LEGAL

Privacy Policy

Nathan Digital Privacy Policy

Published and effective on: 23 June 2026

1.Introduction

This Privacy Policy describes how Nathan Digital ("Nathan Digital", "we", "us", "our") collects, uses, discloses and protects Personal Information / Personal Data in connection with Services & Products, including:

  • Software-as-a-service ("SaaS") offerings ("Subscription Services") and ancillary Professional and Consulting Services;
  • Standalone Professional and Consulting Services; and
  • Ad hoc/custom Software Development and Consulting Services;

as more fully set out in the General Terms and Service Specific Terms.

Our role and obligations may differ depending on the nature of the Services provided.

We are committed to processing Personal Information lawfully, transparently and securely in accordance with Applicable Data Protection Laws.

This Privacy Policy must be read together with:

  • General Terms and Service Specific Terms;
  • Any Data Processing Agreement ("DPA"), if applicable;

In case of conflict between the Applicable Data Protection Laws and this Privacy Policy, the Applicable Data Protection Laws will prevail.

2.Scope and Application

This Privacy Policy applies to:

  • Customers and prospective customers;
  • representatives and personnel of Customers;
  • contractors, suppliers and partners;
  • Website and Platform Users; and
  • individuals whose Personal Information is processed by us.

You accept all the terms in this Privacy Policy when you use our Services & Products and consent to us collecting the Personal Information/Personal Data as referred to in this Privacy Policy.

3.Roles: Controller and Processor

We act in the capacity of Data Controller and Data Processor depending on the context of processing Personal Information (PI) or Personal Data (PD). These roles are exercised in accordance with applicable jurisdiction-specific laws and internal policies aligned with ISO 27001, ISO 42001, ISO 9001, and SOC 2 Type II controls.

3.aController / Responsible Party

We act as Controller/Responsible Party when determining the purpose, manner, and means of processing Personal Information/Personal Data for:

  • Customer relationship management;
  • Billing and administration;
  • Marketing and business development;
  • Finance and compliance;
  • Platform analytics and security;
  • Internal business operations.

Our responsibilities as Controller entails:

  • Implementing measures to ensure data minimization, accuracy, and purpose limitation.
  • Maintaining internal records of processing activities in compliance with jurisdiction-specific regulatory requirements.
  • Ensuring data subject rights can be exercised, including access, rectification, erasure, restriction, objection, and portability.
  • Conducting risk assessments aligned with ISO 27001 and ISO 42001 for AI processing and IT systems handling Personal Data.

3.bProcessor / Operator

We act as Processor/Operator when processing Personal Data on behalf of clients or third parties, including:

  • hosting or processing Customer Data through the Platform as part of the Subscription Services;
  • delivering Consulting Services involving Customer Data;
  • performing Software Development Services using Customer Datasets.

Our responsibilities as Processor entails:

  • Following client instructions and only processing data within agreed purposes.
  • Implementing technical and organizational safeguards to protect Personal Data against unauthorized access, disclosure, or alteration.
  • Ensuring sub-processors are contractually obligated to comply with privacy, confidentiality, and security obligations.
  • Maintaining audit logs, monitoring, and incident response for processing activities.
  • Supporting data subject rights and regulatory inquiries on behalf of the Controller.

In such cases:

  • we act only on documented instructions;
  • a DPA governs processing; and
  • the Customer remains the Controller and is therefore responsible for lawful disclosure of Personal Information/Personal Data provided to us for Services.

4.Personal Information/Data We Collect

We collect only Personal Information necessary for defined business purposes, which may include:

4.aCustomer Information

  • Name and surname/legal entity details and registration information
  • Email and contact details
  • Physical and postal address
  • Tax and VAT numbers
  • Billing and other contractual information

4.bSubscription Service Data

  • User Account Data
  • Authentication credentials
  • Usage logs
  • Customer-uploaded datasets

4.cProfessional Services Data

  • Organisational and operational Data
  • Employee Data
  • Communications and project documentation

4.dDevelopment Data

  • Test datasets
  • Debugging logs
  • Staging environment Data

4.eTechnical Data

  • IP addresses
  • Device/browser information
  • Cookies and analytics

We process Special Category Data only where legally permitted.

5.Sources of Personal Information/Personal Data

We obtain Personal Information/Personal Data:

  • directly from individuals;
  • from Customer organisations;
  • via use of the Platform;
  • from third parties and service providers;
  • from publicly available sources;
  • from regulators or legal proceedings.

We take reasonably practicable steps to maintain accurate and up-to-date information.

6.Sensitive Personal Information

We ask that you do not send us, and do not share any sensitive personal information (for example, government-issued IDs, information related to racial or ethnic origin, political opinions, religion or other beliefs, health, genetic, or biometric data, criminal background or trade union membership).

7.Children's Privacy

Our sites are not directed to minors and Nathan Digital does not promote or market its services to minors. If you believe that we have mistakenly or unintentionally collected personal information of a minor through our sites without appropriate consent, please notify us so that we may immediately delete the information from our servers and make any other necessary corrections.

We process Personal Information/Personal Data for the following purposes:

8.aSaaS Platform Operation

  • Account management
  • Subscription Service delivery
  • System performance

Legal basis: contract/processor role

8.bDelivery of Professional and Consulting Services

  • Delivery of Services;
  • Legitimate interests;
  • Customer instructions (Processor role).

Legal basis: contract / processor role

8.cSoftware Development

  • System design and testing
  • Debugging and deployment

Legal basis: contract

8.dCustomer Relationship Management

  • Finance, compliance, governance

Legal basis: legal obligations, legitimate interests

8.eMarketing and Business Development

  • Communications and outreach

Legal basis: consent or legitimate interests (B2B)

We do not rely solely on consent unless legally required.

Failure to provide the required Personal Information/Personal Data may prevent us from delivering Services or fulfilling legal obligations.

9.Customer Data (Processor Clause)

Where Customers upload or provide Personal Information/Personal Data:

  • the Customer acts as Controller;
  • we act as Processor/Operator;
  • Processing occurs only under written instructions; and
  • a DPA governs such processing.

Customers are responsible for:

  • lawful collection of Data;
  • obtaining required consents; and
  • ensuring accuracy.

10.Sharing of Personal Information/Personal Data

We will keep your Personal Information/Personal Data confidential and only share it with others in terms of this Privacy Policy if you consent to it, or if the Applicable Laws require us to share it.

10.bTrusted Third-Party Service Providers

We have trusted relationships with carefully selected third parties who perform services for us. These service providers are bound by contractual obligations to:

  • Protect Personal Information/Personal Data with the same level of security and confidentiality that Nathan Digital applies.
  • Use the data solely for the purposes approved by Nathan Digital.

Our website may connect to various social media sites or apps, including Facebook, X, LinkedIn and Instagram. Any Personal Information/Personal Data shared via these platforms will be handled in accordance with the terms of this Privacy Policy and applicable data protection laws.

11.Sub-processors and Disclosure

We may engage sub-processors, including:

  • cloud hosting providers;
  • IT and infrastructure providers; and
  • subcontractors and consultants.

All sub-processors are subject to:

  • contractual Data protection obligations;
  • confidentiality requirements; and
  • security controls.

12.Cross-Border Transfers

Personal Information/Personal Data may be transferred to systems or service providers located across the Jurisdictions. Where required, we implement appropriate safeguards, including:

  • adequacy decisions (where applicable);
  • standard contractual clauses (SCCs);
  • Data Protection Law-compliant transfer mechanisms;
  • contractual confidentiality protections.

13.Information Security

We implement appropriate technical and organisational measures to protect Personal Information/Personal Data against loss, unauthorised access, destruction or unlawful processing. Measures are designed to align with ISO 27001, ISO 42001, SOC 2 Type II, and applicable data protection laws, and may include:

  • role-based access controls;
  • encryption where appropriate;
  • secure cloud infrastructure;
  • monitoring and incident detection;
  • staff confidentiality obligations;
  • vendor risk management;
  • incident response procedures; and
  • periodic security reviews.

While absolute security cannot be guaranteed, we maintain safeguards aligned with generally accepted information security practices.

See our Information Security Statement for more information.

14.Storage

We will store your Personal Information/Personal Data through cloud storage providers in highly secure data centres.

Backup copies are maintained for operational continuity, securely encrypted, and periodically tested.

We will keep your Personal Information/Personal Data until you direct us, or we are directed by the law, to delete your Personal Information/Personal Data.

15.Retention

We retain Personal Information/Personal Data only as long as necessary to fulfil the purposes as explicitly set out in this Privacy Policy, depending on the type of Service:

  • Subscription Service Data: duration of Subscription Term and deletion cycles
  • Consulting and Professional Services Data: project lifecycle and legal retention
  • Development Data: project lifecycle and technical needs.

16.Secure Disposal

Once retention is no longer justified, Personal Information/Personal Data is securely deleted, destroyed, or de-identified. All disposal processes ensure that the data cannot be reconstructed or misused, following best practices for digital and physical data destruction.

17.Automated Decision-Making

We do not make decisions producing legal or similarly significant effects based solely on automated processing. If this changes, we will provide the required disclosures and safeguards.

18.Disclosure of Personal Information

We may disclose Personal Information to:

  • subcontracted consultants;
  • cloud hosting and IT service providers;
  • professional advisers and auditors;
  • regulators and authorities;
  • payment processors; and
  • affiliated entities.

All recipients are subject to confidentiality and Data protection obligations.

We do not sell Personal Information/Personal Data.

19.Data Breach Management

In the event of a Personal Information/Personal Data breach, we will:

  • investigate and contain the incident;
  • notify affected individuals and Customers where required;
  • notify regulators within statutory timeframes;
  • implement remediation measures; and
  • document as part of ISMS and AIMS audit records.

In the event of a suspected or confirmed data breach, report immediately to dpo@nathan.com.

20.Your Rights

Subject to Applicable Data Protection Laws, individuals may have the right to:

  • be informed about the collection of Personal Information/Personal Data;
  • access Personal Information/Personal Data;
  • request correction or deletion of Personal Information/Personal Data;
  • object to Processing Personal Information/Personal Data;
  • withdraw consent where applicable;
  • restrict or oppose direct marketing;
  • request Data portability (where applicable);
  • avoid solely automated decisions with significant effects; and
  • lodge complaints with supervisory authorities.

Any requests or objections can be submitted to the Information Officer / Data Protection Contact, as provided in the Contact Details section below.

21.Direct Marketing

We would like to send you information about the Services & Products that we think you might like.

If you have agreed to receive marketing, you may always opt out at a later date.

You have the right at any time to stop us from contacting you for marketing purposes or giving your Personal Information/Personal Data to any of our affiliates.

See our Cookies Policy on how we manage cookies.

If you no longer wish to be contacted for marketing purposes, contact us.

22.Contact Details

For inquiries or to exercise your data privacy rights, contact us at dpo@nathan.com.

23.Policy Updates

We may update this Privacy Policy from time to time, in order to clarify it, to reflect any changes to our website, or to comply with legal obligations. The "Last Updated" mention at the top of the policy indicates the last revision, which is also the effective date of those changes.

24.Complaints

If you have any complaints regarding our compliance with this Privacy Policy, please contact us. We will investigate and attempt to resolve complaints and disputes regarding use and disclosure of personal information in accordance with this Privacy Policy and in accordance with applicable law. You also have the right to file a complaint with a competent data protection authority in the relevant jurisdiction.