Nooks Privacy Notice
Last Modified: October 13, 2025
Nooks Communications, Inc. (“Nooks,” “we,” “our,” and/or “us”) values the privacy of individuals who use our websites, (including https://nooks.ai and https://app.nooks.in) and any of our other websites, applications, or services that link to this Privacy Policy (collectively, our “Services”). This privacy policy (the “Privacy Policy”) explains how we collect, use, and share personal information from users of our Services (“Users”). By using our Services, you agree to the collection, use, disclosure, and procedures this Privacy Policy describes. Beyond this Privacy Policy, your use of our Services is also subject to our Terms of Service.
Nooks is a Processor, not a Controller, of personal data that we process on behalf of our Customers when they use our Services. Nooks Customers are Controllers of their customers’ data, including their personal data. If you have questions related to how a Nooks Customer utilizes your personal data, please contact them directly. This Notice does not apply to personal data about current and former Nooks employees, job candidates, or contractors and agents acting in similar roles.
1. WHAT INFORMATION DO WE COLLECT?
We may collect a variety of personal information from or about you or your devices from various sources, as described below.
A. Information You Provide to Us
Registration. When you register for an account to use our Services, we collect your personal information, including your name, email, job title, Company name, phone number, address and profile picture. If you register using your account with a third-party service (e.g., Microsoft, or Google), we collect your personal information from the applicable third-party service as discussed in “Platform Sign-On” under Section C below.
Payment. When you purchase our services through our Website or by contacting us directly, we collect information about the payment amount, billing address, contact information, date of purchase and purchase history. You may be required to provide your credit card details to Stripe, our third-party payment processor operating as our agent. Payment processing services by Stripe are subject to Stripe’s security and privacy policies found on Stripe’s website. As a condition of Nooks enabling payment processing services through Stripe, you authorize Nooks to share registration and transaction information related to your use of the payment processing services provided by Stripe.
Communications. If you contact us directly, we may receive additional personal information about you. For example, when you contact us for support, we will receive your name, email address, the contents of your message and recordings of calls with us. If you subscribe to our marketing communications, we will receive your email address.
Surveys. If you complete our surveys, we will collect your survey responses and any other personal information you include with your responses.
Marketing Forms: When you complete our marketing forms, we collect your personal information including your name, email, job title, Company name and phone number, in addition to information about how you plan to use our Services.
B. Information We Collect When You Use Our Services
Location Information. When you use our Services, we infer your general location information (for example, your IP address may indicate your general geographic region).
Device Information. We receive information about the device and software you use to access our Services, including internet protocol (IP) address, web browser type, and operating system version.
Usage Information. To help us understand how you use our Services and to help us improve them, we automatically receive information about your interactions with them, such as the length of time you spend on a page, objects such as hyperlinks you click on, and the dates and times of your visits.
Information from Cookies and Similar Technologies. We and our third-party partners may collect information using cookies, pixel tags, or similar technologies. This may include cookie identifiers that are necessary to provide certain features of the Nooks Service. Our third-party partners may use these technologies to collect information about your online activities over time and across different services. For more details about how Nooks uses these technologies, and your opt-out opportunities and other options, please see Nooks’ Cookie Policy.
Customer call recordings and meta-data for Nooks’ proprietary Artificial Intelligence (AI) Model training. If a User decides to record a third-party Customer Call, we may collect that call recording. The User bears all compliance responsibilities with respect to call recording with third-parties, and accordingly, is responsible for obtaining all necessary consents to do so. If a call is recorded, we may use that data solely to provide or improve the functionality of our Services. Users are able to opt out of the use of their call recordings for model training, by emailing privacy@nooks.in. By opting out, Users may lose access to certain functionality of our Services. For clarification, the loss of certain functionality with our Services is strictly due to the nature of how Customer call recordings are used, and it is not punitive nor is it used to coerce an opt-in from the Customer.
C. Personal Information We Receive from Third Parties
Platform Sign-On. When you register for our Services using a third-party account such as Google, or Microsoft, we receive your personal information, including your name, profile picture, and email address.
Partners. We may receive personal information about you from third parties such as data or marketing partners and combine it with other personal information we have about you.
2. HOW DO WE PROCESS YOUR INFORMATION?
We may use the personal information we collect:
● To facilitate account creation and authentication and otherwise manage user accounts.
● To deliver and facilitate delivery of our Services to the Users, as well as to maintain, debug, improve, and enhance our Services.
● To communicate with you, provide you with updates and other information relating to our Services, provide information that you request, respond to comments and questions, and otherwise provide customer support.
● For marketing purposes, such as developing and providing promotional and advertising materials that may be useful, relevant, valuable or otherwise of interest to you. You can unsubscribe from our promotional emails via the link provided in the emails. Even if you opt-out of receiving promotional messages from us, you will continue to receive administrative messages from us.
● To understand and analyze how you use our Services and develop new products, services,features, and functionality.
● To protect our Services, We may process your information as part of our efforts to keep our Services safe and secure, including fraud monitoring and prevention.
● To facilitate the connection of third-party applications and Services, such as social networks.
● To undertake internal research for technological development and demonstration.
● For compliance purposes, including enforcing our Terms of Service or other legal rights, or as may be required by applicable laws and regulations or requested by any judicial processor governmental agency.
● For other purposes for which we provide specific notice at the time the personal information is collected.
3. WHAT LEGAL BASES DO WE RELY ON TO PROCESS YOUR INFORMATION?
If you are located in the EU or UK, this section applies to you.
The General Data Protection Regulation (GDPR) and UK GDPR require us to explain the valid legal bases we rely on in order to process your personal information. As such, we may rely on the following legal bases to process your personal information:
Consent. We may process your information if you have given us permission (i.e., consent) to use your personal information for a specific purpose. You can withdraw your consent at any time. Learn more about withdrawing your consent in Section 10.
Performance of a Contract. We may process your personal information when we believe it is necessary to fulfill our contractual obligations to you, including providing our Services or at your request prior to entering into a contract with you.
Legitimate Interests. We may process your information when we believe it is reasonably necessary to achieve our legitimate business interests and those interests do not outweigh your interests and fundamental rights and freedoms. For example, we may process your personal information for some of the purposes described in order to:
● Send users information about special offers and discounts on our products and services.
● Analyze how our Services are used so we can improve them to engage and retain users.
● Diagnose problems and/or prevent fraudulent activities.
Legal Obligations. We may process your information where we believe it is necessary for compliance with our legal obligations, such as to cooperate with a law enforcement body or regulatory agency, exercise or defend our legal rights, or disclose your information as evidence in litigation in which we are involved.
Vital Interests. We may process your information where we believe it is necessary to protect your vital interests or the vital interests of a third party, such as situations involving potential threats to the safety of any person.
4. WHEN AND WITH WHOM DO WE SHARE YOUR PERSONAL INFORMATION?
We do not share or otherwise disclose personal information we collect from or about you except as described below or otherwise disclosed to you at the time of the collection.
Vendors, Consultants, and Other Third-Party Service Providers. We may share your data with third-party vendors, service providers,contractors, or agents ("third parties") who perform services for us or on our behalf and require access to such information to do that work. We have contracts in place with our third parties, which are designed to help safeguard your personal information. This means that they cannot do anything with your personal information unless we have instructed them to do it. They will also not share your personal information with any organization apart from us. They also commit to protect the data they hold on our behalf and to retain it for the period we instruct.
The categories of third parties we may share personal information with areas as follows:
● User Account Registration & Authentication Services
● Cloud Computing Services
● Communication & Collaboration Tools
● Product Engineering & Design Tools
● Data Storage Service Providers
● Data analytics Services
● Finance and Accounting Tools
● Payment Processors
● Performance Monitoring Tools
● Sales and Marketing Tools
● AI Platforms
As Required by Law. We may access, preserve, and disclose your personal information if we believe doing so is required or appropriate to: (a) comply with law enforcement requests and legal process, such as a court order or subpoena; (b) respond to your requests; or (c) protect your, our, or others’ rights, property, or safety.
Merger, Sale, or Other Asset Transfers. We may transfer your personal information to service providers, advisors, potential transactional partners, or other third parties in connection with the consideration, negotiation, or completion of a corporate transaction in which we are acquired by or merged with another company or we sell, liquidate, or transfer all or a portion of our assets.
Aggregated or de-identified data. We may disclose or use aggregated or de-identified Information. For example, we may share aggregated or de-identified information with prospects or partners for business or research purposes.
Prohibition on re-identification. We do not permit any third party to, attempt to re-identify any de-identified, aggregated, or anonymized data or otherwise associate such data with an identifiable individual, household, or device.
5. DO WE USE COOKIES AND OTHER TRACKING TECHNOLOGIES?
We use cookies and other tracking technologies and offer you the option to manage these settings as described in our Cookie Policy. Some tracking technologies enable us to track your device activity over time and across devices and websites. While some browsers have incorporated Do Not Track or DNT preferences, we do not honor such signals from web browsers at this time.We do not knowingly collect, maintain, or use personal information from children under 13 years of age, and no parts of our Services are directed to children. If you learn that a child has provided us with personal information in violation of this Privacy Policy, then you may alert us at infosec@nooks.in.
6. DO WE OFFER AI-BASED PRODUCTS?
Our Services leverage AI to enhance sales productivity of sales professionals by transcribing conversations, summarizing key points, identifying follow-up actions, surfacing the right prospects at the right time, and offering in-the-moment coaching.
Nooks uses a combination of third-party AI tools and proprietary AI models to support key features of our Services. The third-party AI tools are considered as subprocessors who are bound by Data Processing Agreements (DPAs) to strict contractual obligations about information security standards including compliance with regulations, data confidentiality and data access control. Nooks subprocessors are contractually prohibited from using any data obtained from Nooks (including any de-identified, aggregated, or anonymized data derived therefrom), for the purposes of training, fine-tuning, or otherwise developing any artificial intelligence (AI), machine learning (ML), or large language models (LLMs), including general-purpose models.
No solely automated decisions are made by Nooks’ usage of third-party AI tools or proprietary AI models that produce legal or similarly significant effects for Users without human review.
In accordance with applicable laws, including the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA), as amended by the CPRA, we:
● Ensure that AI/ML systems processing personal data are subject to human oversight and periodic review.
● Conduct audits of AI outputs where they may have a material effect on individuals, to identify and mitigate bias, inaccuracies, or discriminatory patterns.
● Do not rely solely on automated decision-making that produces legal or similarly significant effects without appropriate safeguards, including human intervention, in line with GDPR Article 22.
● Provide individuals with the right to access, correct, and understand how their personal data may have been used in connection with AI-generated outputs, where required by law.
● Limit the use of sensitive personal information in AI processing to what is necessary, proportionate, and consistent with user preferences and applicable law.
You may contact us to learn more about how your data is used in connection with AI features, or to exercise your privacy rights, by emailing privacy@nooks.in
7. HOW LONG DO WE KEEP YOUR INFORMATION?
We will only keep your personal information for as long as it is necessary for legitimate interest as defined under GDPR Article 6(1)(f) , unless a longer retention period is required or permitted by law (such as tax, accounting, or other legal requirements).
When we have no ongoing legitimate interest or business need to process your personal information, we will either delete or anonymize such information. To the extent that this is not possible (for example, because your personal information has been stored in backup archives), then we will securely store your personal information and isolate it from any further processing until deletion is possible.
You may also opt out of the retention of your personal information by notifying us at privacy@nooks.in.
8. DO WE COLLECT INFORMATION FROM MINORS?
We do not knowingly collect, maintain, or use personal information from children under 16 years of age, and no parts of our Services are directed to children under 16. If you believe that we have collected information about a child under 16, please contact us by emailing privacy@nooks.in so that we may delete the information.
9. HOW DO WE KEEP YOUR INFORMATION SAFE?
We have implemented appropriate and reasonable technical and organizational security measures designed to protect the security of any personal information we process. However, despite our safeguards and efforts to secure your information, no electronic transmission over theI internet or information storage technology can be guaranteed to be 100% secure, so we cannot promise or guarantee that hackers, cybercriminals, or other unauthorized third parties will not be able to defeat our security and improperly collect, access, steal, or modify your information. Although we will do our best to protect your personal information, transmission of personal information to and from our Services is at your own risk. You should only access our Services within a secure environment.
10. SUPPLEMENTAL INFORMATION FOR THE EEA, SWITZERLAND, AND THE U.K.
Legal Basis for Processing: Please see Section 3 for the legal basis on which we rely for the collection, processing, and use of personal data.
Your Data Protection Rights: Under applicable data protection laws, you may exercise certain rights regarding your personal data.
● Right to Access. You have the right to obtain confirmation from us whether we are processing your personal data and related information, as well as the right to obtain a copy of your personal data undergoing processing.
● Right to Data Portability. You may receive your personal data, that you have provided to us, in a structured, commonly-used, and machine-readable format, and you may have the right to transmit it to other data controllers without hindrance. This right only exists if the processing is based on your consent or a contract, and the processing is carried out by automated means.
● Right to Rectification. You have the right to request the rectification of inaccurate personal data and to have incomplete data completed.
● Right to Objection. You have the right to object to the processing of your personal data in certain cases.
● Right to Restrict Processing. You may request that we restrict the processing of your personal data in certain cases.
● Right to Erasure. You may request that we erase your personal data in certain cases.
● Right to Lodge a Complaint. If you believe we are unlawfully processing your personal information, you also have the right to complain to your Member State data protection authority or UK data protection authority. If you are located in Switzerland, you may contact the Federal Data Protection and Information Commissioner.
● Right to Refuse or Withdraw Consent. In case we ask for your consent to process your personal data, you are free to refuse to give it. If you have given your consent, you may withdraw it at any time without any adverse consequences. The lawfulness of any processing of your personal data that occurred prior to the withdrawal of your consent will not be affected.
● Right to Not Be Subject to Automated Decision-making. The types of automated decision-making referred to in Article 22(1) and (4) EU/UK General Data Protection Regulation (“GDPR”) do not take place in connection with your personal data. Should this change, we will inform you about why and how any such decision was made, the significance of it, and the possible consequences of it. You will also have the right to human intervention, to express your point of view, and to contest the decision.
You may exercise these rights by contacting us using the details provided below. Please note that we may refuse to act on requests to exercise data protection rights in certain cases, such as where providing access might infringe someone else’s privacy rights or impact our legal obligations.
International Transfers of Personal Data
Our servers are located in the United States. If you are accessing our Services from outside the United States, please be aware that your information may be transferred to, stored by, and processed by us in our facilities and in the facilities of the third parties with whom we may share your personal information (see Section 4 - WHEN AND WITH WHOM DO WE SHARE YOUR PERSONAL INFORMATION? above), in the United States, and other countries.If you are a resident in the European Economic Area (EEA), United Kingdom (UK), or Switzerland, then these countries may not necessarily have data protection laws or other similar laws as comprehensive as those in your country. However, we will take all necessary measures to protect your personal information in accordance with this Privacy Notice and applicable law.
We have implemented measures to protect your personal information,including by using the European Commission's Module 2 of Standard Contractual Clauses and UK International Data Transfer Addendum and Swiss Addendum to the EU SCCs (as applicable) for transfers of personal information between our group companies and between us and our third-party providers. These clauses require all recipients to protect all personal information that they process originating from the EEA or UK in accordance with European data protection laws and regulations. Our Standard Contractual Clauses can be provided upon request via email to privacy@nooks.in. We have implemented similar appropriate safeguards with our third-party service providers and partners and further details can be provided upon request.
Before transferring personal data under these clauses, we perform a Transfer Impact Assessment (TIA) to evaluate the legal environment of the destination country and assess whether additional safeguards are needed. Where necessary, we implement supplementary measures such as data encryption, pseudonymization, and strict access controls to ensure your personal data remains protected.
You may request more information about our international transfer safeguards by contacting us at: privacy@nooks.in.
EU/ UK Representative
The contact details for our EU Representative for GDPR purposes are as follows:
Adam Brogden, Instant EU GDPR Representative Ltd
Email: contact@gdprlocal.com
Tel: + 353 15 549 700
Address: INSTANT EU GDPR REPRESENTATIVE LIMITED Office 2 12A Lower Main Street, Lucan Co. Dublin K78 X5P8 Ireland
Reporting Link: https://nookscommunicationsinc.gdprlocal.com/eu
The contact details for our UK Representative for GDPR purposes are as follows:
Adam Brogden, GDPRLocal Ltd.
Email: contact@gdprlocal.com
Tel: + 441 772 217 800
Address: GDPRLocal Ltd. 1st Floor Front Suite 27-29 North Street, Brighton England BN1 1EB
Reporting Link: https://nookscommunicationsinc.gdprlocal.com/uk
11. SUPPLEMENTAL INFORMATION FOR CALIFORNIA RESIDENTS
This section provides additional details about the personal information Nooks collects about California consumers and the rights afforded to them under the California Consumer Privacy Act, as amended by the California Privacy Rights Act or “CCPA.”
For more details about the personal information we have collected over the last 12 months, including the categories of sources, please see the Section 1 - WHAT INFORMATION DO WE COLLECT above. Nooks collects this information for the business and commercial purposes described in Section 2 - HOW WE PROCESS YOUR INFORMATION above. Nooks shares this information with the categories of third parties described in Section 4 - WHEN AND WITH WHOM DO WE SHARE YOUR PERSONAL INFORMATION.
Subject to certain limitations, the CCPA also provides California consumers the right to request to know more details about the categories or specific pieces of personal information Nooks collects (including how Nooks uses and disclose this information), to delete their personal information, correct their personal information that may be occurring, and to not be discriminated against for exercising these rights. Please also note that Nooks does not collect sensitive personal information as defined under the CCPA & CPRA, except for account login information, payment information and voice data as described in Section 1.
To the extent that Nooks collect Sensitive Personal Information (SPI) as defined in Cal. Civ. Code § 1798.140(ae) and other applicable law. We do not use SPI for purposes beyond those permitted without your consent.
As described in our Cookie Policy, we have incorporated Cookies from certain third parties into our Website. These Cookies allow those third parties to receive information about your activity on our Services that is associated with your browser or device. Those third parties may use that data to serve you relevant ads on our Website or on other websites you visit. Under the CCPA, sharing your data through third party Cookies for online advertising may be considered a “sale” or “share” of information, to which you have the right to opt out. You can opt out of these activities by following the instructions in this section.
We may “sell” or share your Personal Data to the following categories of third parties:
● Analytics providers
● Marketing providers
Over the past 12 months, we may have “sold” the following categories of your Personal Data to categories of third parties listed above:
● Usage Information
● Cookie Information
We have “sold” or shared the foregoing categories of Personal Data for the following business or commercial purposes:
● Improving the Services, including testing, research, internal analytics and product development.
● Showing you advertisements, including interest-based or online behavioral advertising.
You have the right to opt-out of the “sale” or sharing of your Personal Data. You can opt-out using the following methods:
● Accessing your Cookie consent settings in our website footer.
● By implementing the Global Privacy Control (“GPC”) or similar control that is legally recognized by a government agency or industry standard and that complies with the CCPA. We recognize and honor GPC signals in accordance with CPRA. GPC is a browser-based signal that allows you to communicate your privacy preferences—specifically your choice to opt out of the sale or sharing of your personal information—without having to make an individual request through our website. When we detect a GPC signal from your browser or device, we will automatically apply it as a request to opt out of the sale and sharing of personal information for that browser or device, consistent with applicable law. This opt-out applies to data shared through cookies, tracking technologies, and similar tools used for advertising and analytics. The signal issued by the control must be initiated by your browser and applies to the specific device and browser you use at the time you cast the signal. Please note this does not include Do Not Track signals.
Once you have submitted an opt-out request, we will not ask you to reauthorize the sale of your Personal Data for at least 12 months.
To our knowledge, we do not sell the Personal Data of minors under 16 years of age.
California consumers may make all other requests to access, correct, or delete pursuant to their rights under the CCPA by contacting us at privacy@nooks.in, or by mailing us at:
Nooks.ai
Attn: Privacy Team,
350 Bush Street 8th Floor, San Francisco, CA 94104
We will verify your request using the information associated with your account, including email address. Government identification may be required. Consumers can also designate an authorized agent to exercise these rights on their behalf.
12. DO WE MAKE UPDATES TO THIS NOTICE?
We may update this Privacy Notice from time to time. The updated version will be indicated by an updated "Effective" date at the top of this Privacy Notice. If we make material changes to this Privacy Notice, we may notify you either by prominently posting a notice of such changes or by directly sending you a notification. We encourage you to review this Privacy Notice frequently to be informed of how we are protecting your information.
13. HOW CAN YOU CONTACT US?
If you have questions or complaints regarding this Notice or about the Nooks’ privacy practices, please contact us by email at privacy@nooks.in, or at:
Nooks.ai
Attn: Privacy Team,
350 Bush Street 8th Floor, San Francisco, CA 94104
Last reviewed September 24, 2025.