NESSCOAgentic Harness
Legal

Privacy Policy

Effective date: 19 August 2026 · Last updated: 19 August 2026

1. Overview

This policy explains what information Nessco collects through nessco.ai and related subdomains (the "Site"), including the demo questionnaire, GitHub sign-in, and the booking page, and how that information is used, shared and protected.

2. Information we collect

  • Demo questionnaire. Name, work email, company, role, company size band, revenue band, agent count, frameworks in use, what your agents can reach, deployment preference, compliance requirements, timeline, and any free-text notes you provide.
  • GitHub sign-in. If you sign in with GitHub, we receive your GitHub login, display name, avatar URL, and — where the associated scope is granted and available — a verified email address. We do not receive your GitHub password, and we do not store your GitHub access token beyond the request used to read this profile information.
  • Session data. A signed, HttpOnly session cookie that identifies a signed-in browser to our servers. It contains no more than the profile fields above and an expiry; it is not used for cross-site tracking or advertising.
  • Booking. If you proceed to book a consultation, the scheduling provider embedded on that page collects information under its own privacy policy, linked from the booking page once configured. Nessco receives what you schedule but does not receive your scheduling account credentials.
  • Technical data. Standard web server logs (IP address, user agent, timestamps) generated by hosting infrastructure in the ordinary course of serving the Site.

3. How we use it

We use this information to: respond to demo requests and route them to the right expert; generate the non-binding pricing estimate shown on the pricing page and in the questionnaire; operate sign-in; maintain the security and audit integrity of the harness product itself; and improve the Site. We do not sell personal information, and we do not use questionnaire answers to train third-party models.

4. Legal bases (EEA/UK visitors)

Where the GDPR or UK GDPR applies, we rely on: performance of a contract or steps taken at your request prior to entering one (responding to a demo request); legitimate interests (operating and securing the Site); and consent, where we ask for it explicitly (for example, optional cookies, if any are added in future).

5. Sharing & third parties

We share information with: GitHub, as the OAuth identity provider, under its own privacy policy; a scheduling provider once one is configured on the booking page; and infrastructure providers who host the Site and process demo requests on our behalf under a data processing agreement. We do not otherwise sell or rent personal information to third parties.

6. Retention

Demo questionnaire submissions are retained for as long as reasonably needed to progress the enquiry and for a limited period afterward for records purposes, after which they are deleted or anonymized. Session cookies expire automatically after seven days of inactivity. Server logs are retained on a rolling basis determined by our hosting provider's default retention window.

7. Security

Session cookies are signed and HttpOnly, and are never readable by page scripts. OAuth secrets are held only in server-side environment variables and never shipped to the browser. Demo questionnaire submissions are transmitted over HTTPS. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

8. Your rights

Depending on where you live, you may have the right to access, correct, export or delete the personal information we hold about you, and to object to or restrict certain processing. To exercise any of these rights, contact hello@nessco.ai; we will respond within the timeframe required by applicable law.

9. Children's privacy

The Site is intended for business use and is not directed at children. We do not knowingly collect personal information from anyone under the age of 16.

10. International transfers

Information may be processed in countries other than your own. Where required, we rely on appropriate safeguards (such as standard contractual clauses) for international transfers of personal information. [Transfer mechanism to be confirmed by counsel once hosting regions are finalized.]

11. Changes to this policy

We may update this policy from time to time. Material changes will be reflected by updating the "Last updated" date above.

12. Contact

Questions about this policy, or requests relating to your personal information, can be sent to hello@nessco.ai. Security-specific reports go to security@nessco.ai.