitments
Nialli commits to the following principles in its use of AI and automated processing:
- No training on Customer Data without consent: Nialli will not use Customer Personal Data (as defined in our DPA) to train, fine-tune, or improve AI models without the explicit prior written consent of the relevant Customer. This applies to both Nialli’s own AI systems and those of our Subprocessors.
- No training on Site visitor data without disclosure: Nialli will not use personal data collected through the Sites to train AI models without updating this Privacy Policy to reflect that use and, where required, obtaining your consent.
- Transparency: Where AI systems materially affect how we interact with you or process your data, we will disclose this at the relevant point of interaction.
- Human oversight: Nialli maintains human oversight of AI systems that process personal data, and periodically reviews AI outputs for accuracy, fairness, and compliance.
- Vendor accountability: We require our AI-capable Subprocessors to maintain equivalent commitments regarding the use of personal data for AI training and to comply with applicable AI regulations.
16.4 Third-Party AI Features
Certain Nialli Subprocessors offer AI-powered features that may be activated within their platforms. The following AI features are currently active on the Sites or Services:
- Breeze Customer Agent (active on nialli.com): AI-powered chat assistant on the Site. Conversation transcripts processed by HubSpot under its DPA with Nialli. Not used for HubSpot model training (Nialli has not opted in). Chat widget discloses AI interaction to visitors.
- Breeze Copilot (active in HubSpot CRM): AI assistant used by Nialli’s team within HubSpot. Processes CRM data to generate suggestions and summaries for Nialli staff. Covered by Nialli’s HubSpot DPA. Does not directly interact with Site visitors.
- Breeze Intelligence (active): AI-powered data enrichment that automatically researches and updates company and contact records using third-party data sources. HubSpot’s enrichment data sources (including Bombora and similar data vendors) function as sub-subprocessors of HubSpot for enrichment purposes, subject to HubSpot’s DPA. Individuals whose records are enriched may exercise data rights under Section 8.
- Breeze Prospecting Agent (active): AI-assisted prospect research and outreach drafting used by Nialli’s sales team. Draws on CRM and publicly available data. Covered under Nialli’s HubSpot DPA. For EEA/UK contacts, Nialli relies on legitimate interests and fulfils GDPR transparency obligations at first contact.
- Breeze Content Agent and Social Agent (active): AI-assisted content creation and social media scheduling used internally by Nialli’s marketing team. Do not directly process personal data of Site visitors. Content is reviewed and approved by Nialli staff before publication.
- Microsoft (Clarity, Azure, Advertising): AI-assisted analytics and advertising features may be active. These are subject to Microsoft’s AI product terms and DPA.
- Google (Analytics, Ads, reCAPTCHA): AI and machine learning features are integrated across Google’s product suite. Use is governed by Google’s AI principles and DPA.
Nialli reviews Subprocessor AI feature configurations to ensure they are consistent with our obligations under this Privacy Policy and our DPA. Where additional AI features of Subprocessors are activated in future, this section will be updated.
16.5 Applicable AI Regulations
The regulatory landscape for AI is evolving. Nialli monitors and, where applicable, complies with:
- EU AI Act (Regulation (EU) 2024/1689): in force from 2024, with obligations phasing in through 2027. Nialli assesses its AI use cases against the Act’s risk classifications and will implement required transparency, documentation, and human oversight measures as obligations take effect;
- Canadian Artificial Intelligence and Data Act (AIDA): currently in development. Nialli monitors its progress and will adapt practices as obligations are established;
- GDPR/UK GDPR Articles 13, 14, and 22: governing transparency about automated decision-making and the right not to be subject to solely automated decisions with significant effects;
- US state AI and automated decision-making laws: including obligations in Colorado, Texas, Illinois, and other jurisdictions as they take effect.
We will update this section as new AI regulations become applicable to Nialli’s activities.
17. Contact Us
To exercise your privacy rights, ask questions about this Policy, or raise a concern, please contact:
Nialli Inc.
Privacy Officer
401 9th Ave. SW, Suite 1301
Calgary, Alberta, Canada T2P 3C5
Email: PrivacyOfficer@nialli.com
Website: https://www.nialli.com/legal
EEA/UK Representative: If you are in the EEA or UK and have concerns about our privacy practices that we have not resolved to your satisfaction, you may lodge a complaint with your local supervisory authority (e.g., the UK Information Commissioner’s Office at ico.org.uk).