This policy explains how Nortiun (“we”) handles personal data on nortiun.com and the account areas. For any privacy matter — including access, correction or deletion of data — contact our Data Protection Officer at [email protected].
We do not sell your data. We use processors that handle data on our behalf, under contract: Supabase (database, authentication and storage), Cloudflare (hosting and CDN) and Formspree (waitlist form). If we enable payments, we will use a payment processor (merchant of record) that handles billing data directly.
Our processors may process data on servers outside your country. In those cases we seek to ensure the transfer has adequate safeguards under the GDPR and Brazil’s LGPD.
You may request: access, correction, deletion, portability, restriction, objection to processing and withdrawal of consent; and lodge a complaint with your data protection authority (in the EU, your national authority; in Brazil, the ANPD). To exercise these, email [email protected]. You can delete your account yourself in the account area.
We use encryption in transit (TLS) and at rest, row-level access control (RLS) and isolation of sensitive documents in private storage, accessible only to you and our curation team.
We do not use advertising or tracking cookies. We only store your language preference in your browser (localStorage).
Nortiun is not directed to minors and does not knowingly collect children’s data.
We may update this policy. We will post the new version here with the update date.
Depending on your country, the following may apply: the LGPD (Brazil), the GDPR (European Union), the UK GDPR (United Kingdom), the revised Swiss Federal Act on Data Protection (FADP) and the BDSG (Germany). You may lodge a complaint with the competent authority: the ANPD (Brazil), your national authority in the EU — in Ireland, the DPC (dataprotection.ie) —, the ICO (UK) or the FDPIC (Switzerland).
Cookies and device storage: we use only storage strictly necessary for the functionality you requested (remembering your language). There is no tracking or advertising — so no consent banner is required under §25 TDDDG (Germany) and the ePrivacy rules.
Swiss representative: we currently do not meet the threshold of Art. 14 FADP (large-scale, high-risk processing). If that changes, we will appoint a representative in Switzerland and name them here. Contact: [email protected].