Skip to content
NISDESK

Privacy Policy

Last updated: 2026-08-17

At NISDESK (“we”, “the company”), we respect your privacy and process your personal data responsibly in accordance with the European Union General Data Protection Regulation (GDPR) and the Turkish Personal Data Protection Law (KVKK). This policy explains which data we collect through the services offered at nisdesk.com, why we collect it, and what rights you have.

1. Data Controller

The data controller is [COMPANY NAME] (registration in progress). Contact: privacy@nisdesk.com

2. Data We Collect and Purposes of Processing

a) Account and authentication data

We collect your email address at sign-up. This data is processed to create your account, provide secure sign-in, and send service notifications. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).

b) Company information (quiz data)

Our NIS2 scope and DORA readiness tools ask for information such as sector, headcount, and revenue range. This data is evaluated anonymously and is never used to build any individual profile. Legal basis: legitimate interest (Art. 6(1)(f) GDPR).

c) Compliance assessment results

Compliance assessments you save to the platform are stored linked to your account. The purpose is to enable access to past assessments and progress tracking. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).

d) Payment data

Paddle processes checkout, subscription, tax, invoice, and payment information. NISDESK stores only the customer/subscription identifiers and billing status needed to provide paid access; we do not receive complete card details. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).

e) Optional product analytics

If you explicitly accept analytics, we record a limited allowlisted set of product interaction events. When signed in, an event may be linked to your account id. We do not place free-form text, email addresses, assessment contents, document contents, or payment credentials in analytics event properties. Legal basis: consent (Art. 6(1)(a) GDPR).

3. Data Retention Periods

4. Data Processors and Transfers

Your data is shared only with the sub-processors listed below. All sub-processors are bound by a data processing agreement (DPA) under the GDPR:

ProcessorPurposeLocation
PaddleCheckout, subscription billing, tax and invoicesSee Paddle's current privacy and transfer terms
SupabaseDatabase and authenticationEU region (Frankfurt)
Hetzner OnlineServer hostingGermany (EU)
HostingerEmail / SMTPEU
Let's EncryptSSL/TLS certificatesUSA (no data processing)

Where a processor transfers personal data outside the EU/EEA, the transfer is governed by the safeguards described in that processor's current data-processing terms. NISDESK does not use customer content to train its own artificial intelligence models.

5. Your Rights

Under the GDPR and KVKK, you have the following rights:

You may submit requests to privacy@nisdesk.com. We respond within 30 days. You also retain the right to lodge a complaint with the competent data protection authority in your country (the KVKK Authority for Turkey).

6. Security

Data is protected in transit with TLS (Let's Encrypt) and at rest with AES-256 encryption provided by the Supabase infrastructure. Access control is role-based, and only authorized personnel can access personal data.

7. Cookies

For detailed information about our use of cookies, please review our Cookie Policy.

8. Updates to This Policy

We may update this policy from time to time. We will notify you by email of material changes. The current version is always published on this page.

Last updated: 2026-08-17

This document is a template and does not constitute legal advice. We recommend consulting a lawyer for legal guidance specific to your circumstances.