Nutan · Compliance Attestation

NUT-CCPA-001

CCPA Compliance Notice

California Consumer Privacy Act (as amended by CPRA) notice and rights.

Public
AI

AI-generated attestation. This report is produced automatically by Nutan's AI from our codebase, deployment state, and operational runbooks — the primary source of truth about what Nutan does. Nutan is not yet externally certified by an AICPA-licensed firm; formal certification is on our roadmap. This document serves as an internal attestation suitable for procurement review, vendor risk assessment, and internal security review.

Document Record

Document ID
NUT-CCPA-001
Version
2026.04.20-r1
Framework
CCPA / CPRA
Report type
Statement
Reporting period
Effective April 20, 2026
Classification
Public
Generated
April 20, 2026
Source commit
d842878
Prepared by
Nutan AI (Internal statement)
Verification
Hashes of source-of-truth embedded in document ID

1.0 · Executive Summary

This notice describes Nutan's practices concerning personal information of California residents under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA). Nutan does not sell or share personal information, does not use sensitive personal information for inferring characteristics, and offers each right granted by the statute.

2.0 · Findings & Controls

2.1Scope

This notice applies to California residents whose personal information Nutan collects. It covers collection, use, disclosure, retention, and the rights available to consumers.

2.2Categories of Personal Information Collected (Cal. Civ. Code §1798.140(v))

During the reporting period, Nutan collected the following categories of personal information:

  • Identifiers: email address, name, company name (when provided)
  • Commercial information: records of products or services requested (invite requests)
  • Internet or other electronic network activity: browsing behaviour on the marketing site, help chat queries
  • Geolocation data: coarse IP-derived location for security purposes only
  • Inferences: none — Nutan does not derive psychological, behavioural, or consumer profiles

2.3Sources of Personal Information

Information is collected directly from the consumer (form submissions, help chat), from the consumer's device (limited telemetry with consent), and from authentication providers (Google sign-in when used).

2.4Business Purposes for Collection and Use

Personal information is used for the following business purposes:

  • Providing the service requested (account creation, authentication, product functionality)
  • Maintaining service security, integrity, and reliability
  • Communicating about invite status, product updates, and legal notices
  • Compliance with legal obligations

2.5Categories of Third Parties With Whom PI Is Shared

Nutan shares personal information only with sub-processors listed at nutan.ai/sub-processors. No sharing occurs for advertising or behavioural profiling.

2.6Sensitive Personal Information (SPI)

Nutan does not collect sensitive personal information as defined by §1798.140(ae) beyond authentication credentials, which are processed solely to authenticate the consumer and are not used to infer characteristics.

2.7Sale or Sharing of Personal Information

Nutan does not sell personal information and does not share personal information for cross-context behavioural advertising. No opt-out link is required because no such sale or sharing occurs. The "Do Not Sell or Share My Personal Information" choice is effectively the default state for every consumer.

2.8Right to Know (§1798.110)

Consumers have the right to request the categories and specific pieces of personal information Nutan has collected about them. Verifiable requests are fulfilled within 45 days.

2.9Right to Delete (§1798.105)

Consumers have the right to request deletion of personal information. Nutan's granular erasure controls implement this right directly in-product; verifiable requests through other channels are honoured within 45 days.

2.10Right to Correct (§1798.106)

Consumers have the right to correct inaccurate personal information. Most fields can be corrected directly in-product; other fields are corrected on verifiable request.

2.11Right to Opt-out (§1798.120)

Consumers have the right to opt out of the sale or sharing of personal information. Nutan does not sell or share; no action is required from the consumer.

2.12Right to Limit Use of Sensitive Personal Information (§1798.121)

Consumers have the right to limit the use of sensitive personal information. Nutan does not use SPI for purposes that would trigger this right.

2.13Right to Non-Discrimination (§1798.125)

Nutan does not discriminate against consumers who exercise their CCPA rights. Product functionality, pricing, and quality are not conditioned on waiver of rights.

2.14Authorised Agents

Consumers may designate an authorised agent to exercise rights on their behalf. The agent must provide written permission from the consumer and verify their own identity.

2.15How to Exercise Rights

Rights may be exercised through in-product controls (Settings → Privacy) for most requests, or via the online submission form at nutan.ai/privacy/requests — a ticket ID is issued immediately and the privacy agent handles routing. Nutan verifies identity before acting on any request.

2.16Retention

Personal information is retained only as long as necessary for the business purposes described above or as required by law. Invite request data is retained until the consumer requests removal. Account data is retained for the duration of the account plus up to 30 days for safe deletion.

2.17Minors

Nutan does not knowingly collect personal information from consumers under 16. Consent for minors, if applicable, would be obtained through a parental opt-in process.

2.18Changes to This Notice

This notice is regenerated alongside every release. The current version is always published at nutan.ai/trust-center/reports/ccpa.

Attestation

This document was prepared by Nutan AI (Internal statement) on April 20, 2026 from the operational state of Nutan at source commit d842878. The contents reflect the control environment in place as of the reporting period.

Prepared by

Nutan AI

Autonomous operations

Dated

April 20, 2026

Authorised under thesis of

Founder

Nutan

Dated

April 20, 2026

NUT-CCPA-001 · v2026.04.20-r1Classification: PUBLICnutan.ai/trust-center

Need a signed counterpart or an executed contract? Use the self-serve flow.