Nomos — Privacy Policy

Last Updated: October 25, 2025

Operated by Plutas Lab ("Plutas," "we," "us," or "our")

Contact: founders@plutas.in

For a high-level explanation of how we handle your data, please see our Data Controls page.

1. Introduction

This Privacy Policy explains how Plutas collects, processes, and protects personal data ("Personal Data") when you use Nomos, including our website, applications, APIs, and related services ("Services").

By accessing or using the Services, you acknowledge that you have read and understood this Privacy Policy.

If you do not agree with this Privacy Policy, please discontinue use of the Services.

Capitalized terms not defined here have the meanings given in our Terms of Service.

2. Information We Collect

We collect information to deliver and improve our Services. Some information is required to operate the platform, and without it, certain features may not function.

A. Personal Data You Provide to Us

This may include:

  • Name
  • Email address
  • Phone number
  • Organization or employer name
  • Role or professional title
  • Account credentials
  • Cookies and preferences
  • Any additional data you choose to submit

B. Usage Data

We automatically collect information about how you access and interact with the Services, including:

  • IP address
  • Browser type and version
  • Device information
  • Operating system
  • Date/time of visits
  • Pages and features accessed
  • Performance logs and diagnostics
  • Language and location settings

On mobile devices, we may collect:

  • Device identifiers
  • Mobile OS and browser
  • Network information

C. Legal Documents and Content You Upload

You may upload:

  • Contracts
  • Case files
  • Correspondence
  • Regulatory documents
  • Templates
  • Negotiation histories
  • Notes and internal records

Plutas processes this data solely to operate Nomos.

We do not use your legal documents or customer data to train any AI models—ever.

Your data remains fully under your organization's control.

D. Integrations and Third-Party Accounts

If you connect Nomos to a third-party service (e.g., cloud storage or identity provider), we may receive information permitted by your settings on that platform.

You can revoke such permissions directly from the third-party account.

E. Payment Information

If you sign up for paid features, payment information is handled by our payment processor (e.g., Stripe). Plutas does not store your credit card or bank information.

See Stripe's Privacy Policy for details.

F. Additional Information You Choose to Provide

This includes:

  • Feedback
  • Survey responses
  • Support requests
  • Communication preferences

3. How We Use Your Data

We use Personal Data, Usage Data, and Document Content for the following purposes:

A. To Provide and Maintain the Services

  • Operating, securing, and improving Nomos
  • Hosting, processing, and analyzing Customer Content
  • Supporting private deployments (VPC or on-premise)

Your data is never used to train Plutas or third-party AI models.

B. Communication

  • Service and security notices
  • Account updates
  • Technical support
  • Product announcements (opt-out available)

C. Product Improvement

  • Feature development
  • Performance optimization
  • User experience analysis

D. Analytics & Measurement

  • Understanding usage patterns
  • Diagnosing performance issues
  • Evaluating product effectiveness

E. Billing & Administration

  • Subscription management
  • Payment processing
  • Tax compliance

F. Compliance with Law

We may process Personal Data to comply with:

  • Legal obligations
  • Court orders
  • Regulatory requirements

G. Security and Fraud Prevention

We may use data to:

  • Detect abuse or misuse
  • Monitor suspicious activity
  • Protect the integrity of the Services

H. Marketing

We may send marketing communications about Plutas and Nomos.

You may unsubscribe at any time.

Legal Basis for Processing (if applicable)

We process your Personal Data based on:

  • Performance of a contract
  • Legitimate interests
  • Your consent
  • Legal obligations

4. Cookies and Tracking Technologies

We use:

  • Cookies
  • Web beacons
  • Local storage
  • Analytics tools

These help us understand how the Services are used and improve performance.

You may control cookies through your browser settings.

5. Online Analytics and Advertising

A. Analytics Providers

We may use analytics tools (such as Google Analytics) to understand usage trends.

These providers collect information automatically through your interactions with the Services.

B. Tailored Advertising

We may use first-party analytics to display Plutas marketing content on our own site or other platforms.

We do not sell your data or use it to optimize ads for third parties.

6. Data Retention

We retain Personal Data only for as long as needed:

  • To deliver the Services
  • To meet legal requirements
  • To resolve disputes
  • To enforce agreements

When data is no longer required, it will be deleted or irreversibly anonymized.

7. International Transfers

Your data may be processed in locations where Plutas, its affiliates, or service providers operate.

We ensure appropriate safeguards when transferring data across borders.

For private deployments (VPC/on-premise), your data may never leave your infrastructure.

8. Sharing of Data

We may disclose Personal Data only in the following situations:

A. Service Providers

Hosting, analytics, support, or payment partners—bound by confidentiality obligations.

B. Your Organization

If your employer or firm provides your access, certain information may be shared with them.

C. Legal Compliance and Safety

Where required to protect:

  • Rights
  • Security
  • Users
  • Compliance obligations

D. Business Transfers

In the event of:

  • Acquisition
  • Merger
  • Asset sale

Your data may be transferred to the acquiring entity.

E. Affiliates

Within Plutas Lab's corporate group, consistent with this Privacy Policy.

F. With Your Consent

We will only share data with additional third parties if you explicitly authorize it.

9. Security

We use industry-standard administrative, physical, and technical safeguards, including:

  • Encryption (in transit and at rest)
  • Access controls
  • Network segmentation
  • Monitoring and auditing
  • Infrastructure hardening

However, no system is completely secure.

You acknowledge this risk by using the Services.

10. GDPR: Rights of EU/EEA Users

If you are located in the EU/EEA, you have rights to:

  • Access your data
  • Correct inaccuracies
  • Request deletion
  • Restrict or object to processing
  • Data portability
  • Withdraw consent

Requests may require identity verification.

You may also submit complaints to your local Data Protection Authority.

11. Children's Privacy

Nomos is intended for professional use only.

We do not knowingly collect data from individuals under 16 years old.

If you believe a child has submitted Personal Data, contact us at founders@plutas.in.

12. Service Providers

Service Providers may have access to Personal Data solely to perform contracted tasks.

They are prohibited from using it for any other purpose.

13. Links to External Sites

Our Services may contain links to external websites. We are not responsible for:

  • Their content
  • Their data practices
  • Their privacy policies

Please review third-party privacy terms before interacting with their services.

14. Changes to This Privacy Policy

We may update this Privacy Policy periodically.

When changes occur, we will:

  • Update the "Last Updated" date
  • Provide notice for material changes
  • Comply with applicable legal requirements

Continued use of the Services means you accept the updated Privacy Policy.

15. Contact Us

For questions, concerns, or data requests, contact:

📧 founders@plutas.in

🌐 https://www.plutas.in

16. Privacy Notice for California Residents (CCPA)

If you are a California resident, you may have rights under the California Consumer Privacy Act (CCPA), including:

  • Right to know what Personal Data we collect
  • Right to request deletion
  • Right to correct inaccurate data
  • Right to opt out of the "sale" or "sharing" of personal information

(We do not sell your personal information.)

To exercise these rights, email:

📧 founders@plutas.in