Skip to content

Legal · Updated September 2026

Privacy and data handling

NestaAI processes contact data on behalf of the agencies that use it. That makes how we handle it a product decision, not a footnote — so here it is in plain English.

Who controls the data

Your CRM remains the system of record. The agency is the data controller for every contact record; NestaAI is a processor acting on the agency’s instructions. If you disconnect NestaAI, your CRM is exactly as you left it.

What we read and write

We read contact records, enquiry history, property associations and engagement signals from your connected CRM. We write back the things an agent would otherwise type: match results, readiness scores, conversation threads and status changes.

We do not sell data, and we do not pool one agency’s contacts into a shared dataset that another agency can query.

Do Not Call Register

Contacts are checked against the Do Not Call Register before any outbound communication that falls within its scope, and the check result is recorded against the contact so it can be audited later.

Security and residency

Data is encrypted in transit and at rest, held in Australian regions, and access is scoped per agency. Credentials for CRM connections are stored encrypted and are revocable by the agency at any time.

Access to production data by our team is limited to what is required to operate the service and is logged.

Australian Privacy Principles

We build to the Australian Privacy Principles under the Privacy Act 1988, including collection limitation, use and disclosure, data quality, security, and access and correction rights for individuals whose information an agency holds.

Contact

Privacy questions, access requests and complaints: hello@nestaai.com.

This page is a plain-English summary published alongside a pre-launch product. It is not legal advice, and it will be replaced by a reviewed agreement before any customer data is processed.