Privacy Policy
1 · Who we are
Nimble & Cross operates as a dual-entity structure. Nimble AI Inc. (Toronto, ON, Canada) builds and operates the technology platform: the accounts, dashboards, and AI agents you interact with. Cross LLP (Toronto, ON, Canada) is a licensed law and tax firm whose lawyers and CPAs design your structures, sign off on filings, and represent you before revenue agencies. Both are wholly owned subsidiaries of Nimble & Cross Pte. Ltd. (Singapore), the group's parent holding company. This policy describes how the group collects, uses, and shares personal information across the Nimble & Cross platform and professional services.
2 · What we collect
We collect only what we need to provide the service, deliver professional services, and meet our regulatory obligations.
- Account data: name, email, country, and password hash.
- KYC data: date of birth, government ID, address, and business documents. Required before our card-issuing and banking partners can open an account or issue a card in your name.
- Entity and structuring data: cap table and equity ledger entries, share class terms, trust deeds, beneficiary details, and the incorporation records generated when Cross LLP forms or maintains an entity for you.
- Financial activity: bank and card transactions, invoices, receipts, payroll records, and tax filings created or imported through Nimble & Cross.
- Investor and counterparty data: KYC and AML information on investors, lenders, and grant-makers you route through the platform, held in a permissioned enclave separate from your cap table and data room.
- Communications: emails, support tickets, in-app messages, and engagement correspondence with Cross LLP.
- Device data: IP address, browser type, and device identifiers, used for security and fraud prevention.
3 · How we use it
- To operate the platform and execute actions you request: incorporations, payments, filings, cap table updates, and fundraising logistics.
- To let Cross LLP's lawyers and CPAs design your structures, prepare and file returns, and represent you before the CRA, the IRS, and other revenue agencies you authorize us to deal with.
- To meet our regulatory and partner-mandated KYC, AML, sanctions-screening, and tax-reporting obligations.
- To improve our platform, debug issues, and provide client support.
- To send transactional communications you cannot opt out of, such as security notices and filing deadlines.
We do not use your data to train or update AI models, ours or anyone else's. We do not sell your personal information, and we do not share it with third parties for advertising.
4 · Who we share with
To run the platform and deliver professional services, we share necessary data with the following categories of partners, each bound by a data-processing agreement or professional confidentiality obligation:
- Card issuing: i2c and Lithic.
- Banking: RBC Business Banking, National Bank, and Peoples Group.
- Payment and currency rails: Bridge and Paytrie.
- Cap table and closing software: Carta, DocuSign, and Clerky.
- Bookkeeping software: QuickBooks and Xero.
- Government registries and revenue agencies, when you authorize Nimble & Cross to file on your behalf: the Canada Revenue Agency, the IRS, HMRC, the Delaware Division of Corporations, Corporations Canada and provincial registries, the Cayman Islands General Registry, Companies House (UK), and ACRA (Singapore).
- Browserbase: isolated browser environments used to execute government filings on your behalf.
- Cloud providers: Google Cloud Platform (primary), and infrastructure subprocessors listed in the trust center.
5 · Your rights
Depending on your jurisdiction (Canada PIPEDA, GDPR/UK-GDPR, CCPA, etc.), you may have the right to access, correct, delete, port, or restrict the processing of your personal information. To exercise any of these rights, write to privacy@nimblecross.com. We respond within 30 days.
6 · Retention
We retain account data while your account is active and for as long as regulatory and tax obligations require afterwards, typically 7 years for financial records. We delete or anonymize data sooner where permissible.
7 · International transfers
Nimble & Cross's primary data is hosted in Canada (PIPEDA jurisdiction). Limited data is transferred to our parent company in Singapore for group governance purposes, and to partners in the United States, the United Kingdom, and the European Union under appropriate transfer mechanisms (Standard Contractual Clauses, adequacy decisions where available).
8 · Children
Nimble & Cross is not directed at children under 18 and we do not knowingly collect personal information from them.
9 · Security
We protect your data with zero-trust access controls, end-to-end encryption, and least-privilege permissions. Investor KYC data and trust or beneficiary details are held in permissioned enclaves separate from your day-to-day operating records, and agents that touch wire instructions or filings operate under scoped, single-purpose credentials that expire after each transaction. Our practices are independently audited under SOC 2 Type II and ISO 27001, and we align with PIPEDA, GDPR/UK-GDPR, CCPA, and the EU AI Act. See our Security page for detail.
10 · Updates
We will post any material changes to this policy on this page and notify active accounts by email at least 30 days before they take effect.
11 · Contact
Privacy questions or requests: privacy@nimblecross.com
Data protection officer: dpo@nimblecross.com
Postal: Nimble AI Inc. & Cross LLP, Toronto, ON, Canada.