Privacy Policy

Effective Date: August 7,2026  Last Updated: August 7, 2026

Hyper Nimbus, Inc. ("Hyper Nimbus," "we," "us," or "our") provides AI-powered software platforms for businesses and government organizations. This Privacy Policy describes how we collect, use, and disclose personal information when you visit our websites (including hypernimbus.ai), create an account, use our products and services (the "Services"), or otherwise interact with us.

An important distinction. This Privacy Policy covers personal information that Hyper Nimbus handles as a "controller" — information about our website visitors, prospective customers, account holders, and business contacts. When our customers use the Services to process data about their own guests, employees, vendors, or constituents ("Customer Data"), we process that information as a "processor" or "service provider" on the customer’s behalf and on their instructions. Our handling of Customer Data is governed by our agreements with those customers, including any applicable Data Processing Addendum — not by this Privacy Policy. If you have questions about how an organization that uses Hyper Nimbus handles your information, please contact that organization directly.

1. Information We Collect

Information you provide to us:Account and contact information — name, email address, phone number, company name, job title, and password when you create an account, request a demo, or contact us.
Billing information — billing address and payment details. Payments are processed by our third-party payment processor (Stripe); we do not store full payment card numbers.
Communications — information you provide when you contact support, respond to surveys, or communicate with us by email, phone, or through the Services.
Inputs and prompts — content you submit to the Services in the course of using them, which may be Customer Data processed on behalf of your organization as described above.

Information we collect automatically:
Usage and log data
— IP address, browser type, device identifiers, operating system, pages viewed, features used, timestamps, and referring URLs.
Cookies and similar technologies — as described in Section 6 below.
Information from other sources: we may receive information from business partners, resellers, publicly available sources, and service providers that help us with marketing, analytics, and fraud prevention.

2. How We Use Personal Information

We use personal information to:
- provide, maintain, secure, and improve the Services;
- create and administer accounts, process payments, and send transactional communications such as invoices, service announcements, and security alerts;
- respond to inquiries and provide customer support;
- send marketing communications about our products, features, and events, which you can opt out of at any time;
- monitor and analyze usage and trends, and develop new products and features, including through the use of aggregated and de-identified data;
- detect, investigate, and prevent fraud, abuse, security incidents, and violations of our terms and policies; and
- comply with legal obligations and enforce our agreements.

AI model training. We do not use Customer Data to train generalized AI models without the customer’s prior written consent. We may use aggregated, de-identified data derived from the Services to improve our products, services, models, and systems, provided such data does not identify any customer or individual.

3. How We Disclose Personal Information

We disclose personal information to:
Service providers and subprocessors — vendors that perform services on our behalf, such as cloud hosting, payment processing (Stripe), analytics, customer support tooling, and email delivery, under contracts that restrict their use of the information.
Professional advisors — lawyers, accountants, auditors, and insurers where necessary.Legal and safety — government authorities or other parties where required by law, or where we believe disclosure is reasonably necessary to protect the rights, property, or safety of Hyper Nimbus, our customers, or others.
Business transfers — in connection with a merger, acquisition, financing, or sale of all or part of our business, subject to standard confidentiality protections.

We do not sell personal information, and we do not share personal information for cross-context behavioral advertising as those terms are defined under California law.

4. Data Retention

We retain personal information for as long as needed to provide the Services, comply with legal obligations, resolve disputes, and enforce agreements. Retention periods vary based on the type of information and the purposes for which it is used. Customer Data is retained in accordance with our agreements with the applicable customer, including the post-termination export and deletion commitments in our Terms of Service.

5. Security

We implement and maintain commercially reasonable administrative, technical, and physical safeguards designed to protect personal information, including logical segregation of customer environments, access controls, and encryption in transit. Our security program is designed in alignment with recognized industry frameworks, including PCI DSS v4.0 and SOC 2, and we are actively pursuing formal attestation and certification under these frameworks. No system is completely secure, and we cannot guarantee the absolute security of your information.

6. Cookies and Analytics

We use cookies and similar technologies to operate our websites and Services, remember preferences, maintain sessions, and understand how our websites are used. You can control cookies through your browser settings; disabling certain cookies may affect the functionality of the Services.

7. Your Privacy Rights

Depending on where you live, you may have rights regarding your personal information, including the right to access, correct, delete, or receive a copy of your personal information, and the right to opt out of marketing communications.

California residents. If you are a California resident, the California Consumer Privacy Act (CCPA) gives you the right to know what personal information we collect and how we use and disclose it (as described in this Policy), the right to access, correct, and delete your personal information, and the right not to be discriminated against for exercising these rights. As stated above, we do not sell or share personal information as defined by the CCPA. You may exercise these rights by contacting us as described in Section 11, and you may designate an authorized agent to act on your behalf.

Outside the United States. If you are located in a jurisdiction with data protection laws (such as the EEA or United Kingdom), you may have additional rights, including the rights to object to or restrict certain processing and to lodge a complaint with your supervisory authority. Where those laws apply, our legal bases for processing include performance of a contract, legitimate interests, consent, and compliance with legal obligations.

To exercise any of these rights, contact us using the details in Section 11. We may need to verify your identity before responding. We will not discriminate against you for exercising your rights.

8. International Data Transfers

We are based in the United States and process information on servers located in the United States and other jurisdictions. Where we transfer personal information from a jurisdiction with data transfer restrictions, we use appropriate safeguards, such as standard contractual clauses, as required by applicable law.

9. Children

The Services are intended for business use by adults. We do not knowingly collect personal information from anyone under 18. If you believe a person under 18 has provided us personal information, please contact us and we will take appropriate steps to delete it.

10. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by posting the updated Policy on our website with a new "Last Updated" date and, where appropriate, by additional notice such as email. Your continued use of the Services after the effective date constitutes acceptance of the updated Policy.

11. Contact Us

If you have questions about this Privacy Policy or our privacy practices, or wish to exercise your privacy rights, contact us at:

Hyper Nimbus, Inc.
23838 Pacific Coast Highway,
PO 325,
Malibu, CA 90265

Email: privacy@hypernimbus.ai

Questions about these Terms: privacy@hypernimbus.ai