ASK NAMI

Privacy Notice

Last updated: September 2, 2026

1. Who we are

Nami Security provides ASK NAMI and is the data controller for the personal data described in this notice. You can reach us at privacy@namisecurity.io.

2. Data we collect and why

Account data (email address, sign-in identifiers, authentication metadata) — to create and secure your account and let you sign in. Legal basis: performance of our contract with you.

Organization setup and memory (organization type, technology setup, goals, and facts you explicitly ask NAMI to remember) — to personalize answers. Legal basis: performance of our contract.

Content you submit (questions, conversations, uploaded documents and the text extracted from them, feedback) — to provide answers and improve the quality of the Service. Legal basis: performance of our contract and our legitimate interest in improving the Service.

Technical and usage data (IP address, device and browser information, log and error data, feature usage) — for security, fraud prevention, troubleshooting and product improvement. Legal basis: legitimate interests.

Support messages — to answer your questions. Legal basis: legitimate interests and contract performance.

Payment data is collected and processed by Paddle as Merchant of Record; we receive only subscription status and limited order details, not your full payment card data.

Important: The Service is designed for professional cybersecurity inquiries and is not intended for the processing of personal data of identifiable third parties. You should not submit personal data of third parties (such as employee records, customer lists, or health information) to the Service. If you do submit such data, you are responsible for ensuring you have a lawful basis under applicable data protection laws and that you have provided any required notices to the relevant data subjects.

3. AI processing

To generate answers we send your question, relevant conversation history, your organization context and relevant excerpts from documents you uploaded to our AI model provider. We instruct the provider not to retain this data for training. We automatically detect and redact obvious secrets such as API keys and passwords before storing or sending message content, but you should avoid sending credentials. We do not use your content to train general-purpose AI models.

4. Who we share data with

Service providers and subprocessors that host and operate the Service, including cloud hosting and database providers, AI model providers, and error and analytics tooling. A list of our current subprocessors is available upon request at privacy@namisecurity.io.

Paddle.com, our Merchant of Record, for the sale of subscriptions, payments, invoicing, tax compliance and subscription management.

Professional advisers such as legal and accounting advisers, where necessary.

Authorities or third parties where required by law or to protect our rights, users or the security of the Service.

We do not sell your personal data.

5. International transfers

Our providers may process data outside your country, including outside Israel, the UK and EEA. Where that happens we rely on appropriate safeguards recognized under applicable law such as adequacy decisions, Standard Contractual Clauses, or other mechanisms permitted under the Protection of Privacy Law, 5741-1981 and the regulations promulgated thereunder, as well as the UK GDPR and EU GDPR where applicable.

6. Retention

We keep account data, conversations, organization memory and documents for as long as your account is active. You can delete conversations, remembered facts and documents at any time from within the app. After account closure we delete or anonymise your data within 90 days, except where we must keep records for legal, tax or accounting purposes. Technical and usage data is retained in anonymized or aggregated form for product improvement purposes and does not identify you personally after anonymization.

7. Your rights

Depending on where you live, you may have the right to access, correct, delete, restrict or object to the processing of your personal data, to data portability, and to withdraw consent where processing is based on consent. If you are in Israel, your rights under the Protection of Privacy Law, 5741-1981 (as amended) include the right to review, correct, and delete personal data held about you. To exercise any of these rights, email privacy@namisecurity.io; we respond within one month (or within such shorter period as required by applicable law). If you are in Israel, you may also file a complaint with the Privacy Protection Authority (PPA). If you are in the UK or EEA, you also have the right to complain to your local supervisory authority.

8. Security

We apply appropriate technical and organisational measures, including encryption in transit and at rest, row-level access controls that isolate each account's data, private document storage and least-privilege access for our systems. In the event of a personal data breach that is likely to affect your rights, we will notify the relevant supervisory authority to the extent required by applicable law and, where required by applicable law, notify affected users without undue delay.

9. Cookies and local storage

We use strictly necessary cookies and browser storage to keep you signed in and to keep the Service secure. We do not use advertising cookies. You can clear or block this storage in your browser, but the Service will not work correctly without it.

10. Changes

We may update this notice as the Service develops. We will update the date at the top of this page and, for material changes, notify you in the app or by email at least fourteen (14) days before the changes take effect. If you do not agree with the revised notice, you may close your account before the changes become effective.