GDPR

Privacy Policy

Pre-production draft for NOMAION's privacy architecture.

Last updated: October 2026

1. Document status

Pre-production draft. This page describes NOMAION's privacy-by-design direction and requires final legal and DPO review before public production operation. It does not claim full compliance.

2. What data we collect

Data controller: [COMPANY DETAILS]. We may collect:

  • account details (name, email);
  • content you submit (questions, documents);
  • technical data (device, browser, IP address);
  • billing information only if paid services are enabled in the future.

3. How we use data

To provide and improve the service, support users, secure the platform and meet legal obligations. The legal basis is contract performance, legitimate interest, consent or legal obligation, as applicable.

4. User accounts

Account details are used for identification and service operation. Self-service full account deletion and export are not yet enabled and must be completed with real backend processes before an external beta.

5. AI conversations

Questions and answers are currently stored to provide conversation history. The final automatic expiry and retention policy has not yet been finalised. Do not submit third parties' personal data without an appropriate legal basis.

6. Uploaded documents

The secure production document upload and processing flow is under development. Before use with real confidential documents, it will require private storage, ownership checks, file validation and a complete deletion lifecycle.

7. Cookies

We use essential cookies to operate the platform and, with your consent, optional cookies for statistical purposes.

8. Analytics

We may use statistical analysis tools to understand how the platform is used, with aggregated and, where possible, anonymised data.

9. Third-party services

NOMAION uses or may use providers for hosting, authentication, AI and other functions. The final list of subprocessors, processing locations, DPAs and any international transfer mechanisms must be verified and published before production operation.

10. Data security

NOMAION is designed with security-by-design and privacy-by-design principles, including server-side authorisation, restricted access and encryption in transit where supported. Final production security checks have not yet been completed.

11. Data retention

A single retention period has not been finalised. The production policy will be categorised by purpose and data type, with expiry, deletion and legal hold where required. Final time limits require legal and privacy review.

12. Your rights (GDPR)

You have the right to:

  • access and rectification;
  • erasure (the right to be forgotten);
  • restriction of and objection to processing;
  • data portability;
  • withdraw consent at any time.

You also have the right to lodge a complaint with the Hellenic Data Protection Authority (www.dpa.gr).

13. Contact

For personal data matters: [CONTACT EMAIL], [COMPANY DETAILS]. You can also use the Contact.

14. Changes to the Privacy Policy

We may update this policy. The last updated date appears at the top of the page.