Privacy

Privacy policy

Nolmo is a helpdesk that businesses use to handle conversations with their customers. This policy explains what personal data flows through Nolmo, who is responsible for it, and how it is protected and deleted.

Last updated 13 September 2026

Who we are

Nolmo is made and operated by Nuto AS (“Nuto”, “we”), a Norwegian company. Nolmo is a multi-tenant service: many businesses (our “customers”) use the same platform, and each customer's data is kept in its own separate tenant.

Two roles

For conversations handled in Nolmo, the customer using Nolmo is the data controller. They decide which channels to connect, who on their team has access and how long cases are kept. Nuto is the data processor and acts on the customer's instructions under a data processing agreement.

For this website and our own contact with you (a demo request, an email, a sales conversation), Nuto is the data controller.

What data is processed in Nolmo

  • Conversations: messages, attachments and metadata from the channels a customer connects: email, live chat, phone notes, Google reviews, Facebook Page messages and comments, and Instagram direct messages. This includes the sender's name, profile identifier and what they wrote.
  • Context the customer chooses to connect: order and delivery information from the customer's own systems, purchase history and loyalty club membership, so the person answering can see what the enquiry is about.
  • Case data created in Nolmo: case type, priority, internal notes, replies, and the AI's classification, summary and draft replies.
  • Agent accounts: name, work email and activity in Nolmo for the customer's staff.

Data from Facebook and Instagram

When a customer connects a Facebook Page or an Instagram professional account, Nolmo receives messages and comments sent to that Page or account through Meta's APIs, along with the sender's name and identifier. Nolmo uses this data only to show the conversation to the customer's team, let them reply from Nolmo, and prepare the AI's classification and draft for that team.

  • We do not sell this data, share it with other customers, or use it for advertising.
  • We do not use it to train AI models. AI processing is done per request, on the conversation at hand, on behalf of the customer.
  • Access tokens are stored encrypted and used only to read and reply to messages for the connected Page or account.
  • When a customer disconnects a Page or account, or removes Nolmo from their Facebook settings, we stop receiving data and delete what we hold for that connection within 30 days.

Our use of Meta data follows the Meta Platform Terms and Developer Policies.

How the AI uses data

Nolmo's AI reads each case to classify it, summarise it, pull in context and write a draft reply. The draft is shown only to the customer's team; nothing is sent to a person unless a team member sends it, or the customer has explicitly turned on automatic replies for a specific case type. We use AI model providers as sub-processors under contracts that prohibit them from retaining or training on the content.

Separation between customers

Every customer has its own tenant. Conversations, contacts, knowledge and settings are stored and queried per tenant, and a user can only ever access the tenant they belong to. Staff at Nuto access customer data only to provide support the customer has asked for, or to operate the service, and such access is logged.

Where data is stored and who helps us

Nolmo runs on cloud infrastructure in the EU/EEA. We use a small number of sub-processors for hosting, email delivery and AI processing, each bound by a data processing agreement. Customers receive the current list of sub-processors as part of their agreement and are notified of changes.

How long data is kept

  • Conversations and cases: for as long as the customer's subscription is active, or shorter if the customer sets a retention period.
  • After a subscription ends: all tenant data is deleted within 30 days, unless the customer asks for an export first.
  • Backups: kept for up to 30 days and then overwritten.
  • Demo requests sent from this website: kept for up to 12 months.

Your rights

If you have written to a business that uses Nolmo, that business is responsible for your data, and you can ask them to access, correct or delete it. You can also write to us at hei@nuto.no, and we will help or pass the request on. See how to get your data deleted. You have the right to complain to the Norwegian Data Protection Authority (Datatilsynet).

This website

This website sets no tracking cookies. The demo form sends what you type to us by email through a form service and is used only to get back to you.

Contact

Nuto AS, org. no. 833663852, Maurholen 113, 4316 Sandnes, Norway. Email hei@nuto.no.