Privacy Policy
What we collect, why we are allowed to use it, who else receives it, how long we keep it, and how to get a copy of it or have it deleted.
Last updated: 11 August 2026 · Policy version: 2026-08-02-v1
Who controls your data
Nivaronix is operated by Pravin Gyawali, based in Butwal, Nepal, who is the data controller for the personal data described here. Nivaronix is not a registered company — it is operated by an individual — so there is no company registration number or registered office to publish.
You can reach the controller at [email protected].
We have not appointed a data protection officer. At our size the GDPR does not require one, and naming a role nobody holds would send your request to an empty mailbox. Privacy questions go to the address above and reach the operator directly.
We have also not yet appointed a representative in the EU or the UK under Art. 27. If you are in either region, that does not affect any of your rights below, and it does not affect your right to complain to your own supervisory authority.
What we collect
- Account data — your email address, name, and organization information, when you create an account.
- Monitoring data — the domains and assets you add, your monitor settings, and the results and incidents they produce.
- Scanner data — the domain you submit, scan metadata (scan ID, timestamp, status), scan results, and security events.
- Billing data — your billing email and your subscription and transaction records. Card details go directly to our payment provider and never reach us.
- Messages you send us — support and sales enquiries, and anything you write in them.
- Technical data — request logs, device and browser information, and cookies. Every cookie we set is listed in our Cookie Policy.
If you add a client or a contact to your account, you are giving us someone else's personal data. You are responsible for having a basis to do that; we delete those records along with the rest of your data when you erase your account.
Why we are allowed to use it
Data protection law lets us process your data only for a defined reason. Here is every reason we rely on, and which one applies to what. Where the reason is our own legitimate interests, we say what that interest actually is — you can object to any of those, and we explain how below.
Running your account: signing you in, monitoring the assets you add, raising incidents, and sending the alerts you configured
Performance of our contract with you — GDPR Art. 6(1)(b)
Billing, subscriptions and invoicing, including the records our payment provider needs
Performance of our contract with you — Art. 6(1)(b)
Keeping transaction and invoice records after you close your account
Compliance with a legal obligation — Art. 6(1)(c), read with Art. 17(3)(b)
Sending you a report you asked for after a free scan, using the email address you gave us for that
Steps taken at your request before entering a contract — Art. 6(1)(b)
Answering a support or sales message you send us
Performance of our contract, or our legitimate interests where you are not yet a customer — Art. 6(1)(b) / 6(1)(f)
Our interest: Replying to someone who deliberately contacted us and expects an answer
Recording that a scan disclaimer was acknowledged, and what was scanned against which target
Our legitimate interests — Art. 6(1)(f)
Our interest: Being able to show that a scan was authorised, and to answer the owner of a scanned domain who asks us who scanned them
Logging blocked scans against internal networks, rate-limit breaches and other abuse signals
Our legitimate interests — Art. 6(1)(f)
Our interest: Protecting the scanner, our other customers, and third parties who never asked to be scanned, from misuse of the platform
Keeping sign-in and authentication history after an account is deleted
Our legitimate interests — Art. 6(1)(f), read with Art. 17(3)(e)
Our interest: Reconstructing what happened if an account turns out to have been compromised
Analytics and marketing cookies on this website
Your consent — Art. 6(1)(a), and PECR / UK PECR reg. 6
Scanning data and abuse logging
When you submit a domain, we read publicly available information about it: SSL/TLS certificates, DNS records, and HTTP security headers. We do not access non-public data or user content on the scanned site, and our scans are strictly non-intrusive — no penetration testing and no exploitation attempt against any target.
Before a free public scan runs, you acknowledge a disclaimer confirming you are authorized to scan the target. We record that the acknowledgement was given, which version of the disclaimer it was, and basic scan metadata (scan ID, target domain, timestamp, outcome), for compliance and abuse prevention.
To protect the scanner and third parties from abuse, we also log security-relevant events: blocked scan attempts against private or internal network targets, rate limit violations, and invalid scan requests.
We do not store your raw IP address or browser user agent string in either log. We store a one-way salted hash of each instead, which lets us spot abuse patterns such as repeated unauthorized scan attempts without being able to recover the original value.
AI analysis, and what it does not decide
When a monitor raises an incident, we can run an AI analysis of it to suggest a likely cause and what to check. It reads incident telemetry — monitor type, status codes, response times, the incident timeline — and the domain name of the affected asset. Before anything is sent, we strip out your organization and record identifiers and scrub credential-shaped text out of error messages. The domain name is deliberately kept, because an analysis that cannot name the host it is describing is of no use to you at three in the morning.
This analysis is about a server, not about a person. It produces no decision about you, does not score, rank or profile you, and nothing about your account, your pricing or your access depends on its output. So it is not automated decision-making of the kind Art. 22 of the GDPR restricts — there is no legal or similarly significant effect on anyone, because no decision about a person is being made at all.
The AI layer is optional and sits on top of a deterministic rules engine, which remains the authority. If the AI providers are unavailable, incident analysis still works.
Who else receives it
Three providers receive data so that Nivaronix can function: Groq and Google for AI incident analysis, and Resend to deliver email. We do not use an automated payment processor today — payments are billed manually and confirmed by a person, so no payment provider is in this list as an active recipient of your data. We use Google Analytics to understand how this site is used; it loads only after you accept analytics cookies, and never before. It records the pages you view, the device and browser you use, and an approximate location derived from your IP address — typically city level, never a precise position. Google Signals, User ID and user-provided data collection are all switched off on the property, so nothing is associated with a signed-in Google account and nothing is used to build advertising audiences. We run no advertising trackers, and we do not sell personal data or share it for behavioural advertising.
The full list — what each provider receives, what we deliberately never send them, and the source files each claim was checked against — is on our sub-processors page, which is generated from our own code rather than written by hand.
Where in the world your data goes
Nivaronix is operated from Nepal, and our providers are in the United States and the United Kingdom. If you are in the EEA or the UK, your personal data is transferred out of your region — to us, and then to them.
Nepal is not covered by a European Commission adequacy decision or by UK adequacy regulations. That means a transfer here needs one of the safeguards in Chapter V of the GDPR, such as Standard Contractual Clauses or the UK's International Data Transfer Agreement.
We do not have those safeguards in place yet. We are telling you that instead of naming a mechanism we could not produce if you asked for it. It is a real gap and we are working on closing it.
If your organisation needs a data processing agreement or transfer clauses signed before it can use Nivaronix, email [email protected].
How long we keep it
Data | Retained for |
|---|---|
Account, organisation and team data | Until you delete your account |
Assets, monitors, incidents, scan reports and monitoring history | Until you delete your account, then erased with it |
Scanner audit logs (disclaimer acknowledgement, scan outcome) | 90 days |
Security event logs (SSRF, abuse and rate-limit records) | 180 days |
Asset lifecycle events (verification, monitor changes), AI-generated incident root-cause analyses, LLM request/response audit trail, and notification delivery records | 90 days |
Admin and customer action audit trail | 365 days |
A data export you generate | 48 hours, then the file is deleted |
Payment, invoice and transaction records | Kept after account deletion for tax and accounting law. No fixed end date is set yet |
Sign-in and authentication history | Kept after account deletion to investigate account compromise. No fixed end date is set yet |
The 90 and 180 day windows are enforced automatically by a scheduled job that deletes expired rows every hour, not applied by hand. They are practical, configurable windows rather than a regulatory maximum.
The last two rows say no end date is set because none is. We have not yet fixed how long financial records and sign-in history are kept after an account closes, and we would rather say that than publish a number we do not enforce.
You can delete your account and its data at any time from Settings → Privacy & your data. There is a 30-day grace period during which you can cancel; after that the deletion is real and irreversible, not a hidden flag on a row we still hold.
What survives account deletion
Two categories are kept even after you erase your account, because the law allows it. Payment and transaction records are retained as tax and accounting evidence (GDPR Art. 17(3)(b)) with the links to your identity removed, so what remains is an amount, a currency and a date rather than a person. Security and authentication logs are retained to investigate account compromise (Art. 17(3)(e)), and already contain only a salted one-way hash of the requester rather than an IP address.
A complete, itemised list with the lawful basis for each category is shown to you before you confirm a deletion, and is published at /api/privacy/disclosure.
Your rights, and how to use them
If you are in the EEA or the UK these rights are yours under the GDPR and UK GDPR. We apply them to everyone, wherever you are. We answer within one month, as Art. 12(3) requires, and we do not charge for it.
- Access (Art. 15) — get a copy of everything we hold about you. Self-service: generate an export from your account settings and download it as a file.
- Portability (Art. 20) — the same export, in structured, machine-readable JSON you can take elsewhere.
- Erasure (Art. 17) — self-service from your account settings. Before you confirm, we show you exactly what will be kept and why.
- Rectification (Art. 16) — correct anything inaccurate or incomplete. Change your own account details in settings, or email us for anything you cannot edit yourself.
- Restriction (Art. 18) — ask us to pause processing while a dispute about accuracy or a legitimate interest is worked out. Email us.
- Objection (Art. 21) — object to anything we do on the basis of legitimate interests, listed by name above. Email us and tell us which one.
Access, portability and erasure are in Settings → Privacy & your data. You do not need to ask us and you do not need to wait.
For rectification, restriction and objection, write to [email protected]. Say which right you are exercising and what it concerns; that is all we need.
Complaining about us
You can complain to a data protection supervisory authority, and you do not have to raise it with us first. In the UK that is the Information Commissioner's Office. In the EEA it is the authority in the country where you live, work, or where you think the problem happened — every member state has one, and the European Data Protection Board publishes the list.
We would rather hear from you directly and fix it, but that is your choice, not a condition.
Withdrawing consent
The only thing we ask your consent for is analytics and marketing cookies on this website. Everything else runs on one of the other bases in the table above.
You can withdraw that consent at any time, and it takes exactly as many clicks as giving it did: open Cookie Policy and use “Manage cookie preferences”. The change applies immediately, in every open tab — analytics stops there and then rather than at your next page load.
Withdrawing does not undo processing that already happened while your consent was in place, which is what Art. 7(3) says. It does stop it continuing.
Children
Nivaronix is a tool for people who run websites and infrastructure professionally. It is not designed for, marketed to, or intended for children, and we do not knowingly collect personal data from anyone under 16.
There is no age gate on signup — we do not ask your date of birth, because collecting it from every professional user to catch a case we have never seen would take more personal data than it protects. If you believe a child has given us their data, email [email protected] and we will delete the account.
How we protect it
We implement appropriate technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure or destruction. All data transmission is encrypted using TLS/SSL.
Our Security Policy sets out those measures in more detail, and how Nivaronix is built states plainly where the architecture's limits are.
Contact
Questions about this policy, or any request under it, go to [email protected].
Our other policies