Legal
Privacy
Policy.
What we collect, why we collect it, and what you can ask us to do with it. Written to be read, not skimmed past.
Last updated 13 September 2026
01
Who we are
NanoDashboard is operated by NanoWorkers B.V., a company established in the Netherlands. In this policy, “we” and “us” mean NanoWorkers B.V.
This policy explains what personal data we handle when you visit nanodashboard.com or use the NanoDashboard service, why we handle it, and what rights you have. For questions, write to support@nanoworkers.ai.
Where you use NanoDashboard to store or display data about other people, you are the controller of that data and we act as a processor on your instructions.
02
Information we collect
Account and organisation information. Your name, email address, the organisation and dashboards you belong to, your role and permissions, and the invitations you send or accept. If you sign in with Google or Microsoft, we receive the email address and name held by that account.
Billing information. Your plan, subscription status and usage against plan allowances. Payments are handled by our payment processor — we do not receive or store full card numbers.
Technical and security information. Server and application logs recording requests, IP address, browser and device information, timestamps and errors. These let us operate the service, investigate faults and detect abuse.
Data you put into NanoDashboard. Dashboards, boards, widgets, uploaded files, and the contents of tables you import. This content is yours, and may include personal data about your customers or staff if you choose to load it.
Data from systems you connect. When you connect a source such as Google Sheets, Salesforce or a SQL database, we hold the credentials or OAuth tokens needed to reach it and we import the tables you select. We only read from connected sources — we do not write back to them.
03
How we use data, and our legal bases
Under the GDPR we rely on the following legal bases:
- Performance of a contract — to create and administer your account, run the connectors and dashboards you set up, process your subscription, and provide support.
- Legitimate interests — to keep the service secure and available, to prevent and investigate abuse, to understand how the product is used so we can improve it, and to send service-related messages.
- Legal obligation — to meet accounting, tax and other statutory requirements.
- Consent — where we ask for it, such as optional marketing email. You can withdraw consent at any time.
We do not sell personal data, and we do not use your content or your connected data for advertising.
04
Google API Data
NanoDashboard lets you connect Google Sheets and Google Drive so that spreadsheet data can be imported into your dashboards. The connection is made with Google OAuth, and only after you start it and grant permission.
What we request. We ask only for the permissions the connector needs: read-only access to the contents of spreadsheets, per-file access to the files you yourself select, and your basic Google account identity (sign-in identifier and email address).
What we access. You choose the spreadsheets through Google’s own file picker. We can access only the files you pick there — not your wider Google Drive. From those files we read the sheet tabs and cell ranges you select for import, together with the sheet and tab names needed to show you what you are importing. We read only; we do not create, change or delete anything in your Google account.
Google account information. We receive the email address of the connected Google account and store it so you can see which account a connection belongs to.
How the data is used. Google data is used only to provide the features you asked for: importing the sheets you select, keeping those tables available in your dashboard, and refreshing them when you ask us to. It is not used for any unrelated purpose.
Tokens. Authorising a connection gives us an access token and a refresh token. These are held server-side, encrypted at rest, and are never displayed in the interface or returned by our API. The refresh token is used only to obtain a new access token so your imports keep working without you signing in again.
Disconnecting. You can disconnect a Google connection at any time from the connectors screen in NanoDashboard. Disconnecting deletes the stored Google credentials for that connection from our systems and stops any further access, and you choose whether the data already imported is kept or deleted. You can also review or remove NanoDashboard’s access directly in your Google Account under Third-party apps & services.
Deletion. To have data associated with a Google connection removed, disconnect the integration and choose to delete the imported data, or email support@nanoworkers.ai and we will handle it for you.
Limits on our use. We do not sell Google user data, and we do not use it for advertising. NanoDashboard does not use data obtained through Google Workspace APIs to develop, train, or improve generalized artificial intelligence or machine learning models.
NanoDashboard’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
05
AI features
NanoDashboard includes AI features that let you ask questions about your data in plain language.
To answer a question, the information needed to produce the answer — which may include your question and data from the sources you have connected — is sent to a third-party AI provider that generates the response on our behalf. AI features are read-only: they do not change your data or write back to your connected systems.
We do not use your content to develop, train, or improve generalized artificial intelligence or machine learning models.
06
Service providers
We use a small number of providers to run the service. They may process personal data on our behalf, under contract, and only for the purpose we engage them for:
- Cloud hosting, storage and data processing infrastructure.
- Payment processing, including Stripe, for subscriptions and invoicing.
- Email delivery, for account, billing and support messages.
- Customer support and in-product messaging tools.
- Third-party AI providers, where you use AI features.
If you would like more detail about the providers we use, email support@nanoworkers.ai.
07
International transfers
Our primary hosting and storage infrastructure is located in the European Union. Some of our providers — for example certain AI and support services — may process data outside the European Economic Area. Where that happens, we rely on an appropriate transfer mechanism under the GDPR, such as the European Commission’s Standard Contractual Clauses or an adequacy decision.
08
Security
We take reasonable technical and organisational measures to protect your data:
- Traffic to and from NanoDashboard is encrypted in transit over HTTPS.
- Connector credentials and OAuth tokens are encrypted at rest and are never shown in the interface or returned by our API.
- Access is controlled per organisation and dashboard, with roles determining what each user can see and change.
- Internal access to production systems is limited to those who need it.
No online service can be guaranteed completely secure. If you believe you have found a security problem, please contact us at support@nanoworkers.ai.
09
Data retention
We keep data for as long as it is needed to provide the service to you. Content you delete in the product — a dashboard, a table, a connection — is removed from our active systems.
After an account or subscription ends, data may be held for a limited period before deletion so that an account can be restored if it was ended in error. Some records, such as invoices and billing records, are kept longer where we are required to do so for legal, accounting, security or fraud-prevention reasons.
You can ask us to delete your data sooner by emailing support@nanoworkers.ai.
10
Your rights
If you are in the European Economic Area, you have the right to access your personal data, to have it corrected or deleted, to restrict or object to how we process it, to receive it in a portable format, and to withdraw consent where processing is based on consent.
To exercise any of these, email support@nanoworkers.ai. We may need to verify your identity before we act. If the request concerns data held in a customer’s dashboard, we will normally refer you to that customer, who controls it.
You also have the right to lodge a complaint with your local data protection authority. In the Netherlands this is the Autoriteit Persoonsgegevens.
11
Cookies
We use cookies and similar technologies that are necessary to run the service — keeping you signed in, maintaining your session, and protecting against cross-site request forgery. Where we use anything beyond what is strictly necessary, we will ask for your consent first. You can clear or block cookies in your browser, though signing in will not work without the essential ones.
12
Children's privacy
NanoDashboard is a business product and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact support@nanoworkers.ai and we will delete it.
13
Changes to this policy
We may update this policy as the service changes or as legal requirements evolve. The date at the top of this page shows when it was last revised. If a change materially affects how we handle your personal data, we will let account holders know before it takes effect.
14
Contact
For any question about this policy or about your data, email us at support@nanoworkers.ai. NanoDashboard is operated by NanoWorkers B.V., established in the Netherlands.