Back to home
Legal

Privacy Policy

Last updated: 4 June 2026

This policy explains how Nedora (“we”, “us”) processes personal data when you use nedora.co, including when you submit a project request. We are an enterprise software company based in Bucharest, Romania, and we process data in line with the EU General Data Protection Regulation (GDPR) and applicable Romanian law.

1. Who is responsible for your data

The data controller is Nedora, based in Bucharest, Romania. For privacy-related questions or to exercise your rights, contact us using the details at the end of this policy.

2. Data we collect

We collect only what we need to operate the website and respond to enquiries.

  • Contact form: first name, last name, work email, company name, project type, engagement model, timeline, and your message.
  • Technical data: IP address, browser type, device information, and similar logs generated when you visit the site (via our hosting provider).
  • Communication data: the content of emails or messages you send us, and our replies.

3. Why we use your data

We process personal data for the following purposes and legal bases under the GDPR:

  • To respond to your project request and follow up on a potential engagement (legitimate interest, and steps prior to a contract at your request).
  • To operate, secure, and improve our website (legitimate interest).
  • To comply with legal obligations, such as record-keeping where required by law (legal obligation).
  • For newsletter or marketing communications only where you have given explicit consent (consent). We do not subscribe you to marketing from the contact form alone.

4. How long we keep data

Project enquiries are kept for as long as needed to handle your request and any resulting business relationship, then archived or deleted according to our internal retention schedule.

Technical logs are retained for a limited period appropriate for security and troubleshooting, typically no longer than 90 days unless a longer period is required to investigate an incident.

5. Who we share data with

We do not sell your personal data. We use trusted service providers who process data on our instructions and under appropriate agreements:

  • Supabase (database and authentication infrastructure) — stores contact and project request records for our internal CRM.
  • Vercel (website hosting) — may process technical and request logs.
  • Resend or similar email providers — used to send operational notifications to our team, where configured.

6. International transfers

Some providers may process data outside the European Economic Area. Where that applies, we rely on appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms recognised under the GDPR.

7. Your rights

Depending on your location, you may have the right to access, rectify, erase, restrict, or object to processing of your personal data, and to data portability where applicable. Where processing is based on consent, you may withdraw consent at any time without affecting the lawfulness of processing before withdrawal.

You also have the right to lodge a complaint with the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) or your local supervisory authority.

8. Security

We apply technical and organisational measures appropriate to the nature of the data we hold, including access controls, encryption in transit, and restricted internal access to CRM data.

We follow an encryption-by-default strategy: personal data is protected whenever it is stored or handled in our systems. Within our internal tools, personal information is hidden by default and is only revealed to authorised team members when required for a legitimate business purpose.

9. Cookies

Our marketing site uses essential cookies and similar technologies required for basic operation, security, and locale preferences. We do not use advertising or third-party tracking cookies on this site. If that changes, we will update this policy.

10. Changes to this policy

We may update this policy from time to time. The “last updated” date at the top reflects the current version. Material changes will be posted on this page.

Privacy enquiries

For questions about this policy or to exercise your data protection rights, email us at:

privacy@nedora.co