NimbusAI Data Handling
Applies to NimbusAI in NimbusDash, and in NimbusQL when it is offered there
Last updated: September 30, 2026
See also our Subprocessors, our Data Processing Agreementand our Privacy Policy. This page describes the products; the Data Processing Agreement is what binds NimbusLabs.
What NimbusAI is
NimbusAI is the assistant built into NimbusDash: you ask a question about a dashboard in plain language and it answers with a chart, a change to the grid, or a message. In NimbusDash, an administrator chooses where NimbusAI runs: on your own OpenAI or Anthropic API key, or on the AI provider included with your NimbusLabs license. NimbusQL will offer the same assistant for queries when it ships; this page will say what it sends when it does.
Both NimbusDash and NimbusQL run inside your NetSuite account. NimbusLabs holds no shared credentials for that account and has no access to it or to the data in it, except that your administrator can give a named NimbusLabs person access for a support task, through that person's own login and a role you choose, which lasts until you remove it. Apart from the records the applications send to run your license, which our Privacy Policy lists, anything you send with a support request or a support task requires, and the usage records described below, the one thing that leaves your account for NimbusLabs' systems is what NimbusAI sends, and this page describes exactly that.
On your own key (NimbusDash)
When an administrator configures NimbusAI with your own OpenAI or Anthropic API key:
- Requests go from your NetSuite account directly to that provider. Nothing passes through NimbusLabs' systems, and NimbusLabs never receives, sees or stores their content.
- Your API key stays in your NetSuite account, as a NetSuite API Secret. NimbusLabs never handles it.
- What is sent is your question, the recent conversation, your dashboard's structure and current grid state including filter values, and for each column its most frequent values and counts. If an administrator chose a row tier in NimbusDash's settings, sample or filtered rows are sent too, up to the row cap.
- Requests to OpenAI are sent with storage turned off. Each provider's own terms govern what it keeps and what it does with it; NimbusLabs is not a party to them. Regulated or sensitive data may not be sent to NimbusAI on your own key either: the agreement you accepted bars it on every provider.
On the included provider
When an administrator chooses the provider included with your license ("Included with your license" in the settings picker), NimbusAI runs on NimbusLabs' Microsoft Azure account. This is what happens to your data.
What is sent
Your question, the recent conversation (the text of earlier questions and replies, which can contain values from earlier answers, including ones given on your own key), your dashboard's structure and current grid state including filter values, and for each column its most frequent values and counts. NimbusAI never attaches your dashboard's rows on the included provider: the row tiers are not offered there, and the server sends no rows whatever setting is stored. Real values still travel, though. Filter values and column statistics come from your data, so a filter on a customer's name, or a column of email addresses, sends those values; and whatever a user types into a question is sent as typed.
Where it goes
From your NetSuite account, over an encrypted connection, to NimbusLabs' API gateway, a Microsoft-managed service in NimbusLabs' own Azure subscription. The gateway processes the request in transit: it checks the request's token, applies size and output limits, turns the model service's conversation storage off, and forwards the request to the Azure AI service in the same subscription, which generates the answer. The gateway is configured to record no request or response bodies, and NimbusLabs does not enable request tracing or body logging for your requests; it troubleshoots the gateway only with synthetic requests that carry no customer data. The gateway accepts only requests that carry a token issued to your account when your license is validated; tokens live ten minutes.
Processing takes place in the United States. NimbusLabs' Azure resource is in the West US 3 region, and its model deployments are Data Zone Standard, so inference may be processed anywhere within the United States data zone.
What NimbusLabs receives and keeps
Neither the gateway nor NimbusLabs' licensing platform keeps a copy of your question, the data sent with it or the answer, and Microsoft's abuse monitoring, described below, is the one process on this path that can hold them. If you send NimbusLabs a question or an answer with a support request, that copy is handled as support content under our Data Processing Agreement. For each request, NimbusLabs' separate licensing platform receives usage metadata only: your NetSuite account number, the product and environment, the deployment used, request and call identifiers, request status, token counts, computed cost and timestamps.
NimbusLabs keeps those request-level records while the included provider is in use on your account, to enforce the monthly allowance and the gateway's limits, operate and secure the service, and investigate abuse and failed requests, and deletes them within 30 days after that use ends, which is when your license for that product ends and NimbusAI stops working in it: for a paid license, eight days after its expiration date. Each product is counted on its own, so one ending does not wait for the other. A renewal, or a move from a trial to a subscription, is not an end. Turning the included provider off in NimbusDash's settings does not end that use, because the setting stays in your NetSuite account. If you stop using the included provider, your company can ask in writing at legal@nimbuslabs.com for the records to be deleted sooner: NimbusLabs deletes each completed month's records within 30 days of the request, and the current month's within 30 days after it ends, or sooner where the law requires. Separately, NimbusLabs keeps a monthly allowance summary for each account (the account number, the product, the month, the number of calls, the token totals and the cost total, with the record's own creation and retirement dates and no request identifiers or request timestamps) as its own business record, for account administration, reconciling the allowance it funded, accounting and resolving related disputes, for 24 months after the month it describes, and then deletes it. That summary is NimbusLabs' own record rather than data processed on your behalf; sections 2.4 and 10.4 of the Data Processing Agreement say so. The gateway's diagnostic logs, which contain no content, are configured for 30-day retention, with no export rules or additional diagnostic destinations configured for them; the usage metrics the gateway emits, keyed by account and product, are retained by Azure Monitor for 93 days. Copies in backups expire on the backup cycle: a daily job deletes copies on NimbusLabs' server once they are at least 15 full days old, and copies with its hosting provider are configured to expire at 120 days, after which its lifecycle process deletes them, ordinarily within days. Deletion and return are set out in section 10 of the Data Processing Agreement.
What Microsoft may do
Microsoft's standard abuse-monitoring process applies to the included provider; NimbusLabs has no exemption from it. Microsoft may select prompts and completions for review. Its automated abuse-review system does not store prompts or completions. Content selected for human review by authorized Microsoft employees is held in a separate store, isolated to NimbusLabs' Azure resource, not available to OpenAI or to other customers, and not used to train models. Neither NimbusLabs' gateway configuration nor the storage-off setting exempts a request from that process.
Microsoft's current documentation says what the process covers and how long anything is kept; NimbusLabs does not state a period that Microsoft does not state, and NimbusLabs has no direct access to that store. See Microsoft's data, privacy and security documentation for its Azure AI models on Microsoft Learn.
Training
NimbusLabs does not use your content to train, fine-tune or improve any model, and does not authorize Microsoft to. For the included provider, Microsoft states that prompts and completions are not used to train generative AI foundation models, and are not used to improve Microsoft's or any third party's products, without the customer's permission or instruction; NimbusLabs gives neither.
The allowance
Trial licenses include $5 of usage on the included provider per calendar month, and full licenses $50, resetting on the first of each month in UTC; NimbusQL's free version includes none. The allowance belongs to the licensed account and product, as one pool for the production account and its sandbox, development and release-preview accounts together, and is shared by all of their users; it is not per user and not per sandbox. Usage is measured at the list prices of the model used, for input, cached input and output tokens, including any additional model call NimbusAI makes to complete one request. NimbusDash shows what has been used and the reset date on its settings page and in the assistant's panel.
The included allowance never produces a bill: NimbusLabs does not charge for usage beyond it, and there is no overage. Once recorded usage reaches the allowance, new requests are refused until the reset; a request already in progress may complete. Rate limits and other protective limits on the gateway can also pause use briefly before the allowance is spent. In NimbusDash, an administrator can switch to your own key at any time, where usage is billed by that provider under your agreement with it.
Your controls
- The assistant is off until an administrator turns it on.
- An administrator chooses the provider, and can switch it or turn the assistant off at any time. The change applies to requests made after it; it does not recall content already sent or cancel a request in progress.
- An administrator chooses which roles may use the assistant. Users outside those roles cannot call it.
- On the included provider the row tiers are not offered. On your own key, an administrator chooses the tier and the row cap.
Subprocessors and agreements
Two companies process data on NimbusLabs' behalf: Microsoft, which runs the included provider, the gateway and its telemetry and hosts the email that receives support requests, and Amazon Web Services, which hosts the licensing platform that holds the usage records. Both are listed, with the date of every change, on our Subprocessors page. NimbusLabs' Data Processing Agreement is part of the agreement you accept for NimbusDash or NimbusQL from version 1.1 of that agreement, on trial, free and paid accounts alike, and sets these commitments out as contract terms. A customer on earlier terms comes under it on accepting version 1.1 or later. One who bought online under our earlier Terms of Use also comes under it when an administrator accepts it inside NimbusDash or NimbusQL, once the application offers that, and one who signed a Subscription Agreement before version 1.1 comes under it with a copy signed by both parties. Subscription customers can also have a signed copy.