nodus ← back

Privacy policy.

Plain English, because that's how we write everything. Effective 6 July 2026. Our home law is the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021); where we collect personal data in or from other places — including Singapore, under the PDPA — we honor those laws too. The promises below don't vary by jurisdiction.

The short version

You control your data. We collect what you hand us, use it only to represent you, share your identity only when you say yes, never sell it, and destroy the most sensitive documents the moment they've done their job. Ask for everything we hold and we hand it over; ask us to delete it and we do.

1 · Who we are

Nodus is a talent-representation service for go-to-market professionals, operated by ANB Advisory and Commerce FZCO, a company registered with the International Free Zone Authority (IFZA), Dubai, United Arab Emirates. In this policy, "we" (and "I", where Nodus speaks in the product) means Nodus; "you" means anyone who uses the service — talent we represent, hiring leaders who receive our introductions, and visitors to this site.

Data Protection Officer: reachable at hellohaystack@agentmail.to. Every request in this policy starts with a one-line email there.

2 · What we collect

Account. When you sign in with LinkedIn we receive your name, verified email address, and profile photo — nothing else. We cannot see or touch your LinkedIn network, messages, or activity. We never receive a password, because there are none here.

What you hand us. Your career story (roles, dates, metrics, the accounts you carried), your preferences and dealbreakers, your deny list (who must never see you), documents you upload — a LinkedIn export, a resume, an attainment letter, a printed win thread — and anything you write to us.

From hiring leaders. Contact details, preferences about what they want to see, and how they engage with what we send (opens, clicks, replies).

Technical. The minimum to run a session: authentication cookies and standard server logs. No advertising trackers, no analytics resold to anyone.

3 · What we use it for

One purpose: representation. Concretely — reading your career to build your Tape; matching you against roles and markets; producing blinded artifacts (briefs and win wires) that show fit without revealing identity; verifying claims you ask us to verify; contacting you about your own representation; and improving how well the service does exactly these things.

We use AI systems (large language models) to read documents and produce these artifacts. Documents are processed for the purposes above and are not used by us to train foundation models.

4 · What we share — and what we never share

Identity moves only on your yes. Hiring leaders see blinded artifacts: real fit, no name, no employer, no identifying combination of details. Your name and contact are revealed only after you explicitly consent to a specific introduction. Your deny list is enforced on every channel, always; your current employer is excluded by us automatically.

Processors. We use service providers to run the machine: cloud hosting and database (Supabase, Google Cloud), email delivery, and AI providers for document processing. They process data on our instructions, under their own contractual confidentiality and security obligations, and for no other purpose.

Never. We do not sell personal data. We do not share it with advertisers or data brokers. We do not publish anything that identifies you without your consent. If the law compels disclosure, we disclose the minimum required and tell you unless legally barred.

5 · The win-wire promise (destruction by design)

If you send us an internal win thread, we verify it, extract a summary in our own words — ranges instead of exact figures, quarters instead of dates — and then destroy the document itself. You receive a confirmation when that happens. What survives is not quotable back to the original. Documents uploaded for claim verification are likewise reduced to a cryptographic fingerprint once read; we keep the fingerprint, not the file.

This is deliberate: the safest data is data we no longer hold.

6 · Where data lives (overseas transfer)

Our infrastructure providers store and process data in regions where their cloud services operate, including the United States. Wherever personal data crosses a border, we ensure the recipient is bound to protect it to a standard comparable to the laws that apply to you — the UAE PDPL, and the PDPA for data collected in or from Singapore — through the providers' contractual data-processing terms and security certifications.

7 · How long we keep things

As long as we're representing you, we keep your record current. Win-thread documents: destroyed on verification (usually within minutes). Verification documents: reduced to a fingerprint once read. Everything else: kept until you ask us to delete it, or until it no longer serves representation, whichever comes first.

On deletion, representation ends and your record is removed; your deny list is honored to the last second. We may retain the minimum required to meet legal obligations or to enforce your own do-not-contact instruction.

8 · Your rights and your controls

Whichever law applies to you (UAE PDPL, Singapore PDPA), you can ask us: what personal data of yours we hold and how it's been used (access); to fix anything wrong (correction); to stop using it (withdraw consent — which ends representation, since that's all we use it for); and to delete it. Email the DPO; we respond within 30 days, usually much faster.

Most of this you can do yourself, immediately, in your portal: pause everything with one switch, edit your deny list, correct your story, control what's visible. The portal is the policy, made operable.

9 · Cookies · security · age

Cookies: essential session cookies only (keeping you signed in). No third-party advertising or tracking cookies.

Security: encryption in transit, row-level access controls so you can only ever reach your own records, secrets kept out of code, and a bias toward not holding sensitive material at all (see section 5). No system is perfect; if a breach ever affects you, we'll notify you and the PDPC as the PDPA requires.

Age: Nodus is for working professionals and not intended for anyone under 18.

10 · Changes · complaints

If this policy changes materially, we'll post the new version here with a new effective date and tell active users. The current version always lives at this URL.

Not satisfied with how we handled your data or your request? Tell the DPO first — we fix things fast. You can also complain to the UAE Data Office (the PDPL regulator), or — for personal data collected in or from Singapore — to Singapore's Personal Data Protection Commission at pdpc.gov.sg.

Nodus is operated by ANB Advisory and Commerce FZCO (IFZA, Dubai).