Privacy Policy
FDM Maintenance Manager
Last Updated: February 2026
Owner: Nimbeely Extend Solutions Ltd.
1. Introduction
FDM Maintenance Manager (“the App”) is a Built on Workday application developed and operated by Nimbeely Extend Solutions Ltd. (“Nimbeely”, “we”, “us”, or “our”).
This Privacy Policy describes how the App processes data when used within a customer’s Workday tenant.
The App is designed to operate entirely inside Workday, using Workday’s security, data model, and platform services. Nimbeely does not extract, store, or transmit customer data outside the customer’s Workday environment unless explicitly requested by the customer for support purposes.
2. Scope of This Policy
This Privacy Policy applies to:
-
Users of the FDM Maintenance Manager application within a Workday tenant
-
Customer data processed by the App
-
Support interactions between Nimbeely and the customer
This policy does not apply to Workday’s own processing of data. Workday’s privacy practices are governed by Workday’s own agreements and policies.
3. Data Processed by the App
The App processes only the data required to support FDM governance workflows. This includes:
3.1 Data Entered by Users
-
FDM request details (e.g., component name, description, hierarchy placement)
-
Request metadata (effective dates, justification & Types )
3.2 Workday System Data Accessed
-
Workday FDM objects (e.g., cost centers, custom organizations, spend categories & revenue categories)
-
Workday supervisory and cost center hierarchies
-
Workday user and role information for routing approvals
3.3 Audit & Workflow Data
-
Request submission timestamps
-
Approval actions and comments
-
Workflow routing history
3.4 No Sensitive Personal Data
The App does not require or intentionally process sensitive personal data such as health information, financial account numbers, or government IDs.
4. How Data Is Used
The App uses customer data solely for the following purposes:
-
To create, validate, and route FDM change requests
-
To execute approved FDM object creation using Workday-native actions
-
To generate audit logs and reporting within Workday
-
To support customer-defined governance and compliance processes
The App does not use customer data for analytics, profiling, marketing, or any purpose unrelated to the operation of the App.
5. Data Storage & Retention
All data processed by the App is stored exclusively within the customer’s Workday tenant.
Nimbeely does not store, copy, or retain customer data outside Workday.
Retention is controlled by the customer through Workday’s standard data retention and archiving capabilities.
6. Data Access & Security
6.1 Workday-Native Security
The App uses Workday’s security model, including:
-
Domain and business process security policies
-
Role-based access controls
-
Workday authentication and session management
No additional authentication or external access is required.
6.2 Nimbeely Access
Nimbeely does not have access to customer data unless:
-
The customer explicitly grants temporary access for support
-
The customer provides anonymized data for troubleshooting
Any access is time-bound, logged, and governed by the customer’s Workday security policies.
7. Data Sharing & Transfers
Nimbeely does not:
-
Sell customer data
-
Share customer data with third parties
-
Transfer customer data outside the Workday environment
The App does not integrate with external systems unless the customer configures such integrations independently.
8. Customer Responsibilities
Customers are responsible for:
-
Configuring Workday security roles and approvals
-
Ensuring appropriate access controls for users of the App
-
Managing data retention policies within Workday
-
Providing accurate information in FDM requests
9. Subprocessors
The App runs entirely on the Workday platform.
Nimbeely does not use any subprocessors to store or process customer data.
Workday’s own subprocessors are governed by the customer’s Workday agreement.
10. Support & Incident Management
If a customer reports an issue:
-
Nimbeely may request temporary access to logs or configuration
-
Customers may provide anonymized data where possible
-
Any incident involving customer data will be communicated promptly to the customer’s designated contact
Nimbeely maintains internal procedures for secure handling of customer information during support.
11. Compliance
The App is designed to support customer compliance with:
-
SOX and internal control frameworks
-
Audit requirements for FDM governance
-
Workday security and data protection standards
Nimbeely adheres to industry-standard security and privacy practices appropriate for Workday Marketplace partners.
12. Changes to This Policy
Nimbeely may update this Privacy Policy to reflect improvements to the App or changes in regulatory requirements.
Customers will be notified of material changes through their designated contact or via Marketplace updates.
13. Contact Information
For privacy or security inquiries, customers may contact:
Nimbeely Extend Solutions Ltd.
Email: privacy@nimbeely.com
