Privacy Policy

Language

Privacy Policy and Personal Data Processing for Nala Customers

1. Introduction

Nala is a Software as a Service (SaaS) technology platform specialized in talent management, performance management, development, succession, organizational analytics, and other people-management processes within organizations.

The protection of personal data is an essential element in the provision of our services. For this reason, Nala adopts measures intended to ensure transparent and secure processing, seeking to process personal data only for the legitimate purposes associated with the service contracted by each customer.

Nala does not sell or monetize personal data processed through its platform. Our business model consists of providing technology services by subscription, with each customer company determining which data it incorporates into the platform, for what purpose it uses that data, and who may access it.

This Privacy Policy explains how Nala collects, uses, stores, protects, shares, and deletes personal data related to the provision of its services, as well as the rights available to data subjects and how those rights may be exercised. In this regard, Nala processes personal data in accordance with the principles of lawfulness, purpose limitation, proportionality, transparency, security, confidentiality, and accountability established by applicable law.

This Policy exclusively governs the processing of personal data related to Nala’s provision of services to its customers. Data processing associated with job applicants, marketing activities, website visitors, suppliers, or other relationships other than the use of the platform may be governed by specific privacy policies or notices.

2. Service Provider and Contact Details

The entity responsible for providing Nala’s services is:

Legal entity: NALA TECHNOLOGY INC.

Address: 850 New Burton Road, Suite 201, Dover, County of Kent, 19904, United States.

Privacy contact email: legal@nalarocks.com

Website: https://www.nalarocks.com

In the context of Nala’s services, the customer company generally acts as the controller, because it decides which personal data is incorporated into the platform, for what purpose it is used, who may access it, and for how long it will be processed.

Nala, in turn, normally acts as the processor, limiting its processing of personal data to what is necessary to provide the contracted services in accordance with the customer’s instructions and the contracts entered into between the parties.

Notwithstanding the foregoing, Nala may act as controller for certain data processing activities necessary for the operation of its own services, such as information-security management, prevention and detection of security incidents, account administration, billing, support-request handling, platform improvement, and other legitimate purposes directly related to the provision of the service.

Nala provides services to customers located in different jurisdictions. Accordingly, the processing of personal data may be subject to the data-protection laws applicable in each case, without prejudice to the obligations assumed by Nala under its contracts with customers.

3. Scope of this Policy

This Policy governs the processing of personal data carried out by Nala in the context of providing its people-management software services to organizations and customer companies.

This Policy applies to the processing of personal data of:

  • Administrators and other users of customer companies.
  • Employees, leaders, evaluators, process participants, and other users registered on the Nala platform.
  • Individuals whose data is uploaded or integrated into the platform by a customer company, either through manual upload or integrations with other systems, to operate talent, performance, development, succession, survey, reporting, or analytics processes, as well as individuals who interact with platform features.

When a customer company incorporates personal data into the platform, that company generally remains the controller of that data. Accordingly, each customer is responsible for determining the legal basis that enables the processing, complying with the information duties established by applicable law, and ensuring that the processing of personal data is consistent with the purposes for which it was collected.

4. Categories of Personal Data Processed

Nala may process the following categories of data, depending on the contracted modules, enabled configurations, and processes defined by each customer:

4.1 Identification and contact data

  • First and last name.
  • Email address.
  • Internal employee or user identifier.
  • Country, city, or work location.
  • Company, area, unit, department, role, or position.
  • Language or basic usage preferences.
  • Profile photograph, when available.

4.2 Employment and organizational data

  • Organizational structure.
  • Manager, reporting lines, and reporting relationships.
  • Position, role, level, function, area, unit, or cost center.
  • Employment status or operational information necessary to administer access.
  • History of participation in customer-enabled processes.

4.3 Performance, talent, and development data

  • Objectives, goals, OKRs, or indicators defined by the customer.
  • Performance reviews, competencies, skills, and feedback.
  • Results from talent, calibration, Nine Box, succession, or critical-position processes.
  • Development plans, gaps, improvement actions, and follow-up.
  • Recognitions, comments, form or survey responses, when the customer enables those features.

4.4 Integration data

  • Data received from customer systems, such as human resources systems, spreadsheets, APIs, or other authorized mechanisms.
  • Technical identifiers necessary for synchronization, authentication, or record reconciliation.
  • Structure, user, profile, position, or process data sent by the customer.

4.5 Technical and security data

  • IP address, browser, device, operating system, and access date/time.
  • Login records, activity, audit, error, security-event, and feature-usage logs.

4.6 Sensitive data

Nala does not generally require the processing of special categories of personal data or sensitive data to provide its services. However, certain customers may configure processes, forms, integrations, or fields that include specially protected or higher-care information when necessary for their processes, such as compensation data, socioeconomic status, health, disability, union membership, diversity, psychological evaluations, or other sensitive data.

In these cases, the customer is responsible for ensuring that it has the legal basis that enables such processing, including, where applicable, obtaining the consents, authorizations, or other requirements established by applicable law. Nala will process this data only in accordance with the customer’s instructions and will apply security measures appropriate to its nature.

4.7 Information generated by the platform

As a result of the features contracted by the customer, the platform may generate profiles, indicators, metrics, classifications, reports, analyses, or recommendations based on the personal data incorporated by the customer. These features are support tools for people management and do not replace the judgment, analysis, or decision-making of the customer company, which remains responsible for evaluating and making the corresponding decisions.

5. Purposes of Processing

Nala processes personal data for the following purposes:

5.1 SaaS service delivery

  • Create, administer, and authenticate users.
  • Allow access to and use of the modules contracted by the customer.
  • Configure performance, talent, development, succession, survey, reporting, analytics, and other enabled features.
  • Maintain the organizational structure, profiles, roles, and permissions.
  • Generate views, reports, downloads, dashboards, and indicators according to configuration and permissions.

5.2 Support, implementation, and customer administration

  • Implement the platform and configure processes.
  • Handle support requests, incidents, inquiries, and improvements.
  • Manage access, configuration changes, and service continuity.
  • Train users or teams authorized by the customer.

5.3 Security, audit, and operational continuity

  • Protect the platform, data, and user accounts.
  • Detect, prevent, and investigate unauthorized access, abuse, fraud, errors, or security incidents.
  • Maintain audit records, technical logs, and monitoring controls.
  • Perform backups, operational recovery, and controlled testing.

5.4 Product improvement and analytics

  • Measure platform usage, performance, and stability.
  • Improve features, user experience, and service quality.
  • Prepare aggregated or anonymized analyses, where applicable.

Nala will not use identifiable customer personal data for purposes incompatible with the contracted service, unless there is express authorization or a contractual agreement.

5.5 Contractual and administrative service management

  • Administer the contractual relationship with the customer.
  • Manage authorized users, administration contacts, and service owners.
  • Coordinate billing, renewals, operational communications, and account follow-up.
  • Document requests, approvals, configurations, and operational decisions related to the contracted service.
  • Comply with legal or regulatory obligations, respond to requests from competent authorities, or exercise and defend rights in administrative or judicial proceedings.

6. Legal Bases for Processing

The legal basis that enables the processing of personal data will depend on the role performed by Nala in each case and the nature of the processing carried out.

When Nala acts as processor, it will process personal data only in accordance with the instructions of the customer company, which is responsible for determining the legal basis that legitimizes such processing under applicable law.

In this regard, when the customer defines the purposes, data categories, users, processes, and configurations within the platform, the customer is responsible for having the authorizations, notices, legal bases, and communications required with respect to its employees or data subjects.

When Nala acts as controller, it may process personal data on the basis of one or more of the following legal bases, as applicable:

  • Performance of a contract or pre-contractual measures.
  • Compliance with legal obligations.
  • Consent of the data subject, where applicable.
  • Legitimate interest, where permitted by applicable law.

7. Roles of Nala and the Customer

The customer company is responsible for determining the purposes of processing, defining the applicable legal basis, informing data subjects, and configuring the use of the platform in accordance with its internal policies.

Nala will process personal data only in accordance with the customer’s documented instructions and will apply appropriate technical and organizational measures to protect the information.

8. Data Sharing and Subprocessors

Nala may disclose or allow access to personal data only where necessary for the provision of the contracted services, compliance with legal obligations, or the other purposes described in this Policy.

  • Cloud infrastructure, hosting, storage, security, monitoring, artificial-intelligence provider, and operational-continuity providers.
  • Email, support, communications, operational analytics, or internal-tool providers necessary to provide and administer the contracted service.
  • Providers or integrations authorized by the customer.
  • Legal, accounting, audit, or consulting advisors subject to confidentiality obligations.
  • Public authorities, courts, or regulators when there is a legal obligation or valid request.

Nala will not sell or commercialize personal data processed through the platform.

When Nala uses subprocessors to process customer data, it must require confidentiality, security, and processing-limited-to-authorized-purpose obligations. The applicable subprocessor list must be kept available or delivered to the customer in accordance with the contract.

Nala may use subprocessors to support service delivery, including infrastructure, storage, security, support, communications, monitoring, operational analytics, artificial intelligence, and customer-authorized integration providers. Where applicable, Nala will make information about applicable subprocessors available to the customer in accordance with the corresponding contract or data-processing addendum.

9. International Transfers

Nala may process or store personal data in countries other than the country of origin of the customer or data subject when necessary for the use of technology infrastructure, cloud services, support tools, specialized providers, or other services linked to platform operation.

Where international transfers of personal data occur, Nala will adopt appropriate technical, organizational, and contractual measures to protect such data and will seek to ensure that the third parties involved provide adequate protection guarantees, in accordance with applicable law.

Information about international transfers and the providers involved may be made available to customers in accordance with the contracts entered into between the parties.

10. Information Security

Nala applies technical and organizational measures intended to protect the confidentiality, integrity, and availability of data. These measures may include, among others:

  • Encryption of data in transit through secure connections.
  • Encryption of data at rest in critical infrastructure components.
  • Role- and permission-based access control.
  • Logical segregation of data by customer or company.
  • User authentication and SSO support where applicable.
  • Recording, monitoring, and review of technical and security events.
  • Backups and operational-continuity procedures.
  • Vulnerability and production-change management.
  • Internal security, confidentiality, and information-handling policies.
  • Restriction of access to customer data only to authorized personnel and when necessary.

No system can guarantee absolute security. However, Nala maintains reasonable controls to reduce the risks of unauthorized access, loss, alteration, improper disclosure, or misuse of personal data.

11. Data in Non-Production Environments

When it is necessary to use data for testing, support, incident investigation, or non-production environments, Nala will apply controlled procedures and access restrictions. When production information is copied to staging or test environments, Nala will seek to apply obfuscation, scrambling, anonymization, pseudonymization, or equivalent measures to sensitive or personal data, depending on the case and technical availability.

The use of personal data in environments other than production will be limited to cases where it is strictly necessary for the purposes described above and will be subject to security controls appropriate to the nature of the information processed.

12. Data Retention, Export, and Deletion

Nala will retain personal data for the time necessary to provide the service, fulfill the contract, address legal obligations, resolve disputes, maintain security and operational continuity, or comply with the customer’s documented instructions.

At the end of the contractual relationship, the customer company may request, in accordance with the contract entered into between the parties, the export, return, deletion, or de-identification of the personal data processed through the platform. In accordance with Nala’s internal information-security policies, when the relationship with a customer ends, customer information will be deleted from Nala’s servers after a period of six (6) months has elapsed, unless a legal, contractual, security, operational-continuity, audit, or rights-defense obligation justifies a different retention period. Backups, logs, and technical records will be managed according to their ordinary retention cycles and restricted use.

Deletion may be subject to:

  • Technical backup and recovery periods.
  • Legal, accounting, contractual, or security retention requirements.
  • Audit, legal-defense, or operational-continuity needs.
  • The specific scope of the requested data.

13. Exercise of Data Subject Rights

Data subjects whose personal data is processed through the platform may exercise the rights recognized by applicable law, including, where applicable, rights of access, rectification, deletion, objection, portability, or any other applicable right.

Because the customer company generally acts as controller of the personal data incorporated into the platform, requests to exercise these rights should preferably be addressed to that company.

When Nala directly receives a request related to personal data processed on behalf of a customer company, it will refer the request to the corresponding customer or collaborate with the customer to address it, as applicable and in accordance with applicable law and the contracts entered into between the parties.

Channel to exercise rights: legal@nalarocks.com

14. Processing of Data Relating to Minors

Nala is intended for companies and organizations, not for minors as customers. If a customer company incorporates personal data of minors into the platform, that company will be responsible for ensuring that it has the legal basis enabling such processing and for complying with the obligations established by applicable law.

15. Use of Artificial Intelligence and Advanced Analytics

Nala may offer analytics, assistance, automation, or artificial-intelligence features to support talent, performance, development, succession, reporting, or other related service processes.

These features are intended to support the analysis of available information and decision-making by the customer company. They do not, under any circumstances, replace the professional judgment, human evaluation, or decision-making that corresponds to the customer company in accordance with its internal policies and applicable law.

The customer company is responsible for evaluating the relevance and use of the results generated by these features before making decisions about specific individuals.

Nala does not use customers’ personal data to train general-purpose artificial-intelligence models or third-party models. When artificial-intelligence features are used, the data will be processed only to provide the functionality contracted or requested by the customer. Any use of personal data for training, tuning, or improving models will require the customer’s express and documented authorization and an applicable legal basis.

The specific terms for AI use, providers, models, retention, and exclusions must be documented in the contract, data-processing addendum, AI terms, or equivalent document.

16. Confidentiality

Nala adopts measures intended to ensure the confidentiality of personal data processed through the platform.

Access to such data will be limited to personnel and third parties who need to know it for the provision of the contracted services, compliance with legal obligations, or the exercise of expressly authorized functions, and who are subject to confidentiality obligations and the security measures established by Nala.

Nala will seek to ensure that every person who accesses personal data in the context of providing its services does so only to the extent necessary to perform their duties.

17. Security Incidents

Nala has procedures intended to detect, manage, investigate, and mitigate security incidents that may affect the confidentiality, integrity, or availability of personal data processed through the platform.

If a security incident occurs, Nala will adopt appropriate measures to contain its effects, investigate its causes, mitigate associated risks, and restore, where applicable, the security of the affected systems.

When the nature of the incident so requires, Nala will collaborate with the customer company to facilitate compliance with the notification or communication obligations established by applicable law or the contracts entered into between the parties.

18. Changes to this Policy

Nala may update this Policy to reflect legal, contractual, operational, technological, or service changes. The current version will indicate its last-updated date.

When changes are relevant, Nala will seek to communicate them through reasonable means, such as in-platform notification, email, or other channels defined with the customer.

19. Contact

For inquiries about this Policy, personal-data processing, or the exercise of rights, please contact:

Email: legal@nalarocks.com

Privacy owner: Chief Data Officer (CDO)

Address: 850 New Burton Road, Suite 201, Dover, County of Kent, 19904, United States.

Version updated as of April 3, 2026.