Privacy Policy
Last updated: 2026-10-08
1. Data Controller
The data controller under Article 4(7) GDPR is the company Inger s.r.o., ID 50178831 (hereinafter "we" or "Inger"), operating the NISMap platform. Full operator details are listed in the Imprint. Contact: privacy@nismap.com
2. What data we process
2.1 Security scan (Free)
- Domain submitted for scan — publicly available information
- Company ID — public record from business registry
- Technical scan results — automatically generated
- Compliance questionnaire responses
2.2 Registration (Pro/Business)
- Email address
- First and last name
- Company name
- Billing information (processed by Stripe)
2.3 Document import into the questionnaire (signed in)
- Uploaded file (PDF or DOCX) — processed in server memory only and not stored
- Text extracted from the file — after automatic removal of emails, phone numbers, company IDs, IP addresses, birth numbers, the company name from the scan and recognised personal names and addresses, sent to the Claude API (Anthropic, USA), at most the first 60,000 characters
- Suggested answers with a quoted excerpt — shown only to you and not stored; only the answers you accept are saved
3. Legal basis for processing
- Legitimate interest (Art. 6(1)(f) GDPR) — providing the security audit service
- Performance of a contract (Art. 6(1)(b) GDPR) — for registered users
- Legal obligation (Art. 6(1)(c) GDPR) — accounting and tax records
4. Cookies and tracking
NISMap does not use any tracking cookies. Therefore, we do not require a cookie banner or cookie consent.
Types of cookies we use:
- Supabase Auth cookies — strictly necessary for authentication (exempt under ePrivacy Directive)
- Stripe cookies — strictly necessary for payment fraud prevention (exempt under ePrivacy Directive)
Analytics is provided by PostHog in cookieless mode (persistence: 'memory') — no data is stored in the browser.
5. Sub-processors and data transfers
| Service | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, storage | EU (Frankfurt) |
| Hetzner Online | Application hosting (server operated by Inger s.r.o.) | EU (Germany) |
| Stripe | Payment processing | EU / US (SCCs) |
| Anthropic (Claude API) | AI reports, assessments, chat and answer suggestions from an uploaded document (company identifiers and contact details removed before sending) | US (SCCs) |
| Resend | Transactional email (account verification, password reset, report ready) | US (SCCs) |
| PostHog | Product analytics (cookieless mode) | EU Cloud |
| Cloudflare | DNS, Turnstile (bot protection on forms) | US (SCCs) |
| Sentry | Error tracking, performance monitoring | EU (sentry.io EU) |
| Upstash | Rate-limit store (truncated /24 and /64 IPs only) | EU (Frankfurt) |
| entyrix.com | Company registry lookup (ICO/domain) for scope engine, vendor auto-audit and relationship graph — no PII is sent | EU (Hetzner, Germany) |
Before data is sent to the Claude API (Anthropic) we automatically remove company IDs, company names, emails, phone numbers, IP addresses, birth numbers and recognised personal names and addresses. Names and addresses are recognised heuristically, so some may remain in chat text or an uploaded document. Queries to entyrix.com contain only public company identifiers (ICO, domain) and never personal data.
View the full sub-processors list with transfer mechanisms and DPAs →
6. International data transfers (Schrems II)
Some processors have their parent company outside the EU. Transfers take place under the following safeguards per Articles 44-49 GDPR:
- Supabase — data physically hosted in the EU (Frankfurt). The DPA incorporates Standard Contractual Clauses (SCC Module 2) Commission Decision 2021/914 as a fallback for parent-company access in the US.
- Anthropic (Claude API) — transfer to the US under Standard Contractual Clauses (SCC Modules 2 and 3) Commission Decision 2021/914, incorporated in Anthropic's DPA. Company identifiers, contact details and recognised names and addresses are removed before sending.
- Stripe — payments routed through Stripe Payments Europe (Ireland), SCC Module 2 for any US transfer, PCI-DSS Level 1.
- Resend / Cloudflare / Sentry — SCC Module 2 Commission Decision 2021/914; logs limited to what is needed to operate the service.
We can provide the specific contractual documents (DPA + SCC) of the relevant processors on request.
7. Data retention
- Scan results — 90 days (then automatically anonymized)
- Uploaded documents and their text — not stored (processed in memory during the request only)
- Accounting records — 10 years (legal obligation)
- Account data — for the duration of the account + 30 days
8. Automated decision-making and AI
NISMap uses AI (Claude by Anthropic) as an assistant to generate draft compliance reports, recommendations and express assessments. Outputs are always labelled as AI-generated and subject to human review.
We do not make any decisions that produce legal effects concerning you, or similarly significantly affect you, solely on the basis of automated processing within the meaning of Article 22 GDPR. Final compliance decisions are made by the user or a designated auditor — AI only prepares the draft.
You have the right to: (a) know that a particular output was AI-generated, (b) request human review of AI-generated content, (c) express your point of view and object to the processing at privacy@nismap.com.
In line with Article 50 of Regulation (EU) 2024/1689 (AI Act), our AI outputs carry a clear label stating they were produced by an AI system.
9. Your rights
Under the GDPR, you have the right to: access your data, rectification, erasure, restriction of processing, data portability and objection to processing. To exercise your rights, contact us at privacy@nismap.com. We will respond without undue delay and in any event within one month of receiving your request (Art. 12(3) GDPR).
You also have the right to lodge a complaint with a supervisory authority — in Slovakia this is the Office for Personal Data Protection (dataprotection.gov.sk), in the Czech Republic the Office for Personal Data Protection (uoou.cz).
10. Changes to this document
We may update this document. The current version is always available on this page. We will notify registered users by email about material changes.