Product
Use cases
Book a demo Español
Legal Updated August 18, 2026 8 min read Nirby Team

Privacy policy

What data Nirby processes, for what purpose, for how long, and what you can ask us for at any time.

This is a courtesy translation. The binding version of this policy is the Spanish one: Política de privacidad. If the two texts differ, the Spanish version prevails.

Last updated: 2026-08-18

This policy explains what personal data we process in Nirby, for what purpose, who we share it with and what you can ask us for. It is written to be understood; if something is not clear, write to us and we will explain it.

Who we are

Nirby: Foreby (from here on, “Nirby”) is a product of Nirby SpA, with address at 2 Oriente 124, Oficina 205, Edificio 02, 2340000 Viña del Mar, Chile, and contact email for privacy matters privacy@nir.by.

Two different situations, and it is worth not confusing them

Nirby processes personal data in two different roles:

1. As controller — our customers’ data. When you create an account, take out a plan or use the application, we decide what we use that data for: providing you the service, billing you, supporting you and keeping the platform secure. This policy covers it in full.

2. As processor — the data you collect from your visitors. When you publish a Form, the answers, the files and the contact details of the people who complete it are yours, not ours. You decide what you ask, what you use it for and how long you keep it; we process it on your behalf and following your instructions. If you are a visitor to a Form built with Nirby and you want to exercise your rights over that data, the organisation that published that Form is who you deal with — and we assist them in answering you.

What data we process

From you, as a customer:

  • Account: name, email address and access credentials (stored encrypted; nobody on our team can read your password).
  • Workspace: organisation name, members, roles and the configuration you define.
  • Billing: the plan taken out, consumption and the data needed to issue tax documents. Payment details are processed by our payment gateway; we do not store card numbers.
  • Usage: technical activity logs (date, action, IP address, browser) that we use for security, diagnostics and quota control.
  • Support: what you tell us when you write to us.

Content you upload: the questions and configuration of your Forms, the documents and URLs of your Knowledge Base, your company context, your templates and your deliverables.

From the visitors to your Forms and Sales Rooms (processed on your behalf): the answers they send, the files they attach, the contact details they provide, the consent they give, and the analysis generated from all of it.

From the public website: we use a cookieless analytics tool, which measures visits in aggregate and does not build profiles or track anyone across sites.

What we use the data for

  • Providing the service: publishing your Forms, processing what you receive, generating analyses and deliverables, and keeping your Sales Rooms available.
  • Billing the plan taken out and controlling usage and storage quotas.
  • Supporting you and answering what you ask us.
  • Keeping the platform secure: preventing fraud, abuse and unauthorised access.
  • Improving the product from aggregate usage metrics.
  • Complying with legal obligations.

We do not sell personal data, and we do not pass it to third parties for advertising purposes.

Artificial intelligence

Nirby uses Google artificial intelligence models to converse with whoever completes a Form, to analyse what is received and to prepare documents. For that, the necessary content is sent to our model provider(s), who process it to return the result and do not use it to train models. More information in the Google Cloud Platform documentation: Zero Data Retention.

We send what is needed for each task, not everything we hold. The outputs the AI produces are assistance: they may contain errors and must be reviewed before being used to make decisions that affect a person.

We process personal data in accordance with Chilean personal data protection legislation — Law 21,719, which regulates the processing of personal data and creates the Personal Data Protection Agency — and this policy is governed by it.

Each processing activity relies on one of these bases:

  • Performing the contract with you: everything needed to provide the service you took out, bill it and support you.
  • Your consent, where we ask for it expressly. It is also the basis of the consent a visitor gives before completing a Form: it is collected by the organisation that published that Form, not by us.
  • Legitimate interest in keeping the platform secure, preventing abuse and improving the product from aggregate metrics.
  • Complying with the law, where a rule requires us to keep or hand over information.

Each Form can require explicit consent before collecting anything, with the text defined by the organisation publishing it. That consent is recorded alongside the answer. As a customer, it is your responsibility that the text is correct and sufficient for what you are going to do with the data.

Who we share it with

We work with providers who supply us with infrastructure and operations services, and who may only process the data following our instructions:

ProviderWhat we use it forWhere
Google Cloud PlatformHosting, database and artificial intelligence modelsUSA
SupabaseDatabase and storage of uploaded filesUSA
CloudflarePublishing our applications and protecting public forms against automated useUSA
StripePayment gatewayUSA
ResendTransactional email (product notices and sends)USA
FirecrawlReading the web pages you add to your Knowledge BaseUSA
SentryApplication error loggingUSA
UmamiCookieless analytics for the public websiteUSA

We may also hand data to authorities where a rule or a court order requires it.

International transfers: some of those providers operate outside Chile. Where that happens, we require adequate safeguards to protect the data, such as standard contractual clauses or other mechanisms recognised by law.

How long we keep it

  • Account and Workspace data: while the account is active. After closure we keep it for 30 days to allow recovery and export, and then delete or anonymise it.
  • Content and answers: for as long as you decide. You can delete them at any time from the application, and you can also ask for everything associated with a specific contact to be deleted.
  • Technical and billing records: for the period required by applicable tax and commercial regulations, and for as long as we need to evidence compliance with our legal obligations.

How we protect it

  • Each Workspace is isolated: one organisation’s data is not accessible from another.
  • Access within your team is controlled by roles and permissions that you administer.
  • Data travels encrypted and is stored encrypted. For example, with our provider Supabase, data is encrypted at rest with AES-256 and encrypted in transit with TLS 1.2 or higher. With GCP as the AI provider, data is encrypted in transit with TLS 1.2 or higher and at rest with AES-256.
  • We log accesses and relevant actions so they can be audited.
  • Our team accesses a customer’s content only when it is essential to provide support or resolve an incident, and under a duty of confidentiality.

No system is infallible. If a security incident affecting personal data were to occur, we will notify you and inform the authorities where the law requires it.

Your rights

You can ask us, at any time, for:

  • Access to the personal data we process about you.
  • Rectification of anything that is incorrect.
  • Deletion of anything no longer necessary.
  • Objection or restriction regarding certain processing.
  • Portability: the application lets you export your data, and if you need another format, ask for it.

Write to privacy@nir.by and we will answer within the period set by applicable regulations. If you are a visitor to a Form published by one of our customers, go to that organisation first: the data is theirs and we help them attend to you.

If you believe we have not handled your request properly, you can complain to the Personal Data Protection Agency (APDP), the body that oversees compliance with Law 21,719 in Chile: www.agpd.cl.

Cookies

The public site uses cookieless analytics: we do not install tracking or advertising cookies, and that is why you will not see a banner asking for permission. The application uses only the cookies strictly necessary to keep your session open.

Minors

Nirby is a work tool and is not aimed at people under 18. We do not knowingly collect data from minors; if we become aware that we have, we delete it.

Changes to this policy

If we update it, we will change the date in the header and, where the change is significant, we will notify you by email or inside the application before it takes effect. Previous versions remain available on request.

Contact

Nirby SpA · 2 Oriente 124, Oficina 205, Edificio 02, 2340000 Viña del Mar, Chile · privacy@nir.by

Sigue leyendo