Nodiq.euThe Intelligence Node for Your Business

Privacy Policy

Last updated: September 2026 · Compliant with GDPR (EU Regulation 2016/679)

1. Data Controller

NICOMM TEAM SRL

CUI: RO18593040

Trade Registry No.: J40/6412/2006

Registered address: Bucharest, Str. Toamnei 36A, Sector 2, Romania

Platform: nodiq.eu

Email: contact@nodiq.eu

2. Data We Collect

CategoryDataPurpose
AccountEmail, name, company, WhatsAppAccount creation, authentication, contact
Phone numberPhone number (verified via SMS code at registration)Preventing abusive multiple-account creation (free plan)
Company data (billing)Tax ID, trade registry number, registered address (only for business invoicing)Issuing tax invoices
PaymentsTransaction history, purchased plansBilling, support
UsageCredits consumed, work sessionsService operation
Uploaded filesPDF, DOCX, XLSX, images, audio, video (temporary, during processing only)AI processing — deleted immediately after
Extracted data (Smart Docs)Structured data extracted from your documents (may include data of third parties mentioned in documents, e.g. contractual partners)Work session — deleted on download or automatically after 30 days of inactivity
Glossary termsDomain-specific terms added by the userImproving translation consistency
Job historyMarket Intelligence queries (entered text), SEO and Market analysis results, generated Ads campaignsService operation, access to personal history
Connected social accountsOAuth access token for the connected account (YouTube, Facebook, Instagram, LinkedIn, Pinterest), account name/IDPublishing content on your behalf, at your request
Content safety screeningEmail, name, phone — logged ONLY if a submitted file/text is automatically flagged as possibly dangerous contentAbuse prevention, legal compliance (see section 10)

3. Legal Basis for Processing

  • Contract performance — to provide purchased services (Art. 6(1)(b) GDPR)
  • Consent — for marketing communications if you opted in (Art. 6(1)(a) GDPR)
  • Legal obligation — for financial record retention (Art. 6(1)(c) GDPR)
  • Legitimate interest — for automated screening of submitted content, abuse and fraud prevention, platform security (Art. 6(1)(f) GDPR)

4. Third Parties and Sub-processors

Supabase Inc.

Database & authentication · USA (SCCs)

Privacy →

Google LLC (Gemini API)

AI content processing · USA (SCCs)

Privacy →

Google LLC (PageSpeed Insights)

Website speed analysis (SEO Optimizer) — receives the analyzed site's URL, no personal data · USA (SCCs)

Privacy →

Stripe Inc.

Payment processing · USA (SCCs)

Privacy →

Vercel Inc.

Frontend hosting · USA (SCCs)

Privacy →

Railway Corp.

Backend API hosting · USA (SCCs)

Privacy →

Serper.dev

Google Search (Market Intelligence) — receives product keywords, no personal data · USA (SCCs)

Privacy →

Scrape.do

Marketplace price scraping (Market Intelligence) — receives product URLs, no personal data · USA (SCCs)

Privacy →

Bright Data Ltd.

Proxy for price scraping (Market Intelligence, fallback) — receives product URLs, no personal data · Israel/USA (SCCs)

Privacy →

Twilio Inc.

Sending SMS phone verification codes at registration · USA (SCCs)

Privacy →

Resend

Sending transactional emails (contact, account notifications) · USA (SCCs)

Privacy →

ConvertAPI / CloudConvert / PDF.co

Document format conversion (Smart Translator) — receive document content during conversion, do not store it permanently · EU/USA (SCCs)

Privacy →

Spotify AB

Audio features (Social Media Content Generator) — only if you provide a Spotify link · EU (Suedia)

Privacy →

Meta Platforms Inc. (Facebook/Instagram)

Publishing content to your Facebook/Instagram account — only if you explicitly connect it · USA (SCCs)

Privacy →

Google LLC (YouTube Data API)

Publishing video to your YouTube channel — only if you explicitly connect it · USA (SCCs)

Privacy →

LinkedIn Corporation

Publishing content to your LinkedIn account — only if you explicitly connect it · USA (SCCs)

Privacy →

Pinterest Inc.

Publishing content to your Pinterest account — only if you explicitly connect it · USA (SCCs)

Privacy →

SCCs = EU Standard Contractual Clauses for international data transfers.

5. Data Retention

  • Account data is retained for the duration of the contractual relationship and 3 years after account closure.
  • Financial data (invoices, payments) is retained for 10 years per Romanian tax law.
  • Files uploaded for processing are deleted immediately after the operation completes.
  • Glossary terms (Smart Translator module) are retained for the lifetime of the account and deleted upon user request or account closure.
  • Job history (Market Intelligence, SEO Optimizer, Ads) — entered queries and analysis/campaign results — is retained for the lifetime of the account and deleted with it.
  • Data extracted from documents (Smart Docs work session) is deleted automatically upon downloading the result, or, if you never download it, automatically after 30 days of inactivity.
  • Phone verification codes (OTP) are retained in hashed form for a maximum of 10 minutes and are not reused afterward.
  • Tokens for connected social accounts (YouTube, Facebook, Instagram, LinkedIn, Pinterest) are retained as long as the account stays connected and are deleted immediately upon disconnection, at your request from the dashboard.
  • Content safety screening records (created only when possibly prohibited content is detected) are retained for 3 years, to prevent repeated abuse and for potential legal compliance obligations.

6. Your GDPR Rights

🔍 Access

Right to request a copy of your data

✏️ Rectification

Right to correct inaccurate data

🗑️ Erasure

Right to request data deletion

⏸️ Restriction

Right to restrict processing

📦 Portability

Right to receive data in structured format

🚫 Objection

Right to object to processing

To exercise your rights or withdraw consent, contact us at contact@nodiq.eu. We will respond within 30 days.

You have the right to lodge a complaint with the National Supervisory Authority for Personal Data Processing (ANSPDCP): www.dataprotection.ro

7. Cookies

The platform uses strictly necessary session cookies for authentication and proper functioning. We do not use tracking or advertising cookies without your explicit consent.

8. Security

We implement appropriate technical and organizational measures to protect data: encrypted HTTPS connections, secure authentication, role-based access, and continuous monitoring. However, no internet transmission method is 100% secure.

9. Policy Changes

We may update this policy periodically. Significant changes will be communicated by email at least 14 days before taking effect.

10. Automated Content Screening

All files, texts, and URLs you submit for processing are automatically analyzed by an AI system to identify exclusively explicitly dangerous content: illegal drugs, terrorism, violence, child exploitation, illegal weapons, pornography. The system does not analyze or block ordinary medical, legal, journalistic, or business content.

If content is flagged, we log your account data (email, name, phone) together with the detected threat type, in a record accessible exclusively to platform administrators — not visible to other users. Upon accumulation of repeated flags, the account may be automatically suspended.

You have the right to contest an automated suspension and request human intervention by contacting us at contact@nodiq.eu. We will manually review the decision and inform you of the outcome.

11. Connected Social Media Accounts

The Social Media Content Generator module lets you optionally connect YouTube, Facebook, Instagram, LinkedIn, and Pinterest accounts to publish generated content directly. Connection is done via OAuth authentication — we never see or store your password for those platforms.

We store the access token (and, where the platform provides one, a refresh token) needed to publish on your behalf, along with the connected account's name/ID. This data is accessible only to our system and the relevant third-party platform — we do not share it with other third parties.

You can disconnect an account at any time from the module's dashboard — the associated token is immediately deleted from our system. Disconnecting does not affect your account on the third-party platform, only the access you granted us.