nadicode Privacy Policy

In vigore dal 26 settembre 2026

1. Controller identity and contact

The data controller for the personal data described in this Privacy Policy is:

NADICODEAI S.R.L. Registered in Romania, trade register number J2026030859009, tax identification code (CUI) 54659885, VAT number RO54659885. Registered office: Calea Circumvalațiunii 43, Timișoara, Romania. Italian contact address: Via Astolfo Lunardi 23, 25124 Brescia, Italy.

General contact: sales@nadicode.ai.

2. Privacy contact and DPO status

NADICODEAI S.R.L. has not appointed a Data Protection Officer. This decision follows a documented assessment of the Article 37 GDPR appointment criteria, recorded in legal/dpo-assessment.md, which concluded that none of the mandatory triggers (core activity consisting of large-scale regular and systematic monitoring, or large-scale processing of special categories of data) apply to the company's current processing activities.

For all privacy questions, requests, or complaints, contact sales@nadicode.ai.

3. Scope

This Privacy Policy covers personal data that NADICODEAI S.R.L. processes as controller about users of the portal (portal.nadicode.ai) and the marketing site (nadicode.ai): the people who create accounts, sign in, administer organizations, and browse the marketing site.

It does not cover the business data that a customer's Agents operating inside Nadia process in the course of performing that customer's tasks. NADICODEAI S.R.L. processes that data as a processor, on the customer's documented instructions, under the terms of the Data Processing Agreement agreed with each customer. That processing is out of scope for this Privacy Policy; it is governed by the Data Processing Agreement and by the customer's own privacy notice to its data subjects.

4. Categories of personal data

NADICODEAI S.R.L. processes the following categories of personal data:

  • Identity and account data: user name, email address, and (if the user signs in with Google) the Google account identifier.
  • Authentication credentials: for users who sign in with email and password, a salted hash of the password (never the password itself); and, where a user enables two-factor authentication, the user's two-factor authentication secret and backup recovery codes.
  • Company data: the organization name, which the portal derives from the verified domain of the first signing-up user's email address rather than collecting it as a field entered at account creation..
  • Billing data: billing email address; billing and payment transaction data held by Stripe (see Section 7).
  • Usage and metering data: Member-account usage observations, current Included and Extra Usage balances, and the related billing ledger, kept for billing and fair-use enforcement. Each member account's shared key does not attribute model cost to an individual Agent. NADICODEAI S.R.L. is the controller of this account and billing data.
  • Nadia connection data: when a user approves a Nadia deployment through the Portal, its device information, the approving user and browser session, and the connection approval and disconnection records.
  • Email-domain data: the domain of the user's email address, used to match colleagues to the same company account.
  • Acceptance records: when a person accepts the Terms of Service at signup, their account identifier and email address, the version of the Terms, the time of acceptance and of their confirmation of the email link, whether they specifically approved the onerous clauses, and the IP address and browser from which they accepted.
  • Technical and log data: session and authentication cookies (see the Cookie Policy), IP address, browser and device information, and server access logs generated by ordinary use of the portal and marketing site.

5. Purposes and legal bases

Activity
Account creation and authentication
Purpose
Creating and operating the user's portal account, signing the user in, maintaining sessions
Legal basis
Article 6(1)(b) GDPR, performance of a contract
Credential verification and two-factor authentication
Purpose
Verifying the user's password and, where enabled, a second authentication factor, to secure account access
Legal basis
Article 6(1)(b) GDPR, performance of a contract, and Article 6(1)(f) GDPR, legitimate interest in the security of the service
Nadia connection approval
Purpose
Approving a deployment to connect Nadia to the user's member account within a Customer company
Legal basis
Article 6(1)(b) GDPR, performance of a contract, and Article 6(1)(f) GDPR, legitimate interest in the security of the service
Usage metering and fair-use enforcement
Purpose
Recording each member account's usage against its own Included Usage Allowance and Extra Usage balance, billing for it, and enforcing fair use
Legal basis
Article 6(1)(b) GDPR, performance of a contract, and Article 6(1)(f) GDPR, legitimate interest in fair-use enforcement and preventing abuse
Company identity and email-domain matching
Purpose
Correctly attributing users to their company account in a B2B context; preventing account misuse or misattribution
Legal basis
Article 6(1)(b) GDPR, performance of a contract, and Article 6(1)(f) GDPR, legitimate interest in correct B2B account attribution and fraud prevention
Billing and invoicing
Purpose
Issuing invoices, processing payments, keeping statutory accounting records
Legal basis
Article 6(1)(b) GDPR, performance of a contract, and Article 6(1)(c) GDPR, compliance with a legal obligation (statutory retention)
Service emails
Purpose
Sending account, security, and service-related communications necessary to operate the portal
Legal basis
Article 6(1)(b) GDPR, performance of a contract
Evidence of contract acceptance
Purpose
Keeping proof of who accepted which version of the Terms of Service for the Customer, and of the specific approval of its onerous clauses, to establish, exercise or defend legal claims
Legal basis
Article 6(1)(b) GDPR, performance of a contract, and Article 6(1)(f) GDPR, legitimate interest in proving the contract and its terms
Marketing communications
Purpose
Telling business contacts about nadicode's services, where nadicode does so, with a way to object in every message
Legal basis
Article 6(1)(f) GDPR, legitimate interest in business-to-business marketing
Security and abuse prevention
Purpose
Detecting, preventing, and responding to fraud, abuse, and security incidents
Legal basis
Article 6(1)(f) GDPR, legitimate interest in the security of the service

6. Legitimate interests statement

Where NADICODEAI S.R.L. relies on Article 6(1)(f) GDPR (legitimate interest), the following interests apply:

  • Company identity and email-domain matching: NADICODEAI S.R.L. has a legitimate interest in ensuring that portal accounts are correctly attributed to the right business customer, so that access, billing, and support are accurate, and so that one company's users are not mistakenly or fraudulently mixed with another's.
  • Security and abuse prevention: NADICODEAI S.R.L. has a legitimate interest in protecting the portal, its customers, and its infrastructure from unauthorized access, fraud, and abuse.

In each case, this interest is balanced against the data subject's rights and expectations: the data involved is limited to what is necessary for the stated purpose, users are informed through this Privacy Policy, and users can exercise the rights described in Section 10.

7. Recipients and processors

NADICODEAI S.R.L. shares personal data with the following categories of recipients, each acting under a data processing agreement unless stated otherwise:

  • Vercel (hosting provider for the portal and marketing site).
  • Neon (database provider).
  • Stripe (payment processing). Stripe has a dual role: it acts as a processor for NADICODEAI S.R.L. when executing payment transactions, and as an independent controller for its own fraud prevention, KYC, and regulatory compliance processing. See Stripe's own privacy policy for that independent processing: https://stripe.com/privacy.
  • Google (sign-in authentication, when a user chooses to sign in with a Google account).

The account, billing, and website data covered by this Privacy Policy is not sent to AI inference providers. OpenRouter and the downstream model providers process only customer content routed through a customer's Agents, as sub-processors under the Data Processing Agreement (see Section 3, Scope).

A full, current list of subprocessors, including their role and location, is maintained in legal/subprocessors.md.

8. International transfers

Personal data is processed within the following framework of safeguards:

  • Neon: the database instance used by NADICODEAI S.R.L. is hosted in the EU region aws-eu-central-1 (Frankfurt, Germany), so data at rest resides in the EU. Because Neon Inc. is incorporated in the United States, transfers relating to support, administration, or other incidental processing by the US parent are additionally covered by the 2021 Standard Contractual Clauses.
  • Vercel: a US company, certified under the EU-US Data Privacy Framework and additionally relying on the 2021 Standard Contractual Clauses.
  • Stripe and Google: transfers are covered by the EU-US Data Privacy Framework where the recipient is certified, and otherwise by the 2021 Standard Contractual Clauses, per each provider's own privacy policy.

A copy of the relevant safeguards (Data Privacy Framework certifications or executed Standard Contractual Clauses) can be requested using the privacy contact in Section 2.

9. Retention

Personal data is retained only for as long as necessary for the purpose it was collected for:

  • Account and profile data: for as long as the account remains active, plus a limited period after closure to handle residual requests and legal claims.
  • Company account data: for as long as the account remains active, plus a limited period after closure to handle residual requests and legal claims. Billing and tax data collected at a future checkout will be retained for the applicable statutory accounting and tax period.
  • Billing records and invoices: for the statutory accounting retention period.
  • Acceptance records: for as long as the Customer's contract lasts, and afterwards for the limitation period for claims under it.
  • Technical and log data: for a limited operational period sufficient for security and troubleshooting purposes.

10. Data subject rights

Subject to the conditions set out in the GDPR, data subjects have the right to:

  • Access the personal data NADICODEAI S.R.L. holds about them.
  • Rectify inaccurate or incomplete personal data.
  • Erasure of their personal data, where applicable.
  • Restrict the processing of their personal data, where applicable.
  • Object to processing based on legitimate interest, including profiling based on that interest.
  • Portability of the personal data they have provided, in a structured, commonly used, machine-readable format, where the processing is based on consent or contract and carried out by automated means.

To exercise any of these rights, contact NADICODEAI S.R.L. using the privacy contact in Section 2.

11. Withdrawal of consent

Where processing is based on consent (for example, marketing communications, if and where consent is the applicable basis under Section 5), the data subject may withdraw that consent at any time, with the same ease with which it was given, without affecting the lawfulness of processing carried out before the withdrawal.

12. Complaints

Data subjects have the right to lodge a complaint with a supervisory authority.

The determination of NADICODEAI S.R.L.'s lead supervisory authority under the GDPR's one-stop-shop mechanism depends on where decisions on the purposes and means of processing are actually taken..

Regardless of the lead authority determination, Italian users may always contact the Garante per la protezione dei dati personali, and Romanian users may always contact the Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP).

13. Whether providing data is required

Providing account data (name and email) is required to create and operate a portal account; the organization record is derived from the verified email domain rather than entered as a separate field. The portal does not currently collect a legal name, VAT number, or registered address at account creation.. If required account data is not provided, NADICODEAI S.R.L. cannot create or maintain the account; if future checkout data is not provided, it cannot complete the purchase or issue the corresponding invoice.

14. Automated decision-making

NADICODEAI S.R.L. does not make decisions based solely on automated processing, including profiling, that produce legal effects concerning data subjects or similarly significantly affect them.

Separately, and for transparency: Nadia is an AI system. Users who interact with Agents operating inside Nadia are informed that they are interacting with an AI system, not a human.

15. Cookies

The portal and marketing site use cookies. See the Cookie Policy for the full list of cookies in use and how to control them.

16. Security

NADICODEAI S.R.L. applies technical and organisational measures appropriate to the risk, including: encryption of data in transit, hashed storage of account passwords, optional two-factor authentication for user accounts, access controls limiting who can reach production systems and data, and EU data residency for the primary database (hosted in Frankfurt, Germany).

17. Children

The portal and marketing site are business-to-business services, directed at business users acting on behalf of their company. They are not directed at, and are not intended for use by, individuals under 18 years of age.

18. Changes to this policy

NADICODEAI S.R.L. may update this Privacy Policy from time to time. Material changes will be notified to users through the portal or by email.

This policy is in effect from the date of the version shown at its top.

19. Contact

For any question about this Privacy Policy or to exercise the rights described above, contact sales@nadicode.ai, or write to NADICODEAI S.R.L., Calea Circumvalațiunii 43, Timișoara, Romania.