Security and data protection
Last Updated: September 7, 2026
If you are reviewing Nuggetz for a trial
Four things usually decide whether a pilot is approved. All four are true today, and none of them require a call with us.
- The processing terms are already in force. Our Data Processing Addendum applies from the moment a trial starts, on exactly the same terms as for a paying customer — nothing to negotiate first. We will sign a copy on request.
- Your interviews never leave the EU. Application in Azure West Europe, database in Azure North Europe, and speech transcription on an EU Azure resource. No interview content is transferred outside the EEA.
- Nothing is used to train AI models. Not ours, not a provider's.
- You can delete everything yourself, immediately. See the next section — it is the one most evaluations forget to ask about until the end.
What happens to your data if the trial does not proceed
A pilot means asking real employees to talk about how they work. The fair question before that happens is what becomes of what they said.
You can delete it yourself, at any time, without asking us. An administrator can delete a single response, or delete an entire interview. Deleting an interview permanently deletes its questions, every response and transcript, every nugget extracted from those transcripts, and the handbook written from them. There is no soft-delete and no archive; it is gone from the live service at once.
You can keep the knowledge without keeping the personal data. Export the handbook as Markdown first. The document survives; the interviews behind it do not have to.
Or ask us and we do it. Email privacy@nuggetz.ai and we delete all your data within thirty days and confirm in writing. The same applies if you close your account. We do not delete on a timer — absent a request your data stays available to you, because how long to keep it is your decision to make, not ours.
Backups are the honest caveat. Deleted data can persist in encrypted database backups on a 35-day rolling retention, after which it is overwritten. We never selectively restore a backup to recover data a customer deleted.
Where your data lives
The Nuggetz application runs on Microsoft Azure in West Europe, with its database in North Europe. Transcription of spoken answers and read-aloud run on an Azure resource in the EU. Everything your colleagues say in an interview — the audio, the transcript, the nuggets and the handbook — is processed and stored inside the EU and is never transferred outside the EEA.
What does leave the EEA, stated plainly. Not your interview content. Two things: authentication records held by Clerk, and the workspace product analytics described below. Each is named with its purpose and location in Annex III of the DPA and covered by standard contractual clauses. We would rather draw that line precisely than claim nothing at all leaves Europe.
A small number of sub-processors are established outside the EEA and are engaged under standard contractual clauses. Each is named, with its purpose and location, in Annex III of the DPA. We give thirty days' notice before adding or replacing one, and you can object.
AI, and what happens to your content
AI processing runs on Microsoft Azure AI Foundry within our own Azure tenant. Your content is not used to train, fine-tune or improve any model — ours or a third party's — and we engage AI providers only under terms that prohibit them from doing so.
Nuggetz does not evaluate, score, rank or profile the people it interviews, and makes no automated decision producing legal or similarly significant effects about them. It documents how work is done; it does not assess the people who do it.
Voice recordings are never stored
Respondents can answer by speaking. When they do, the audio is streamed to the transcription service inside a single request, held only in memory while it is turned into text, and gone the moment that request completes. It is never written to disk or to a database, and the transcription resource that briefly handles it is in the EU. There is no recording to retrieve afterwards — by us, by you, or by anyone compelling either of us. Only the transcript is retained.
Access and identity
- Your team's data is scoped to your team on every query, not checked afterwards.
- Respondents have no account and see one interview. Their ability to write into a transcript is bound to a per-interview HttpOnly cookie, enforced as a condition of the query itself.
- Interview and handbook links carry no-index instructions, so your content does not enter public search results.
- Stopping an interview immediately prevents new responses; revoking a shared handbook makes its link stop resolving at once.
- Authentication is provided by Clerk. SAML single sign-on and SCIM provisioning are not configured today — see the limits below.
- Our staff access customer content only where necessary to operate or support the service, on a least-privilege basis, under confidentiality obligations.
Application and infrastructure
- TLS on all connections, HSTS enforced, HTTPS-only, FTP disabled.
- Azure platform encryption at rest for database, storage and backups.
- A nonce-based Content Security Policy with
strict-dynamic,frame-ancestors 'none', a restrictive permissions policy and cross-origin opener policy. - CSRF protection on every state-changing request, including unauthenticated respondent endpoints.
- Schema validation, request size limits and per-endpoint rate limiting on every API route.
- Centralised error handling that scrubs personal data from logs.
- The application runs inside a virtual network; the rate-limit store is reachable only through a private endpoint with public access disabled. Secrets are held in Azure Key Vault with purge protection.
- Automated database backups on a 35-day rolling retention.
If something goes wrong
We will notify you of a personal data breach affecting your data without undue delay and within 48 hours of becoming aware of it, with what we know at the time and the rest as it emerges. To report a vulnerability, write to security@nuggetz.ai; our disclosure policy is at /.well-known/security.txt. We will not pursue good-faith research that respects user privacy and does not access data belonging to others.
Trial and paid: what changes, and what does not
We limit our financial liability more tightly during a free evaluation than under a paid subscription. That is the only thing that changes. It is worth being precise about it, because a lower cap is easy to mistake for a lower standard.
| Free evaluation | Paid subscription | |
|---|---|---|
| Data Processing Addendum | In force | In force |
| Security measures | Identical | Identical |
| No AI training on your content | Yes | Yes |
| Deletion rights and 30-day commitment | Yes | Yes |
| 48-hour breach notification | Yes | Yes |
| Service levels and support commitments | None | Per your agreement |
| Our liability cap | EUR 1,000 | 12 months' fees, and 3× that for data protection, security, confidentiality and indemnity claims |
Nothing on either tier limits your people's own statutory rights. A data subject's right to compensation under Article 82 GDPR is theirs, not your organisation's, and no agreement between us can cap it.
Certifications — stated plainly
Nuggetz does not hold SOC 2 or ISO/IEC 27001 certification. We are an early-stage company and we would rather say so than imply otherwise. Our cloud providers hold both for the services we build on, which covers the infrastructure layer but not our own controls.
What we offer instead: this page, a DPA in force from day one with a documented security annex, and our commitment to complete your own security questionnaire on request. Many enterprise review processes have a path for early-stage suppliers who can evidence compensating controls — this is ours. Write to security@nuggetz.ai and send us the questionnaire your process uses.
How to scope a low-risk pilot
We are a small company and we would rather you ran a pilot that is easy to approve than a large one that stalls in review. The exposure in an evaluation is set by what goes into it, so this is what we suggest.
- Pick one process, not a department. An escalation path, a handover, an exception procedure. Enough to tell whether the product works.
- Avoid sensitive ground for a first pilot. Special category data, records about your own customers, regulated material, or safety-critical procedures. Those are the right things to document eventually and the wrong things to test an unproven vendor with.
- Leave respondent email blank. It is optional. A pilot works with names alone, and that is less personal data in play.
- Set an end date, then delete. Two or three weeks is usually enough. Export the handbook as Markdown, delete the interviews, and you keep the finding without keeping the personal data.
- Do not put a trial handbook into live operations until someone who knows the work has read it. That is true of any generated document, and it is in our Terms.
If the knowledge you actually need to capture is more sensitive than this, say so before you start. We will tell you honestly whether we are the right stage of company for it — losing a pilot we should not be running is a better outcome for both of us than winning it.
What Nuggetz does not do yet
A reviewer finding a gap after the demo is a worse outcome than one reading it here. As of today:
- No SAML single sign-on and no SCIM provisioning.
- No SOC 2 or ISO 27001 certification, and no third-party penetration test report.
- No automatic retention schedule — data is kept until you delete it, or until the deletion commitment above applies.
- No customer-managed encryption keys, no data residency choice beyond the EU regions above, and no self-serve audit log export.
- The signed-in product is English. Only the respondent-facing interview is translated, into the languages you choose for it.
- No direct integrations. Handbooks leave as Markdown.
If one of these blocks an evaluation, tell us — it is useful to know which gap costs us a pilot.
Contact
Nuggetz is operated by Sabiedrība ar ierobežotu atbildību "GoProst", registration number 44103112931, Valmieras iela 24, Smiltene, Smiltenes novads, LV-4729, Latvia. Security: security@nuggetz.ai. Data protection: privacy@nuggetz.ai. See also the DPA, the Privacy Policy, and the interview privacy notice shown to respondents.
