Privacy Policy
What we collect, why we are allowed to use it, who else receives it, how long we keep it, and how to get a copy of it or have it deleted.
Last updated: 19 August 2026 · Policy version: 2026-08-02-v1
Who controls your data
Nivaronix is operated by Pravin Gyawali, based in Butwal, Nepal, who is the data controller for the personal data described here. Nivaronix is not a registered company — it is operated by an individual — so there is no company registration number or registered office to publish.
You can reach the controller at admin@nivaronix.com.
We have not appointed a data protection officer. At our size the GDPR does not require one, and naming a role nobody holds would send your request to an empty mailbox. Privacy questions go to the address above and reach the operator directly.
We have also not yet appointed a representative in the EU or the UK under Art. 27. If you are in either region, that does not affect any of your rights below, and it does not affect your right to complain to your own supervisory authority.
What we collect
- Account data — your email address, name, and organization information, when you create an account.
- Monitoring data — the domains and assets you add, your monitor settings, and the results and incidents they produce.
- Scanner data — the domain you submit, scan metadata (scan ID, timestamp, status), scan results, and security events.
- Billing data — your billing email, your subscription and transaction records, and, because payment is arranged by hand today, the wallet or bank transaction reference you give us and any payment screenshot you choose to upload as proof. We never see or hold your card details: there is no card form anywhere on Nivaronix, and you pay from your own wallet or bank rather than through us.
- Messages you send us — support and sales enquiries, and anything you write in them.
- Technical data — request logs, device and browser information, and cookies. Every cookie we set is listed in our Cookie Policy.
If you add a client or a contact to your account, you are giving us someone else's personal data. You are responsible for having a basis to do that; we delete those records along with the rest of your data when you erase your account.
Why we are allowed to use it
Data protection law lets us process your data only for a defined reason. Here is every reason we rely on, and which one applies to what. Where the reason is our own legitimate interests, we say what that interest actually is — you can object to any of those, and we explain how below.
Running your account: signing you in, monitoring the assets you add, raising incidents, and sending the alerts you configured
Performance of our contract with you — GDPR Art. 6(1)(b)
Billing, subscriptions and invoicing, including the payment reference and any proof of payment you send us
Performance of our contract with you — Art. 6(1)(b)
Keeping transaction and invoice records after you close your account
Compliance with a legal obligation — Art. 6(1)(c), read with Art. 17(3)(b)
Sending you a report you asked for after a free scan, using the email address you gave us for that
Steps taken at your request before entering a contract — Art. 6(1)(b)
Answering a support or sales message you send us
Performance of our contract, or our legitimate interests where you are not yet a customer — Art. 6(1)(b) / 6(1)(f)
Our interest: Replying to someone who deliberately contacted us and expects an answer
Recording that a scan disclaimer was acknowledged, and what was scanned against which target
Our legitimate interests — Art. 6(1)(f)
Our interest: Being able to show that a scan was authorised, and to answer the owner of a scanned domain who asks us who scanned them
Logging blocked scans against internal networks, rate-limit breaches and other abuse signals
Our legitimate interests — Art. 6(1)(f)
Our interest: Protecting the scanner, our other customers, and third parties who never asked to be scanned, from misuse of the platform
Keeping sign-in and authentication history after an account is deleted
Our legitimate interests — Art. 6(1)(f), read with Art. 17(3)(e)
Our interest: Reconstructing what happened if an account turns out to have been compromised
Analytics and marketing cookies on this website
Your consent — Art. 6(1)(a), and PECR / UK PECR reg. 6
Scanning data and abuse logging
When you submit a domain, we read publicly available information about it: SSL/TLS certificates, DNS records, and HTTP security headers. We do not access non-public data or user content on the scanned site, and our scans are strictly non-intrusive — no penetration testing and no exploitation attempt against any target.
Before a free public scan runs, you acknowledge a disclaimer confirming you are authorized to scan the target. We record that the acknowledgement was given, which version of the disclaimer it was, and basic scan metadata (scan ID, target domain, timestamp, outcome), for compliance and abuse prevention.
To protect the scanner and third parties from abuse, we also log security-relevant events: blocked scan attempts against private or internal network targets, rate limit violations, and invalid scan requests.
We do not store your raw IP address or browser user agent string in either log. We store a one-way salted hash of each instead, which lets us spot abuse patterns such as repeated unauthorized scan attempts without being able to recover the original value.
AI analysis, and what it does not decide
When a monitor raises an incident, we can run an AI analysis of it to suggest a likely cause and what to check. It reads incident telemetry — monitor type, status codes, response times, the incident timeline — and the domain name of the affected asset. Before anything is sent, we strip out your organization and record identifiers, remove the name you gave the asset, and scrub credential-shaped text out of error messages. The domain name is deliberately kept, because an analysis that cannot name the host it is describing is of no use to you at three in the morning — but a domain is public DNS, whereas an asset name is free text you typed, so that is removed.
The weekly incident recap, which used to be broken down by asset name, is sent as counts with the labels removed.
Where you have confirmed a root cause yourself on a past incident — for the same asset, or for the same kind of check on another one — that text is included, so the analysis can take account of what you already diagnosed. It is bounded to a recent window and a fixed number of entries, length-capped, and scrubbed of credential-shaped text like any other free text you type. It never crosses an organization boundary, and nothing here trains or fine-tunes a model.
This analysis is about a server, not about a person. It produces no decision about you, does not score, rank or profile you, and nothing about your account, your pricing or your access depends on its output. So it is not automated decision-making of the kind Art. 22 of the GDPR restricts — there is no legal or similarly significant effect on anyone, because no decision about a person is being made at all.
The AI layer is optional and sits on top of a deterministic rules engine, which remains the authority. If the AI providers are unavailable, incident analysis still works.
Who else receives it
Three providers receive data so that Nivaronix can function: Groq for AI incident analysis and the in-product assistant, NVIDIA's API Catalog as the backup that is called only when Groq fails, and Resend to deliver email.
No payment company is one of them today: payment is arranged by hand — we invoice you, you pay from your own wallet or bank, and a person confirms the money arrived — so nothing about you is sent to a payment processor as part of it. We have built an integration with Dodo Payments for a future self-serve checkout, and it is not switched on: no checkout runs through it and no customer data has been sent to it. If we turn it on, it is added to the sub-processor register first and this page says so.
We use Google Analytics to understand how this site is used; it loads only after you accept analytics cookies, and never before. It records the pages you view, the device and browser you use, and an approximate location derived from your IP address — typically city level, never a precise position. Google Signals, User ID and user-provided data collection are all switched off on the property, so nothing is associated with a signed-in Google account and nothing is used to build advertising audiences. We run no advertising trackers, and we do not sell personal data or share it for behavioural advertising.
The full list — what each provider receives, what we deliberately never send them, and the source files each claim was checked against — is on our sub-processors page, which is generated from our own code rather than written by hand.
Where in the world your data goes
Nivaronix is operated from Nepal, and our providers are in the United States and the United Kingdom. If you are in the EEA or the UK, your personal data is transferred out of your region — to us, and then to them.
The servers themselves are not in Nepal. The platform runs on Amazon Web Services in the eu-west-1 region — Ireland — and that is where the database holding your account, assets, monitors and incidents lives. In front of it sits Cloudflare, which terminates and caches requests at whichever of its edge locations is nearest to you, so traffic in transit is handled globally even though the data at rest is not.
We are describing where the infrastructure is configured to run, not making you a residency promise. We have not committed contractually to keeping data in any region, and we could move it without your agreement, so please do not read the paragraph above as a guarantee. Two things already sit outside Ireland: our email provider routes mail through infrastructure we do not choose the region of, and Cloudflare's edge is worldwide by design. If in-region processing is a requirement for you rather than a preference, ask us before you rely on it — we will tell you what we can and cannot commit to in writing.
Nepal is not covered by a European Commission adequacy decision or by UK adequacy regulations. That means a transfer here needs one of the safeguards in Chapter V of the GDPR, such as Standard Contractual Clauses or the UK's International Data Transfer Agreement.
We do not have those safeguards in place yet. We are telling you that instead of naming a mechanism we could not produce if you asked for it. It is a real gap and we are working on closing it.
If your organisation needs a data processing agreement or transfer clauses signed before it can use Nivaronix, email admin@nivaronix.com.
How long we keep it
Data | Retained for |
|---|---|
Account, organisation and team data | Until you delete your account |
Assets, monitors, incidents, scan reports and monitoring history | Until you delete your account, then erased with it |
Scanner audit logs (disclaimer acknowledgement, scan outcome) | 90 days |
Security event logs (SSRF, abuse and rate-limit records) | 180 days |
Asset lifecycle events (verification, monitor changes), AI-generated incident root-cause analyses, LLM request/response audit trail, and notification delivery records | 90 days |
Admin and customer action audit trail | 365 days |
A data export you generate | 48 hours, then the file is deleted |
Payment, invoice and transaction records | Kept after account deletion for tax and accounting law. No fixed end date is set yet |
Sign-in and authentication history | Kept after account deletion to investigate account compromise. No fixed end date is set yet |
The 90 and 180 day windows are enforced automatically by a scheduled job that deletes expired rows every hour, not applied by hand. They are practical, configurable windows rather than a regulatory maximum.
The last two rows say no end date is set because none is. We have not yet fixed how long financial records and sign-in history are kept after an account closes, and we would rather say that than publish a number we do not enforce.
You can delete your account and its data at any time from Settings → Privacy & your data. There is a 30-day grace period during which you can cancel; after that the deletion is real and irreversible, not a hidden flag on a row we still hold.
What survives account deletion
Three categories are kept even after you erase your account, because the law allows it. Everything else is deleted outright.
Payment, invoice and transaction records are retained as tax and accounting evidence (GDPR Art. 17(3)(b)), with the links to your identity severed rather than kept, so what remains is an amount, a currency and a date beside an identifier that no longer resolves to anyone.
Security records— sign-in and authentication history, abuse and intrusion logs, and the scanner audit log — are retained under Art. 17(3)(e) and Art. 6(1)(f) so that an account compromise or an abuse complaint can still be reconstructed. The scanner audit log is the one worth naming, because it is the one people are surprised by: it is the record that permission to scan a given target was acknowledged, and it is append-only. If we deleted it on request, anyone could scan a third party's domain through us and then erase the proof that they said they were authorised to. So it survives your erasure, and it survives it deliberately.
It is not a full record of you: the requester's IP address is stored only as a salted one-way hash, never in plain text, and has been since the row was written.
The record of the erasure itself — that you asked, when, and that we carried it out — is kept as well. It is the only evidence we would have that we honoured your request, and deleting it would destroy our own proof of compliance along with yours.
These three are the closed list. They are not a general licence to keep things: every other table in the product is classified for outright deletion, and a new table that nobody classifies fails our own test suite rather than quietly surviving an erasure.
A complete, itemised list with the lawful basis for each category is shown to you before you confirm a deletion, and is published at /api/privacy/disclosure.
Your rights, and how to use them
If you are in the EEA or the UK these rights are yours under the GDPR and UK GDPR. We apply them to everyone, wherever you are. We answer within one month, as Art. 12(3) requires, and we do not charge for it.
- Access (Art. 15) — get a copy of everything we hold about you. Self-service: generate an export from your account settings and download it as a file.
- Portability (Art. 20) — the same export, in structured, machine-readable JSON you can take elsewhere.
- Erasure (Art. 17) — self-service from your account settings. Before you confirm, we show you exactly what will be kept and why.
- Rectification (Art. 16) — correct anything inaccurate or incomplete. Change your own account details in settings, or email us for anything you cannot edit yourself.
- Restriction (Art. 18) — ask us to pause processing while a dispute about accuracy or a legitimate interest is worked out. Email us.
- Objection (Art. 21) — object to anything we do on the basis of legitimate interests, listed by name above. Email us and tell us which one.
Access, portability and erasure are in Settings → Privacy & your data. You do not need to ask us and you do not need to wait.
For rectification, restriction and objection, write to admin@nivaronix.com. Say which right you are exercising and what it concerns; that is all we need.
Complaining about us
You can complain to a data protection supervisory authority, and you do not have to raise it with us first. In the UK that is the Information Commissioner's Office. In the EEA it is the authority in the country where you live, work, or where you think the problem happened — every member state has one, and the European Data Protection Board publishes the list.
We would rather hear from you directly and fix it, but that is your choice, not a condition.
Withdrawing consent
The only thing we ask your consent for is analytics and marketing cookies on this website. Everything else runs on one of the other bases in the table above.
You can withdraw that consent at any time, and it takes exactly as many clicks as giving it did: open Cookie Policy and use “Manage cookie preferences”. The change applies immediately, in every open tab — analytics stops there and then rather than at your next page load.
Withdrawing does not undo processing that already happened while your consent was in place, which is what Art. 7(3) says. It does stop it continuing.
Children
Nivaronix is a tool for people who run websites and infrastructure professionally. It is not designed for, marketed to, or intended for children, and we do not knowingly collect personal data from anyone under 16.
There is no age gate on signup — we do not ask your date of birth, because collecting it from every professional user to catch a case we have never seen would take more personal data than it protects. If you believe a child has given us their data, email admin@nivaronix.com and we will delete the account.
How we protect it
We implement appropriate technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure or destruction. All data transmission is encrypted using TLS/SSL.
Our Security Policy sets out those measures in more detail, and how Nivaronix is built states plainly where the architecture's limits are.
Contact
Questions about this policy, or any request under it, go to admin@nivaronix.com.
Our other policies