Who we are
Nomi is a digital credentials platform operated by Codingraph S.A., registered as 3-101-938304 Sociedad Anónima, a company organised under the laws of Costa Rica.Codingraph provides and invoices the service under licence of the NOMI trademark, and is the company responsible for the personal data described here. In this policy, “we” and “us” mean Codingraph S.A.
This policy covers the public site at www.nomi-tech.com, the console at console.nomi-tech.com, the API at service.nomi-tech.com, the documentation at docs.nomi-tech.com, and the digital credentials issued and maintained through them on behalf of our customers. Questions go to privacy@nomi-tech.com.
Two roles: controller and processor
The same platform handles two kinds of personal data, and the difference decides who answers to you about it.
We are the controller of data about the people who deal with us directly: visitors to our website, people who ask for a demo, and the staff of a customer who sign in to the console. We decide why that data exists and what happens to it.
We are a processor of the data a customer loads into Nomi about the people they issue credentials to — their members, employees, students or attendees. The customer decides what to collect, what to put on a credential and who may hold one. We act on their documented instructions, and nothing else. If you hold a Nomi-issued credential, the company whose name is on it is your first point of contact; see If a business gave you a credential.
What we collect
Website and demo requests
If you ask for a demo, we receive the work email address and company name you type into the form. Our web servers and content delivery provider record ordinary request data — IP address, user agent, timestamps, the page requested — which we use to serve the site and keep it up.
Console accounts
To give a customer's staff access we hold a name, a work email address, a hashed authentication credential or an identifier from the identity provider they sign in with, the role assigned to them, and a record of security-relevant actions taken in the console — who issued, suspended or revoked a credential, and when. API keys are stored hashed; we cannot read them back.
Credential holder data, on behalf of a customer
Customers send us the data they want a credential to carry, through the console, the API, a file feed or a directory connector. Typically that is:
- an identifier the customer already uses for that person, and their display name;
- an email address, where the customer chooses to supply one;
- a photograph, where the credential is meant to show one;
- attributes the customer defines — membership tier, department, group, valid-from and valid-until dates, entitlements;
- the lifecycle of the credential itself: when it was issued, updated, suspended, revoked or presented for verification.
When a credential is added to a wallet, we also hold what the wallet platform needs in order to keep it current — device registrations and push tokens for Apple Wallet, and the identifier of the object created under the customer's issuer account for Google Wallet.
Operational records
We keep application and delivery logs, webhook delivery attempts, and billing records — plan, usage counts and invoices. We do not receive or store full payment card numbers.
Why we use it, and on what basis
Where Costa Rica law (Ley N.º 8968) applies, we rely on the informed consent of the data subject or on another basis that law allows. Where the EU or UK GDPR applies, our legal bases are:
- Performance of a contract — creating accounts, issuing and maintaining credentials, supporting and billing the customer.
- Legitimate interests — keeping the service secure and available, preventing abuse and fraud, understanding how the site performs in aggregate, and replying to a business enquiry someone sent us. We weigh those interests against your rights and stop where yours prevail.
- Legal obligation — tax, accounting and answering lawful requests from authorities.
- Consent — where we ask for it, such as optional product emails. You can withdraw it at any time, without affecting what was lawful before.
For credential holder data we process on a customer's behalf, the legal basis is the customer's to establish, not ours. We do not decide it and we do not repurpose the data.
What we never do: we do not sell personal data, we do not share it for cross-context behavioural advertising, and we do not use credential holder data to train machine learning models or to advertise to anyone. Aggregated, de-identified statistics that cannot be traced back to a person may be used to improve and describe the service.
Wallet platforms and Google APIs
A credential only becomes useful once it reaches a wallet, and that means data leaves us for the platform the customer chose.
Apple Wallet. The fields the customer put on the credential design are placed in a signed pass and delivered to the holder's device. So that later changes reach the pass, the device registers with our web service and we store its registration and push token; updates are announced through Apple's Push Notification service, which carries a signal to fetch, not the contents.
Google Wallet. We call the Google Wallet API to create and update an object under the issuer account of the customer, using credentials the customer or we hold for that purpose. The fields on that object are the ones the credential design specifies.
Once a credential is in a wallet, the platform's own privacy terms govern what the platform does with it. Nomi is not affiliated with Apple Inc. or Google LLC.
International transfers
Nomi is operated from Costa Rica and its infrastructure is currently hosted in the United States. If you are in the European Economic Area, the United Kingdom or Switzerland, that means your data is transferred outside your country. Where those laws require it, we rely on the European Commission's Standard Contractual Clauses, with the UK Addendum where relevant, together with technical measures such as encryption in transit and at rest. A copy of the clauses we use is available on request.
How long we keep it
- Credential and holder data: for as long as the customer's account is active. On termination, the customer has 30 days to export; after that we delete or irreversibly anonymise it. Backups roll off within a further 35 days.
- Deletion during the term: when a customer deletes a subject or a credential, we remove it from live systems promptly and it disappears from backups on the cycle above.
- Console accounts: until the account is removed by the customer's administrator.
- Security and audit events: up to 24 months, because an audit trail that is deleted on request is not an audit trail.
- Application logs: up to 90 days.
- Demo requests and business correspondence: up to 24 months from our last exchange.
- Invoices and accounting records: for the period Costa Rican tax and commercial law requires, generally five years.
Security
The controls that protect this data — encryption, how signing material and API keys are held, access control, the audit trail and how we handle an incident — are set out on the Security page, which also explains how to report a vulnerability. No system is perfectly secure, and we do not claim otherwise.
Your rights
Subject to the law that applies to you, you may ask us to give you access to your personal data, correct it, delete it, restrict or object to how we use it, hand it over in a portable format, or withdraw a consent you gave us. You may also lodge a complaint with a supervisory authority — in Costa Rica, the Agencia de Protección de Datos de los Habitantes (PRODHAB); in the EEA or UK, your national authority.
If you are in California, you additionally have the rights to know, delete, correct and limit the use of sensitive personal information, and not to be discriminated against for exercising them. We do not sell or share personal information as those terms are defined by the CCPA.
Write to privacy@nomi-tech.com. We answer within 30 days, and will tell you if we need longer or need more information to identify you — we will not ask for more data than the request requires.
If a business gave you a credential
If you hold a membership card, employee badge, student ID or ticket issued through Nomi, the business named on it decides what it contains and how long you keep it. Send your request to that business first — they can act on it directly in the console. If you contact us instead, we will pass your request to them without undue delay and support them in answering it, but we cannot change or delete their data on our own initiative.
Children
Nomi is a business tool and is not directed to children. We do not knowingly collect data from children on our own account. A customer may issue credentials to minors — a student ID, for instance — and where it does, that customer is responsible for obtaining any parental consent the law requires and for the notices given to those families.
Changes to this policy
We update this policy when the product or the law changes. The date at the top always reflects the current version. If a change materially affects how we handle personal data, we will notify customers by email or in the console at least 30 days before it takes effect. This policy is published in English; if we publish a translation and the two differ, the English version governs.
How to reach us
Data protection requests and questions about this policy go to privacy@nomi-tech.com. The controller is Codingraph S.A., registered in Costa Rica as 3-101-938304 Sociedad Anónima; our registered address is on that company file and we provide it on request where formal service of a notice requires it. Every other address is on the Contact page.