Nintex procurement policy evidence
Only topics backed by verified findings appear below. Each row preserves the platform's exact policy words and capture provenance.
| Topic | Plan or tier | Risk | Their words | Source |
|---|---|---|---|---|
| DPA, audit rights & data residency | All applicable tiers | low | “ The U.S. based subsidiaries of Nintex, as identified in our self-certification submission, have also certified that they adhere to the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the U.K. Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) for transfers of Personal Data from the EU, EEA, U.K., and Switzerland to the U.S.” | Captured 2026-06-08Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ Nintex may transfer your data to a country other than where it was collected or where you reside. When we transfer Personal Data, we implement safeguards to ensure the adequate protection of the transferred Personal Data. For applicable data transfers, Nintex complies with the EU-U.S. Data Privacy Framework Principles (hereinafter “EU-U.S. DPF”), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework Principles (Swiss-U.S. DPF) as set forth by the U.S. Department of Commerce, the European Commission, and the Swiss Administration, and the UK GDPR regarding the collection, use, and retention of Personal Data transferred from the EEA, the UK and Switzerland. In light of the invalidation of the Privacy Shield Framework by the Court of Justice of the EU on July 16, 2020, Nintex also uses other mechanisms to ensure the adequate protection of Personal Data. We offer a Data Protection Addendum (https://www.nintex.com/legal/data-protection-addendum) which incorporates EU Standard Contractual Clauses (“SCCs”). The European Commission has approved of the use of SCCs as an adequate cross-border data transfer mechanism.” | Captured 2026-06-08Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ Nintex is responsible under the EU-U.S. DPF, Swiss-U.S. DPF, and the UK Extension to the EU-U.S. DPF for the processing of Personal Data that it receives under the EU-U.S. DPF and subsequently transfers to third parties acting as agents on our behalf. If third party agents process Personal Data on our behalf in a manner inconsistent with the principles of EU-U.S. DPF, Swiss-U.S. DPF, and the UK Extension to the EU-U.S. DPF, we remain liable unless we prove we are not responsible for the event giving rise to the damage.” | Captured 2026-06-08Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ Nintex complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF) and the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) as set forth by the U.S. Department of Commerce. Nintex has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework Principles (EU-U.S. DPF Principles) with regard to the processing of personal data received from the European Union and the United Kingdom in reliance on the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF. Nintex has certified to the U.S. Department of Commerce that it adheres to the Swiss-U.S. Data Privacy Framework Principles (Swiss-U.S. DPF Principles) with regard to the processing of personal data received from Switzerland in reliance on the Swiss-U.S. DPF. If there is any conflict between the terms in this privacy policy and the EU-U.S. DPF Principles and/or the Swiss-U.S. DPF Principles, the Principles shall govern. To learn more about the Data Privacy Framework (DPF) program, and to view our certification, please visit https://www.dataprivacyframework.gov/ ” | Captured 2026-06-08Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ In compliance with the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF, Nintex commits to cooperate and comply respectively with the advice of the panel established by the EU data protection authorities (DPAs) and the UK Information Commissioner’s Office (ICO) and the Swiss Federal Data Protection and Information Commissioner (FDPIC) with regard to unresolved complaints concerning our handling of personal data received in reliance on the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF.” | Captured 2026-06-08Open source →Finding permalink → |
| Data retention | All applicable tiers | medium | “ We will retain your Personal Data for as long as your account is active or as needed to provide you services. We may also retain Personal Data in order protect our legal rights, comply with the legal requirements, or comply with record keeping requirements. We keep the data that we process on behalf of customers in accordance with our customers’ instructions. If you wish to request that we no longer use your information to provide you services, contact us at GDPR@nintex.com . Please keep in mind that we may need to keep your data to comply with our legal obligations, resolve disputes or enforce legal agreements.” | Captured 2026-06-08Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ Comply with legal process and other lawful requests, and verification requests in connection with internal and external audits.” | Captured 2026-06-08Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | low | “ With your consent. Nintex may share your Personal Data when we have your permission and consent, including when you choose to comment on our blogs or in our community forums, or otherwise post information on the Nintex Community site.” | Captured 2026-06-08Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ From time to time, we also partner with third parties who may place cookies on your browser when you visit our websites, and may use those cookies to provide track and collect information about you and your online activities over time and across different websites, devices and applications, and to offer advertising based on your interests and previous browsing history.” | Captured 2026-08-14Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ Nintex is responsible under the EU-U.S. DPF, Swiss-U.S. DPF, and the UK Extension to the EU-U.S. DPF for the processing of Personal Data that it receives under the EU-U.S. DPF and subsequently transfers to third parties acting as agents on our behalf. If third party agents process Personal Data on our behalf in a manner inconsistent with the principles of EU-U.S. DPF, Swiss-U.S. DPF, and the UK Extension to the EU-U.S. DPF, we remain liable unless we prove we are not responsible for the event giving rise to the damage.” | Captured 2026-08-14Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ It is important to Nintex that we keep your Personal Data secure. In some circumstances and subject to compliance with applicable law, Nintex may share your Personal Data with third parties, for example:” | Captured 2026-06-08Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ Third Party Accounts. You may connect to third party accounts through the Nintex Services and partner ecosystem, and we may share some Personal Data with those third-party services. For example, information may be shared to authenticate you, or we may share your username and your preferences in connection with those services. These third-party accounts and services are not owned or controlled by Nintex, and they may have their own policies and practices for the collection and use of Personal Data. Please review the privacy policies of those third-party accounts to understand how they use your information.” | Captured 2026-06-08Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | low | “ The Nintex Services may contain links to third party websites, online services, or social media platforms. The fact that we link to a website is not an endorsement or indication of affiliation with that third party website. We exercise no control over third party services or websites, and third-party services and websites have their own privacy policies, which may be different than ours.” | Captured 2026-06-08Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ Enforce our terms and conditions, or protect our business, our partners, or our users.” | Captured 2026-06-08Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ Merger, sale, or other business transfer. We may disclose information as part of a proposed or actual reorganization, merger, sale, joint venture, assignment, transfer, or other disposition of all or a portion of Nintex’s business, assets, or stock; or in the event of insolvency or bankruptcy.” | Captured 2026-06-08Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ Third Party Data. Nintex may receive your Personal Data from third parties, including our suppliers, vendors or partners. If you connect with Nintex accounts on third party social media sites, then we may receive information about your social media accounts, for instance, your name, user name, public profile, photos, and email address. We may combine the information you provide with information that we collect automatically, and with data that we receive from third parties.” | Captured 2026-06-08Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ With respect to Personal Data received or transferred pursuant to the EU-U.S. DPF, Swiss-U.S. DPF, and the UK Extension to the EU-U.S. DPF, Nintex is subject to the regulatory enforcement powers of the Federal Trade Commission. In certain situations, Nintex may be required to disclose Personal Data in response to lawful requests by public authorities, including to meet national security or law enforcement needs.” | Captured 2026-06-08Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ Business partner services. We share information with our trusted partners who work on behalf of Nintex to provide us with services. For example, we may share information with our certification partners, our data storage and data analysis providers, implementation, customer support, and marketing vendors, and software providers. These companies may use your Personal Data to perform services and to help Nintex communicate with you about offers from Nintex and our marketing partners. We maintain contracts with these companies that restrict their access, use and disclosure of Personal Data in compliance with this Privacy Policy and any legal obligation.” | Captured 2026-06-08Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ Aggregated and de- identified data. We may share de-identified data (i.e. data that can no longer be linked to an individual person) with others for a variety of purposes. For example, we may share data to show trends or benchmark performance indicators.” | Captured 2026-06-08Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ We may facilitate third party services or ways to share data through third parties, including social media platforms, websites, applications, and services through “plug-ins,” widgets, buttons, and other third-party features on and connected with our websites, communications, or products. Third parties whose services you use in connection with Nintex, for instance third party websites we link to, may have information practices that are different than ours. This Privacy Policy does not apply to the activities of third parties when they are collecting or using data for their own purposes or on behalf of others. We are not responsible for the activities of these third parties. We encourage you to review their privacy policies to understand how they use your information.” | Captured 2026-06-08Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ For legal reasons. Nintex may disclose Personal Data if we have a good-faith belief that the access, use, preservation or disclosure of that Personal Data is reasonably necessary to: comply with any applicable law, regulation, legal process, or enforceable government request; enforce our Terms of Service, Agreements or any other applicable policy or agreement; detect, prevent, or otherwise address fraud, security or technical issues; or protect against harm to the rights, property, or safety of Nintex, our users, or the public as required or permitted by law.” | Captured 2026-06-08Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | low | “ Nintex does not sell (as that term is defined in the California Consumer Privacy Act, or CCPA) any personal information collected from consumers.” | Captured 2026-06-08Open source →Finding permalink → |
Informational only, not legal advice. Terms can change; verify every cited source and capture date during procurement review.
AIRIN Brief
Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.