California
Dated:
California Residents
We provide the following information to California residents pursuant to the California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA”). This information supplements our general Privacy Policy. For a description of all of our data collection, use and disclosure practices, please read our Privacy Notice in its entirety. Terms that are capitalized but not defined below have the meanings set forth in our Privacy Notice.
Categories of Personal Information
Below, we describe the categories of Personal Information (as defined in the CCPA), that we have collected within the preceding 12 months and may collect on a going-forward basis:
- Identifiers
- Personal information categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e)) (e.g., name, address, email address)
- Characteristics of protected classifications under California or federal law
- Commercial information (e.g., transaction data)
- Internet or other similar network activity
- Geolocation data (e.g., general location derived from an IP address)
- Sensory data (e.g., audio, video)
- Professional or employment-related information
- Education information
- Inferences drawn from the preceding categories of Personal Information
Within these categories of Personal Information, we may also collect the following categories of Sensitive Personal Information (as defined in the CCPA): Account log-in, financial account, debit card, or credit card number, in combination with any required security or access codes, password, or credentials allowing access to the account
Categories of Recipients of Personal Information
For each category of Personal Information (including Sensitive Personal Information) listed above, we disclose this information as described in the “How we share your information“ section of our Privacy Notice. In addition, we disclose Identifiers and Internet or other similar network activity to advertising providers that tailor online ads to your interests based on information they collect about your online activity (known as interest-based advertising).
Sources of Personal Information
We obtain the categories of Personal Information listed above directly from you or from devices on which you use our Nusu Services, as well as from the following categories of sources: our corporate affiliates, publicly-available databases, third-party business partners, social media sites, and other third-party sources, and as described in our “Information We Collect About You“ section of the Privacy Notice.
Purposes for Which We Use Personal Information
We use Personal Information for a variety of business and commercial purposes, as described in the “How We Use Your Information“ section of our Privacy Notice, which is linked above.
Retention Period Criteria
Nusu retains Personal Information for specific periods based on the category of information and the purpose for which it was collected:
| Category of Personal Information | Retention Period | Criteria |
|---|---|---|
| Identifiers (name, email, IP address) | Duration of account plus 30 days | Deleted within 30 days of account termination; backups purged within 90 days |
| California Customer Records (contact info, financial info) | Duration of account plus 30 days | Deleted within 30 days of account termination; backups purged within 90 days |
| Protected Classifications (gender, age, date of birth) | Duration of account plus 30 days | Deleted within 30 days of account termination |
| Commercial Information (transaction data, purchase history) | 7 years from transaction date | Retained to comply with tax, accounting, and legal requirements |
| Internet or Network Activity (browsing, search history) | 13 months from collection | Aggregated or deleted after 13 months |
| Geolocation Data (IP-derived location) | 13 months from collection | Aggregated or deleted after 13 months |
| Sensory Data (audio, video from customer support) | 90 days from collection | Deleted after 90 days unless required for dispute resolution |
| Professional or Employment-Related Information | Duration of relationship plus 3 years | Retained for legal compliance and dispute resolution |
| Education Information | Duration of account plus 30 days | Deleted within 30 days of account termination |
| Inferences | Duration of account plus 30 days | Deleted within 30 days of account termination |
| Sensitive Personal Information (payment credentials) | Duration of account plus 30 days | Payment credentials are stored by Stripe; access credentials deleted within 30 days of account termination |
We may retain Personal Information for longer periods if required by law (such as tax, accounting, or other legal obligations), to resolve disputes, enforce our agreements, or as otherwise communicated to you. When retention is no longer necessary, we delete or anonymize the information.
CCPA Rights and Requests
You may make the following types of requests under the CCPA with respect to Personal Information that we process on our own behalf. Note: If you wish to make a CCPA request with respect to Personal Information submitted through or otherwise made available to the Platform Services, please direct your request to the relevant Customer directly, as that data is governed by the terms of our agreement with our Customer.
Requests to Know, Correct, and Delete: You may request:
(i) Access to a copy of the specific pieces of Personal Information that we have collected about you;
(ii) Correction of Personal Information that we maintain about you, if it is inaccurate; and/or
(iii) Deletion of Personal Information, subject to certain exceptions.
You can submit a request online by filling out a request form here or emailing us at dsr@nusu.ai. We will respond to your request consistent with the CCPA, and subject to any exceptions that may apply under the CCPA. We may need to request additional Personal Information from you, such as email address, state of residency, or mailing address, in order to verify your identity and protect against fraudulent requests. If you maintain a password-protected account with us, we may verify your identity through our existing authentication practices for your account and require you to re-authenticate yourself before disclosing or deleting your Personal Information.
Requests to Opt-Out of Sale, Sharing, and Limit Use of Sensitive Personal Information: You have the right to:
- Opt out of the "sale" or "sharing" of your Personal Information for cross-context behavioral advertising; and
- Limit the use and disclosure of your Sensitive Personal Information to purposes necessary to perform the services or provide the goods you request.
You may exercise these rights by:
- Visiting our Your Privacy Choices page (accessible via the footer link displaying the opt-out preference icon)
- Submitting a request at nusu.ai/legal/data-request
- Emailing us at dsr@nusu.ai
We do not sell Personal Information in the traditional sense of exchanging information for monetary payment. However, because the definitions of "sale" and "sharing" under the CCPA may include the disclosure of your information to certain types of advertising and marketing partners, we provide California residents with the right to opt-out of any such sale or sharing of their Personal Information. As noted above, we may disclose or make available Identifiers or Internet or other similar activity to advertising partners. We allow you to opt out of such disclosures, as they may constitute "sale" or "sharing" as defined under the CCPA. We do not knowingly "sell" or "share" the Personal Information of individuals under 16 years of age.
Global Privacy Control and Opt-Out Preference Signals
We recognize and honor opt-out preference signals, including the Global Privacy Control (GPC) signal. When we detect a GPC signal from your browser or device:
- We will treat it as a valid request to opt out of the sale and sharing of your Personal Information
- We will process this request automatically without requiring additional action from you
- You will see confirmation that your opt-out request has been honored (displayed as "Opt-Out Request Honored" or similar language) when visiting pages that would otherwise involve sale or sharing of your information
To enable GPC, you can use a browser or browser extension that supports this signal. For more information about GPC, visit globalprivacycontrol.org.
Note: The GPC signal applies specifically to the browser or device from which it is sent. If you use multiple browsers or devices, you should enable GPC on each one.
Applicability to Employees, Job Applicants, and Business Contacts
Effective January 1, 2023, the CCPA extends privacy rights to California residents in their capacity as:
- Job applicants for positions at Nusu
- Employees, contractors, and other personnel of Nusu
- Business-to-business (B2B) contacts representing other companies with which Nusu has or seeks to have a business relationship
If you are a California resident and fall into one of these categories, you have the same rights described in this notice, including the rights to know, correct, delete, and opt out of the sale or sharing of your Personal Information.
For Job Applicants and Employees: We collect Personal Information such as contact information, employment history, professional qualifications, background check information (with consent), and payroll data. This information is used for recruiting, employment administration, payroll processing, benefits administration, and legal compliance. For specific retention periods applicable to employment-related data, please contact hr@nusu.ai.
For B2B Contacts: We collect business contact information such as name, title, company name, business email, and business phone number. This information is used for business communications, sales, marketing (with consent), and maintaining business relationships.
To exercise your rights as a job applicant, employee, or B2B contact, submit a request at nusu.ai/legal/data-request or email dsr@nusu.ai.
Authorized Agents
To make a request as an authorized agent on behalf of a California resident, you may use the submission methods noted above. As part of our verification process, we may request that you provide, as applicable, proof concerning your status as an authorized agent.
If you are making a Request to Know, Correct, or Delete on behalf of a California resident and have not provided us with a qualifying power of attorney from the resident, we may also require the resident to verify their own identity directly with us; or directly confirm with us that they provided you permission to submit the request.
Nondiscrimination
You have the right to be free from unlawful discriminatory treatment for exercising any of your CCPA rights.