Privacy Policy
Effective Date: Last updated July 2026
At Nesthing, we provide enterprise AI infrastructure for law firms and legal departments. Data privacy, strict confidentiality, and regulatory compliance are foundational to our system architecture.
1. Regulatory Compliance
This policy governs data processed via nesthing.com and our enterprise agentic infrastructure. Our operations and data handling workflows strictly comply with regional data protection standards:
- Singapore Personal Data Protection Act (PDPA)
- Malaysia Personal Data Protection Act 2010 (Act 709)
2. Zero Public Model Training & Data Isolation
Your work product, matter files, and legal queries remain entirely yours:
- Zero Training Commitments: We do NOT use client documents, user inputs, or matter telemetry to train, retrain, or improve public or foundation LLMs.
- Multi-Tenant Isolation: Customer environments are isolated via Postgres Row-Level Security (RLS) and scoped ephemeral API credentials.
- Transient Processing: Document indexing and inference operations are executed in isolated, ephemeral compute environments with automatic lifecycle purging.
3. Information We Collect
We limit data collection exclusively to what is required for operation and security:
- Account & Contact Details: Name, corporate email, firm name, and contact details provided when requesting a demo or initializing workspace tenancy.
- Audit Telemetry: Anonymized token counts, matter/case identifiers, and execution timestamps logged solely for billable disbursement reporting.
- System Telemetry: IP addresses and basic technical logs required for platform security, fraud prevention, and session integrity.
4. Third-Party Service Infrastructure
We do not sell, rent, or trade personal or enterprise data. Data is shared exclusively with tier-1 enterprise infrastructure providers under strict zero-data-retention (ZDR) agreements and regional residency bounds (Singapore / Malaysia data centers).
5. Data Subject Rights & Retention
Under SG PDPA and MY Act 709, you reserve the right to request access to, correction of, or permanent deletion of your account records. Audit logs tied to matter IDs are retained in accordance with statutory record-keeping periods or client workspace deletion requests.
6. Contact Our Data Protection Officer
For privacy inquiries, audit reporting requests, or to exercise statutory rights, please contact our DPO:
Email: [email protected]