Privacy Policy
Last updated: August 15, 2026 · Effective for nifi.us and all NIFI products and services
1. Introduction
This Privacy Policy describes how NIFI (“NIFI”, “we”, “us”, “our”) collects, uses, stores, encrypts, and otherwise processes information when you visit nifi.us, create an account, use NIFI software products, or contact us for sales, onboarding, or support.
We design our platform to meet internationally recognized privacy and security expectations, including principles drawn from the EU General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act as amended by the CPRA (CCPA), Vietnam’s Decree 13/2023/ND-CP on personal data protection, ISO/IEC 27001 information security management practices, and SOC 2–aligned operational controls.
If you do not agree with this Policy, do not use the services. By using NIFI, you acknowledge the practices described here. Our Terms of Service govern the contractual relationship.
2. Who we are and what this Policy covers
NIFI operates an interconnected suite of business applications and professional services. This Policy covers the public portal nifi.us and product applications including, without limitation: niTel (PMS), niUp (CRM), niGo (fleet), niPOS (F&B), niPages (CMS), niTask (project management), niTeam (HRM), niLogix (WMS), niFinly (finance), Lexfi (CLM), Sella (sales operations agent), CaliNi (calendar UI), niHub (central management), and NiOps AI (operations assistant), together with related websites, APIs, desktop/Tauri clients, and support channels.
For workspace (tenant) data, your organization is typically the data controller (or equivalent) of business records entered into the products. NIFI acts as a processor / service provider on that organization’s documented instructions, except where we determine purposes and means ourselves (for example, account security, billing, product telemetry needed to run the platform, and this website).
3. Information we collect
3.1 Account and identity data
When you register or sign in we may collect name, email address, username, phone number, password hashes (never stored in reversible plaintext), authentication identifiers, organization / company name, job title, and billing contacts. If you use OAuth (Google, Apple, GitHub, or similar), we receive the identifiers the provider shares with your consent.
3.2 Personal data of end customers (your records)
Depending on the product you use, you or your staff may enter guest, passenger, patient, employee, supplier, or consumer records (names, contact details, identity documents, stay/order history, payroll fields, and similar). That content belongs to your organization. We host and process it solely to provide the contracted service.
3.3 Corporate and commercial data
We process business information such as invoices, inventory, contracts, warehouse movements, CRM deals, workspace configuration, roles, and audit logs. We treat this as confidential customer data, not as a marketing asset.
3.4 Technical, security, and usage data
We collect device and browser type, IP address, approximate location derived from IP, session tokens, diagnostic logs, feature usage needed to operate and secure the service, and crash/error reports. We use this to authenticate users, detect abuse, and keep systems available.
3.5 Communications
Messages you send to sales or support, meeting notes you ask us to keep, and partnership inquiries are retained as needed to respond and to maintain the customer relationship.
We do not knowingly collect data from children under 16. The services are B2B tools.
4. Legal bases for processing (GDPR and similar laws)
Where a legal basis is required, we rely on one or more of the following:
- Contract: to create accounts, deliver the products you subscribed to, and provide support.
- Legitimate interests: to secure the platform, prevent fraud, improve reliability, and communicate service-critical notices — balanced against your rights.
- Legal obligation: tax, accounting, lawful requests, and mandatory retention.
- Consent: where required (for example certain cookies or optional marketing). You may withdraw consent without affecting prior lawful processing.
5. How we use information
- Provide, maintain, host, and improve NIFI products and nifi.us
- Authenticate users, enforce roles, and protect accounts and workspaces
- Process subscriptions, invoices, and related finance operations
- Deliver customer support and operational notifications
- Detect, investigate, and prevent security incidents, abuse, and fraud
- Comply with law and enforce our Terms of Service
We do not use customer personal or corporate records to train public generative-AI models for unrelated third parties. Product AI features (for example NiOps AI or Sella) operate on the workspace data you choose to process, under the security controls in Section 6.
6. Encryption and AWS security controls
All sensitive personal data and all sensitive corporate / enterprise data processed by NIFI is encrypted using Amazon Web Services (AWS). We do not store this class of data in unprotected cleartext on production systems.
- In transit: connections to NIFI applications and APIs use TLS (HTTPS). Internal service traffic is encrypted in line with AWS networking controls.
- At rest: databases, object storage, backups, and volumes that hold personal or corporate records are encrypted with AWS encryption services, including AWS Key Management Service (KMS) and server-side encryption on AWS storage (for example Amazon S3, Amazon RDS / equivalent managed databases, and encrypted EBS volumes).
- Key management: cryptographic keys are managed in AWS KMS under NIFI-controlled IAM policies. Access to decrypt production data is limited to authorized operational roles and is logged.
- Access control: least-privilege IAM, workspace-scoped application roles, and authentication (including optional multi-factor authentication) restrict who can read customer data.
- Isolation: tenant data is logically separated by workspace / user-nifi-service boundaries. Operators do not browse customer records as a matter of routine.
These measures implement confidentiality, integrity, and availability controls consistent with ISO/IEC 27001 and industry cloud-security practice. No encryption scheme eliminates all risk; you remain responsible for endpoint security, staff credentials, and the lawfulness of data you upload.
7. We do not provide your data to third parties
NIFI does not sell, rent, trade, barter, or otherwise provide personal data or corporate data to third parties for their own marketing, profiling, advertising, data-brokerage, or independent commercial use. We do not operate a data marketplace. We do not hand customer databases to partners, affiliates, or “ecosystem” vendors for them to exploit.
In particular we do not disclose guest lists, employee files, invoices, contracts, CRM pipelines, or similar business records to any outside organization except as strictly necessary to run the encrypted AWS infrastructure under our control, or as described in Section 8 (narrow, exceptional cases).
AWS is our infrastructure provider. Customer data stays in NIFI-operated AWS accounts. AWS does not receive a license to use your content for its own products. We do not grant advertisers, social networks, or analytics resellers access to your production datasets.
8. Exceptional disclosures
We may disclose information only when one of the following applies:
- Your organization: workspace administrators and users you authorize already have access under your own roles.
- You instruct us: for example an export you request, or a migration you contract.
- Lawful compulsion: a binding court order, warrant, or equivalent legal process. We will narrow the request where legally permitted and notify the customer unless prohibited.
- Imminent harm: to protect the rights, property, or safety of NIFI, our users, or the public, where we believe in good faith disclosure is necessary.
- Corporate transaction: merger or asset transfer, subject to this Policy continuing to protect the data.
Payment card details, if collected at checkout, are handled by the payment processor under PCI DSS; NIFI does not store full card PAN in application databases.
9. International transfers
We may process data in AWS regions selected for the service. Where data is transferred from the EEA, UK, or similar jurisdictions, we use appropriate safeguards such as Standard Contractual Clauses and the encryption and access controls in Section 6.
10. Retention
We keep account and workspace data for the life of the subscription and for a limited period afterward as needed for backups, dispute resolution, tax, and legal holds. When retention expires we delete or irreversibly anonymize data from production systems, subject to backup rotation. You may request earlier deletion of personal data we control, subject to legal exceptions.
11. Your rights
Depending on your location, you may have the right to access, correct, delete, or restrict personal data, to object to certain processing, to data portability, to withdraw consent, and to lodge a complaint with a supervisory authority. California residents may have additional rights to know, delete, and opt out of “sale” or “sharing” as those terms are defined under the CCPA — NIFI does not sell or share personal information as those terms are defined for advertising.
Workspace content is administered by your organization. Contact your administrator first. For data NIFI controls (portal accounts, billing contacts), email [email protected]. We will verify the request before acting.
12. Cookies and similar technologies
We use cookies and local storage for sign-in sessions, language, theme, CSRF/security, and essential load balancing. These are required for the portal and applications to function. We do not use third-party advertising cookies to profile you across unrelated sites. Blocking all cookies may prevent login.
13. Security incidents
We maintain monitoring, logging, and incident-response procedures. If a personal-data breach is likely to result in a high risk to individuals, we will notify affected customers and, where required, supervisory authorities, within the timeframes set by applicable law.
14. Contact
Privacy and data-protection questions: [email protected]
Policy URL: https://nifi.us/privacy
15. Changes
We may update this Policy when products, infrastructure, or law change. The current version is always published at this URL with a revised “Last updated” date. Material changes will be highlighted on this page or notified to account contacts where required. Continued use after the effective date constitutes acknowledgment of the update unless mandatory law requires additional consent.