Privacy policy
This policy explains what happens to personal data on this website, nucem.ai, and inside the product at app.nucem.ai. Both are operated by Nucore Software Solutions (P) Ltd., 5th Floor, ULCSS Ltd Special Economic Zone, Nellikode, Calicut, Kerala, India. One company answers for every customer, wherever they are.
It does not cover nucore.in, which is a separate website with its own policy, and it does not cover the websites our customers run. Any question, or any request about your own data: sales@nucore.in.
The two roles we play
For this website, and for the accounts of the people who use nuCEM, we decide what is collected and why. The GDPR and the UK GDPR call that role the controller; India's Digital Personal Data Protection Act calls it the data fiduciary; the UAE's personal data protection law calls it the controller.
For everything a customer puts inside their workspace, their contacts, their conversations and their requests, the customer decides and we only hold it for them. There we are the processor and their instructions govern what we do. If you are a traveller or a client of one of our customers and you want your data corrected or removed, ask that company: they hold the relationship, and we act on their instruction.
This website
No cookies. nucem.ai sets no cookies, runs no analytics and embeds no third-party trackers. The fonts are served from our own domain, so nothing about your visit reaches a font service.
Two values are stored in your browser, and only if you cause them: whether you dismissed the announcement bar, and whether you switched to the dark theme. They stay in your browser and we cannot read them.
Book a demo. The form opens your own mail app with what you typed, addressed to sales@nucore.in, so an enquiry reaches us as ordinary email. We use it to answer you, and for nothing else: we do not add you to a mailing list, we do not use your address to market other Nucore products, and we do not sell it or pass it on. We keep it while your enquiry and any discussion that follows are live, and we delete it whenever you ask.
Our web server keeps short-lived technical logs so the site can be operated and protected. They are not used to profile visitors.
What a workspace holds
A nuCEM workspace holds the working record of a travel business: staff accounts with a name, work email, role, branch and team; the leads and requests they work; the email and WhatsApp conversations behind them with their attachments; contacts and companies; tasks; notes; and an audit log.
Some of it is sensitive. Passport and visa numbers are stored as AES-256-GCM ciphertext, shown as the last four digits, and every reveal is written to the audit log. What else a workspace holds is the customer’s decision, not ours.
WhatsApp calls answered inside nuCEM connect browser to browser. The audio never passes through our servers, and we neither record nor transcribe calls.
Where it runs, and how customers are kept apart
Production runs on Amazon Web Services in Ireland, the eu-west-1 region, in a dedicated cloud account. Every customer workspace has its own database, so a query cannot reach across customers. Message bodies and attachments live in object storage rather than in the database.
Traffic is encrypted in transit; storage, volumes and secrets are encrypted at rest. Sign-in runs on Nucore's shared identity platform, so nuCEM stores no passwords, and a logout or a deactivation ends live sessions at once. The app keeps its session tokens in your browser's local storage and sets no cookies.
The audit log is append-only and kept for at least a year: sign-ins, permission changes, views of sensitive documents, exports and deletions.
Who at Nucore can see customer data
Nobody at Nucore opens a customer's workspace on their own. We look only when that customer asks us to help with a problem, and only for as long as the problem takes to solve.
While helping, a developer may ask you for more detail, or for a screenshot or a short video of what you are seeing, so that the case is understood before anything is touched. What is done inside a workspace leaves its trace in that workspace’s audit log.
The companies that process data with us
These are our sub-processors. Google, Microsoft and Meta appear only when a customer connects their own mailbox or WhatsApp number. We update this list before adding anyone to it.
| Who | What they do for nuCEM | Where |
|---|---|---|
| Amazon Web Services | Hosting: servers, databases and object storage | Ireland |
| Amazon SES | Sending the product's own email, such as notifications | Ireland |
| Cloudflare | DNS for our domains, and the optional spam check on a customer's website form | Global network |
| Meta Platforms | WhatsApp Cloud API: the messages and calls a customer sends and receives | Meta's own infrastructure |
| Connecting a customer's Google Workspace mailbox, under that customer's own account | Google's own infrastructure | |
| Microsoft | Connecting a customer's Microsoft 365 mailbox, under that customer's own account | Microsoft's own infrastructure |
Data that crosses a border
Customer data is stored in Ireland. Our people support customers from India and the Gulf, so when a customer asks for help, their data is reached from outside the European Economic Area.
For customers in the EEA and the UK we will sign a data processing agreement including the European Commission's standard contractual clauses, which cover that access. Ask for one at sales@nucore.in.
How long we keep things
Inside a live workspace nothing is deleted automatically: archive and spam are states, not deletions.
When a customer leaves, the workspace is deleted 30 days after the account is closed.
Backups are taken every day and each one is deleted after seven days, so a backup copy of deleted data can survive for up to a week.
The audit log is kept for at least a year. A demo enquiry is kept while it is live and deleted whenever you ask. A customer can ask us to delete particular records at any time, and we act on that instruction.
Your rights
Whatever law applies to you, you can ask us to:
- tell you what personal data we hold about you
- correct it if it is wrong
- delete it
- give you a copy in a portable form
- stop or limit what we do with it
- withdraw a consent you gave us
In the EEA and the UK you may also complain to your national supervisory authority. In India you can raise a grievance with us and then with the Data Protection Board. In the UAE the PDPL gives equivalent rights.
Write to sales@nucore.in and we will answer as quickly as we can, and within the time the law allows. If you are a client of one of our customers, we will pass your request to them, because the data is theirs to decide about.
Security
A database per customer, encryption in transit and at rest, single sign-on with instant revocation, an append-only audit log, branch partitioning and three access levels enforced on the server, and server-side validation of every upload. The security page lists what is built and what is not there yet.
Children
nuCEM is a tool for businesses. It is not meant for children, and accounts are created by an administrator for members of staff.
Changes to this policy
When something material changes we tell customers by email and update the date at the top of this page.
Contact
Nucore Software Solutions (P) Ltd., 5th Floor, ULCSS Ltd Special Economic Zone, Nellikode, Calicut, Kerala, India. Questions about this policy, a request about your data, or a security report: sales@nucore.in.