Transparent. Secure. Compliant by Design.
How we handle your business data with the seriousness it deserves.
Last reviewed May 2026
NOMADXIHow we handle your business data with the seriousness it deserves.
Last reviewed May 2026
We do not sell, rent, or share your business data with third parties. Your client lists, lead pipelines, and workflow data belong to you.
All data transmitted to and from NomadXI systems uses TLS 1.2+ in transit and AES-256 at rest.
Our team only accesses your systems with explicit permission and only the minimum access required to complete the agreed scope of work.
We conduct internal access reviews and revoke permissions whenever an engagement changes or concludes.
Platform-level certifications backed by enterprise-grade infrastructure.
Annual independent audit of security controls
Information security management standard
Lawful EU–US data transfer mechanisms
Full EU general data protection compliance
Healthcare data protection standards
California consumer privacy rights
All foundational agreements governing how NomadXI operates, handles your data, and protects your rights.
Your rights and obligations when using NomadXI platforms and services, including acceptable use, billing, SLAs, and dispute resolution.
How we collect, use, store, and protect your personal data including your rights under GDPR, CCPA/CPRA, and applicable privacy law.
A detailed breakdown of our technical and organizational security measures, encryption standards, access controls, and infrastructure protections.
Enterprise-grade controls deployed at every layer of the NomadXI platform.
Data Protection
AES-256 encryption at rest. TLS 1.2 enforced for all data in transit. No plaintext data storage anywhere in our stack.
RBAC, MFA enforcement, SSO support, and least-privilege access principles. Admin accounts audited quarterly.
24/7 SIEM monitoring, real-time intrusion detection, automated anomaly alerts, and security event logging with 90-day retention.
Infrastructure
Enterprise-grade Web Application Firewall and DDoS mitigation at the network edge. Automatic traffic scrubbing on all endpoints.
Third-party penetration testing by certified professionals. Vulnerability findings triaged, tracked, and remediated under defined SLAs.
Documented IR plan with defined RTO/RPO targets. Incidents contained, investigated, remediated, and disclosed per regulation.
Operations
Mandatory security awareness training at hire and annually. Phishing simulations and background checks for all personnel with system access.
Automated daily backups with geographic redundancy. Point-in-time recovery. Backup integrity verified through regular restoration tests.
Security integrated across the full development lifecycle. Code reviews, SAST/DAST scanning, dependency audits, and pre-production validation.
Independent verification of our security and privacy practices against globally recognized frameworks. Detailed implementation notes for the certifications shown above.
Annual independent audit of our security, availability, and confidentiality controls by a licensed CPA firm under AICPA Trust Services Criteria.
Our information security management system is aligned with ISO/IEC 27001:2022, the international standard for information security management.
Full compliance with the EU General Data Protection Regulation. DPAs available for enterprise customers. Data subject rights fulfilled within 30 days.
HIPAA-ready infrastructure and BAA available for healthcare-adjacent customers. Administrative, physical, and technical safeguards implemented.
California Consumer Privacy Act and California Privacy Rights Act compliant. Opt-out mechanisms, deletion rights, and disclosure obligations honored.
Certified under the EU–US Data Privacy Framework for lawful transatlantic data transfers. All transfers governed by Standard Contractual Clauses (SCCs).
A transparent breakdown of our data collection, processing, retention, and residency practices.
Primary data stored in AWS US-East. EU customers may request EU-region storage to comply with data sovereignty requirements.
Customer data retained for the duration of the service agreement plus 90 days. Deleted securely per NIST 800-88 upon account closure.
We collect only data necessary to provide the service. No sale or sharing of personal data with third parties for advertising.
All international transfers governed by Standard Contractual Clauses (SCCs) or the EU–US Data Privacy Framework.
Your data is never used to train AI models without explicit opt-in consent. No customer data shared with third-party AI providers without authorization.
Your Data Rights
Export all your data at any time via the platform dashboard or written request. Exports delivered within 30 days.
Deletion requests processed within 30 days in compliance with GDPR Article 17 and CCPA. Submit to privacy@nomadxi.com.
Access, rectification, restriction, and portability requests acknowledged within 5 business days and fulfilled within 30 days.
Our platform is engineered for high availability with transparent, published service level commitments.
* Contractual SLA: 99.9% | Actual trailing 90-day performance: 99.98%
NomadXI uses a limited, vetted set of third-party providers. All are bound by Data Processing Agreements and must meet our security standards.
CRM, marketing automation, funnel management, and client portal infrastructure
Cloud infrastructure, compute, storage, networking
SMS, voice, and transactional email delivery
Payment processing and billing infrastructure
CDN, DDoS protection, WAF, DNS management
Internal productivity and communication tools
Incident management and on-call alerting
Application performance and security monitoring
Source code management and CI/CD pipeline
Subprocessor list last updated May 2026. Updated as changes occur. Enterprise customers may subscribe to change notifications at privacy@nomadxi.com. All subprocessors undergo annual security review.
NomadXI leverages AI to serve you — never to exploit your data.
Customer data is never used to train, fine-tune, or improve any AI model without explicit opt-in written consent.
When AI providers are used, customer data is not stored, logged, or retained by the provider beyond the immediate request lifecycle.
Any AI-generated content or automated decisions that affect your account are disclosed. You always know when AI is involved.
High-stakes automated decisions (account suspension, billing disputes) require human review. No fully autonomous adverse actions.
AI providers currently used: OpenAI API (language processing), integrated within GoHighLevel AI workflows. All providers are listed in our Authorized Subprocessors table above. No customer data is retained by any AI provider beyond the immediate request lifecycle.
Answers to the questions enterprise customers ask most during vendor evaluation.
We take security vulnerabilities seriously. If you discover a potential security issue, we encourage responsible disclosure. We commit to acknowledging your report within 48 hours, keeping you informed throughout the process, not pursuing legal action for good-faith reports, and recognizing your contribution publicly if desired.
A transparent record of security events. We disclose incidents proactively to maintain customer trust.
In the event of a future incident, this log will be updated within 72 hours of confirmation. Enterprise customers receive direct notification per their DPA. Request a DPA →