Niural launches Niural AI LabsRead Announcement

Niural Logo

Privacy Policy

Privacy Policy

Last Updated: Sep 19, 2026

Introduction

Niural, Inc. ("Niural", "we", "us", or "our") provides payroll, human resources, workforce management, employment, contractor, benefits, payment, and related services (the "Services"), including through (the "Site").

This Privacy Policy describes how Niural collects and processes personal information for its own purposes when you interact with Niural and the Services.

This Privacy Policy is provided for transparency and does not itself constitute consent to any processing. Where applicable law requires consent for a particular processing activity, we will obtain that consent separately.

Unless otherwise defined here, capitalized terms have the meanings given in our Terms of Service.

What This Privacy Policy Covers

This Privacy Policy applies to the personal information we collect and process when you:

  • visit, interact with, or use the Site or any Services that link to this Privacy Policy;
  • create or administer a Niural account;
  • communicate with us, including by email, phone, chat, support request, or through our social media pages;
  • participate in benefits, insurance, or payment services that we provide or administer;
  • are hired, engaged, onboarded, or paid through Services in which Niural acts as an employer, co-employer, employer of record, or agent of record;
  • are a contractor, vendor, accountant, broker, or other authorized representative interacting with the Services; or
  • register for or attend our events, or take part in our marketing or promotions.

What This Privacy Policy Does Not Cover

Customer Personal Data. Personal information submitted to Niural so that Niural can provide the Services to a customer — for example, payroll instructions, timekeeping records, or benefits enrollment details. This does not include account, contact, authentication, communications, or other information that Niural processes for its own account administration, security, support, legal, compliance, or business purposes, which this Privacy Policy does cover. Niural processes Customer Personal Data under its agreement with the relevant customer, including any applicable data processing addendum. That organization is generally responsible for responding to requests concerning it; contact your employer, engaging entity, or account administrator, and Niural will assist as required by law and contract.

Third-party products and services. Products, services, websites, or content offered by third parties through integrations with the Services. Those third parties’ own privacy notices govern their processing.

Where you make a request to us about personal information covered by this Privacy Policy, some requests, including requests to delete, are subject to legal, tax, payroll, and anti-money-laundering recordkeeping obligations that require us to retain certain records. Where such an exception applies, we will tell you.

Certain benefits or health-related information may also be subject to additional privacy notices, plan documents, or contractual protections, including applicable business associate agreements.

Information We Collect

We may collect contact information; account and authentication information; employment, payroll, tax, benefits, and workforce information; financial, payment, and transaction information; identity and verification information; device, usage, and technical information; location information; communications and support information; marketing preferences; information you provide through AI-powered features; and other information you or others provide through the Services.

Some of this information may be considered sensitive personal information under applicable law. This may include government identification numbers, financial account information, health or insurance information, and biometric information, including facial-geometry information that may be generated when an identity-verification process compares a photograph you provide with the photograph on a government-issued identification document.

Please do not submit personal information to an AI-powered feature unless you are authorized to do so.

Where We Collect Personal Information

We may collect personal information directly from you; from customers and other users of the Services; from employers, engaging entities, plan sponsors, and their authorized representatives; from service providers and business partners, including benefits, payment, and identity-verification providers; from government and public sources; and from other sources permitted by applicable law. We may combine information from these sources with information collected through the Services.

Where required by applicable law, we will provide any additional notice required when personal information is obtained from a source other than you.

Cookies and Similar Technologies

We and our service providers may use cookies and similar technologies to operate, secure, analyze, and improve the Site and the Services, and to support communications and marketing. Where required by applicable law, we provide choices regarding these technologies.

How We Use Personal Information

We may use personal information to:

  • provide, administer, support, and improve the Services;
  • process payroll, payments, benefits, tax, employment, and workforce activities;
  • create and manage accounts;
  • verify identity and prevent fraud or misuse;
  • communicate with you and provide support;
  • comply with legal, regulatory, contractual, and operational requirements;
  • protect our rights, systems, users, and business;
  • analyze use of the Services and develop new features;
  • conduct permitted marketing and business-development activities; and
  • carry out other purposes disclosed at the time of collection or permitted by applicable law.

We process personal information on the legal bases available under applicable law, including as necessary to provide the Services, to comply with legal obligations, for our legitimate interests, and with consent where required.

AI-Powered Features and Automated Processing

We may use automated tools and artificial-intelligence-powered features to provide, support, secure, evaluate, and improve the Services. We may use service providers to support these functions.

We do not use personal information that customers submit to the Services to train general-purpose artificial-intelligence or machine-learning models.

We may use aggregated or de-identified information that cannot reasonably be used to identify an individual for analytics and service improvement. Where we maintain information in de-identified form, we maintain and use it without attempting to reidentify it, except as permitted by applicable law, and we contractually require recipients to do the same.

Where automated processing is subject to specific legal requirements, we will provide the notices, choices, and rights required by applicable law.

How We Share Personal Information

We may disclose personal information to service providers, business partners, financial institutions, insurers, benefits providers, government and tax authorities, professional advisers and auditors, customers, employers or engaging entities, and other parties as reasonably necessary to provide the Services, comply with law or legal process, protect rights, security, and integrity, complete or evaluate a corporate transaction, or carry out the purposes described in this Policy.

We may also disclose personal information at your direction or with your consent.

We may publish reports containing aggregated or de-identified information that does not identify any individual.

Marketing Communications

We may contact you with newsletters and other marketing information. You may opt out at any time by following the unsubscribe instructions in any marketing email or by contacting us. We may still send transactional or administrative messages relating to the Services.

How Long We Keep Personal Information

We retain personal information for as long as reasonably necessary for the purposes described in this Policy, including to provide the Services, comply with legal, tax, and regulatory obligations, resolve disputes, enforce agreements, maintain security, and support legitimate business operations. Retention periods vary depending on the type of information, the purpose for which it was collected, the sensitivity of the information, and the duration of our relationship with you. When information is no longer required, we delete or de-identify it in accordance with applicable law.

Following termination or expiration of Services provided under an agreement with a customer, we delete or de-identify personal information processed in connection with those Services in accordance with that agreement, except where continued retention is required by applicable law or is necessary to establish or defend legal claims.

Biometric identifiers and biometric information, where collected, are retained only until the initial purpose for collection has been satisfied or within three years of your last interaction with us, whichever occurs first, and are then permanently destroyed.

Security

We maintain administrative, technical, and physical safeguards designed to protect personal information. However, no security measure and no method of transmission or storage is completely secure, and we cannot guarantee absolute security. If you become aware of any breach of security or privacy, please contact us. We will notify affected individuals and applicable regulators of a security incident where, and within the time period, required by applicable law.

Our Privacy Commitments

Niural is committed to protecting personal information against unauthorized access, use, disclosure, alteration, loss, and destruction. We implement and maintain a layered program of administrative, technical, and physical safeguards proportionate to the sensitivity of the information involved, including:

  • Unauthorized access: access controls, role-based permissions, authentication requirements, and network security measures designed to restrict personal information to authorized personnel and systems;
  • Unauthorized use: internal policies, contractual restrictions, and training designed to limit use of personal information to purposes disclosed in this Policy or otherwise permitted by law;
  • Unauthorized disclosure: confidentiality obligations for employees and service providers, encryption in transit and at rest where appropriate, and vetting of third parties before personal information is shared;
  • Unauthorized alteration: change-management controls, audit logging, and data-integrity checks designed to detect and prevent improper modification of records;
  • Loss and destruction: backup, redundancy, and disaster-recovery practices designed to maintain the availability of personal information, and secure disposal or de-identification practices when retention is no longer required.

These commitments apply across the personal information Niural processes for its own purposes under this Policy and, where applicable, inform the safeguards Niural maintains for Customer Personal Data under its customer agreements and data processing addenda.

Privacy Governance and Oversight

Niural maintains organizational accountability for privacy governance. A designated individual or function, described further in Niural's internal Privacy program, is responsible for overseeing privacy governance throughout the organization, including:

  • developing, implementing, and maintaining privacy policies, procedures, and this Privacy Policy;
  • monitoring compliance with applicable privacy and data-protection laws;
  • coordinating the response to data subject and data controller requests, security incidents, and regulatory inquiries;
  • advising on privacy risk in new products, features, and AI-powered functionality; and
  • serving as the internal and, where required by law, external point of contact for privacy matters.

Details of this role's scope, reporting line, and authority are maintained in Niural's internal Privacy Program Charter and associated job description documentation, which are reviewed and updated periodically.

Instructions for Processing on Behalf of Data Controllers

Where Niural processes Customer Personal Data on behalf of a customer acting as data controller or processor as applicable, Niural processes that personal information only in accordance with the customer's documented instructions, including instructions set out in the applicable master services agreement and Data Processing Addendum ("DPA"), except where otherwise required by applicable law. These instructions generally address:

  • the subject matter, duration, nature, and purpose of processing;
  • the types of personal information processed and categories of data subjects;
  • the obligations and rights of the controller (where applicable), including instructions on collection, use, storage, transfer, retention, and deletion of personal information;
  • confidentiality obligations applicable to personnel who process the data;
  • the use of subprocessors, including notice and objection rights where applicable;
  • assistance to be provided to the controller in responding to data subject requests and regulatory obligations; and
  • return or deletion of personal information upon termination of the Services.

If Niural reasonably believes an instruction infringes applicable data protection law, Niural will inform the customer unless prohibited by law. The full terms governing Niural's role as processor, including any additional or conflicting terms, are set out in the applicable DPA, which controls this Policy with respect to Customer Personal Data.

Data Access Request Procedure

Niural maintains a documented procedure for handling requests from data controllers (such as customers, employers, or engaging entities) relating to Customer Personal Data, and from individuals exercising rights under this Policy with respect to information Niural holds for its own purposes. The procedure generally follows these steps:

  • Intake: requests are submitted through the contact details in this Policy, or through the channel specified in the applicable DPA, and are logged upon receipt;
  • Verification: Niural takes reasonable steps to verify the identity of the requester and, where applicable, the authority of an agent submitting a request on another's behalf;
  • Assessment and fulfillment: Niural assesses the request against applicable legal, contractual, and recordkeeping obligations, and takes the appropriate action, which may include providing, correcting, restricting, or deleting the relevant personal information, or assisting the controller in doing so;
  • Exceptions: where a legal, tax, payroll, anti-money-laundering, or other record keeping obligation limits Niural's ability to fulfill a request (for example, a deletion request), Niural will inform the requester of the applicable exception; and
  • Escalation: requests that cannot be resolved through this procedure may be escalated to the individual or function responsible for privacy governance described above.

Specific timeframes for particular jurisdictions or request types may be shorter where required by applicable law or by the terms of an applicable DPA, in which case the shorter timeframe controls.

International Transfers

Personal information may be transferred to, and processed in, countries other than the country in which it was collected, including the United States, where data-protection laws may differ from those in your jurisdiction.

Where required by applicable law, we use recognized legal mechanisms and appropriate safeguards for international transfers, which may include standard contractual clauses approved by the relevant authority. You may contact us for further information about, or a copy of, the safeguards applicable to your personal information.

Children and Dependents

The Services are not directed to children. We may, however, process information about dependents or other minors when that information is provided by a parent, guardian, employer, plan sponsor, or other authorized person for benefits, payroll, tax, or related purposes. We do not knowingly collect personal information directly from children in a manner prohibited by applicable law. If you believe a child has provided us with personal information other than as described above, please contact us.

Third-Party Sites

The Services may contain links to sites we do not operate. We have no control over, and assume no responsibility for, the content, privacy policies, or practices of any third-party site or service. We encourage you to review the privacy policy of every site you visit.

U.S. State Privacy Rights

Depending on where you live and subject to applicable law, you may have rights to request access to, correction of, deletion of, or a copy of your personal information, to object to or opt out of certain processing, to appeal a decision on your request, and to use an authorized agent. To exercise an applicable right, contact us using the details below. We may take reasonable steps to verify your identity and the authority of any agent before responding, and we will use information provided for verification only for that purpose. We will not discriminate against you for exercising rights provided by applicable law.

Where applicable law provides a right to opt out of the sale of personal information, sharing for cross-context behavioral advertising, targeted advertising, or profiling, we provide the methods required by law.

California. The categories of personal information we may collect are identifiers; customer records information; characteristics of protected classifications; commercial information; internet or other electronic network activity information; geolocation data; audio, electronic, visual, or similar information; professional or employment-related information; education information; inferences; and sensitive personal information. We collect this information from the sources, use it for the purposes, and disclose it to the categories of recipients described in this Policy. We use and disclose sensitive personal information only for purposes for which the right to limit does not apply, unless we provide notice and a method to exercise that right. We do not knowingly sell or share the personal information of consumers under 16 years of age. California residents may also request information about disclosures of personal information to third parties for those parties’ own direct marketing purposes.

EEA, United Kingdom, and Switzerland

If you are located in the EEA, the United Kingdom, or Switzerland, Niural processes personal information where it has an appropriate legal basis, which may include performance of a contract, compliance with legal obligations, our legitimate interests, consent, or another basis permitted by applicable law. Our legitimate interests include providing, securing, and improving the Services; communicating with users; preventing fraud and misuse; and operating our business. Where we rely on consent, you may withdraw it at any time without affecting processing carried out before withdrawal.

Subject to applicable law, you may have rights to access, correct, delete, restrict or object to the processing of, or receive a copy of your personal information, and to withdraw consent. You may also lodge a complaint with the data-protection authority where you live or work or where an alleged infringement occurred.

Where personal information is required by law or contract, or is necessary to enter into a contract, we will identify that requirement and the consequences of not providing the information at or before collection.

Additional contact information may be provided where required by applicable law.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time. The "Last Updated" date indicates when it was most recently revised. Where required by applicable law, we will provide additional notice of material changes.

Contact Us

If you have questions about this Privacy Policy, or wish to exercise a right described above, contact us at legal@niural.com.

If you have questions about Customer Personal Data handled by your organization, please contact your organization’s account administrator.