Skip to content
Trust Center

Data Protection at Nitro

Nitro is committed to protecting personal and business data across all our products and services. Our data protection program ensures that your information is handled in accordance with global privacy regulations, including EU/EEA and UK GDPR, US privacy laws like CCPA, HIPAA, and other regional frameworks.

man looking at tablet

Data protection around the world

Nitro is committed to protecting personal data globally and complies with international privacy laws and evolving regulations. We value the privacy of our customers, partners, and users, and implement initiatives to safeguard personal information in every region we operate. This includes adherence to regulations such as GDPR in the EU and UK, CCPA in the United States, HIPAA for healthcare data, and regional frameworks in Australia, Switzerland, Singapore, and Hong Kong.

Our global approach ensures that data protection principles are applied consistently, helping organizations maintain compliance while using Nitro products and services.

Europe

Nitro complies with the EU and UK General Data Protection Regulation (GDPR) and takes a proactive approach to data privacy. We continuously monitor the European regulatory landscape, including eIDAS (electronic identification and trust services) and PECR (Privacy and Electronic Communications Regulations), to ensure we uphold the highest standards for protecting personal data.

USA

Nitro adheres to key data protection legislations in the United States, including the California Consumer Privacy Act (CCPA), HIPAA and HITECH act, and the Fair Credit Reporting Act (FCRA). Our compliance program ensures that personal, financial, and health information is processed securely, giving organizations confidence in their use of Nitro solutions.

Australia

Nitro complies with Australia’s Electronic Transactions Act (ETA) and Corporation Act, maintaining lawful and secure handling of personal and business data. Our initiatives align with Australian privacy principles, helping organizations meet regulatory obligations while safeguarding information across Nitro products and services.

How does Nitro process personal data?

Nitro processes personal data in accordance with applicable privacy laws and industry best practices, tailored to the specific products and services you use. The types of data processed may include contact information, account details, usage data, and documents, each with defined retention periods based on legal, regulatory, and operational requirements.

We provide transparency by offering a detailed overview of data categories, processing purposes, and retention timelines, allowing customers to understand how their information is managed securely and responsibly.

woman using mobile device

How can I delete my data or request more information on how Nitro processes my data?

icon of data

Data subject access request

You have the right to request more information from Nitro on how we process your personal data. Fill in the form and our DPO Office will follow up on your request.
Submit a request
icon of rotating gears

Subprocessors and subcontractors

Nitro engages subprocessors and subcontractors for different features and functionality within our solutions. For a full overview, visit our subprocessors page.
View subprocessors & subcontractors

Cookie Policy

Cookie Policy defines what cookies are for Nitro and how they are used on our website(s). Nitro’s website(s) uses cookies and similar technologies for operation.
See Cookie Policy woman using tablet

CCPA

Learn more about the California Consumer Privacy Act.
Learn about CCPA man using mobile device

Explore Our Tips, Tricks, & Tutorials

Stay on top of the latest trends in PDF and esignature software.

How does Nitro protect personal data?

Nitro implements technical, organizational, and administrative measures to safeguard personal and business data across all products and services.

This includes encryption, access controls, secure storage, monitoring, and employee training to ensure that data is processed securely and in compliance with global privacy regulations.

Which privacy laws does Nitro comply with?

Nitro complies with major international privacy regulations, including:
  • GDPR (European Union and UK)
  • CCPA (California, USA)
  • HIPAA  and HITECH (USA healthcare data)
  • Electronic Transactions Act (ETA) and Corporation Act (Australia)
  • Regional frameworks in Switzerland, Singapore, and Hong Kong

What types of personal data does Nitro process?

The types of personal data Nitro processes depend on the products and services used.

Examples include contact information, account details, documents, and usage data. Nitro applies retention periods and security measures appropriate to the type of data and regulatory requirements.

How long does Nitro retain personal data?

Retention periods vary based on product, service, and legal obligations.

Nitro provides transparency regarding retention timelines, ensuring that data is stored only as long as necessary for legitimate purposes and deleted securely afterward.

How can I exercise my rights as a data subject?

Customers and users can exercise their rights under the General Data Protection Regulation (GDPR), including the rights to access, rectify, erase, restrict, and object to the processing of their personal data, as well as the right to data portability. These requests can be submitted through Nitro’s Data Subject Request (DSR) process.

All requests are managed by Nitro’s Data Protection Officer (DPO) Office, ensuring that each inquiry is handled promptly, transparently, and in full compliance with applicable data protection laws.

Does Nitro share personal data with third parties?

Nitro engages subprocessors and subcontractors to deliver specific features and services. All subprocessors are carefully vetted and contractually bound to comply with data protection regulations and Nitro’s security standards. A full list of subprocessors is publicly available.

How does Nitro handle cross-border data transfers?

Nitro relies on established data transfer mechanisms, including DPF and Standard Contractual Clauses (SCCs), to ensure that personal data shared across borders is protected in accordance with applicable privacy laws.

In addition, Nitro adheres to international frameworks such as the EU–U.S. Data Privacy Framework, including its U.K. and Swiss extensions, to provide strong and consistent safeguards for the protection of personal data transferred internationally.

How does Nitro stay up-to-date with evolving data protection laws?

Nitro actively monitors global regulatory developments, updates internal policies, trains employees, and conducts regular audits.

This ensures that products and services remain compliant as privacy laws and standards evolve worldwide.

How does Nitro ensure privacy by design and by default?

Nitro embeds privacy into its secure software development lifecycle (SSDLC), ensuring that data minimization, access controls, and security measures are implemented from the start.

Users have control over their personal data, and all processing activities are designed to protect privacy.

How can customers verify Nitro’s data protection practices?

Nitro provides transparent documentation through its Trust Resources. Customers can review  security whitepapers to understand how Nitro protects personal data.

See what Nitro can do for you

Take the next step to digital success today.

Icon-48px-Rapid Support

Contact sales

Talk to our experts about your business needs, and explore cost-effective options for Nitro's world-class PDF and eSign solutions.
Get in touch
Icon-48px-Smart signing

Free trial

Try Nitro’s PDF and eSign solutions to edit, sign, and organize documents effortlessly—free for 14 days!
Start your free trial
icon of people with a plus sign

Become a partner

Learn about our exciting partner opportunities for Nitro's trusted document solutions.
Partner with Nitro today