Kyei Residential Ltd (“Kyei Residential,” “we,” “us,” or “our”) provides a business intelligence platform that connects to your company’s documents, tools, and third-party accounts to help you find information and generate insights (the “Service”). This Privacy Policy explains what information we collect, how we use it, who we share it with, and the choices you have.
By using the Service, you agree to the collection and use of information in accordance with this policy. If you do not agree, please do not use the Service.
1. Information We Collect
1.1 Information you provide directly
- Account information: name, email address, password (hashed), company/workspace name.
- Content you upload or connect: documents, spreadsheets, and files you upload to Nansa, and messages you send through the Service (including questions asked to Nansa’s AI features).
- Billing information: processed by our payment provider (Stripe); we do not store full card numbers.
1.2 Information from connected third-party accounts
When you choose to connect a third-party account, we access only the data necessary to provide the specific integration you enable, and only for as long as the connection remains active. Depending on which integrations you connect, this may include:
- Meta (Facebook and Instagram): your public profile, the Facebook Pages you manage, Page insights (impressions, reach, engagement, follower/fan counts), and, if applicable, the Instagram Business account linked to a connected Page and its account-level insights (reach, profile views, engagement, follower counts). We request only the minimum permissions needed (e.g. pages_show_list, pages_read_engagement, read_insights, instagram_basic, instagram_manage_insights) and only access data belonging to Pages and accounts you explicitly select and authorize during the Meta login flow.
- Google (Drive, Sheets, Docs, Analytics): file metadata and content from files you select, and website analytics metrics.
- Accounting tools (QuickBooks, Xero): invoices, customers, and related financial records.
- Email (Gmail): message metadata only — sender, subject, timestamp, and labels — used to power an inbox activity chart in your dashboard. We never read message bodies or content, and Nansa does not send email on your behalf.
- Other connectors you enable (e.g. Slack, Notion, Salesforce, GitHub, OneDrive): data from those services as scoped by the permissions you grant.
We access this data using OAuth, the industry-standard authorization protocol. You can revoke Nansa’s access at any time from the Integrations page inside the Service, or directly from the third-party provider’s own account settings (for example, Facebook’s “Business Integrations” settings for Meta).
1.3 Information collected automatically
- Usage data: pages visited, features used, timestamps, and general interaction data, collected to improve the Service.
- Device and log data: IP address, browser type, and operating system.
- Cookies and similar technologies, used for authentication and basic analytics.
2. How We Use Information
We use the information we collect to:
- Provide, operate, and maintain the Service, including syncing and displaying data from the third-party accounts you connect.
- Generate AI-powered summaries, insights, and answers based on your connected data and documents.
- Authenticate you and secure your account and workspace.
- Process payments and manage subscriptions.
- Send you service-related communications (such as daily briefings you’ve opted into, account notifications, and support responses).
- Monitor, debug, and improve the reliability and performance of the Service.
- Comply with legal obligations and enforce our Terms of Service.
We do not use data obtained through Meta’s APIs, or any other connected platform, for advertising purposes, and we do not sell your data or any Platform Data to third parties.
AI processing and Limited Use compliance: Nansa uses OpenAI’s API (not a consumer chat product) to generate summaries, insights, and answers from the data you connect. Per OpenAI’s API data usage policy, data submitted through the API is not used to train or improve OpenAI’s models. The use of raw or derived user data received from Google Workspace APIs (Gmail, Drive, Sheets, and Docs) will adhere to the Google API Services User Data Policy, including the Limited Use requirements: this data is never used to develop, train, or improve generalized or foundational AI/ML models, is never used for advertising, and is never sold to third parties.
3. How We Share Information
We do not sell your personal information. We share information only in the following circumstances:
- Within your workspace: data you connect or upload is visible to other authorized members of your workspace, consistent with your organization’s access settings.
- Service providers: we use trusted third-party subprocessors to operate the Service, including hosting (Railway), database and authentication (Supabase), AI processing (OpenAI), email delivery (Resend), and payments (Stripe). These providers are contractually bound to use data only to provide services to us and to protect it appropriately.
- Legal requirements: we may disclose information if required by law, subpoena, or other legal process, or to protect the rights, property, or safety of Nansa, our users, or others.
- Business transfers: if Nansa is involved in a merger, acquisition, or sale of assets, information may be transferred as part of that transaction, subject to this Privacy Policy.
4. Data Retention and Deletion
We retain your information for as long as your account is active or as needed to provide the Service. If you disconnect a third-party integration (such as a Meta/Facebook connection), we delete the associated access tokens immediately and stop syncing new data from that source; previously synced metrics remain in your workspace until you delete them or close your account.
You may request deletion of your account and associated data at any time by contacting us at privacy@nansa.io. We will delete or anonymize your information within 30 days of a verified request, except where retention is required by law.
5. Your Rights and Choices
Depending on your location, you may have the right to:
- Access, correct, or delete the personal information we hold about you.
- Withdraw consent for a specific data connection at any time by disconnecting it from the Integrations page.
- Object to or restrict certain processing of your information.
- Request a copy of your data in a portable format.
- Lodge a complaint with a relevant data protection authority.
To exercise any of these rights, contact us at privacy@nansa.io.
6. Data Security
We use industry-standard technical and organizational measures to protect your information, including encryption of data in transit (TLS) and encryption of sensitive credentials such as OAuth access tokens at rest. Access to customer data is restricted to authorized personnel who need it to operate and support the Service. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
7. International Data Transfers
Nansa may process and store information in countries other than your own. Where required, we rely on appropriate safeguards (such as standard contractual clauses) to protect information transferred internationally.
8. Children’s Privacy
The Service is intended for business use by adults and is not directed to individuals under 16. We do not knowingly collect personal information from children.
9. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or through the Service prior to the change becoming effective. The “Effective date” at the top of this page reflects the most recent revision.
10. Contact Us
If you have questions about this Privacy Policy or how we handle your data, contact us at:
Kyei Residential Ltd (company number 13693388), a private limited company registered in England and Wales
Email: privacy@nansa.io