1. Who is the controller
The controller for the processing described here is {{LEGAL_COMPANY_NAME}}, {{LEGAL_FORM}}, registration number {{COMPANY_REGISTRATION_NUMBER}}, registered at {{REGISTERED_ADDRESS}}, {{COUNTRY_OF_REGISTRATION}}. NikaliSoft is its trading name; the controller is the legal company, not the brand.
Privacy contact: nikalisoft@gmail.com.
2. What this notice covers
This notice covers:
- data submitted through the proposal form;
- evaluation of a proposal;
- proposal-related communication;
- evidence of the policy versions accepted;
- abuse prevention;
- minimal security events.
It does not govern any future independent product. Each product has its own privacy notice.
3. Categories of data
- company legal name;
- country of registration;
- registration or VAT number;
- company website;
- company size;
- contact name;
- role or job title;
- business email address;
- problem description;
- current process;
- business impact;
- who is affected;
- market reasoning and evidence;
- existing alternatives;
- affected industries;
- described partner contribution;
- pilot-user availability;
- readiness statements;
- additional context;
- the declaration text and the accepted policy versions;
- timestamps;
- the proposal reference code;
- idempotency data used to prevent duplicate submissions;
- a pseudonymous, salted, daily-rotating rate-limit fingerprint;
- minimal security events (for example: received, rejected, rate-limited).
The NikaliSoft application database does not store raw IP addresses or full user-agent strings for proposal submissions.
Hosting and security providers may nevertheless process ordinary connection data in their own infrastructure logs, as is normal for any website.
4. Where the data comes from
- the submitting representative, through the form;
- technical security controls operating on the submission;
- later correspondence about the proposal.
5. Purposes and legal bases
Proposal evaluation and response
To receive, assess and clarify a proposal and decide whether to continue.
Legal basis: legitimate interests under Article 6(1)(f) GDPR in evaluating B2B product opportunities; and Article 6(1)(b) GDPR where processing is necessary for steps requested by a data subject before entering into a contract and that basis applies.
Company and authority verification
To confirm EU-company eligibility, confirm the representative's authority and prevent misleading submissions. Legal basis: legitimate interests under Article 6(1)(f) GDPR.
Policy acceptance records
To prove which terms were acknowledged and accepted at submission, handle disputes and maintain legal records. Legal basis: legitimate interests under Article 6(1)(f) GDPR, and a legal obligation under Article 6(1)(c) GDPR where applicable.
Security and abuse prevention
For rate limiting, bot prevention, duplicate prevention and system security. Legal basis: legitimate interests under Article 6(1)(f) GDPR.
Consent is not used as the general legal basis for the processing required above.
6. Our legitimate-interest assessment in short
NikaliSoft needs to evaluate genuine business opportunities and protect the service from abuse. The data involved is limited professional business-contact information supplied deliberately by a company representative, and confidential material must not be submitted at all. We consider that balance reasonable. You can object to processing based on legitimate interests, and we will stop unless we have compelling legitimate grounds that override your interests, or the processing is needed for legal claims.
7. Required and optional information
Most fields are required, because a proposal cannot be evaluated without a clear description of the company, the problem, the market reasoning and the intended contribution. If required information is not provided, the form cannot be submitted.
Optional fields are the company website, company size, available evidence, affected industries and additional context. Leaving them empty does not prevent submission.
8. Recipients and processors
Data may be made available to the following categories of recipient:
- the Lovable Cloud platform and the hosting and database infrastructure it uses;
- Lovable's managed transactional email infrastructure, which processes the internal notification message and its delivery data;
- Google, as the provider of the Gmail inbox that receives the internal notification;
- security and technical service providers protecting the website;
- professional legal, accounting or technical advisers, where necessary;
- competent authorities, where legally required.
After a proposal has been stored successfully, a minimal internal notification is sent to a mailbox controlled by NikaliSoft. That notification contains only the reference code, the submission date and time, the legal company name, the country, the professional contact name, role and business email address, and the problem title. The full proposal is never sent by email; it is reviewed only inside the secured Lovable Cloud data environment.
Delivery is handled by Lovable's managed transactional email infrastructure. The receiving mailbox is a Gmail inbox controlled by NikaliSoft, so Google may process ordinary email metadata and message content in its role as the receiving email provider. The purpose is internal proposal administration, and the legal basis is NikaliSoft's legitimate interest in reviewing and responding to business-to-business proposals. No automated email is sent to the person submitting a proposal.
The notification is attempted only after the proposal has been stored. If the notification cannot be sent, the proposal, its reference code and the record of the accepted document versions are unaffected.
NikaliSoft does not sell proposal personal data.
Legal review required: the exact processor entities, their roles and the data-processing agreements in place must be verified and named before this notice is activated.
9. International transfers
Proposal data is stored in managed cloud infrastructure. Some providers operate global networks, which can mean processing outside the European Economic Area — typically under an adequacy decision or the European Commission's Standard Contractual Clauses, together with supplementary measures where required.
Unresolved: the concrete hosting region and the applicable transfer mechanism for this project have not yet been verified with the providers. This notice cannot be activated until the exact position is confirmed and stated here. No transfer mechanism is claimed in the meantime.
10. Retention
The following retention periods are proposed and await owner and legal confirmation:
- Proposals not taken forward: 24 months after the last meaningful interaction.
- Proposals leading to a contractual relationship: the duration of the relationship plus 5 years, unless a longer statutory period applies.
- Policy acceptance evidence: the same period as the related proposal or relationship.
- Daily pseudonymous rate-limit fingerprints and short-lived security events: no longer than 30 days, and shorter where technically sufficient.
- Session draft in your browser: the current browser session only.
- Infrastructure logs: the verified retention period of the infrastructure provider.
Data may be kept longer where necessary for:
- establishing, exercising or defending legal claims;
- investigating fraud or abuse;
- complying with a legal obligation;
- handling an active dispute.
11. Automated decision-making
NikaliSoft does not use solely automated decision-making to accept or reject product proposals. Technical validation, spam protection and rate limiting are protective measures and are not commercial acceptance decisions.
12. Your rights
Subject to the conditions and limitations in the GDPR, you may request:
- access to your personal data;
- rectification of inaccurate data;
- erasure;
- restriction of processing;
- objection to processing based on legitimate interests;
- data portability, where that right applies;
- withdrawal of consent, where processing actually relies on consent.
These rights are not absolute; each has legal conditions and exceptions. You may also lodge a complaint with the competent supervisory authority — see section 14.
13. Security
Protective measures include:
- authoritative server-side validation of every submission;
- restricted database access with no public read path for proposals;
- records of the exact policy version accepted;
- rate limiting against abuse;
- data minimisation;
- no storage of raw IP addresses in the application database.
Operational thresholds, secrets and algorithm details are deliberately not published.
14. Contact and complaints
Privacy contact: nikalisoft@gmail.com.
Competent supervisory authority: {{SUPERVISORY_AUTHORITY_NAME}} ({{SUPERVISORY_AUTHORITY_URL}}). The competent authority depends on where the controller is established, which is not yet confirmed. This notice cannot be activated while the authority or the privacy contact address is unresolved.
Document identity
Document: Proposal Privacy Notice. Version 0.1-draft. Published by {{LEGAL_COMPANY_NAME}}, trading as NikaliSoft. Contact: nikalisoft@gmail.com.
Each published version keeps its own identifier, effective date and content fingerprint. A version that was accepted with a proposal always remains retrievable at /proposal-privacy?version=0.1-draft.