Nintex
Graded against 804 verified platforms, from its own policy text. Automated assessment against a published rubric — not legal advice.
“The Nintex Services do not retain user data obtained via third party applications or software, including but not limited to Google Workspace’s API, to develop, train, or improve generalized AI or ML models.”
Watch: governing law disputes
Start here. These are the highest-risk verified clauses AIRIN found in the platform's own policy text.
This segment restricts users from accessing or using the services except as authorized by applicable laws, places the responsibility for compliance with jurisdictional laws on the user, and identifies Nintex's headquarters location, establishing geographic and legal compliance obligations tied to use of the site and services.
Establishes Nintex's obligation to retain personal data for the duration of account activity or as needed for services, legal rights compliance, legal requirements, and record-keeping, and to process customer data per customer instructions, with a procedure for requesting deletion.
Establishes Washington State law as governing law, designates Seattle, Washington courts as the exclusive jurisdiction for disputes, requires user consent to personal jurisdiction there, and restricts use in jurisdictions that do not give effect to all Terms provisions.
Scores derived from 55 enriched findings — same verbatim citations as below. AI-generated, not legal advice.
- Data handling is conditional — 9 privacy or retention clauses warrant review before using Nintex at scale.
Derived from AI-enriched analysis of the verified findings below — informational only, not legal advice.
How to read this page: Overall risk rates what Nintex's own policy terms mean for your prompts, outputs, and data. The benchmark bands below grade those same verified terms relative to peers — a platform in a risky-by-default category can rate HIGH risk and still grade STRONG against its peer set. Both trace to the cited findings.
Policy benchmark
rubric v1.0 — how this is scoredBased on 125 verified, verbatim-cited findings below — read the citations.
Based on 154 verified, verbatim-cited findings below — read the citations.
Automated assessment against a published rubric — not legal advice.
Fully verified — complete core corpus captured and read in full.
- Terms of ServiceVerified - read in full - 33 citationsstaticLast captured 2026-08-14
- Privacy PolicyVerified - read in full - 95 citationsstaticLast captured 2026-08-14
Only citation-backed plan differences are shown here; absent cells mean AIRIN has not verified a tier-specific claim.
Expressly restricts Nintex from retaining user data obtained via third-party applications or software, including Google Workspace's API, for the purpose of developing, training, or improving generalized AI or ML models, constituting a binding prohibition on training data use.
" The Nintex Services do not retain user data obtained via third party applications or software, including but not limited to Google Workspace’s API, to develop, train, or improve generalized AI or ML models."
Describes the purposes and sources of Nintex's personal data collection, including voluntary provision by users, registration, use of services, events, and receipt from third-party partners, establishing the factual and legal basis for collection practices.
" In order to provide and continually improve the Nintex Services, we collect information which may include Personal Data. Our collection practices are intended for interaction in the business environment. In most cases, you will voluntarily..."
Establishes Nintex's legal obligation under California law to disclose the categories of personal data collected and disclosed for business purposes, introducing the enumerated categories that follow.
" California law requires that we detail the categories of Personal Data that we collect, and the categories of personal data that we disclose for business purposes; those categories are:"
Defines the 'Contact Data' category of personal data collected by Nintex, including name, employer, job title, business email, physical address, and phone number.
" Contact Data. Name, employer, job title, business email address, physical business address, phone number, and similar contact information."
Restricts users from accessing or using the Site and Services except in compliance with U.S. law and applicable local jurisdiction laws, and places responsibility on users to maintain compliant internet connections, including export and import controls, limiting geographic and legal permissibility of use.
" Nintex, the owner and controller of the Site, is headquartered in the State of Washington in the United States. You are responsible for securing, using, and monitoring an internet connection, which may include a VPN, that is compliant with..."
States a purpose for which personal data is used — enforcing terms and conditions and protecting the business, partners, and users — creating an operative data-use obligation tied to enforcement activity.
" Enforce our terms and conditions, or protect our business, our partners, or our users."
Issues a broad 'as is' and 'as available' warranty disclaimer, negating all express and implied warranties regarding the accuracy, reliability, availability, and non-infringement of the Site, Site Content, and Services, thereby shifting risk of use entirely to the user.
" YOUR USE OF THE SITE, SITE CONTENT, AND ANY SERVICES OR ITEMS OBTAINED THROUGH THE SITE IS AT YOUR OWN RISK. THE SITE, SITE CONTENT, AND ANY SERVICES OR ITEMS OBTAINED THROUGH THE SITE ARE PROVIDED WITHOUT ANY WARRANTIES OF ANY KIND, EITHE..."
Establishes Nintex's obligation to maintain contracts with business partners restricting their access, use, and disclosure of personal data, while permitting sharing with trusted partners for service delivery purposes.
" Business partner services. We share information with our trusted partners who work on behalf of Nintex to provide us with services. For example, we may share information with our certification partners, our data storage and data analysis p..."
Clause A states third parties collect personal data through the platform's websites, while Clause B explicitly states the privacy policy does not apply to third parties collecting data for their own purposes, creating ambiguity about the policy's coverage for data collected on the platform's own domain.
" Some third parties, including analytics companies, advertisers, and ad networks, may automatically collect information about you through our websites using cookies, web beacons, and device identifiers. The information collected can include Personal Data about your online activities over time and across different websites, devices, online channels and applications."
" We may facilitate third party services or ways to share data through third parties, including social media platforms, websites, applications, and services through “plug-ins,” widgets, buttons, and other third-party features on and connected with our websites, communications, or products. Third parties whose services you use in connection with Nintex, for instance third party websites we link to, may have information practices that are different than ours. This Privacy Policy does not apply to the activities of third parties when they are collecting or using data for their own purposes or on behalf of others. We are not responsible for the activities of these third parties. We encourage you to review their privacy policies to understand how they use your information."
Within one documentClause A states third parties collect personal data through the platform's websites, while Clause B explicitly states the privacy policy does not apply to third parties collecting data for their own purposes, creating ambiguity about the policy's coverage for data collected on the platform's own domain.
" Some third parties, including analytics companies, advertisers, and ad networks, may automatically collect information about you through our websites using cookies, web beacons, and device identifiers. The information collected can include Personal Data about your online activities over time and across different websites, devices, online channels and applications."
" We may facilitate third party services or ways to share data through third parties, including social media platforms, websites, applications, and services through “plug-ins,” widgets, buttons, and other third-party features on and connected with our websites, communications, or products. Third parties whose services you use in connection with Nintex, for instance third party websites we link to, may have information practices that are different than ours. This Privacy Policy does not apply to the activities of third parties when they are collecting or using data for their own purposes or on behalf of others. We are not responsible for the activities of these third parties. We encourage you to review their privacy policies to understand how they use your information."
Within one documentClause A describes third-party tracking on the platform's websites, while Clause B states that the policy does not apply to third-party data collection for their own purposes, creating confusion about the policy's scope for the activity described in A.
" From time to time, we also partner with third parties who may place cookies on your browser when you visit our websites, and may use those cookies to provide track and collect information about you and your online activities over time and across different websites, devices and applications, and to offer advertising based on your interests and previous browsing history."
" We may facilitate third party services or ways to share data through third parties, including social media platforms, websites, applications, and services through “plug-ins,” widgets, buttons, and other third-party features on and connected with our websites, communications, or products. Third parties whose services you use in connection with Nintex, for instance third party websites we link to, may have information practices that are different than ours. This Privacy Policy does not apply to the activities of third parties when they are collecting or using data for their own purposes or on behalf of others. We are not responsible for the activities of these third parties. We encourage you to review their privacy policies to understand how they use your information."
Within one documentClause A describes the platform partnering with third parties to place cookies on its websites for tracking and advertising, while Clause B explicitly states that the policy does not apply to third-party data collection for their own purposes, creating confusion about the policy's scope for activities facilitated on its own property.
" From time to time, we also partner with third parties who may place cookies on your browser when you visit our websites, and may use those cookies to provide track and collect information about you and your online activities over time and across different websites, devices and applications, and to offer advertising based on your interests and previous browsing history."
" We may facilitate third party services or ways to share data through third parties, including social media platforms, websites, applications, and services through “plug-ins,” widgets, buttons, and other third-party features on and connected with our websites, communications, or products. Third parties whose services you use in connection with Nintex, for instance third party websites we link to, may have information practices that are different than ours. This Privacy Policy does not apply to the activities of third parties when they are collecting or using data for their own purposes or on behalf of others. We are not responsible for the activities of these third parties. We encourage you to review their privacy policies to understand how they use your information."
Within one documentClause A describes the platform partnering with third parties to place cookies on its websites for tracking and advertising, while Clause B explicitly states that the policy does not apply to third-party data collection for their own purposes, creating confusion about the policy's scope for activities facilitated on its own property.
" From time to time, we also partner with third parties who may place cookies on your browser when you visit our websites, and may use those cookies to provide track and collect information about you and your online activities over time and across different websites, devices and applications, and to offer advertising based on your interests and previous browsing history."
" We may facilitate third party services or ways to share data through third parties, including social media platforms, websites, applications, and services through “plug-ins,” widgets, buttons, and other third-party features on and connected with our websites, communications, or products. Third parties whose services you use in connection with Nintex, for instance third party websites we link to, may have information practices that are different than ours. This Privacy Policy does not apply to the activities of third parties when they are collecting or using data for their own purposes or on behalf of others. We are not responsible for the activities of these third parties. We encourage you to review their privacy policies to understand how they use your information."
Within one document
Evidence appendix
Showing priority citations first. The full appendix is available for audit trails; not every citation is a severe risk.
" Many of our products and services are intended for use by organizations. When you use the Nintex Services through an organization (e.g. your employer), that organization may have access to certain information, such as username or training course completion. Please contact your organization for more information."
Informs end users that their employer or organization may access certain personal data such as username or training course completion when they use Nintex services through that organization, describing a data-sharing arrangement that affects individual privacy rights.
AI-generated interpretation, not legal advice.
" Communicate with you and for referrals regarding any promotions, upcoming contests and events, and news about products and services offered by Nintex and selected partners."
Permits Nintex to use personal data to communicate with users about promotions, contests, events, and products offered by Nintex and selected partners, including referral communications.
AI-generated interpretation, not legal advice.
" If you decline to provide your personal information or ask us to delete it, we may be unable to continue to provide or support our products or services."
Notifies users that declining to provide personal information or requesting its deletion may result in Nintex's inability to continue providing or supporting products or services, disclosing a consequence of exercising privacy rights.
AI-generated interpretation, not legal advice.
" Like many companies, Nintex uses cookies and similar technologies, like web beacons and pixel tags, to collect additional information. Cookies are small files that may be downloaded onto your device. When you visit a Nintex website again, the cookie allows that site to recognize your browser. Cookies may store preferences, like language, as well as other information and settings. Web beacons and pixel tags are small pieces of code placed on a web page or within the body of an email in order to collect data about the visitors viewing a web page or opening an email. We also use a variety of analytics tools, including Google Analytics. Analytics tools help website and app owners like Nintex understand how visitors engage with our properties."
Describes Nintex's use of cookies, web beacons, pixel tags, and analytics technologies to collect information, establishing the scope of automated data collection practices as a procedural disclosure.
AI-generated interpretation, not legal advice.
" Images, Videos, and Recordings. We may collect pictures, videos, or audio recordings of you. For example, if you attend a Nintex event, your image may be captured in a photo or video; or if you call Nintex Support, we may record the call after providing appropriate notice to you; or when you create a Nintex Community profile you may opt to include a photo."
Defines the 'Images, Videos, and Recordings' data category, listing specific scenarios (events, support calls, community profiles) where Nintex may collect such media, and notes that notice is provided before call recording.
AI-generated interpretation, not legal advice.
" Your use of the Nintex Services constitutes consent to the processing of any Personal Data as described in this Privacy Policy."
States that use of the Nintex Services constitutes the user's consent to processing of Personal Data as described in this Privacy Policy, thereby creating a legal basis for processing and imposing a consent mechanism on users.
AI-generated interpretation, not legal advice.
" Any legitimate reason to collect and use your information, including, but not limited to, gathering usage data which can include Personal Data to improve our products and services, advising you about changes to this Privacy Policy or other Nintex policies; or promoting Nintex events and products, offers and promotions."
Grants Nintex permission to process personal data based on legitimate interests, including gathering usage data to improve products, advising on policy changes, and promoting events and products.
AI-generated interpretation, not legal advice.
" We will retain your Personal Data for as long as your account is active or as needed to provide you services. We may also retain Personal Data in order protect our legal rights, comply with the legal requirements, or comply with record keeping requirements. We keep the data that we process on behalf of customers in accordance with our customers’ instructions. If you wish to request that we no longer use your information to provide you services, contact us at GDPR@nintex.com . Please keep in mind that we may need to keep your data to comply with our legal obligations, resolve disputes or enforce legal agreements."
Establishes Nintex's obligation to retain personal data for the duration of account activity or as needed for services, legal rights compliance, legal requirements, and record-keeping, and to process customer data per customer instructions, with a procedure for requesting deletion.
AI-generated interpretation, not legal advice.
" Nintex, the owner and controller of the Site, is headquartered in the State of Washington in the United States. You are responsible for securing, using, and monitoring an internet connection, which may include a VPN, that is compliant with laws and regulations of the jurisdiction from which you access the Site. You may not access the Site or use, export, re-export, import, or transfer the Services except as authorized by United States law, the laws of the jurisdiction in which you obtained the Services or accessed the Site, and any other applicable laws. In particular, but without limitation, the Nintex Services may not be exported or re-exported: (a) to any country or territory that is the subject of an embargo by the United States Government (e.g., Cuba, Iran, North Korea, Sudan, Syria, and the Crimea); or (b) to any individual or entity on a U.S. Government list of prohibited or restricted parties, including, but not limited to, the U.S. Treasury Department’s list of Specially Designated Nationals or the U.S. Department of Commerce’s Denied Persons List or Entity List. You are solely responsible for compliance with all applicable laws, and you will not use the contents of the Site or the Services for any purposes prohibited by U.S. or other applicable laws."Permalink to this finding →
This segment restricts users from accessing or using the services except as authorized by applicable laws, places the responsibility for compliance with jurisdictional laws on the user, and identifies Nintex's headquarters location, establishing geographic and legal compliance obligations tied to use of the site and services.
AI-generated interpretation, not legal advice.
" Devices, Usage and Transactional Data. We collect data related to how you access and use our products, services and websites, and analyze that usage data so we can improve the Nintex Services and your experience with the Nintex Services. Usage data may include information about your computer or mobile device’s operating system and browser type; your device type; details about how you are using Nintex Services; your Internet Protocol (IP) address; browser type and networking connection information; cookie information; file information; metadata; time stamped logs regarding access times and duration of visits; website visited before coming to a Nintex website, including pages you request, and other clickstream data."
Defines the 'Devices, Usage and Transactional Data' category, enumerating the types of technical and behavioral data (OS, browser, IP address, cookies, metadata, logs, etc.) collected to analyze and improve the Nintex Services.
AI-generated interpretation, not legal advice.
" We also collect information that you voluntarily provide by subscribing to Nintex marketing communications, registering for events, or providing testimonials for our use on our Websites or other promotional materials. Information you directly provide to us include your personal identification data (for example, name, surname) and contact information (phone, email, address, country). Additional transaction and billing information is also required when procuring Services or registering for a Nintex fee-based event."
Enumerates the categories of personal data voluntarily provided by users through marketing subscriptions, event registration, and testimonials, including identification and contact data, and notes additional billing data requirements, defining what data is collected in these contexts.
AI-generated interpretation, not legal advice.
" Do Not Track. Nintex does not respond to web browsers’ “do not track” signals. While some internet browsers offer a “do not track” or “DNT” option that lets you tell websites that you do not want to have your online activities tracked, these features are not yet uniform and there is no common standard that has been adopted by industry groups, technology companies or regulators. Therefore, we do not currently commit to responding to browsers’ DNT signals with respect to our websites."
Disclaims any obligation by Nintex to respond to browser Do Not Track signals, stating a specific non-commitment to honoring DNT requests due to lack of industry-wide standards.
AI-generated interpretation, not legal advice.
" In order to provide and continually improve the Nintex Services, we collect information which may include Personal Data. Our collection practices are intended for interaction in the business environment. In most cases, you will voluntarily provide your Personal Data. For example, we collect personal information through your registration for and use of the Nintex Services; when you use or visit Nintex sites, attend a Nintex event, or participate in the Nintex Community. We may also receive Personal Data from our third-party partners. If you are a Nintex Partner or vendor, we may also collect your personal information. If you have other agreements with Nintex, then those agreements control with respect to their subject matter."
Describes the purposes and sources of Nintex's personal data collection, including voluntary provision by users, registration, use of services, events, and receipt from third-party partners, establishing the factual and legal basis for collection practices.
AI-generated interpretation, not legal advice.
" We use the Personal Data we collect for the purposes described in this Privacy Policy, and as covered in any Agreement that incorporates this Privacy Policy, or as otherwise disclosed to you in connection with the Nintex Services. For example, we use Personal Data to:"
Introductory paragraph establishing that personal data is used for purposes described in the Privacy Policy, any incorporating Agreement, or as otherwise disclosed, framing the scope of permitted data use purposes.
AI-generated interpretation, not legal advice.
"The Services may need updating from time to time. These updates may temporarily disrupt use of the Services and are designed to improve, enhance, and further develop our Services and may take the form of bug fixes, enhanced functions, new service offerings, and updated Services. You agree to receive such updates as part of your use of the Services."
Obligates users to accept and receive service updates, including bug fixes and new features, as a condition of using the Services, and acknowledges that updates may temporarily disrupt service availability.
AI-generated interpretation, not legal advice.
" Nintex may, in its sole discretion, modify these Terms at any time. Any updated version will become effective when posted. By continuing to use the Site after these Terms have changed, you are agreeing to the revised Terms. If you do not agree to the changes, you must stop accessing, using, or, as applicable, logging in to the Site."
This segment establishes Nintex's unilateral right to modify the Terms at its sole discretion, sets the procedure by which updates become effective (upon posting), and specifies that continued use constitutes acceptance, creating a binding amendment mechanism that governs the contractual relationship.
AI-generated interpretation, not legal advice.
" By accessing or using the Site, you agree that you: (1) are at least 18 years old; (2) will comply with all applicable laws, rules and regulations; (3) will use the Site and Site Content in accordance with these Terms; (4) will not use the Site or Site Content in violation of the terms of Nintex’s Acceptable Use Policy; (5) will not submit to the Site any content or data that is defamatory, pornographic, threatening or offensive, that promotes discrimination or bigotry, or that infringes intellectual property rights or otherwise violates a third party’s rights; (6) will not access or use, or attempt to access or use, portions of the Site that Nintex has not authorized you to access or use; (7) will not scan, test, or probe the vulnerability of the Site or any network connected to the Site, or breach the security or authentication measures on the Site or any network connected to the Site; (8) will not reproduce, copy, sell, resell, or otherwise exploit for any commercial purposes any portion of, use of, or access to the Site (including any Site Content, software, and other materials available through the Site); (9) will not use any robot, spider, data scraping or extraction tool, or similar mechanism on the Site; (10) will not frame or mirror any portion of the Site; and (11) will not interfere or attempt to interfere in any manner with the functionality or proper working of the Site or another individual’s access to the Site."Permalink to this finding →
This segment imposes affirmative obligations on users including age requirements, legal compliance, adherence to Acceptable Use Policy, prohibitions on submitting defamatory/infringing/offensive content, and restrictions on unauthorized access — establishing enforceable conduct requirements and content submission rules tied to platform moderation.
AI-generated interpretation, not legal advice.
" 4.4 Content posted by others. Nintex is not responsible for, and does not pre-screen or endorse, content posted by any other individual. Accordingly, Nintex is not liable, directly or indirectly, for any loss or damage caused to you in connection with any content posted by another Site user."
This segment disclaims Nintex's responsibility for and liability arising from content posted by third-party Site users, stating Nintex does not pre-screen or endorse such content and bears no direct or indirect liability for resulting harm — a liability limitation and disclaimer for user-generated third-party content.
AI-generated interpretation, not legal advice.
Common questions about Nintex's policies
- Does Nintex train its AI models on your data?
- No training on your content by default — based on 1 verified finding from Nintex's published policy. Informational only, not legal advice.
- Who owns the content you create with Nintex?
- You own your outputs — based on 1 verified finding from Nintex's published policy. Informational only, not legal advice.
- Can you use Nintex's output commercially?
- Commercial use allowed — based on 1 verified finding from Nintex's published policy. Informational only, not legal advice.
Clause detail — protections, your obligations, and coverage
Every clause below is a verbatim quote from Nintex's own published policy, read in full and linked to its exact location. Protections and user obligations are reported separately from risk because they are different kinds of clause — an obligation on you is not a risk to your data. Informational only, not legal advice.
✅ Protections found
16 verified clausesClauses in Nintex's policies that work in your favour — commitments the platform made to you.
- Audit rights, DPA & residency
“Nintex may transfer your data to a country other than where it was collected or where you reside. When we transfer Personal Data, we implement safeguards to ensure the adequate protection of the transferred Personal Data. For applicable data transfers, Nintex…”
Imposes an obligation on Nintex to implement safeguards when transferring personal data internationally and to comply with EU-U.S. DPF, UK Extension, and Swiss-U.S. DPF frameworks, establishing a legal duty of adequate p…
📍 Privacy Policy › “International Data Transfers and EU-U.S. Data Privacy Framework Principles”Jump to exact text → - Audit rights, DPA & residency
“Nintex complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF) and the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) as set forth by the U.S. Department of Commerce. Nintex has certified to the U.S. Departme…”
States Nintex's certified compliance with EU-U.S. DPF and Swiss-U.S. DPF frameworks as set by the U.S. Department of Commerce, creating a binding obligation to adhere to the respective Data Privacy Framework Principles f…
📍 Privacy Policy › “International Data Transfers and EU-U.S. Data Privacy Framework Principles”Jump to exact text → - Privacy & data use
“If you would like to exercise any of these rights, please contact us at GDPR@nintex.com . In your request, please describe the nature of your request, the Personal Data it relates to, and we will comply as soon as we reasonably can, and consistent with applica…”
Sets out the procedure for exercising privacy rights by contacting Nintex, describes Nintex's obligation to comply as soon as reasonably practicable, and notes that requesting deletion of necessary personal data may affe…
- Designated security contact: GDPR@nintex.com
📍 Privacy Policy › “Your Privacy Rights”Jump to exact text → - Privacy & data use
“We typically collect or use personal information only where we have your consent to do so, where we need the personal information to perform any of our Agreements with you, or where the processing is in our legitimate interests and not overridden by your data…”
Defines the legal bases Nintex relies upon for processing personal data, including consent, contractual necessity, legitimate interests, legal obligation, and vital interests, establishing the foundational framework for…
📍 Privacy Policy › “The Lawful Basis On Which We Use Your Data”Jump to exact text → - Audit rights, DPA & residency
“In compliance with the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF, Nintex commits to cooperate and comply respectively with the advice of the panel established by the EU data protection authorities (DPAs) and the UK Information…”
Commits Nintex to cooperate with EU DPAs, the UK ICO, and the Swiss FDPIC regarding unresolved DPF complaints, establishing a procedural compliance obligation and supervisory accountability mechanism for cross-border dat…
📍 Privacy Policy › “International Data Transfers and EU-U.S. Data Privacy Framework Principles”Jump to exact text → - Audit rights, DPA & residency
“Nintex is responsible under the EU-U.S. DPF, Swiss-U.S. DPF, and the UK Extension to the EU-U.S. DPF for the processing of Personal Data that it receives under the EU-U.S. DPF and subsequently transfers to third parties acting as agents on our behalf. If third…”
Establishes Nintex's liability for onward transfers of personal data to third-party agents under the DPF frameworks, imposing accountability for third-party mishandling unless Nintex proves it is not responsible, which i…
📍 Privacy Policy › “International Data Transfers and EU-U.S. Data Privacy Framework Principles”Jump to exact text →
+ 10 more verified clauses of this kind on this platform, cited in full in the report.
📋 Rules you must follow
9 verified clausesWhat Nintex requires of YOU. These are your obligations, not risks to your data or IP, so they are cited here and excluded from this platform's risk rating.
- Moderation & enforcementconduct restrictions
“By accessing or using the Site, you agree that you: (1) are at least 18 years old; (2) will comply with all applicable laws, rules and regulations; (3) will use the Site and Site Content in accordance with these Terms; (4) will not use the Site or Site Content…”
This segment imposes affirmative obligations on users including age requirements, legal compliance, adherence to Acceptable Use Policy, prohibitions on submitting defamatory/infringing/offensive content, and restrictions…
📍 § 1Jump to exact text → - Moderation & enforcementconduct restrictions
“Nintex, the owner and controller of the Site, is headquartered in the State of Washington in the United States. You are responsible for securing, using, and monitoring an internet connection, which may include a VPN, that is compliant with laws and regulations…”
Restricts users from accessing or using the Site and Services except in compliance with U.S. law and applicable local jurisdiction laws, and places responsibility on users to maintain compliant internet connections, incl…
📍 § 7Jump to exact text → - Prompt ownership
“4.1 Content on the Site. All Site Content, including the design, structure, coordination, “look and feel,” and arrangement of such Site Content, is owned, controlled, or licensed by Nintex. Site Content and elements of the Site are protected by trade dress, co…”
This segment asserts that all Site Content is owned, controlled, or licensed by Nintex and protected by IP laws, restricts users from removing copyright notices, and requires appropriate ownership attribution when disclo…
📍 § 4.1Jump to exact text → - Moderation & enforcementconduct restrictions
“You are expected to engage in security research responsibly. For example, if you discover a publicly exposed password or key, you should not use the key to test the extent of access it grants or attempt to download or exfiltrate data in order to prove it is an…”
Restricts the conduct of security researchers by prohibiting exploitation of discovered vulnerabilities beyond the minimum steps needed for proof-of-concept demonstration, specifically barring use of exposed credentials…
📍 Privacy Policy › “Reporting security vulnerabilities found in our production environment”Jump to exact text → - Moderation & enforcement
“Cause no harm. Any exfiltration or disclosure of Nintex confidential information, including customer data, and/or disrupting our customers’ experience are all outside the scope of this program and outside any protections the program affords from legal recourse…”
Restricts program participants from exfiltrating or disclosing Nintex confidential information or customer data, and from disrupting customer experience, explicitly placing such conduct outside the program's scope and ou…
📍 Privacy Policy › “Reporting security vulnerabilities found in our production environment”Jump to exact text →
+ 4 more verified clauses of this kind on this platform, cited in full in the report.
What the policies actually cover
14 topics- Product telemetry & usage tracking14 clauses
- Advertising & tracking1 protective4 clauses
- Sale or sharing of personal data1 protective1 clause
- Sensitive data (biometric, location, health)1 protective4 clauses
- Children's data1 protective1 clause
- Government & law-enforcement disclosure5 clauses
- Does not train on your content1 protective1 clause
- Arbitration & class-action waiver1 clause
- Damages & liability cap2 clauses
- Indemnity direction1 clause
- Terms can change at any time2 clauses
- Deletion rights & post-termination survival1 clause
- Breach-notification promises1 protective3 clauses
- Conduct restrictions4 obligations4 clauses
84 further verified clauses are cited on this page but not yet assigned a topic.
Cross-clause notes
Two verified clauses intersect on the same subject matter: the Privacy Policy, Privacy Policy › “Data Retention” addresses how long content is retained, and the Privacy Policy, Privacy Policy › “Links to Third Party Platforms” addresses use of content in connection with model training or service improvement. Both clauses are in force at the same time — read them together.
Automated cross-reference against the published rubric — not legal advice.
Clause intelligence
Canonical clauses and stance patterns extracted from the same gate-verified citations shown on this page.
The clause restricts commercial use.
“In accordance with these Terms, and unless you have a separate agreement with Nintex regarding your use of the Site, you may access and use the Site and all information, text, graphics, images, videos, documents, templates, content, and other materials made available on or through the Site (“Site Content”) solely for Non-Commercial Personal Purposes or to learn about Nintex products and services. ̶...”Open source citation
The clause restricts commercial use.
“In accordance with these Terms, and unless you have a separate agreement with Nintex regarding your use of the Site, you may access and use the Site and all information, text, graphics, images, videos, documents, templates, content, and other materials made available on or through the Site (“Site Content”) solely for Non-Commercial Personal Purposes or to learn about Nintex products and services. ̶...”Open source citation
The clause imposes arbitration, class-action waiver, or jury-trial waiver terms.
“Under certain conditions, more fully described on the Data Privacy Framework website ( https://www.dataprivacyframework.gov/framework-article/ANNEX-I-introduction ), you may be entitled to invoke binding arbitration when other dispute resolution procedures have been exhausted.”Open source citation
The clause imposes arbitration, class-action waiver, or jury-trial waiver terms.
“Under certain conditions, more fully described on the Data Privacy Framework website ( https://www.dataprivacyframework.gov/framework-article/ANNEX-I-introduction ), you may be entitled to invoke binding arbitration when other dispute resolution procedures have been exhausted.”Open source citation
The clause includes sublicensable, transferable, or assignable rights.
“4.2 Content You Submit to the Site. You are solely responsible for any text, images, photos, audio, video, data, and communications that you submit to Site (collectively, “Your Content”), including, but not limited to, Nintex Community available at https://community.nintex.com . Under no circumstances will Nintex be liable in any way for Your Content, including, but not limited to, liability for any errors or omis...”Open source citation
Tier matrix
Plan-level conditions detected from citation-backed clauses. Empty tiers mean AIRIN has not captured decisive tier language yet.
| Tier | Surface | Verdict | Risk | Citations |
|---|---|---|---|---|
| All applicable tiers | commercial use | conditional | MEDIUM | 2 |
| All applicable tiers | indemnity liability | conditional | MEDIUM | 6 |
| All applicable tiers | output ownership | conditional | MEDIUM | 1 |
| All applicable tiers | privacy data use | worsens | HIGH | 7 |
| All applicable tiers | prompt ownership | conditional | MEDIUM | 1 |
| All applicable tiers | subprocessors data sharing | conditional | MEDIUM | 9 |
| Api | training use | worsens | HIGH | 2 |
| Free | indemnity liability | conditional | MEDIUM | 2 |
| Free | output ownership | worsens | HIGH | 2 |
| Free | prompt ownership | worsens | HIGH | 2 |
| Government | governing law disputes | conditional | MEDIUM | 2 |
| Team / Business | privacy data use | conditional | MEDIUM | 3 |
Policy evolution
Open full timelineBefore/after stance changes across captured policy versions. When no material delta exists yet, AIRIN shows the latest citation-backed stance events instead.
legal burden changed from medium/indemnity to medium/liability limited.
“The necessity for Nintex to comply with a legal obligation, or to establish, exercise and defend Nintex from a legal claim.”Before citation
“YOUR USE OF THE SITE, SITE CONTENT, AND ANY SERVICES OR ITEMS OBTAINED THROUGH THE SITE IS AT YOUR OWN RISK. THE SITE, SITE CONTENT, AND ANY SERVICES OR ITEMS OBTAINED THROUGH THE SITE ARE PROVIDED WITHOUT ANY WARRANTIES OF ANY KIND, EITHER EXPRESS OR IMPLIED, ON AN “AS IS” AND “AS AVAILABLE” BASIS. WITHOUT LIMITING THE FOREGOING, NEITHER NINTEX NOR ANYONE ASSOCIATED WITH NINTEX REPRESENTS OR WARRANTS THAT THE SITE, SITE CONTENT, OR ANY SERVICES OR ITEMS OBTAINED THROUGH THE SITE WILL BE ACCURATE, RELIABLE, ERROR-FREE, NON-INFRINGING, OR UNINTERRUPTED, THAT DEFECTS WILL BE CORRECTED, THAT THE SITE OR THE SERVER THAT MAKES IT AVAILABLE ARE FREE OF VIRUSES OR OTHER HARMFUL COMPONENTS, OR THAT THE SITE OR ANY SERVICES OR ITEMS OBTAINED THROUGH THE SITE WILL OTHERWISE MEET YOUR NEEDS OR EXPECTATIONS. NINTEX MAY, IN ITS SOLE DISCRETION, MODIFY, UPDATE, SUSPEND OR DISCONTINUE THE SITE OR ANY PORTION THEREOF, INCLUDING SITE CONTENT, AT ANY TIME AND WILL NOT BE LIABLE TO YOU OR ANY OTHER THIRD PARTY FOR ANY SUCH MODIFICATION, UPDATE, SUSPENSION, OR DISCONTINUATION.”After citation
Latest stance: third party or vendor sharing on privacy data use
“Your privacy is important to Nintex, and we are committed to the careful handling of personal information, About customers and other individuals (collectively “you”). Our privacy policy (“Privacy Policy”) is intended to explain how Nintex Global Ltd. and its worldwide affiliates and subsidiaries (collectively, “we” or “Nintex”) collect, use, and disclose the information you provide to us, when using our products and services (collectively, the “Nintex Services”) or which we otherwise collect in providing the Nintex Services to you, including any personal information (“Personal Data”). When we use the term Personal Data in this Privacy Policy, we mean information relating to an identified or identifiable natural person. An identifiable person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, and online identifier or to one or more factors specific to his/her physical, physiological, genetic, mental, economic, cultural, or social identity. By using the Nintex Services, you understand that we may collect Personal Date as described in this Privacy Policy.”Open timeline citation
Latest stance: third party or vendor sharing on privacy data use
“In order to provide and continually improve the Nintex Services, we collect information which may include Personal Data. Our collection practices are intended for interaction in the business environment. In most cases, you will voluntarily provide your Personal Data. For example, we collect personal information through your registration for and use of the Nintex Services; when you use or visit Nintex sites, attend a Nintex event, or participate in the Nintex Community. We may also receive Personal Data from our third-party partners. If you are a Nintex Partner or vendor, we may also collect your personal information. If you have other agreements with Nintex, then those agreements control with respect to their subject matter.”Open timeline citation
Latest stance: arbitration or waiver on governing law disputes
“Under certain conditions, more fully described on the Data Privacy Framework website ( https://www.dataprivacyframework.gov/framework-article/ANNEX-I-introduction ), you may be entitled to invoke binding arbitration when other dispute resolution procedures have been exhausted.”Open timeline citation
Latest stance: third party or vendor sharing on subprocessors data sharing
“Nintex is responsible under the EU-U.S. DPF, Swiss-U.S. DPF, and the UK Extension to the EU-U.S. DPF for the processing of Personal Data that it receives under the EU-U.S. DPF and subsequently transfers to third parties acting as agents on our behalf. If third party agents process Personal Data on our behalf in a manner inconsistent with the principles of EU-U.S. DPF, Swiss-U.S. DPF, and the UK Extension to the EU-U.S. DPF, we remain liable unless we prove we are not responsible for the event giving rise to the damage.”Open timeline citation
Capture recency
- Terms of Service:Last captured 2026-08-14· verified 2026-08-14
- Privacy Policy:Last captured 2026-08-14· verified 2026-08-14
Dates state when our pipeline captured and verified each document — not when the vendor last changed it. Documents are re-scanned on a recurring cadence; a document verified once says so until a re-scan confirms it again.
↑ 133 more findings this quarter vs last (257 vs 124). First scan: June 2026.
Compare and stack are saved in your browser. Open compare · View your stack. A correction triggers an automated re-read of Nintex's policies — no human edits the data.
Need this for procurement or legal diligence?
Free shows today's risk. A Stack Audit gives you a citable, verbatim-sourced PDF across your whole AI stack — and flags the moment a vendor's terms change.
Every finding above is a verbatim quote from Nintex's own published policy, captured to an immutable snapshot and read in full through a two-gate verification pipeline. Confidence labels and any analysis are AI-generated and informational only — not legal advice.
AIRIN Brief
Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.