Skip to content
Nítido
Menu

This policy explains what personal data Nítido (“we”, “us”) collects, why, who we share it with, and the choices you have. It applies to nitido.in, to enquiries and conversations with us, to our outreach to businesses, to the services we provide to clients, and to the tools we use that connect to your Google, Meta or other accounts with your permission.

We process personal data in line with the Digital Personal Data Protection Act, 2023, the Information Technology Act, 2000 and the rules made under them. For the purposes of that law, Nítido is the data fiduciary.

1. What we collect

What you give us. Your name, business name, email address, phone number and anything you write to us, through this site, email, phone, WhatsApp or in a meeting.

When you become a client. Information about your business, brand files, photographs and videos, login access or permissions to the accounts we manage for you (for example your Google Business Profile, Instagram, Facebook Page, ad accounts and website), and billing details such as your billing name, address and GSTIN. We do not store card or bank account numbers; payments are handled by your bank or a payment provider.

Publicly available business information. To find businesses we may be able to help, we collect business details that the business itself has made public: business name, category, address, public phone number, public email address, website, ratings and listing details from sources such as Google Maps, business websites and public social media profiles. We use this only to contact the business about our services.

Conversations. Emails, WhatsApp messages and notes we make about calls and meetings with you. We do not record calls.

This website. This site does not set cookies, does not use analytics, and does not run advertising trackers. Like every website, our hosting provider and the providers that serve our fonts and page scripts receive standard technical data (IP address, browser type, the page requested) in order to deliver the page.

2. How we use it

  • To reply to you and discuss what you need.
  • To prepare proposals, deliver the services you engage us for, report on them, and invoice for them.
  • To contact businesses about our services, using the business’s public contact details. Every message tells you how to opt out, and we honour opt-outs permanently.
  • To keep our systems secure, prevent misuse, and meet legal, tax and accounting obligations.

We process your data with your consent, to perform a contract with you or take steps you asked for before one, and for the other legitimate uses permitted under Section 7 of the Digital Personal Data Protection Act, 2023. We do not sell personal data, and we do not use it for any purpose unrelated to the ones above.

3. Data from Google accounts

Some of our work requires connecting to a Google account, for example a Google Business Profile, Gmail, Google Calendar, YouTube or Google Ads, through Google’s secure sign-in (OAuth). When you grant that access:

  • We request only the permissions needed for the specific feature you are using, and we tell you what each one is for before you grant it.
  • We use the data only to provide or improve the user-facing features you asked for: for example managing your listing and replying to reviews, scheduling meetings, sending email you have approved, or reporting on your campaigns.
  • We do not sell Google user data, use it for advertising, use it to build user profiles for unrelated purposes, or use it to train or improve general artificial intelligence or machine learning models.
  • People at Nítido do not read Google user data unless you have given us explicit permission for a specific item, it is needed for security or to investigate abuse, or the law requires it.
  • You can revoke our access at any time from your Google Account at myaccount.google.com/permissions, and ask us to delete what we hold (see your rights).

Nítido’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

4. Data from Meta platforms

When you connect a Facebook Page, Instagram account, WhatsApp Business account or Meta ad account, we access the data needed to publish content, manage messages and comments, run ads and report results for you. We follow Meta’s Platform Terms and Developer Policies, use this data only to provide our services to you, and never sell it. You can remove our access at any time in your Facebook or Instagram settings under Business Integrations or Apps and Websites. To have us delete the data we hold, follow the steps on our data deletion page.

5. Artificial intelligence

We use AI tools to research, draft, design and edit. Business information you share may be processed by AI service providers to produce your work. We keep passwords, payment details and your customers’ personal data out of these tools. Every output is reviewed by a person before it is used. Read more on our AI use page.

6. Who we share it with

We share personal data only with:

  • Service providers who process it for us under contract: cloud hosting and database providers, email and productivity providers, AI model providers, and payment processors.
  • Platforms acting on your instructions, such as Google and Meta, when we publish content or run campaigns for you.
  • Authorities when the law requires it, or to protect our rights, our clients or the public.
  • A successor business if Nítido is merged or sold, subject to this policy.

Some of these providers store or process data outside India. Where they do, we use providers bound by contractual confidentiality and security obligations, and we follow any restrictions the Government of India notifies under the Act.

7. How long we keep it

  • Enquiries that do not become work: up to 24 months from our last conversation, then deleted.
  • Outreach records: until you opt out or ask for deletion. After an opt-out we keep only the minimum needed to make sure we never contact you again.
  • Client data: for the length of our engagement, then returned or deleted within 30 days of it ending, except records we must keep longer under tax and accounting law.
  • Access to your accounts: removed when our engagement ends. Please also revoke it from your side.

8. Security

We protect data with access controls, encryption in transit, encrypted storage where our providers support it, and least-privilege access for our team. No system is perfectly secure. If a breach affects your personal data, we will tell you and the Data Protection Board of India as the law requires.

9. Your rights

You can ask us to:

  • tell you what personal data we hold about you and how we use it;
  • correct, complete or update it;
  • erase it, where we are not required to keep it;
  • stop contacting you, or withdraw a consent you gave (this does not affect what was done before you withdrew it);
  • nominate someone to exercise these rights for you in case of death or incapacity.

Email dakshdayalani@nitido.in from the address we know you by, or tell us how else to verify you. We respond within 30 days. If you are not satisfied with our response, you may complain to the Data Protection Board of India.

10. Children

Our services are for businesses. This site is not directed at children, and we do not knowingly collect personal data from anyone under 18. If you believe we have, write to us and we will delete it.

11. Grievance officer

Daksh Dayalani
Nítido, I1-103, The Meadows, Adani Shantigram, Gandhinagar, Gujarat 382421, India
home@nitido.in

We acknowledge every grievance within 48 hours and resolve it within 30 days.

12. Changes to this policy

We will update this page when our practices change and revise the date at the top. If a change materially affects how we use data you have already given us, we will tell you directly before it takes effect.