GDPR Compliance at CSNook

Customer Data Deserves More Than Compliance

Customer success depends on data. Protecting that data should never be an afterthought.

CSNook is built to support organizations in managing customer information responsibly while meeting their obligations under the General Data Protection Regulation (GDPR). From how customer data is collected and processed to where it is stored, how long it is retained and how deletion requests are handled, privacy is considered throughout the data lifecycle.

We provide customers with the controls, processes and transparency they need to use CSNook while maintaining their own GDPR compliance responsibilities.

Protect Customer Data. Maintain Control. Build Trust.

How GDPR Applies to CSNook

GDPR establishes requirements for organizations that collect, use, store or otherwise process Personal Data relating to individuals protected by the regulation.

When organizations use CSNook to manage their customer relationships, two different privacy roles can apply.

For information CSNook collects directly for purposes such as operating our website, managing accounts, providing support and managing our own business activities, Nook Ventures Private Limited generally acts as the Data Controller.

When a customer imports, connects, synchronizes or otherwise makes Personal Data available through the CSNook platform, the customer generally acts as the Data Controller and CSNook acts as the Data Processor.

This means our customers determine why their Customer Data is processed and how they intend to use it, while CSNook processes that data to provide the Services requested by the customer and in accordance with applicable contractual and legal requirements.

GDPR Compliance Built Around the Customer Data Lifecycle

Collect Only What You Need

CSNook enables customer success teams to consolidate the information they need to understand customer relationships without requiring unnecessary categories of Personal Data.

Depending on the integrations and configuration selected by a customer, this may include customer contact information, product activity, feature adoption, account details, communications, support history, customer sentiment, lifecycle information, onboarding activity, health scores, subscription information and customer-success milestones.

Customers determine what information they connect to CSNook and remain responsible for ensuring that they have an appropriate lawful basis for collecting and processing that information.

CSNook does not use Customer Data to train generalized CSNook artificial-intelligence or machine-learning models.

Know Where Your Data Is Stored

CSNook uses Google Cloud Platform infrastructure for production hosting and operates infrastructure across multiple geographic regions.

Where available and technically feasible, we seek to keep primary Customer Data in a hosting region selected for, or geographically aligned with, the customer. This approach allows customers to better manage data-residency requirements while benefiting from scalable cloud infrastructure.

Certain supporting services, integrations, security systems, backups, monitoring systems and subprocessors may process information in other jurisdictions where necessary to operate the Services.

Where international transfers of Personal Data are subject to GDPR requirements, CSNook supports the implementation of appropriate safeguards and transfer mechanisms required under applicable data-protection law.

Keep Control of Your Customer Data

Your data remains your data.

CSNook customers determine what Customer Data is connected to the platform, which integrations are enabled, which users have access to their environment and how customer-success information is used by their organization.

If an integration is no longer required, customers can disconnect the relevant service to prevent future synchronization through that integration.

Customers may also request access, export or deletion of their Customer Data in accordance with their contractual relationship with CSNook and applicable law.

Designed to Support GDPR Principles

Lawful, Fair and Transparent Processing

We believe organizations should understand what happens to their data throughout its lifecycle.

Our Privacy Policy describes the categories of information we process, why information is processed, the circumstances in which information may be disclosed, how long information may be retained and the privacy rights available to individuals.

Where CSNook acts as a processor, customers remain responsible for establishing the appropriate lawful basis for their processing. CSNook processes the relevant Customer Data for the purpose of providing and supporting the Services requested by the customer.

Purpose Limitation

Customer Data processed through CSNook is used to provide the platform and functionality requested by our customers.

We do not sell Customer Data to advertisers or data brokers, and Customer Data is not used by CSNook for third-party behavioral advertising.

We also do not use Customer Data to train generalized CSNook AI or machine-learning models.

Data Minimization

CSNook is designed to allow customers to determine what systems they connect and what information they make available to the platform.

Customers can configure their customer-success environment around their operational requirements instead of being required to provide categories of Personal Data that are unnecessary for their use of CSNook.

Data Accuracy

Customer success decisions depend on current and reliable information.

Through integrations with customers’ business systems, CSNook helps consolidate customer information from connected sources. Customers remain responsible for the accuracy of information originating within their systems and may update or correct information through their underlying systems and applicable CSNook functionality.

Storage Limitation

We do not intend to retain Customer Data indefinitely.

Unless otherwise agreed with a customer, Customer Data may be retained for up to 180 days following termination of the customer’s CSNook Services.

Customers do not have to wait for that period to expire. An authorized customer may request earlier deletion, subject to applicable legal, contractual and technical requirements.

Information removed from active systems may remain temporarily within protected backups until those backups are overwritten or deleted through normal backup-retention procedures.

Security and Confidentiality

CSNook maintains administrative, organizational and technical safeguards designed to protect Personal Data against unauthorized access, disclosure, alteration, misuse, loss or destruction.

Access to Personal Data is intended to be limited to authorized personnel and service providers who require access for legitimate operational purposes and who are subject to appropriate confidentiality obligations.

Our infrastructure and operational environment uses established technology providers to deliver functions such as cloud hosting, databases, network protection, monitoring, communications and operational support.

Your GDPR Rights

GDPR gives individuals greater visibility and control over their Personal Data.

Depending on the circumstances and applicable law, individuals may have the right to know whether their Personal Data is being processed and obtain access to it; have incorrect or incomplete information corrected; request deletion of Personal Data where the applicable conditions are satisfied; request that processing be restricted; obtain certain Personal Data in a portable, machine-readable format; object to certain processing based on legitimate interests; object to direct marketing at any time; and withdraw consent where consent is the legal basis for processing.

Individuals may also have rights concerning decisions based solely on automated processing where those decisions produce legal or similarly significant effects.

CSNook’s customer health scores, churn indicators, adoption metrics and similar customer-success analytics are designed to provide decision-support information to customer teams. CSNook does not independently use these indicators to make solely automated decisions that have legal or similarly significant effects on individuals.

Handling GDPR Requests

When CSNook Is the Controller

Where CSNook acts as the Data Controller, individuals may submit an applicable privacy request by contacting:

support@nookventures.com

We may need to verify the requester’s identity before providing access to, correcting or deleting Personal Data.

Where GDPR applies, valid requests will be addressed without undue delay and generally within one month of receipt, subject to extensions permitted under applicable law for complex or numerous requests.

When Our Customer Is the Controller

Most Personal Data contained within a customer’s CSNook environment is processed by CSNook on behalf of that customer.

If you are an employee, user, customer or other individual whose information has been provided to CSNook by one of our customers, the organization that provided the information will generally be the Data Controller.

You should therefore submit your GDPR request directly to that organization.

If CSNook receives a request concerning Customer Data for which one of our customers is the controller, we may refer the individual to the relevant customer and provide reasonable assistance to that customer in fulfilling the request where required.

The Right to Be Forgotten

GDPR may give individuals the right to request erasure of their Personal Data in certain circumstances.

Where CSNook acts as controller and a valid deletion request applies, we will take appropriate steps to remove the relevant Personal Data, subject to any legal basis or obligation requiring continued retention.

Where CSNook processes the information on behalf of a customer, the relevant customer should determine whether the deletion request should be fulfilled and instruct CSNook accordingly.

Our customers may also request deletion of Customer Data before CSNook’s standard 180-day post-termination retention period expires.

The Right to Object

Individuals may have the right to object to processing based on legitimate interests in circumstances provided by GDPR.

Individuals also have the right to object to the use of their Personal Data for direct marketing.

Where CSNook receives a valid objection relating to processing for which it acts as controller, we will evaluate and action that objection as required under applicable law.

Where the processing is performed on behalf of a CSNook customer, the request should ordinarily be directed to the relevant customer as the controller.

Privacy Across Your Integrations

Customer success teams rarely work from a single application. CSNook is therefore designed to connect customer information from the systems teams already use.

Customers may integrate CSNook with services such as Google Workspace and Gmail, Microsoft 365 and Outlook, Slack, CRM platforms, product analytics systems, customer-support applications, communication platforms, billing systems and other business tools.

The customer controls which integrations are enabled and determines what information is made available through those integrations.

CSNook processes information received from connected services as necessary to provide the functionality authorized by the customer.

Where a customer disconnects an integration, future synchronization from that connection can be stopped. Information previously processed through that integration remains subject to applicable retention and deletion requirements unless an appropriate deletion request is made.

Google Workspace Privacy

Where a customer connects Google Workspace functionality to CSNook, access is limited to the permissions required for the functionality authorized by the customer or user.

CSNook does not sell Google Workspace user data, use it for advertising, create advertising profiles from it or use Google Workspace user data to train generalized artificial-intelligence or machine-learning models.

Our use of information obtained through Google APIs is intended to comply with applicable Google API Services User Data Policy and Limited Use requirements.

Users may revoke applicable access through the relevant Google account settings or through available CSNook integration controls.

Customer Data and AI

Your AI. Your Choice. Your Data Controls.

CSNook does not currently operate its own large language model that independently consumes Customer Data, and Customer Data is not used to train generalized CSNook AI or machine-learning models.

CSNook may provide Model Context Protocol (MCP) functionality that allows customers to connect their CSNook environment to an AI assistant or large language model selected by that customer.

This allows authorized users to ask questions and generate insights from their customer information through an AI service they choose.

The customer determines whether an MCP connection is enabled, which AI provider is used, who is authorized to use it and what data may be requested through the connection.

When a third-party AI provider receives Personal Data, that provider’s processing is governed by the applicable configuration, terms, privacy commitments and contractual relationship associated with that AI service.

Organizations should therefore assess the privacy and data-processing terms of their selected AI provider before enabling Personal Data to be accessed through MCP.

CSNook remains responsible for the processing performed within CSNook and does not transfer its own data-protection responsibilities merely because a customer chooses to connect another service.

Subprocessors

Delivering a secure, scalable SaaS platform requires working with specialized technology providers.

CSNook uses subprocessors and infrastructure providers for functions such as cloud hosting, databases, network protection, monitoring, logging, communications, analytics, engineering and operational support.

Our environment may include established providers such as Google Cloud Platform, Cloudflare, MongoDB Atlas, BigQuery, Grafana and Prometheus, Mailgun, Google Cloud Logging, Zoho, Amplitude, Atlassian and GitHub.

We maintain information about relevant subprocessors through our Trust Center so customers can understand the third parties involved in delivering the Services.

Where required, subprocessors are subject to appropriate contractual privacy and confidentiality requirements.

International Data Transfers

CSNook serves organizations that may operate across different jurisdictions. As a result, Personal Data may in certain circumstances be processed outside the country in which it was originally collected.

Our use of geographically distributed GCP infrastructure is intended to help customers maintain primary Customer Data closer to their selected or applicable operating region where technically feasible.

Where GDPR applies to an international transfer requiring safeguards, the transfer will be handled using an applicable lawful mechanism or safeguards required by data-protection law.

These mechanisms may include approved contractual safeguards, such as the European Commission’s Standard Contractual Clauses, where appropriate, together with supplementary measures where required.

Our customers should also assess international transfers generated by integrations or external services that they independently choose to connect to CSNook.

What Happens When You Stop Using CSNook?

Privacy obligations do not end when a subscription does.

When a CSNook account is terminated, Customer Data may enter a retention period of up to 180 days, unless another period has been contractually agreed.

This period allows appropriate account administration and, where applicable, customer-requested recovery while maintaining a defined endpoint for Customer Data retention.

Customers may request deletion before the 180-day period has elapsed.

Following deletion from active systems, residual information may remain temporarily in protected backup systems until normal backup cycles remove or overwrite it.

Certain information may be retained for longer where required to comply with law, resolve disputes, maintain necessary business records or establish, exercise or defend legal claims.

Privacy by Design, Not as an Add-On

For CSNook, GDPR readiness is not limited to a privacy policy.

Our approach is based on giving organizations transparency over where Customer Data comes from, the ability to determine which systems are connected, controls over who can use their CSNook environment, defined retention and deletion processes, responsible use of subprocessors, support for privacy requests and clear boundaries around the use of Customer Data for advertising and AI training.

As CSNook evolves, we continue to review our privacy and data-governance practices alongside changes to our Services and applicable regulatory requirements.

GDPR Responsibilities: CSNook and Our Customers

GDPR compliance is a shared responsibility.

When CSNook acts as a Data Processor, we are responsible for the processing activities we perform on behalf of our customers and for maintaining appropriate safeguards around the Services we provide.

Customers acting as Data Controllers remain responsible for matters such as determining their lawful basis for processing, providing appropriate privacy notices to their users, responding to Data Subject Requests, determining what Personal Data is connected to CSNook, configuring access appropriately and ensuring their use of CSNook and connected third-party services complies with applicable law.

We work with customers to support these responsibilities rather than replacing them.

Frequently Asked Questions

Is CSNook GDPR compliant?

CSNook is designed and operated to support the requirements of GDPR applicable to its processing activities and to help customers meet their own GDPR obligations when using the platform.

GDPR responsibilities depend on the role of each organization and the specific processing involved. In most Customer Data scenarios, the customer acts as the Data Controller and CSNook acts as the Data Processor.

Does CSNook own my Customer Data?

No. Customers retain control over the Customer Data they provide to or connect with CSNook, subject to their applicable agreements with CSNook.

Does CSNook sell Customer Data?

No. CSNook does not sell Customer Data to advertisers or data brokers.

Does CSNook use Customer Data to train AI models?

No. CSNook does not use Customer Data to train generalized CSNook AI or machine-learning models.

Can CSNook connect to third-party AI tools?

Yes. Customers may be able to use CSNook’s MCP functionality to connect their CSNook environment with a compatible AI or LLM service selected by them.

The customer determines whether that connection is enabled and is responsible for evaluating the data-processing practices of the external AI provider.

Where does CSNook store Customer Data?

CSNook uses Google Cloud Platform infrastructure across multiple regions. Where available and technically feasible, we seek to align primary Customer Data hosting with a region selected for, or geographically appropriate to, the relevant customer.

Some supporting services and subprocessors may process data from other jurisdictions.

How long does CSNook retain Customer Data?

Unless otherwise agreed, Customer Data may be retained for up to 180 days after termination of Services.

Customers may request deletion before that period expires.

Can a customer request immediate deletion?

Customers may submit an authorized request for earlier deletion. Such requests are processed subject to applicable legal, contractual and technical requirements.

Can I ask CSNook to delete Personal Data about me?

Yes, where CSNook is the Data Controller for that information and the applicable requirements for deletion are satisfied.

Where CSNook processes your information on behalf of one of our customers, you should generally contact that customer first because it is normally the Data Controller responsible for your request.

Does CSNook make automated decisions about individuals?

CSNook may provide health scores, churn indicators, engagement metrics and similar analytics, but these are designed as decision-support information for customer teams.

CSNook does not independently use these metrics to make solely automated decisions that produce legal or similarly significant effects on individuals.

Who can I contact about GDPR?

For privacy enquiries or applicable GDPR requests relating to CSNook, contact:

support@nookventures.com

Take Control of Customer Data Without Compromising Customer Success

Bring customer information together while maintaining the visibility, control and privacy practices modern customer-success teams require.

Build stronger customer relationships with privacy at the center.

Company Information

Nook Ventures Private Limited
Room No 112, 2-A/3, S/F Kundan Mansion
Turkman Gate, Darya Ganj
New Delhi, Central Delhi – 110002
India

Privacy Contact: support@nookventures.com