Privacy Policy

Last updated: 3 October 2025

This Privacy Policy explains how Nabuza Ltd (“Nabuza”, “we”, “us”) collects, uses, shares and protects personal data when you interact with our public-facing channels.

1) Who we are (Data Controller)

Nabuza Ltd is the data controller for personal data collected via our public-facing channels.

  • Company: Nabuza Ltd (registered in England & Wales)
  • Company number: 16538277
  • Registered office: 7 Burwell Avenue, Newcastle upon Tyne NE5 2AY
  • Privacy email: privacy@nabuza.com

2) Scope of this notice

This notice applies to our public-facing channels (the “Public Channels”), including: our website (e.g., nabuza.com), marketing pages, emails sent to @nabuza.com addresses (such as privacy@nabuza.com), lead-generation forms on third-party platforms (e.g., LinkedIn), event/webinar signups, and similar touchpoints.

It does not cover how customer data is processed inside the authenticated product (“Nabuza Studio”). If you sign up or log in to Nabuza Studio, please refer to the separate Product Privacy Notice available within the app.

3) What data we collect

A. Information you provide directly

  • Contact details – name, company, role, and any details you submit via website forms, third-party lead forms (e.g., LinkedIn), or email.
  • Messages – the content of enquiries, support requests, or feedback (including emails to privacy@nabuza.com).
  • Event & webinar registrations – preferences and attendance intent.
  • Recruitment – CV/resume details if you apply for roles via our public channels.

B. Information collected automatically (when you visit our website)

  • Usage data – pages viewed, time on page, referring/exit pages, clicks, and similar essential diagnostics.
  • Device & technical – IP address, approximate location (city/region), browser type/version, OS, language, user agent, and related request metadata.
  • Security logs – error logs and events needed to protect services against abuse.

C. Information from third parties

  • Platform providers – if you submit a third-party lead form (e.g., LinkedIn Lead Gen), we receive the fields you authorise that platform to share.
  • Public sources – business contact information available publicly (e.g., LinkedIn) when we assess interest in our services.

4) Cookies

On our website, we only use strictly necessary cookies and similar technologies that are essential to operate and secure the site. We do not set analytics, advertising, or other non-essential cookies on the public site at this time.

Third-party platforms (e.g., LinkedIn) may use their own cookies according to their privacy policies. For details of any essential cookies we set, see our Cookie Policy.

5) How we use your data

  • Operate and secure our Public Channels, diagnose issues, and prevent fraud or abuse.
  • Respond to enquiries and provide support.
  • Communicate by email, including responding to messages sent to privacy@nabuza.com and providing legally required notices.
  • Analyse service performance using operational logs and aggregated diagnostics (without non-essential cookies).
  • Comply with legal obligations and enforce our terms.

7) How we share information

We do not sell personal information. We share limited data with:

  • Service providers that help us host, secure, and deliver our Public Channels, process emails, and store contact records (bound by contracts and confidentiality).
  • Platform providers (e.g., LinkedIn) when you interact with our profiles or lead forms on those platforms.
  • Professional advisors such as legal and accounting where necessary.
  • Authorities when required by law or to protect rights, safety, or security.
  • Business transfers in connection with a reorganisation, merger, or acquisition.

8) International data transfers

We primarily host in the UK or EEA. Some service providers may process data in other countries, including the United States. Where such transfers occur, we use one or more of the following safeguards:

  • Adequacy decisions (UK/EU), where available.
  • Standard Contractual Clauses with the UK Addendum/IDTA, and additional technical or organisational measures where appropriate.

By design, data from our Public Channels may be processed in the UK/EU and the USA.

9) Data retention

We keep personal data only for as long as needed for the purposes in this policy or as required by law. Typical periods are:

  • Contact/enquiry records: up to 24 months after our last meaningful interaction.
  • Security & error logs: typically 12 months (shorter where feasible).
  • Recruitment data: up to 12 months unless you consent to a longer talent-pool retention.

We may retain minimal information to comply with legal obligations, resolve disputes, and enforce agreements.

10) Your rights

A. UK/EU data protection rights

You have the right to request access, correction, deletion, restriction, portability, and to object to certain processing (including direct marketing). Where we rely on consent, you may withdraw it at any time.

To exercise these rights, email privacy@nabuza.com or write to us at the postal address below. We may need to verify your identity. You also have the right to complain to a supervisory authority. In the UK, this is the Information Commissioner’s Office (ICO).

B. US state privacy notices (summary)

If you are a resident of a US state with comprehensive privacy laws (for example, California, Colorado, Virginia, Connecticut, Utah), you may have rights to access, correct, delete, and opt out of certain processing, including targeted advertising or “sharing”. We do not sell personal information. To submit a request, email privacy@nabuza.com.

11) Security

We use appropriate technical and organisational measures to protect personal data, including encryption in transit, access controls, logging, and vulnerability management. No system is perfectly secure, and the internet has inherent risks. Please take care when sending information online.

12) Children’s privacy

Our Public Channels are not directed at children. We do not knowingly collect personal data from anyone under the age of 13 (or under 16 where applicable). If you believe a child has provided us with personal data, please contact us so we can delete it.

13) Third-party links

Our Public Channels may contain links to third-party sites or services. Their privacy practices are not covered by this policy. We encourage you to review their privacy notices.

14) Changes to this policy

We may update this Privacy Policy from time to time. We will change the “Last updated” date at the top and, where appropriate, notify you via our Public Channels or by email.

15) Contact us

If you have questions about this policy or how we handle personal data, contact us at:

  • Email: privacy@nabuza.com
  • Post: Nabuza Ltd, 7 Burwell Avenue, Newcastle upon Tyne NE5 2AY