We take your privacy seriously. This Policy explains what information we collect when you use the NAS Platform, how we use it, and the choices you have. It applies to all Platform users — nonprofit organizations, institutional funders, and practice consultants.
Article 1Scope & Applicability
1.1 This Privacy Policy ("Policy") governs the collection, use, storage, sharing, and protection of Personal Information submitted to or generated through the NAS Platform, including all web-based portals, APIs, email communications, and related services operated by MONK3Y Studio LLC.
1.2 This Policy applies to all categories of Platform users, including nonprofit organization clients, institutional funder clients, practice consultant clients (also referred to as Partners in NAS marketing materials), operator and analyst accounts managed by MONK3Y Studio LLC, and any individual who submits information through public-facing application and signup pages.
1.3 This Policy does not govern the data practices of any third-party platform, service, or application linked to or integrated with the Platform. You are solely responsible for reviewing the privacy policies of such third parties.
1.4 This Policy is incorporated by reference into the NAS Platform Terms of Service.
↑ Back to contents
Article 3How We Use Your Information
We use collected information for the following purposes:
- Account Management — creating and verifying accounts, authentication, membership status management, and order fulfillment.
- Platform Operation — generating and delivering Reports, tracking SignalPoint credit balances, and managing case workflows.
- Communications — magic-link login emails, order confirmations, status updates, support responses, and operational announcements.
- Billing & Payments — processing fees, maintaining transaction records, and complying with financial record-keeping obligations.
- Legal & Compliance — complying with applicable law, enforcing our Terms, protecting rights and safety, and detecting fraud or unauthorized access.
- Platform Improvement — analyzing usage patterns, diagnosing errors, and improving functionality and security, primarily on aggregated or de-identified data.
- AI-Assisted Processing — certain features, including report generation, involve AI systems. Information you submit may be processed by these systems to produce your requested outputs. See Article 7.
We do not sell, rent, or trade your Personal Information to third parties for their independent marketing or commercial purposes.
We do not use your Personal Information to train generalized AI models made available outside our organization, except with your explicit written consent.
↑ Back to contents
Article 4Disclosure of Your Information
4.1 Service Providers. We share data with vetted third-party providers who process data on our behalf, including payment processors (Stripe), email delivery providers (Resend), cloud infrastructure providers, AI platform providers, and analytics providers. All such providers operate under contractual data protection obligations.
4.2 White-Label Consultants. If you access the Platform through a Consultant's white-label portal, NAS may share account metadata, case metadata, and Report delivery status with that Consultant for order fulfillment. The Consultant has agreed to data handling obligations under the Terms of Service.
4.3 Legal Obligations & Safety. We may disclose information without notice when required to comply with applicable law, legal process, or governmental request; to enforce our Terms; or to protect the rights, property, or safety of the Company, our clients, or the public.
4.4 Business Transfers. In the event of a merger, acquisition, or asset sale, Personal Information may transfer to the successor entity with prior notice and the opportunity to close your account before new privacy terms apply.
4.5 Aggregate & De-Identified Data. We may share aggregate or anonymized data that does not identify any individual or organization for research, benchmarking, or business development purposes.
4.6 No Sale of Personal Data. We do not sell Personal Information as defined under applicable state privacy laws, including the CCPA/CPRA.
↑ Back to contents
Article 5Data Retention
We retain Personal Information for as long as your account is active and for additional periods necessary to fulfill legal, regulatory, and contractual obligations.
| Data Type |
Retention Period |
| Account records, billing history, case/report data |
Duration of account + 7 years following closure |
| Authentication and login event logs |
Rolling 12 months |
| Encrypted backup systems |
Up to 90 days after deletion from primary systems |
You should maintain your own copies of all Reports and submitted materials, as we cannot guarantee indefinite access to historical data.
↑ Back to contents
Article 6Data Security
We implement commercially reasonable safeguards including:
- TLS 1.2+ encryption for all data in transit
- Encryption of sensitive fields at rest
- Passwordless (magic-link) authentication — eliminating password-based credential theft risks
- Role-based access controls limiting internal data access to what is necessary for each function
- Regular security reviews and vulnerability assessments
NO METHOD OF ELECTRONIC TRANSMISSION OR STORAGE IS COMPLETELY SECURE. WE CANNOT GUARANTEE ABSOLUTE SECURITY OF YOUR PERSONAL INFORMATION. IN THE EVENT OF A SECURITY INCIDENT, WE WILL NOTIFY AFFECTED USERS AS REQUIRED BY APPLICABLE LAW.
You are responsible for securing your email account, through which magic-link login credentials are delivered. Report suspected unauthorized access immediately to legal@npastudio.com.
↑ Back to contents
Article 7Artificial Intelligence Disclosure
7.1 The NAS Platform uses artificial intelligence systems — including large language models, data analysis models, and automated research tools — in the generation, synthesis, and presentation of Reports and analytical outputs.
7.2 When you submit case information or documents to the Platform, portions of that information may be transmitted to third-party AI providers under confidentiality obligations for the purpose of generating your requested output.
7.3 We contractually require AI providers to: (a) process your data solely to generate your requested output; (b) not use your data to train publicly available AI models; and (c) maintain data security and confidentiality standards consistent with this Policy.
7.4 AI-generated outputs are not infallible. Reports may contain errors, omissions, or outdated information and are provided "as is" for informational purposes only. Certain Reports undergo human analyst review before delivery; this review does not guarantee accuracy and does not create a professional advisory relationship.
↑ Back to contents
Article 8Cookies & Tracking
8.1 The Platform uses session cookies to maintain authenticated sessions and provide core platform functionality. These are strictly necessary and cannot be disabled without impairing your ability to use the Platform.
8.2 We may use analytics technologies to collect aggregate usage data for platform improvement. Where required by applicable law, we will seek consent before deploying non-essential cookies.
8.3 We do not use third-party advertising cookies or cross-site behavioral tracking technologies.
8.4 You may configure your browser to refuse cookies, but doing so may prevent use of the Platform. Session-based authentication requires functional cookies to operate.
↑ Back to contents
Article 9Non-Reliance on Reports
THE INFORMATION AND REPORTS PROVIDED THROUGH THE PLATFORM ARE FOR INFORMATIONAL PURPOSES ONLY AND DO NOT CONSTITUTE LEGAL, FINANCIAL, INVESTMENT, ACCOUNTING, REGULATORY, OR ANY OTHER PROFESSIONAL ADVICE. NO ATTORNEY-CLIENT, FIDUCIARY, OR ADVISORY RELATIONSHIP IS CREATED BY YOUR USE OF THE PLATFORM OR RECEIPT OF ANY REPORT.
All decisions made in reliance on Reports are made solely at your own risk and discretion. The Company is not responsible for any outcome, consequence, loss, or liability arising from your reliance on any Platform output. Reports are prepared solely for the internal use of the ordering client — no third party may rely on them.
↑ Back to contents
Article 10Your Privacy Rights
Depending on your jurisdiction, you may have the following rights:
- Access — Request confirmation of whether we process your information and obtain a copy.
- Correction — Request correction of inaccurate or incomplete information.
- Deletion — Request deletion of your Personal Information, subject to legal retention obligations (Article 5).
- Restriction — Request restriction of processing in certain circumstances.
- Data Portability — Where technically feasible and legally required, receive your information in a machine-readable format.
- Opt-Out of Sale — We do not sell Personal Information. If our practices change, we will update this Policy and provide opt-out mechanisms as required by law.
- Non-Discrimination — We will not discriminate against you for exercising your privacy rights.
To exercise any of these rights, submit a written request to legal@npastudio.com. We will respond within the timeframe required by applicable law and may require identity verification.
California Residents (CCPA/CPRA): MONK3Y Studio LLC is a "business" under the CCPA. We do not sell or share Personal Information for cross-context behavioral advertising. To submit a CCPA rights request, contact legal@npastudio.com.
EEA/UK Residents: The Platform does not actively market to EEA or UK users. If you access it from those jurisdictions, you may have additional rights under the GDPR or UK GDPR. Contact us to learn more.
↑ Back to contents
Article 11Children's Privacy
The Platform is not directed to individuals under the age of 18. We do not knowingly collect Personal Information from minors. If you believe we have inadvertently collected such information, contact us immediately at legal@npastudio.com and we will promptly delete it.
↑ Back to contents
Article 12Required Acceptance Before Ordering
No Report or other paid work product may be ordered through the Platform without the ordering account's affirmative, recorded acceptance of both the Terms of Service and this Privacy Policy then in effect.
A record of your acceptance — including timestamp, document version, and account identifier — is retained by the Company and constitutes a binding agreement between you and the Company.
This mechanism ensures you are fully informed of your rights and our data practices before submitting sensitive organizational data in connection with a Report request.
↑ Back to contents
Article 13Changes to This Policy
We may modify this Policy at any time. Material changes will be communicated via email to the address on file and/or by prominent Platform notice.
Your continued use of the Platform following the effective date of any updated Policy constitutes acceptance of the revised terms. If you do not agree to a revised Policy, you must discontinue use and contact us to initiate account closure.
↑ Back to contents
Article 14Contact Information
Questions, privacy rights requests, or reports of suspected data security incidents:
MONK3Y Studio LLC — Privacy Officer
For legal notices, use the contact information specified in the Terms of Service.
↑ Back to contents
Article 15Governing Law
This Policy is governed by the laws of the State of New York, without regard to its conflict-of-law provisions. Any disputes arising under or relating to this Policy shall be subject to the dispute resolution provisions set forth in the Terms of Service.
↑ Back to contents