Legal

Privacy Policy

What Nustro collects, why, for how long — and what it never collects. Data minimization is a design constraint of the scheme, not a preference.

Version1.0
IssuerNustro, LLC (“Nustro”)
Effective dateAugust 11, 2026
Supersedes

1.Who we are and what this covers

Nustro, LLC (“Nustro,” “we”) operates the Nustro scheme — the trust layer for transacting AI agents. This policy explains how we handle personal data across nustro.com, the dashboard, the management APIs, and the sandbox. Where your platform holds production accreditation, the Platform Operator Agreement and any Data Processing Addendum apply alongside it.

2.What we collect

Account data: the name, business email, and password (stored hashed) of the people who register and operate a platform account, and the profile the account carries.

Business verification (KYB): the legal-entity information, registration numbers, ownership and control details, and supporting documents your business submits for production accreditation, together with the results of our review and of sanctions screening.

Principal verification data: the identity and verification details your platform submits when it registers a Principal — the person or company accountable for its agents — and the verification status and certificates we issue against them.

Scheme records: transaction, settlement, escrow, dispute, and rating records. These reference agents, certificates, and Principal identifiers — not the people your principals or their counterparties serve.

Usage data: dashboard and API activity logs, webhook delivery records, device and connection information, and support correspondence.

3.What we deliberately do not collect

We do not collect personal data about your principals’ customers or the parties your agents transact with, beyond what verification requires. We do not build advertising profiles, we do not use personal data to train advertising or profiling systems, and we do not sell or rent personal data to anyone. Data minimization is a design constraint of the scheme, not a preference.

4.Why we process it

We process personal data to provide and secure the service (performance of our contract with you); to verify businesses and Principals and to certify agents, which is the trust function of the scheme (our legitimate interest in operating a scheme counterparties can rely on, and yours in participating); to meet legal obligations, including KYB, anti-money-laundering, and sanctions requirements; to communicate with you about the account and the scheme; and to understand and improve the service using data that is aggregated or de-identified wherever possible.

5.Cookies and analytics

nustro.com and the dashboard use cookies that are necessary for sign-in, security, and session integrity, and privacy-respecting analytics to understand aggregate usage. We do not use advertising cookies and we do not track you across other sites. Where consent is required for non-essential cookies, we ask for it.

6.What the scheme itself makes visible

Certain records are visible across the scheme by design, because counterparties rely on them: agent identity documents, certificate status, ratings, and escrow state are readable by scheme participants, and settlement events are recorded on-chain in the form the protocol specifies. These records carry agent and Principal identifiers and verification status — never the underlying verification documents, which stay with Nustro.

7.How we share data

We share personal data with service providers who work for us under contract — hosting, identity-verification and sanctions-screening vendors, email delivery, and support tooling; with professional advisers; with authorities where the law requires it; and as part of a merger, acquisition, or asset sale, in which case this policy continues to apply to the data transferred. We do not share personal data with anyone for their own advertising.

8.International transfers

We operate from the United States. Where we transfer personal data from jurisdictions that restrict international transfers, we rely on recognized safeguards such as standard contractual clauses.

9.Retention

Account and verification data are kept for the life of the account and thereafter as long as the law requires — verification and screening records typically five years after the relationship ends. Scheme records — certificates, settlement history, ratings, and statements — are append-only records of the scheme and are retained as such; they are why we keep the personal data inside them to identifiers and status. Usage logs are kept on a rolling basis and then deleted or de-identified.

10.Your rights

Depending on where you are, you may have the right to access, correct, delete, or receive a copy of your personal data, to object to or restrict certain processing, and to complain to a supervisory authority. Write to legal@nustro.com and we will respond within the time the law allows. Some requests have limits we will explain when they apply: verification records we must keep by law, and scheme records that are append-only by design, where deletion takes the form of severing the link between the record’s identifier and you.

11.Principals and your platform’s responsibilities

Your platform decides which Principals to register and submits their data; we verify them and issue certificates because scheme trust requires it. You are responsible for having a lawful basis for the data you submit and for your own privacy notices to your Principals — including telling them that verification is performed by Nustro and what the scheme makes visible. A Data Processing Addendum is available on request through contact sales.

12.Security

Personal data is protected with encryption in transit and at rest, scoped access controls, and audit logging. The same bounded-custody discipline that governs funds governs data: systems and people get the narrowest access that does the job.

13.Children

The service is for business use by adults. It is not directed to anyone under 18, and we do not knowingly collect personal data from them.

14.Changes to this policy

We may update this policy. For material changes we give at least 30 days’ notice to the account email before the new version takes effect. Each version carries its version number and effective date, and superseded versions remain published at nustro.com/legal.

15.Contact

Nustro, LLC · legal@nustro.com. If you are unsatisfied with our response, you may have the right to raise the matter with your local data-protection authority.

Questions about this policy: legal@nustro.com · Print or save as PDF

The trust layer for transacting AI agents. Verified identity, escrowed liability, and binding recourse — Nustro never holds your agents’ keys.

Patent pending OWASP GenAI Cloud Security Alliance Open specification
Product
Agent IdentityProof of PerformanceLiability EscrowDispute ResolutionHow settlement worksTrust & SecurityPricing
Developers
Nustro docsAPI referenceWebhooks & eventsReference apps ↗Changelog Status
Protocol
What is AEA/P ↗Framework ↗Specification ↗AEA/P docs ↗AEA/P reference ↗AEA/P certified ↗
Company
AboutContactLegalPrivacy
© 2026 Nustro, LLC nustro.com