Effective August 18, 2026

Privacy Policy

This Privacy Policy describes how Nahar Labs ("Nahar," "we," "us," or "our") collects, uses, discloses, and otherwise processes Personal Information in connection with our website, platform, products, and related services (collectively, the "Services"). It also describes the rights and choices that may be available to individuals with respect to their Personal Information.

For purposes of this Privacy Policy, "Personal Information" means information that identifies, relates to, describes, or may reasonably be linked to an identified or identifiable individual.

1. Scope

This Privacy Policy applies to Personal Information that we process in connection with the Services, including information relating to website visitors, prospective and current customers, authorized users, individuals who request a demonstration or support, and other persons who communicate or otherwise interact with us.

This Privacy Policy does not apply to third-party websites, products, or services, even if they are linked to or integrated with the Services. Such third parties process information in accordance with their own terms and privacy policies.

We may provide additional or supplemental privacy notices in connection with particular products, services, or processing activities. To the extent of a conflict, the supplemental notice will control with respect to the applicable processing activity.

2. Our role with respect to Customer Data

"Customer Data" means data, content, records, prompts, instructions, files, credentials, and other information submitted to the Services by or on behalf of a customer, accessed through a customer-authorized connection, or generated for a customer through its use of the Services. Customer Data may include security alerts, logs, identities, cloud and endpoint records, evidence, agent findings, outputs, and execution records.

Our customers determine the systems they connect, the Customer Data made available to the Services, and the purposes for which such data is processed. Where Nahar processes Personal Information contained in Customer Data on behalf of a customer, the customer acts as the controller or business and Nahar acts as its processor or service provider, as those terms are defined under applicable law.

If your Personal Information has been submitted to the Services by or on behalf of a Nahar customer, you should direct any inquiry or request concerning that information to the applicable customer. We will provide reasonable assistance to the customer in responding to such requests as required by applicable law or contract.

3. Personal Information we collect

The Personal Information we collect depends on the nature of your relationship and interactions with us. We may collect the following categories of Personal Information:

  • Account and profile information, including name, business email address, company, title, role, username, authentication information, and account preferences.
  • Customer Data, including information obtained from customer-selected systems and information generated through use of the Services.
  • Connection and credential information, including integration settings, authorization scopes, tokens, API keys, certificates, and other credentials required to connect a customer-controlled system.
  • Usage, device, and technical information, including features used, actions taken, timestamps, browser and device type, operating system, IP address, approximate location derived from IP address, referring page, error reports, and performance and security logs.
  • Communications and support information, including emails, support requests, feedback, demonstration conversations, and any information or files included in those communications.
  • Scheduling information, including name, business email address, selected meeting time, and notes submitted through our scheduling provider.
  • Commercial and transaction information, including order, subscription, invoicing, and payment-related records. Payment card information may be collected directly by our payment provider rather than Nahar.

We collect Personal Information directly from you, from the organization that provides or administers your account, automatically when you use the Services, from systems a customer elects to connect, and from service providers and business partners.

4. Connected systems and credentials

The Services enable customers to connect third-party security and business systems. The applicable customer is responsible for ensuring that it has all rights, permissions, and lawful bases necessary to establish each connection and authorize Nahar to access and process the resulting information.

We process connection credentials solely as necessary to establish and maintain the applicable connection, perform customer-directed operations, protect the security and integrity of the Services, and provide support. We do not use connection credentials for unrelated purposes.

5. Purposes and legal bases for processing

We may process Personal Information for the following purposes:

  • To provide, operate, maintain, and support the Services.
  • To create and administer accounts, authenticate users, and manage customer relationships.
  • To establish customer-authorized connections and perform customer-directed operations.
  • To generate requested findings, evidence, recommendations, proposed actions, and other outputs.
  • To monitor, secure, and protect the Services, our customers, and connected systems; prevent fraud and abuse; and investigate suspected violations.
  • To diagnose errors; maintain availability; analyze performance and usage; and develop, test, and improve the Services.
  • To communicate with you, respond to inquiries, provide support, and schedule demonstrations.
  • To administer commercial relationships, process transactions, maintain business records, and enforce our agreements.
  • To comply with applicable law, legal process, and regulatory obligations and to establish, exercise, or defend legal claims.
  • To evaluate or complete an actual or proposed financing, merger, acquisition, reorganization, sale, or other corporate transaction.

Where the laws of the European Economic Area, United Kingdom, or Switzerland apply, we rely on one or more of the following legal bases: performance of a contract or steps taken at your request before entering into a contract; compliance with legal obligations; our legitimate interests in operating, securing, and improving the Services and conducting our business; and consent where we expressly request it.

6. Artificial intelligence and model training

We do not use Customer Data, including prompts, data obtained from connected systems, agent findings, or outputs, to train or fine-tune generalized artificial intelligence or machine-learning models.

Certain features may require Customer Data to be transmitted to a third-party model or service provider for processing. We transmit such information only as necessary to provide the applicable feature and require providers processing Customer Data on our behalf to protect the information and process it only for the applicable service.

We may process Service usage information and aggregated or de-identified information to operate, secure, analyze, and improve the Services, provided such information does not identify a customer, individual, or connected environment.

7. Disclosure of Personal Information

We may disclose Personal Information to the following categories of recipients and for the purposes described in this Privacy Policy:

  • Service providers that perform hosting, infrastructure, security, monitoring, analytics, communications, scheduling, support, payment, professional, and other services on our behalf.
  • Model and integration providers where disclosure is required to perform customer-directed operations or provide a requested feature.
  • The customer or organization that provides, sponsors, or administers your account.
  • Professional advisers, auditors, insurers, financing sources, and other parties subject to appropriate confidentiality obligations.
  • Government authorities, regulators, courts, law enforcement, or other third parties where disclosure is required by law or reasonably necessary to protect rights, safety, property, the Services, our customers, or the public.
  • A buyer, investor, successor, or other relevant participant in connection with an actual or proposed corporate transaction.

We do not sell Personal Information or share Personal Information for cross-context behavioral advertising, as those terms are defined under applicable U.S. state privacy laws.

8. Security

We maintain reasonable technical and organizational safeguards designed to protect Personal Information against unauthorized access, acquisition, loss, misuse, alteration, and disclosure.

No security measure or method of transmission or storage is completely secure. In the event of a security incident affecting Personal Information, we will investigate, take appropriate remedial action, and provide notice as required by applicable law or contract.

9. Data retention and international transfers

We retain Personal Information for no longer than reasonably necessary for the purposes for which it was collected, including to provide and secure the Services, perform contractual obligations, maintain appropriate business records, resolve disputes, enforce agreements, and comply with applicable law. The applicable retention period varies based on the nature of the information, the purposes for processing it, and applicable legal and contractual requirements.

Nahar is based in the United States. We and the service providers supporting the Services may process Personal Information in the United States and other jurisdictions that may not provide the same level of data protection as your home jurisdiction. Where required by applicable law, we implement contractual or other safeguards designed to protect Personal Information transferred across national borders.

10. Automated processing and human review

The Services use automated systems to analyze security-related information and generate findings, evidence, recommendations, proposed actions, and other outputs.

Nahar does not use Personal Information to make decisions based solely on automated processing that produce legal or similarly significant effects concerning an individual. Customers determine their authorized users, connected systems, agent permissions, and approval requirements and remain responsible for decisions made through their use of the Services.

11. Privacy rights and choices

Subject to applicable law, you may have the right to request access to, correction of, deletion of, or a portable copy of your Personal Information; to restrict or object to certain processing; and to withdraw consent where processing is based on consent.

Residents of certain U.S. states may also have rights to confirm whether we process their Personal Information, obtain information concerning the categories and sources of Personal Information collected and disclosed, and appeal a decision concerning a privacy request. We will not discriminate against you for exercising a privacy right.

To submit a request, contact us at connor@usenahar.com. We may take reasonable steps to verify your identity, authority, and jurisdiction before processing a request. If a request relates to Customer Data controlled by a Nahar customer, we may direct the request to the applicable customer.

Where applicable, you may lodge a complaint with the data protection authority in the jurisdiction where you reside or work.

12. Website analytics and third-party services

We use Vercel Web Analytics to measure aggregate website traffic and usage. Vercel Web Analytics is cookieless and is not used by us to track visitors across unaffiliated websites or create advertising profiles.

Our website loads a font from a third-party font provider. As with other internet services, the provider receives technical information, such as an IP address, when responding to the request.

Links used to schedule a demonstration direct you to a scheduling service operated by a third party. Information submitted to that service is also subject to the third party's privacy policy.

13. Children's privacy

The Services are intended for organizations and professional users and are not directed to children under 16 years of age. We do not knowingly collect Personal Information from children under 16. If you believe a child has provided Personal Information to Nahar, please contact us.

14. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in the Services, our processing activities, or applicable law. The "Effective" date at the top of this page identifies the current version. Where required by law, we will provide additional notice of material changes.

15. Contact us

If you have any questions concerning this Privacy Policy or our privacy practices, please contact us at:

Nahar Labs131 Continental DrNewark, DE 19702connor@usenahar.com