01
Who this policy applies to
This policy applies when you visit a Nidget website, create or use a Nidget account or workspace, contact us, or interact with a Nidget-powered widget where Nidget determines how the information is handled.
Newsrooms and other customers may use Nidget to publish widgets and collect audience responses. In those cases, the customer decides what to collect and why. Its privacy notice also applies, and it is usually the best first contact for a request about that information.
02
Information we collect
Depending on how you use Nidget, we may collect:
- Account and workspace details, such as your name, work email, company or team name, website, role and account status.
- Company information found from the work-email domain and public website you provide, such as a company name, public description, favicon, branding and publishing platform.
- Content and assets uploaded, recorded, created or published through a workspace, including text, images, audio, fonts and widget configurations.
- Audience interactions, such as quiz, poll or form responses, impressions, interaction events, publisher page and article path. Depending on a customer’s widget, this may include information the respondent chooses to submit.
- Usage and device information, such as IP address, browser or device details, referring page, session information, feature activity, timestamps and diagnostic logs.
- Commercial and support information, such as plan, subscription status, billing contact, payment events, messages and feedback. Payment providers may collect payment details directly under their own privacy policies.
We do not ask you to provide sensitive information unless it is reasonably necessary and permitted by law. Customers should avoid collecting sensitive information through a widget unless they have a lawful basis and provide an appropriate notice.
03
How we collect information
We collect information directly from you when you sign up, configure a workspace, publish content or contact us; automatically when you use the service; from other members of your workspace; and from public sources when we use your company domain or website to simplify setup.
We use essential cookies and similar local technologies to maintain secure sessions and remember preferences. Audience analytics for published widgets is disabled by default. A publisher may use consent-managed analytics, in which case Nidget does not set the audience analytics cookie or record impressions and interactions until the publisher’s consent system sends an affirmative signal. Withdrawing that signal stops further collection and removes the cookie. Workspace editors may also enable a clearly labelled testing mode that starts collection without a publisher consent signal; this mode is intended only for controlled development or staging traffic and should not be used on live audience pages.
04
How we use information
We use personal information to provide, secure and administer Nidget; verify work email addresses; create accounts and workspaces; deliver and measure widgets; personalise branding; communicate about the service; provide support; process subscriptions; prevent abuse; diagnose problems; improve features; comply with law; and establish or defend legal claims.
We may create aggregated or de-identified insights that do not reasonably identify an individual and use those insights to operate, analyse and improve Nidget.
06
Overseas processing
Some service providers may process information outside Australia in the countries where they and their infrastructure operate, which may include the United States. The locations can change as providers update their infrastructure. We take reasonable steps required by applicable law when disclosing personal information overseas.
07
Security and retention
We use technical and organisational safeguards designed to protect personal information, including access controls, secure session handling and measures appropriate to the nature of the information. No internet service can guarantee absolute security.
We keep information for as long as reasonably needed to provide the service, meet legal and accounting requirements, resolve disputes and enforce agreements. Retention periods vary by record type. We delete or de-identify information when it is no longer required, subject to backups and legal obligations.
08
Access, correction and choices
You may ask for access to or correction of personal information we hold about you. You may also ask us to delete information or close an account, subject to legal, security and operational requirements. Workspace administrators can manage some account and content information directly.
To make a request, email hello@nidget.app. We may need to verify your identity and authority before acting. If your request concerns a customer’s widget, we may direct you to that customer.
09
Privacy questions and complaints
Send privacy questions or complaints to hello@nidget.app with enough detail for us to investigate. We will acknowledge and respond within a reasonable time and generally aim to respond within 30 days.
If you are not satisfied with our response, you may be able to complain to the Office of the Australian Information Commissioner or another regulator that applies to you.
10
Changes to this policy
We may update this policy to reflect changes to Nidget, our practices or the law. We will publish the updated version here and change the effective date. If a change materially affects how we handle personal information, we will take reasonable steps to provide additional notice.
11
Contact Nidget
Nidget operates from Sydney, New South Wales, Australia. Contact us at hello@nidget.app for privacy requests or to ask for a copy of this policy in another accessible form.