Privacy Policy
Last updated: 23 July 2026 · Version: 2026-07
We, at nBold, know you care about how your personal information is used and shared, and we take your privacy more than seriously — we make it a core component of our software development and internal processes. As a general principle, we only use the data that is necessary to the well-functioning of nBold software. We don’t sell, and we don’t share, your data from nBold software for the purpose of making money; this is not our business model.
In this policy, we lay out what data we collect and why, how your data is handled, the lawful bases on which we process it, and your rights to your data. We promise we never sell your data: never have, never will.
What we collect and why
Our guiding principle is to collect only what we need. Here is what that means concretely.
Identity & access in the App
When, as a Microsoft 365 administrator, you sign up for nBold, you grant consent for the Microsoft Graph to the nBold App. This means all users in your organization are authorized to log in (otherwise they are not).
nBold relies 100% on Microsoft Entra ID (Azure Active Directory) for identity management. This means we do not access, collect, or store any password. The personal information nBold relies on is only the information declared in your organization’s Microsoft Entra ID tenant, such as:
- First and last name
- Email address
- Language
- Time zone
- Application settings and preferences
This data is sourced from the customer’s Microsoft Entra ID tenant — that is, it is not obtained directly from the data subjects. We will never sell your personal information to third parties, and we will not use your name or company in marketing statements without your permission.
Billing information
When you pay for nBold, we ask for your billing information, such as credit card or bank transfer details and billing address, so that we can charge you for the service, calculate taxes due, and send you invoices. Your credit card is passed directly to our payment processor and never goes through our servers. We store a record of the payment transaction, including the last four digits of the card number and the as-of billing address, for account history, invoicing, and billing support. We store your billing address to calculate any sales tax or VAT due, to detect fraudulent transactions, and to print on your invoices.
Geolocation and access logs
We log access to accounts by full IP address so that we can verify no unauthorized access has occurred. We keep this login data for as long as your product account is active.
We also log the full IP address used to sign up for a product account and retain it for 24 months for the purpose of preventing fraudulent and abusive sign-ups, after which it is deleted.
Web analytics data — described further in the Website interactions section — are also tied temporarily to IP addresses to assist with troubleshooting. We blind all web analytics data after 30 days.
Website interactions
When you browse our marketing pages or applications, your browser automatically shares certain information, such as which operating system and browser version you are using. We track that information, along with the pages you visit, page-load timing, and which website referred you, for statistical purposes such as conversion rates. These web analytics data are tied to your IP address and, if you are signed in, your user account. Google Analytics, HubSpot, and LinkedIn tracking code are currently used as third-party software for this purpose, subject to your consent via the cookie banner.
Cookies
We use persistent first-party cookies to store certain preferences, make our applications easier to use, and support some in-house analytics. Marketing and third-party analytics trackers are set only if you accept them via the cookie banner, and you can change your choices at any time via Cookie preferences. You can also adjust cookie retention settings in your browser.
Voluntary correspondence
When you write to nBold with a question or for help, we keep that correspondence, including your email address, so we have a history to reference if you reach out again. We also store information you volunteer, such as survey responses. When we conduct customer interviews, we may ask your permission to record the conversation; we only do so with your express consent.
Information we do not collect
We do not collect any characteristics of protected classifications, including age, race, gender, religion, sexual orientation, gender identity, gender expression, or physical and mental abilities or disabilities. We also do not collect biometric data. Profile pictures may appear in the nBold product experience, but we do not extract any information from them.
Lawful basis for processing
We process personal data under the following legal bases of Article 6 GDPR:
- Performance of a contract — identity and access data from your organisation’s Microsoft Entra ID tenant, application settings, and support correspondence, processed to provide the nBold service you or your organisation subscribed to.
- Legal obligation — billing information, invoices, and tax records, processed to meet accounting and tax-law requirements.
- Legitimate interests — IP address and access logging for the security of the service and the prevention of fraud and abuse, and first-party analytics to maintain and improve the service. We have balanced these interests against your rights, and you may object at any time.
- Consent — marketing cookies and third-party marketing/analytics trackers on our website, set only if you accept them via the cookie banner. You may withdraw consent at any time via Cookie preferences.
When we access or share your information
Our default practice is not to access your information. The only times we will access or share your information are:
- To provide the products or services you have requested. We use some third-party services (subprocessors) to run our applications, and only to the extent necessary to process your personal information. You can view the parties we share data with in our public List of Processors.
- To help you troubleshoot or fix a software bug. If we need to access your account to help with a support case, we will ask for your consent before proceeding.
- To investigate, prevent, or act regarding restricted uses. Accessing a customer’s account when investigating potential abuse is a measure of last resort, undertaken to protect the privacy and safety of our customers and of those reporting issues. If we discover you are using our products for a restricted purpose, we will report the incident to the appropriate authorities.
- To comply with the law. We may share information to comply with a valid legal request from competent authorities. Where permitted, we will notify you.
The current list of parties we share data with is published at nbold.com/legal/list-of-processors/.
Location of site and data, and international transfers
Our products and other web properties are operated in Microsoft Azure datacenters with data located in France. If you are located in the European Union or elsewhere outside of France, please be aware that information you provide to us will be transferred to France.
International transfers. Some of our processors (see our List of Processors) are established in the United States or otherwise process data outside the EU/EEA. Where personal data is transferred outside the EU/EEA, we rely on the European Commission’s Standard Contractual Clauses (SCCs) and, where the recipient is certified, the EU–US Data Privacy Framework, together with additional technical measures such as encryption in transit and at rest.
Your rights with respect to your information
We apply the same data rights to all customers, regardless of location. nBold recognizes all of the rights granted under the European Union’s General Data Protection Regulation (GDPR), except as limited by applicable law. These rights include:
- Right to be informed / to know. You have the right to know what personal information is collected, used, and shared. We outline the categories and specific data we collect, and how they are used, in this policy.
- Right of access. You have the right to access the personal information we hold about you, and to obtain information about its sharing, storage, security, and processing.
- Right to rectification. You have the right to request correction of your personal information.
- Right to erasure (“right to be forgotten”). You have the right to request, subject to legal limitations, that your personal information be erased from our possession and that of our service providers. Fulfilling some deletion requests may prevent you from using nBold and may result in closing your account.
- Right to restriction of processing. You have the right to request restriction of how and why your personal information is processed.
- Right to data portability. You have the right to receive the personal information we hold about you and to transmit it to another party.
- Right to object. You have the right, in certain situations, to object to how or why your personal information is processed.
- Rights in relation to automated decision-making, including profiling. You have the right to object to and prevent decisions with legal or similarly significant effects being made solely by automated means, subject to the limited exceptions permitted by law.
Many of these rights can be exercised in the product itself or through the communications you receive. We respond to any Subject Access Request (SAR) within no more than 30 days. To verify a deletion or access request, we first confirm your identity using at least two pieces of information already collected, including your account email address. If an authorized agent acts on your behalf, we require written, signed consent from the account holder first.
If you have questions about exercising these rights or need assistance, please contact us at privacy@nbold.com.
How long we keep your data
When you stop using the nBold App, all personal data we hold about you and your users is deleted no later than 6 months after cessation of use. This includes identity and access data, application settings, access logs, and support correspondence. The only exceptions are:
- Sign-up IP logs — retained for 24 months for anti-fraud purposes, as described in the Geolocation and access logs section, after which they are deleted.
- Billing, invoice, and tax records — retained only for as long as required to meet legal accounting and tax obligations.
Web analytics data are IP-blinded after 30 days. On your request, you can ask for deletion of your personal data at any time by emailing privacy@nbold.com.
How we secure your data
Security is built in from the code phase through to network and everyday operations. All data is encrypted via TLS in transit, and database backups are encrypted. Development follows OWASP Security-by-Design principles and includes automated testing and security auditing (static analysis, dependency and vulnerability scanning, and security alerting). For more information, see our security overview.
Right to complain
You have the right to lodge a complaint regarding our handling of your personal information with a supervisory authority. As we are established in France, our lead authority is the Commission Nationale de l’Informatique et des Libertés (CNIL), 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France — www.cnil.fr. If you are in another EU member state, you may also contact your local authority via the EDPB members directory at https://edpb.europa.eu/about-edpb/board/members_en.
Who we are, changes, and questions
Data controller. SalesTim, Registration No. 898 922 638 RCS Paris, 231 rue Saint-Honoré, 75001 Paris, France.
Data Protection Officer. nBold is not required to designate a Data Protection Officer under Article 37 GDPR and has not appointed one. For all privacy matters, contact privacy@nbold.com.
We may update this policy as needed to comply with relevant regulations and reflect new practices. Whenever we make a significant change, we announce it to customers and publicly. If you have any questions, comments, or concerns about this privacy policy, your data, or your rights, please email us at privacy@nbold.com and we will be happy to help.
SalesTim · Registration No. 898 922 638 RCS Paris · 231 rue Saint-Honoré, 75001 Paris, France · privacy@nbold.com