Nanobase AI builds enterprise AI systems and the EasyMeeting meeting assistant. This policy explains what personal data we collect through this website and through EasyMeeting when we host it, why we collect it, how long we keep it, where it is processed and what rights you have. We keep it short and specific on purpose: if something is not listed here, we do not do it.
This policy is published in ten languages. If a translation differs from the English text, the English text applies.
1. Who we are
Nanobase AI is an enterprise AI engineering company with its engineering headquarters in Silicon Valley, California, and its corporate office in Delaware, USA. For the purposes of data protection law, Nanobase AI is the controller of the personal data described in sections 3 and 4, and the processor of customer data described in section 5.
You can reach us at hello@bumu.tech for anything in this policy.
2. What this policy covers
It covers the website nanobase.ai in all its languages, the contact and demo request forms on it, and the EasyMeeting service when Nanobase AI hosts it for a customer (Team and Enterprise plans). When EasyMeeting runs on a customer's own infrastructure (On-Premise plan), Nanobase AI does not receive, store or access any meeting content, and only section 3 of this policy applies to that customer's contact with us.
3. Data we collect on the website
The website sets no cookies and loads no advertising or third-party tracking scripts. Your language choice may be stored in your browser's local storage so the site opens in the same language next time; that value never leaves your device.
When you use a contact or demo form, we receive what you type: typically your name, work email address, company and message. We use it only to answer you and to prepare the proposal or pilot you asked for.
Our hosting provider keeps standard server logs (IP address, browser type, requested page, time) for security and capacity management. These logs are kept for a limited period and are not combined with form submissions.
4. Data we hold about customers
When an organisation buys an EasyMeeting plan or an engineering engagement, we hold the business contact details of the people we work with (name, role, work email, phone), the contract, invoices and support correspondence. We process this data to perform the contract, to bill, to provide support and to meet our legal and accounting obligations.
5. EasyMeeting meeting data
When we host EasyMeeting, the recordings, transcripts, summaries, action items and calendar information it handles belong to the customer. We process them only on the customer's documented instructions, as a processor, under a data processing agreement that is part of the subscription terms.
EasyMeeting always joins a meeting as a visible participant. Notifying participants that a meeting is recorded, and obtaining any consent required by the laws that apply to them, is the customer's responsibility as the organiser of the meeting.
Meeting data is stored in the region the customer selects at sign-up (United States, European Union or Türkiye), encrypted in transit and at rest. It is retained for as long as the customer's retention settings specify and deleted when a meeting, a workspace or the subscription is deleted. Meeting content is never used to train models that serve other customers.
6. Legal bases
Where the GDPR or a similar law applies, we rely on the performance of a contract (customer and subscription data), our legitimate interest in running a secure website and answering enquiries (server logs, form submissions), and legal obligations (invoicing and accounting records). Where a law requires consent for a specific processing activity, we ask for it separately and you can withdraw it at any time.
8. International transfers
Nanobase AI is a United States company. Where personal data from the European Economic Area, the United Kingdom, Switzerland or Türkiye is transferred to the United States, we rely on the European Commission's Standard Contractual Clauses and the UK Addendum, together with the technical measures in section 10. Enterprise customers can choose EU or Türkiye data residency so that meeting content never leaves that region; On-Premise customers keep everything inside their own network.
9. How long we keep data
- Contact and demo requests: 24 months after our last exchange, then deleted.
- Customer contract, billing and accounting records: the period required by tax and commercial law, typically 7 years.
- Server logs: at most 90 days.
- EasyMeeting meeting data: as configured by the customer; deleted within 30 days after the subscription ends, or immediately on request.
10. Security
We encrypt data in transit and at rest, restrict access on a need-to-know basis with single sign-on and role-based permissions, keep audit logs of access to customer data, and test our own systems the way we test our customers' systems. EasyMeeting is designed to support GDPR, KVKK, HIPAA and SOC 2 obligations; the specific controls that apply to a deployment are set out in the customer's order form.
11. Your rights
Depending on where you live you may have the right to access the personal data we hold about you, to correct or delete it, to restrict or object to its processing, to receive it in a portable format, and to withdraw consent. Residents of California have the rights set out in the CCPA, including the right to know and the right to delete; we do not sell or share personal data as those terms are defined there. Data subjects in Türkiye have the rights set out in article 11 of the KVKK.
To exercise any right, email hello@bumu.tech. We answer within 30 days. If you are an EasyMeeting meeting participant and your request concerns meeting content, we will forward it to the customer that controls that data, because only they can act on it. You also have the right to lodge a complaint with your data protection authority.
12. Children
Our website and services are intended for businesses and are not directed at children under 16. We do not knowingly collect personal data from them.
13. Changes to this policy
We update this policy when our practices change. The date at the top shows the current version. For material changes affecting EasyMeeting customers we give at least 30 days' notice by email.
14. Contact
Nanobase AI, Delaware, USA. Email: hello@bumu.tech. Please write "Privacy" in the subject line so we can route your message quickly.