1. Controller
This website is operated by {{LEGAL_COMPANY_NAME}}, registered at {{REGISTERED_ADDRESS}}. Privacy contact: nikalisoft@gmail.com.
2. Scope
This policy describes personal data processing for ordinary visitors to {{WEBSITE_DOMAIN}}. Processing connected to a submitted business problem is described separately in the Proposal Privacy Notice, which is not repeated here.
3. What is processed when you browse
- Ordinary hosting and network logs generated by the infrastructure provider when a page is requested.
- A session-scoped flag recording that the brand intro animation has already played, so it is not repeated.
- A proposal draft stored in your browser's sessionStorage while you fill in the form.
- Access to public policy pages, which requires no account and no identification.
- Any business correspondence you choose to send us directly.
- Minimal service-security data used to protect the site against abuse.
The proposal draft stays inside your current browser session and is not sent anywhere until you submit the form. Declarations and policy acceptances are never restored from a draft; they must always be given again by a person.
There is currently no advertising analytics on this website, and there are currently no marketing cookies.
4. Purposes and legal bases
- Delivering and securing the website — legitimate interests under Article 6(1)(f) GDPR.
- Preventing abuse and technical attacks — legitimate interests under Article 6(1)(f) GDPR.
- Responding to business correspondence you initiate — legitimate interests under Article 6(1)(f) GDPR, or Article 6(1)(b) GDPR where pre-contractual steps apply.
5. Recipients
Data may be processed by the Lovable Cloud platform and its hosting, database and security infrastructure providers, by Lovable's managed transactional email infrastructure where an internal operational notification is sent, by Google as the provider of the NikaliSoft mailbox that receives such notifications, and by professional advisers or authorities where necessary or legally required. Personal data is not sold.
6. International transfers
Managed cloud providers may operate outside the European Economic Area, in which case an adequacy decision, the Standard Contractual Clauses or another lawful mechanism applies. The precise hosting region and mechanism for this project have not yet been verified, so no specific mechanism is claimed here. This policy cannot become effective until the position is confirmed.
7. Retention
- Session-scoped browser storage: the current browser session only.
- Infrastructure logs: the verified retention period of the infrastructure provider.
- Security events: no longer than 30 days, and shorter where technically sufficient.
- Business correspondence: as long as needed for the matter and any applicable statutory period.
8. Your rights
Subject to the conditions in the GDPR, you may request access, rectification, erasure, restriction, portability where applicable, and you may object to processing based on legitimate interests. Where processing relies on consent, you may withdraw it at any time. These rights have legal limitations and do not all apply in every situation.
10. Future independent products
Any product NikaliSoft develops is operated separately, with its own application, database and privacy notice. This policy does not cover those products.
11. Changes
This policy is versioned. Each published version carries its own version identifier and effective date, and earlier published versions remain retrievable.
Document identity
Document: Privacy Policy. Version 0.1-draft. Published by {{LEGAL_COMPANY_NAME}}, trading as NikaliSoft. Contact: nikalisoft@gmail.com.
Each published version keeps its own identifier, effective date and content fingerprint. A version that was accepted with a proposal always remains retrievable at /privacy?version=0.1-draft.