Nodiris

Privacy Policy

Nodiris ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains what information we collect, how we use it, how we store it, and the rights available to you under applicable regulations. By using our website or services (the "Site" and the "Service"), you agree to the practices described in this Privacy Policy.

1. Information We Collect

We may collect and process the following categories of data:

1.1. Website Visitors (non-customers)

We collect only the data necessary for the operation, security, and performance of our Site:

Server logs and HTTP request data, including:
IP address
Browser type and version
Device information
Pages visited, time and date of visit
Referrer URL
Error logs
Email address, if you subscribe to our newsletter.

1.2. Customers & Users of Our Service

When you subscribe to Nodiris via Stripe or use our platform, we collect:

Email address
Company name
Company website URL
Service usage logs, including HTTP requests made to our API or platform
Account configuration data
Billing information, which is processed securely by Stripe (we do not store credit card numbers)

We do not collect sensitive personal data as defined under GDPR.

2. How We Use Your Information

We use the information we collect to:

2.1. Operate the Site and Service

Enable the delivery of our Service and platform features
Authenticate access
Maintain performance and detect technical issues
Ensure security and prevent abuse

2.2. Manage Customer Accounts

Handle subscriptions and billing (via Stripe)
Provide customer support
Send essential operational emails (account notifications, billing, service updates)

2.3. Communications (optional)

With your consent:

Send you product updates, news, and marketing emails

2.4. Analytics & Improvements

Analyze aggregated traffic and usage patterns
Improve our product experience and website performance

We never sell or rent your data to third parties.

3. Legal Basis for Processing (GDPR)

We process your personal data based on:

Contractual necessity: to provide our Service to paying customers
Legitimate interest: for security, fraud prevention, and analytics
Consent: for newsletter subscriptions or marketing communications
Legal obligations: financial and accounting compliance related to Stripe

4. Data Retention

Server and HTTP logs: retained for security and diagnostic purposes for up to 12 months (unless required longer for fraud/security investigations).
Customer account data: retained for the duration of the subscription and up to 6 years thereafter for legal/accounting compliance.
Email addresses for newsletters: retained until you unsubscribe or request deletion.
Analytics data: aggregated and anonymized; may be kept indefinitely.

5. Sharing of Information

We only share your data with trusted third-party providers essential to our operations:

AWS (Amazon Web Services): hosting and infrastructure
Stripe: payment processing and billing
Email service providers (e.g., transactional email sending)
Analytics or monitoring tools, processing anonymized or aggregated data

These providers act as "data processors" and are contractually obligated to protect your information and process it only according to our instructions.

We do not share your data for advertising or commercial resale.

6. International Data Transfers

Some of our service providers (e.g., AWS or Stripe) may process data outside the EU/EEA.

When this occurs, transfers are protected through:

Adequacy decisions (e.g., EU–US Data Privacy Framework), or
Standard Contractual Clauses (SCCs)

7. Data Security

We use industry-standard technical and organizational security measures to protect your data, including:

Secure hosting on AWS
Encryption in transit (HTTPS)
Access controls and authentication
Monitoring and logging

No method of transmission over the Internet is 100% secure, but we continually improve our security practices.

8. Your Rights (GDPR, UK GDPR, CCPA)

You have the right to:

Access the personal data we hold about you
Request correction of inaccurate data
Request deletion ("right to be forgotten")
Object to certain processing
Withdraw consent at any time for optional communications
Request data portability in a structured format

To exercise your rights, please contact: contact@nodiris.ai

If you believe your data is misused, you may lodge a complaint with your local data protection authority (CNIL in France).

9. Children's Privacy

Our Site and Service are not intended for individuals under 16.

We do not knowingly collect data from children. If you believe a child has provided personal data, please contact us for deletion.

10. Changes to This Privacy Policy

We may update this Privacy Policy from time to time.

Changes will be posted on this page with an updated "Last updated" date.

Continued use of our Site or Service after changes indicates acceptance of the updated Policy.

11. Contact Us

If you have any questions about this Privacy Policy or our data practices, you can contact us at:

Email: contact@nodiris.ai

Company: Nodiris

Website: https://nodiris.ai