Nugget Privacy Policy
Carthero Technologies Private Limited
Last updated: August 20261. Applicability and Scope
Carthero Technologies Private Limited (“Carthero”, the “Company”, “we”, “us” and “our”) owns and operates Nugget, a cloud-based customer service, support automation and communications platform made available to businesses on a software-as-a-service basis (the “Platform”). Carthero is a subsidiary of Eternal Limited.
This Privacy Policy describes the types of information that Carthero collects when a business subscribes to or uses the Platform, when an individual accesses or uses the Platform, and when you access or use our websites, marketing and campaign pages, documentation and support channels, and other online or offline services offered under the Nugget brand (collectively, the “Services”). It also describes our practices for collecting, using, maintaining, protecting and disclosing that information.
Your relationship with the Services determines which parts of this Privacy Policy apply to you and who is accountable to you for your information.
- If you use the Platform on behalf of a business that subscribes to Nugget, whether as a support agent, supervisor, administrator, read-only user, developer or other authorised user of a Client (defined below), this Privacy Policy describes how Carthero processes information about you, and Sections 4 to 17 apply to you directly.
- If you are a customer, user or other individual who has contacted or transacted with a business that uses Nugget, whether by raising a support ticket, sending a message on a channel that business operates, or speaking to its support team (including automated systems and bots), Carthero processes information about you only on that business’s behalf and under its instructions. That business, and not Carthero, determines why your information is processed and is accountable to you for it. This Privacy Policy does not govern that processing. Please refer to that business’s own privacy notice, and contact it directly to exercise your rights. Sections 3 and 13 explain the arrangement and how a request addressed to us will be handled.
- If you visit our websites, engage with our marketing, apply for a role with us, or interact with us as a supplier, adviser, business contact or visitor, this Privacy Policy describes how Carthero processes information about you.
This Privacy Policy does not apply to information that you provide directly to, or that is collected and processed independently by, a third party under its own privacy practices, including a Client, a messaging or social-media platform, a payment service provider, an identity provider or any other third-party service you use outside the Services. We encourage you to review the privacy practices of any such third party.
Please read this Privacy Policy carefully. Where consent is required for any processing, we will seek it in the manner required by applicable law. If you do not provide information that is necessary for a particular Service or feature, we may be unable to provide it.
The Services are intended for businesses and for individuals acting in a professional capacity on their behalf, and are not directed to or intended for use by children.
Individuals in the European Economic Area, the United Kingdom and the State of California should also read Annex 1, which applies in addition to this Privacy Policy and, to the extent of any inconsistency, prevails over it.
2. Our roles: Data Processor and Data Fiduciary
Carthero processes personal data in two distinct capacities, and the difference determines who is accountable for what.
As a Data Processor. When a business subscribes to the Platform (a “Client”), it uploads, transmits, generates and otherwise makes available information through the Platform in the course of operating its own customer service and communications functions, including information relating to its own customers and users. We refer to this information as “Client Data”. The Client is the Data Fiduciary in respect of Client Data and Carthero is a Data Processor acting on the Client’s behalf, under a written agreement with that Client and in accordance with its instructions. The Client determines the purposes and means of processing, the categories of information submitted to the Platform, the retention configuration, the lawful basis for processing, and the manner in which individuals are given notice and exercise their rights. Carthero determines none of those matters and does not process Client Data for its own purposes.
As a Data Fiduciary. Carthero acts as a Data Fiduciary in respect of a narrower and distinct set of information: information about the individuals who administer and use the Platform on a Client’s behalf; information about visitors to our websites, prospective clients and marketing contacts; operational and technical information generated by our systems about the operation and security of the Platform; and information about applicants, personnel, suppliers, advisers, business contacts and visitors. In respect of this information, Carthero determines the purposes of processing and is accountable under applicable law, including the Digital Personal Data Protection Act, 2023 and the Information Technology Act, 2000 and the rules made under them.
Practices described in this Privacy Policy without qualification are those we follow as a Data Fiduciary. Practices applying to Client Data are identified as such.
3. Client Data: information we process on behalf of our Clients
A Client decides what information is submitted to the Platform, for what purpose, and on what lawful basis, and gives notice of that processing to the individuals concerned as Data Fiduciary. The categories below describe what the Platform is capable of processing, and what a given Client’s environment holds will depend on the modules it enables, the channels it connects and the configuration it selects.
- Contact and identification information submitted by or on behalf of a Client’s customer or user, such as name, telephone number, email address, account or order identifier, address and other identifiers a Client chooses to capture.
- Support interaction content, including tickets, ticket fields, subject lines, message bodies, internal notes, side conversations, tags, categories, attachments, screenshots, documents and other content submitted through a ticket form, help centre, in-application flow or connected channel.
- Channel and conversation data from channels a Client connects to the Platform, including email, web chat, in-application messaging, WhatsApp and other messaging services, and public or direct interactions on social-media and application-store platforms that the Client elects to manage through the Platform.
- Voice and telephony data, where a Client enables dialler or telephony integration, including call metadata, call logs associated with tickets, and call recordings and transcripts where the Client enables and configures recording.
- Automated and AI-assisted interaction data, including queries submitted to a self-help or chatbot experience, prompts and responses generated in the course of an interaction, language detection and translation output, and routing, classification and escalation records.
- Data received through integrations, where a Client connects the Platform to its own systems, customer relationship or order-management databases, identity provider or third-party tools through application programming interfaces, webhooks or middleware. The fields exchanged are determined by the schema mapping and access scopes the Client configures.
- Migrated historical data, where a Client asks us to support migration of its existing records from another platform.
- Client user and configuration records, including agent identifiers, permissions and role assignments, workflow and automation rules, audit logs of activity within the Client’s environment, and reporting and performance data generated from the foregoing.
We process Client Data to provide, maintain, secure and support the Platform for the relevant Client, to perform the services described in our agreement with that Client, and to comply with our legal obligations. We do not use Client Data to develop or market our own products or services except as described in Section 6, and we do not sell Client Data.
We are not in a position to verify whether a Client has given notice, obtained consent or otherwise established a lawful basis for information it submits, and we rely on the Client’s representations in our agreement with it in that regard.
4. Information we process as a Data Fiduciary
A. Information you provide to us
- Platform user account information. Where you are given access to the Platform by a Client, we process your name, business email address, telephone number, employee or agent identifier, designation, team, reporting relationship, role and permission assignments, authentication credentials and multi-factor authentication records, language and notification preferences, profile photograph where you provide one, and your activity within the Platform, including sessions, assignments, actions taken, productivity, occupancy and schedule information generated by workforce-management and reporting features.
- Enquiry, trial and prospect information. Name, business contact details, employer, role, and the content of your enquiry, where you request a demonstration, download material, register for a trial, attend an event or webinar, or otherwise contact us about the Services.
- Support and communications. Communications with our support, engineering, relationship-management or commercial teams by email, telephone, in-Platform channels or otherwise; the content of support requests and escalations you raise with us; and responses to surveys, feedback requests, beta programmes and user-research activities. Some interactions may be recorded or retained for the purposes described in Section 5.
- Commercial and administrative information. Information relating to the negotiation, execution and administration of an agreement with a Client or supplier, including signatory and authorised-representative details, purchase orders, invoicing and billing contacts, tax registration details, bank and payment information, and correspondence.
- Applicant, personnel and engagement information. Where you apply to work with us or are engaged by us as an employee, intern, contractor or through a staffing arrangement, we process identification and contact details, application, education and employment records, assessment and interview records, background and reference checks, attendance, access and device records, compensation, payroll, bank, tax and statutory-benefit information, performance, training, disciplinary, grievance and separation records, and emergency-contact, insurance, travel and expense information, where applicable.
- Information volunteered by you. Any other information you choose to provide, including in response to a survey, campaign, research programme or optional feature.
Where you provide information about another individual, you should do so only where you are authorised to do so, and should inform them that their information may be shared with us.
B. Information we collect through automatic data collection technologies
We may automatically collect information about the devices you use to access the Services and about your use of the Services, including where you use them without registering or logging in.
- Service usage and activity data. Pages and screens viewed, features used, queries run, reports generated, clicks, session duration, timestamps, referral URLs and other interaction patterns.
- Device and connection information. IP address, device type, operating system, browser type and version, application version, device settings such as language and time zone, connection type, and network information.
- Diagnostics and telemetry. Crash records, error and exception logs, latency and performance measurements, request and response metadata, queue and throughput metrics, network diagnostics, integration and webhook delivery records, and other technical information generated by the operation of the Platform.
- Security and access records. Authentication and authorisation events, session records, administrative actions, permission changes, access from permitted network ranges, and records generated by our security monitoring and fraud- and abuse-detection controls.
- Cookies and similar technologies. We and providers we engage may use cookies, software-development kits, pixel tags, web beacons, device identifiers and similar technologies on our websites and, to a limited extent, within the Platform, to maintain sessions, remember preferences, measure and improve performance, conduct analytics, support security, and measure our marketing. You may be able to manage these through your browser or device settings and through any preference controls we make available. Disabling a technology may affect the availability or operation of some features.
Telemetry, diagnostic and security records of this kind are generated by our systems in the course of operating the Platform and are processed for the purposes in Section 5. Where such records incidentally contain identifiers derived from Client Data, we treat those records as Client Data.
C. Information from third parties
- From a Client. A Client may provide or update information about its authorised users in order to provision, modify or revoke access, configure roles and teams, or administer its use of the Platform.
- Identity and authentication providers. Where you access the Platform through single sign-on or a directory service operated by a Client or a third party, we receive the identifiers and attributes that the provider makes available under the configuration and permissions established.
- Commercial, marketing and verification sources. We may receive business contact and firmographic information from marketing, events, lead-generation, data-enrichment and business-verification providers, from publicly available sources, and from referrals, subject to applicable law.
- Service providers and affiliates. Providers engaged by us, and Eternal group companies performing corporate or administrative functions for Carthero, may provide information in connection with the purposes described in this Privacy Policy.
- Recruitment and verification providers. Recruitment platforms, staffing agencies, assessment providers and background-verification providers, in connection with applicants and personnel.
We may combine information received from third parties with information collected directly from you or automatically through your use of the Services, where needed for the purposes described in this Privacy Policy.
5. How we use the information we collect
We use information we process as a Data Fiduciary for the following purposes:
- Provisioning and administering access. To create, authenticate, maintain, modify and deactivate Platform accounts; apply roles and permissions; maintain settings and preferences; and communicate account, security, policy and service information.
- Providing, operating and supporting the Platform. To make the Platform available to Clients and their authorised users, provide relationship management and support, respond to and resolve support requests and escalations, conduct root cause analysis, perform maintenance and migrations, and communicate service status, changes and planned or emergency maintenance.
- Reliability, availability and performance. To monitor and measure availability, latency, capacity and throughput; diagnose and resolve defects and incidents; test and validate changes; and meet the service levels agreed with Clients.
- Security, integrity and abuse prevention. To authenticate users; protect accounts, systems and information against unauthorised access, misuse and abuse; investigate suspected security incidents and policy violations; detect and prevent fraud; and enforce our agreements and acceptable-use requirements.
- Service improvement, analytics and research. To understand how the Services are used and how they perform; measure feature adoption; identify defects and areas for improvement; develop, test and evaluate features and models; conduct internal research; and plan capacity and roadmap, in each case as described in and subject to Section 6.
- Commercial administration. To administer agreements, subscriptions, entitlements and user counts; issue invoices and process payments; maintain accounting, tax and audit records; and manage procurement and supplier relationships.
- Marketing and communications. To send communications about the Services, features, events, research and offers that may be relevant to you or your organisation, by email, telephone, messaging channels or otherwise; to administer events, campaigns and surveys; and to measure the effectiveness of our marketing. You may opt out of marketing communications using the available preference or unsubscribe options. We may continue to send transactional, administrative, security, service and legal communications.
- Recording and retention of interactions. To maintain service quality, resolve disputes, support security and fraud prevention, and conduct internal training, we may retain and, where permitted and notified, record support calls, meetings and chats involving Client personnel and our personnel.
- Workforce administration. To recruit, verify, onboard and manage applicants, employees, contractors, interns and personnel engaged through a staffing arrangement; administer access, attendance, payroll, benefits, performance, training, health and safety, investigations and separation; and comply with employment, tax and other legal requirements.
- Legal and regulatory compliance. To comply with applicable law and lawful requests; respond to and cooperate with regulators, courts and authorities; conduct audits and assurance activities; establish, exercise or defend legal claims; and give effect to corporate transactions.
- Aggregation and de-identification. To aggregate, anonymise or de-identify information and to use the resulting information, which does not identify any individual, for analytics, benchmarking, reporting, planning, product development, security research and other lawful purposes.
- Other disclosed purposes. For any other purpose we explain to you at the time the information is collected, or with your consent where required.
Client Data is processed only as described in Section 3 and in accordance with the relevant Client’s instructions and our agreement with that Client. The purposes in this Section 5 do not extend our processing of Client Data.
6. Artificial intelligence, machine learning and model training
The Platform uses artificial intelligence and machine learning to provide features including automated responses, self-help experiences, classification, routing, summarisation, language detection and translation. The following provisions apply to those features and are to be read together.
Client Data is not used to train general-purpose or foundation models. We do not use Client Data to train, fine-tune, re-train or otherwise develop general-purpose, foundation or shared machine-learning models, whether our own or those of a third party. We do not make Client Data available to any provider of a general-purpose or foundation model for that provider’s own training, model development or other independent purposes, and our agreements with such providers prohibit that use.
Configuration within a Client’s own environment is not model training. To provide the Platform, we configure and operate features within a Client’s own environment using that Client’s information. This includes indexing a Client’s help-centre articles, knowledge base and historical tickets so that they can be retrieved and used to answer a query; supplying relevant information to a model as part of a request so that a response is specific to the Client and the interaction; applying the Client’s workflow, routing, classification and template configuration; caching for performance; and evaluating, testing and tuning the accuracy of features for that Client. Where a Client asks us to tune or adapt a model for its exclusive use, we do so within that Client’s environment and the result is not made available to any other Client. References in this Privacy Policy to training a model do not include any of the activities described in this paragraph.
Aggregated and de-identified information. We use aggregated, anonymised or de-identified information, and operational and technical telemetry that does not identify any individual, to operate, secure, measure, evaluate and improve the Platform, including to assess the accuracy, quality, safety and performance of automated features, to detect abuse and misuse, and to develop and evaluate our own models and features. We do not attempt to re-identify information that has been anonymised or de-identified for these purposes.
Human review. Where a Client enables a feature that involves review of interactions or automated output, or where review is necessary to investigate a support request, a suspected security incident or suspected abuse, a limited number of authorised personnel may access the relevant information. Such access is role-based, logged and limited to what is necessary for the purpose.
Accuracy of automated output. Automated and AI-assisted features generate output by predicting a likely response. Output may be incomplete or inaccurate, and does not constitute advice or a decision by Carthero. Carthero does not use the Platform to make decisions about individuals. A Client is responsible for how it configures automated features, for the extent of human oversight it applies, and for any decision it takes on the basis of Platform output.
8. Relationship with the Eternal group
Carthero is a subsidiary of Eternal Limited, and Eternal group companies operate consumer-facing businesses in a number of sectors. The boundary between the Platform and the wider group is as follows.
- Client Data is held in the Platform environment operated by Carthero, segregated from the systems of other Eternal group companies, and is not made available to any Eternal group company for that company’s own purposes.
- No Eternal group company receives Client Data for its own commercial, product, marketing, analytics or research purposes. Client Data is not used to inform the products, pricing, operations or commercial strategy of any Eternal group company.
- Where an Eternal group company subscribes to the Platform as a Client, it is treated in the same manner as any other Client, and its environment is segregated from those of other Clients on the same basis.
- Personnel of Eternal group companies do not have standing access to Client environments. Where a group company provides Carthero with a function that requires access to systems on which Client Data is held, that access is provided under written obligations equivalent to those applying to any other sub-processor, is limited to authorised individuals on a need-to-know basis, is role-based, time-bound and logged, and the relevant group company is identified in the sub-processor list referred to in Section 7.
- We may share information we process as a Data Fiduciary with Eternal group companies for corporate and administrative functions performed for Carthero, including finance, tax, legal, human resources, procurement, insurance, information security, internal audit and group reporting, and for shared corporate technology and communications systems.
9. Client configuration and controls
Several protections available in the Platform are selected and configured by the Client rather than determined by Carthero, and their operation depends on those selections.
- Detection and masking of identifiers. The Platform offers automated detection and masking of certain categories of identifier in real time, with configurable rules and role-based access to unmasked values. Detection operates on a probabilistic basis and is not capable of identifying every instance in every format or language. Masking is a risk-reduction control that a Client configures, and should not be relied upon as a guarantee that a particular identifier will be detected, masked or excluded from any given record, log or downstream system.
- Access control and permissions. A Client determines which of its personnel have access to its environment, the roles and permissions assigned to them, and the scope of access granted to any third party or integration it connects. A Client may restrict access by permitted network range where that feature is enabled.
- Recording, retention and audit settings. Where the Platform offers configurable recording, retention or deletion settings, the Client selects them. Audit logs of activity within an environment are maintained as a control feature and are designed not to be alterable.
- Channels and integrations. A Client determines which channels and third-party systems are connected to the Platform, which fields are exchanged, and the access scopes granted.
- Content submitted to the Platform. A Client determines what information its users, agents and customers may submit, and what its ticket forms, fields and workflows capture.
10. Storage, retention and deletion
Location of processing. We process and store information on systems located in India and, in respect of certain functions, on systems operated by us or by providers we engage in other jurisdictions. Where information is processed outside India, we do so subject to applicable law and to appropriate contractual and technical safeguards. Where a Client requires processing to be confined to a particular jurisdiction or in jurisdictions outside India, such requirements are addressed in our agreement with the Client.
Retention of Client Data. Client Data is retained in accordance with the Client’s configuration and our agreement with the Client. On expiry or termination, and on a Client’s request made in accordance with that agreement, we delete or return Client Data within the period and by the process set out in that agreement. A Client should exercise any request relating to Client Data through the mechanisms available in the Platform or the contacts identified in its agreement.
Retention of information we hold as a Data Fiduciary. We retain information for as long as reasonably necessary for the purposes for which it was collected, including to provide and support the Services, maintain account and access records, administer agreements, maintain financial, tax and accounting records, resolve disputes, investigate and respond to security incidents and abuse, enforce our agreements, establish, exercise or defend legal claims, and comply with legal, regulatory and record-retention requirements. Retention periods vary according to the category of information, the Service and the applicable requirement.
Deletion, backups and records that persist. When information is no longer required for a purpose described in this Privacy Policy, we delete or anonymise it. Deletion from live systems does not immediately or necessarily remove information from every location. Copies may remain for a limited period in backup, replication and disaster-recovery systems until they are overwritten in the ordinary course. Audit and security logs are designed to be immutable and are retained for their own defined periods. Information may also be retained beyond a request where it is subject to a legal hold, is required for an investigation, dispute, regulatory requirement, tax or accounting obligation, or is necessary to protect against fraud, abuse or a security risk. Information retained on these bases is not used for any other purpose.
11. Security
We implement physical, technical, administrative and organisational measures designed to protect information against unauthorised access, use, disclosure, alteration, loss and destruction. These measures take into account the nature of the information, the risks presented by our processing and the state of technology, and include access control on a need-to-know basis, authentication controls, segregation of environments, encryption in transit and at rest, logging and monitoring, secure development and change-management practices, personnel screening and training, and supplier assurance. Details of our current security controls, certifications and assessments are made available to Clients and prospective Clients on request, and are maintained separately from this Privacy Policy so that they can be kept current.
No method of transmission or storage is completely secure and we cannot guarantee absolute security. You are responsible for maintaining the confidentiality of your credentials, for using any additional authentication controls made available to you, and for notifying us promptly of any suspected unauthorised access. Where we receive an instruction through an authenticated account or a valid credential, we may treat it as authorised, subject to our security and fraud controls.
12. Security incidents
We maintain processes to identify, investigate, escalate, contain and remediate security incidents, and we require providers we engage to report incidents affecting information they process for us.
Where an incident affects Client Data, we notify the affected Client without undue delay, in accordance with our agreement with that Client, and provide the information reasonably available to us to enable the Client to assess the incident and to discharge its own obligations, including any obligation to notify a regulator or affected individuals. As Data Processor, we do not notify a Client’s customers or users directly, and we do not make notifications to a regulator on a Client’s behalf, unless the Client instructs us in writing to do so or we are independently required by law.
Where an incident affects information we hold as a Data Fiduciary, we notify the Data Protection Board of India and affected individuals to the extent and in the manner required by applicable law.
13. Your rights and how to exercise them
If we hold your information as a Data Fiduciary, you may, subject to applicable law and to verification of your identity have certain rights in relation to such data. You may exercise these rights by contacting us using the details in Section 17. We may require information to verify your identity and to locate the relevant records. We may decline or limit a request to the extent permitted by applicable law, including where a request is manifestly unfounded, repetitive or excessive; where complying would adversely affect the rights, privacy or safety of another person; where the information is subject to legal privilege or relates to existing or anticipated proceedings; where compliance would prejudice an investigation, a fraud- or abuse-prevention measure or the security of our systems; or where a legal, regulatory or record-retention requirement applies.
If you are a customer or user of a business that uses Nugget, your rights in respect of Client Data are exercisable against that business as Data Fiduciary, and not specifically against Carthero. We are not permitted to grant access to, correct, erase or otherwise act on Client Data except on that business’s instructions, and we are not in a position to verify your identity in relation to its records. If you send us such a request, we will, where we are able to identify the relevant Client, forward the request to it or direct you to it, and we will take no further action on the request. Where a Client asks us to assist it in responding to a request, we will do so as provided in our agreement with that Client.
Grievance redressal. If you are dissatisfied with how a request or a concern relating to your personal data has been handled, you may escalate it using the details in Section 17, and we will respond within the period prescribed by applicable law.
14. Children’s data
The Services are directed to businesses and to individuals acting in a professional capacity. We do not knowingly collect personal data of children as a Data Fiduciary, and we do not undertake tracking, behavioural monitoring or targeted advertising directed at children. If we become aware that we have collected personal data of a child as a Data Fiduciary otherwise than as permitted by law, we will delete it.
Where a Client’s customers or users include children, or persons with a disability who have a lawful guardian, the Client is the Data Fiduciary in respect of that information. The Client is responsible for identifying such individuals, for obtaining the verifiable consent of a parent or lawful guardian where required, and for complying with the restrictions on tracking, behavioural monitoring and targeted advertising that apply to children. Carthero processes such information only as a Data Processor on the Client’s instructions, and is not in a position to determine the age or status of an individual whose information a Client submits to the Platform.
15. Information we ask Clients not to submit
The Platform is built for customer service and communications data. It is not designed or made available for the following categories of information, and Clients should not submit them unless we have expressly agreed in writing to receive them and the necessary arrangements are in place:
- payment card numbers, card verification values, magnetic-stripe or chip data and other cardholder authentication data;
- protected health information or other information subject to sector-specific health-data regulation, in the absence of an executed arrangement addressing it;
- biometric templates and identifiers;
- government-issued identity numbers and identity-authentication data, including Aadhaar numbers, virtual identifiers, authentication logs and any information subject to the Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016;
- account credentials, cryptographic keys, tokens and other secrets;
- information subject to a specific regulatory regime that imposes requirements beyond those in our agreement with the Client, including localisation, retention, audit or reporting requirements, unless those requirements have been agreed in writing; and
- classified, privileged or export-controlled information.
Where such information is nonetheless submitted, we process it as Client Data in accordance with this Privacy Policy and our agreement with the Client, and the Client remains responsible for its submission. Nothing in this Section 15 is a representation as to the treatment of any particular category of information, and the requirements applicable to a Client are those in its agreement with us.
16. Precedence, amendments and interpretation
Precedence. This Privacy Policy is a notice describing our practices. It does not vary, expand or limit the rights and obligations of Carthero or of any Client under an agreement between them. In the event of any inconsistency between this Privacy Policy and a written agreement between Carthero and a Client, including any data processing addendum, that agreement prevails in respect of Client Data. This Privacy Policy is not incorporated into any such agreement unless expressly stated in it.
Amendments. We may amend this Privacy Policy from time to time to reflect changes in applicable law, our practices, the Services or technology. We will post the amended version with a revised “last updated” date and, where required by applicable law, provide additional notice or seek consent. Where an amendment materially affects our processing of Client Data, we will notify affected Clients in accordance with our agreements with them.
Interpretation. The terms “Data Fiduciary”, “Data Processor”, “personal data”, “Data Principal” and “consent” have the meanings given to them in the Digital Personal Data Protection Act, 2023. Headings are for convenience and do not affect interpretation. References to including and similar expressions are illustrative and not limiting. This Privacy Policy is governed by the laws of India.
17. Contact us
If you have a query, concern or request relating to this Privacy Policy or to our processing of personal data, or wish to raise a grievance, you may contact us at the following address.
Data Protection Officer and Grievance Officer, Carthero Technologies Private Limited
Email: privacy@nugget.com
If you are a customer or user of a business that uses Nugget, please contact that business directly, as explained in Section 13.
If you use the Platform on behalf of a Client, please raise queries relating to your organisation’s use of the Platform through your organisation’s administrator or the contacts identified in its agreement with us.
The officer named above is designated under the Digital Personal Data Protection Act, 2023 and holds no role, function or accountability under the laws referred to in Annex 1. Requests and complaints within the scope of Annex 1 should be addressed to privacy@nugget.com or, where applicable, to the representative identified in Part A, and not to that officer.
Annex 1: Jurisdiction-specific Disclosures
Each Part below applies only to the processing and the individuals identified in it, and applies in addition to this Privacy Policy.
Part A: European Economic Area and United Kingdom
Application. This Part applies only where Carthero acts as a controller in respect of processing to which the EU General Data Protection Regulation or the UK General Data Protection Regulation applies. That processing is limited to the categories described in Section 4.
Client Data. Carthero is a processor in respect of Client Data and the Client is the controller. Carthero processes Client Data only on the controller’s documented instructions, under a written agreement containing the terms required by Article 28(3). The controller is responsible for the information required by Articles 13 and 14, for establishing a lawful basis and for responding to data subject requests. If you are a customer or user of a business that uses Nugget, please direct any request or complaint to that business.
Controller and representative. The controller is Carthero Technologies Private Limited, contactable at privacy@nugget.com.
Purposes, legal bases and recipients. The purposes for which we process personal data as a controller are those in Section 5, and the recipients are those in Sections 7 and 8. We rely on the performance of a contract with you or with your organisation, or steps preparatory to it, to provision and administer Platform access, deliver and support the Services and administer agreements and payments; on our legitimate interests in securing the Services and our systems, preventing fraud and abuse, monitoring and improving reliability and performance, conducting business-to-business marketing and relationship management, managing suppliers, and establishing, exercising or defending legal claims; on compliance with a legal obligation, for accounting, tax, employment, regulatory, disclosure and record-retention requirements; and on consent, where we ask for it. We do not take decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you.
Transfers outside the EEA and the United Kingdom. Personal data is transferred to and processed in India and in other jurisdictions in which we or providers we engage operate. India is not the subject of an adequacy decision. We rely on the European Commission’s standard contractual clauses and, for transfers from the United Kingdom, the International Data Transfer Agreement or the UK Addendum to those clauses, together with supplementary measures where appropriate. A copy of the relevant mechanism, with commercial terms redacted, is available on request.
Retention. Retention periods and the bases on which we determine them are set out in Section 10.
Your rights. Requests regarding your rights under applicable laws may be made to privacy@nugget.com and are subject to the conditions and exemptions in applicable law and to verification of identity.
Part B: California
Application. This Part applies only where Carthero acts as a business under the California Consumer Privacy Act, as amended, in respect of personal information of California residents. That processing is limited to the categories described in Section 4, which are within the scope of that Act notwithstanding that our relationship with the individuals concerned is a commercial or employment one.
Client Data. Carthero acts as a service provider in respect of Client Data. We receive it under a written contract that limits our processing to the business purposes specified in it, and under which we do not sell or share it, do not retain, use or disclose it for any purpose other than performing the services and the purposes permitted by that Act, do not combine it with personal information received from another source except as permitted, and impose equivalent obligations on the persons we engage. If you are a customer or user of a business that uses Nugget, that business is responsible for responding to your requests, and requests sent to us will be handled as described in Section 13.
Categories of personal information. In the twelve months preceding the date of this Privacy Policy we collected the following categories as a business: identifiers, including name, business email address, telephone number, account identifier, IP address and device identifiers; personal information as described in Cal. Civ. Code § 1798.80; professional and employment-related information; education information, in respect of applicants; commercial information, including subscription, billing and transaction records; internet and network activity information, including usage, diagnostic, telemetry and security records; geolocation inferred from IP address at city level; audio and electronic information, including recorded support or meeting interactions where recording is notified; and inferences drawn from the foregoing. The sources of that information are set out in Section 4, the purposes for collecting it in Section 5, and the categories of recipients to whom we disclose it in Sections 7 and 8. Retention is addressed in Section 10.
Sensitive personal information. The only sensitive personal information we collect as a business is account log-in credentials in combination with information permitting access to an account, which we process to authenticate users and secure accounts. We do not use or disclose sensitive personal information for any purpose that requires an option to limit its use.
Sale and sharing. We do not sell personal information and do not share it for cross-context behavioural advertising, and have not done so in the twelve months preceding the date of this Privacy Policy. We do not sell or share the personal information of any individual we know to be under sixteen years of age.
Your rights. Requests regarding your rights under applicable laws may be made to privacy@nugget.com and are subject to the conditions and exemptions in applicable law and to verification of identity.