Privacy Policy

Last Updated: September 27, 2025

1. Introduction

Nortilus Analytics ("we," "our," or "us") is committed to protecting your privacy and personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website, use our services, applications, or products (collectively, the "Services"). Please read this Privacy Policy carefully. If you do not agree with the terms of this Privacy Policy, please do not access the Services.

2. Information We Collect

2.1. Personal Information

We may collect personal information that you voluntarily provide to us when you:

  • Register for an account
  • Subscribe to our services
  • Contact us for support or inquiries
  • Participate in surveys or feedback forms
  • Sign up for newsletters or marketing communications

This personal information may include:

  • Name and contact information (email address, phone number)
  • Account credentials (username, password)
  • Billing and payment information (processed through Stripe)
  • Professional information (company name, job title, industry)
  • Communication preferences

2.2. Automatically Collected Information

When you access our Services, we may automatically collect certain information about your device and usage patterns, including:

  • IP address and geolocation data
  • Browser type and version
  • Operating system
  • Device identifiers
  • Pages visited and time spent on our Services
  • Referring website or application
  • Click-through and navigation patterns
  • Search queries and interactions with our Services

2.3. Cookies and Tracking Technologies

We use cookies, web beacons, and similar tracking technologies to enhance your experience and collect information about how you use our Services. These technologies help us:

  • Remember your preferences and settings
  • Authenticate your account
  • Analyze website traffic and usage patterns
  • Improve our Services and user experience
  • Provide personalized content and recommendations

You can control cookie settings through your browser preferences, but disabling cookies may affect the functionality of our Services.

3. How We Use Your Information

We use the information we collect for the following purposes:

3.1. Service Provision

  • Create and manage your account
  • Process subscriptions and payments
  • Provide access to our research, analytics, and market data
  • Deliver personalized content and recommendations
  • Send service-related communications and updates

3.2. Communication

  • Respond to your inquiries and provide customer support
  • Send newsletters, market insights, and promotional materials (with your consent)
  • Notify you about changes to our Services or policies
  • Send important account and billing notifications

3.3. Improvement and Analytics

  • Analyze usage patterns to improve our Services
  • Conduct research and development
  • Monitor and analyze trends in cyclical markets
  • Enhance security and prevent fraud
  • Comply with legal obligations under Italian and EU law

4. Information Sharing and Disclosure

We do not sell, trade, or rent your personal information to third parties. We may share your information in the following limited circumstances:

4.1. Service Providers

We may share your information with trusted third-party service providers who assist us in operating our Services, including:

  • Payment Processing: Stripe for secure payment processing
  • Email Services: Resend for transactional and marketing emails
  • Authentication & Database: Supabase for user authentication and database services
  • Hosting & Infrastructure: Vercel for website hosting and deployment services
  • Analytics: Web analytics providers to understand usage patterns
  • Cloud Services: Additional hosting and infrastructure providers as needed

These service providers are contractually obligated to protect your information and use it only for the purposes we specify, in compliance with Italian data protection laws.

4.2. Legal Requirements

We may disclose your information if required to do so by Italian law or in response to:

  • Valid legal processes (subpoenas, court orders)
  • Government requests or investigations by Italian authorities
  • Compliance with Italian and EU regulatory requirements
  • Protection of our rights, property, or safety
  • Prevention of fraud or illegal activities

4.3. Business Transfers

In the event of a merger, acquisition, or sale of all or part of our business, your information may be transferred to the acquiring entity, subject to the same privacy protections outlined in this policy and Italian law requirements.

5. Data Security

We implement appropriate technical and organizational security measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction, in accordance with Italian data protection standards. These measures include:

  • Encryption of data in transit and at rest
  • Secure authentication and access controls
  • Regular security assessments and updates
  • Employee training on data protection practices
  • Incident response and breach notification procedures

However, no method of transmission over the internet or electronic storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.

6. Data Retention

We retain your personal information for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by Italian law. Specifically:

  • Account Information: Retained while your account is active and for a reasonable period after account closure
  • Transaction Records: Retained for accounting and tax purposes as required by Italian law
  • Communication Records: Retained for customer service and legal compliance purposes
  • Analytics Data: May be retained in aggregated, anonymized form for business intelligence

7. Your Rights and Choices

7.1. Access and Control

Under Italian and EU law, you have the right to:

  • Access and review your personal information
  • Update or correct inaccurate information
  • Delete your account and associated data
  • Export your data in a portable format
  • Opt out of marketing communications

7.2. Communication Preferences

You can manage your communication preferences by:

  • Updating your account settings
  • Using unsubscribe links in our emails
  • Contacting us directly at support@nortilus.com

7.3. Cookie Management

You can control cookies through your browser settings and opt out of certain tracking technologies. Note that disabling cookies may affect the functionality of our Services.

8. International Data Transfers

Our Services utilize infrastructure provided by Supabase, Vercel and Stripe, which may involve data processing in various locations. When we transfer personal data outside the European Economic Area (EEA), we ensure appropriate safeguards are in place, including:

  • Standard contractual clauses approved by the European Commission
  • Adequacy decisions by the European Commission
  • Other legally recognized transfer mechanisms under Italian and EU law

9. Children's Privacy

Our Services are not intended for individuals under the age of 18. We do not knowingly collect personal information from children under 18. If we become aware that we have collected personal information from a child under 18, we will take steps to delete such information promptly, in accordance with Italian law.

10. Third-Party Links and Services

Our Services may contain links to third-party websites or integrate with third-party services. This Privacy Policy does not apply to those third-party services. We encourage you to review the privacy policies of any third-party services you access through our Services.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of any material changes by:

  • Posting the updated policy on our website
  • Sending you an email notification
  • Providing notice through our Services

Your continued use of our Services after any changes indicates your acceptance of the updated Privacy Policy.

12. Contact Information

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:

Nortilus Analytics

Email: support@nortilus.com

Subject Line: Privacy Policy Inquiry

13. GDPR Compliance (For EU Residents)

If you are a resident of the European Union (including Italy), you have additional rights under the General Data Protection Regulation (GDPR) - yes, all that bureaucratic nonsense that makes everything more complicated but supposedly protects your data:

  • Right to Access: Request copies of your personal data
  • Right to Rectification: Request correction of inaccurate data
  • Right to Erasure: Request deletion of your personal data (the "right to be forgotten")
  • Right to Restrict Processing: Request limitation of data processing
  • Right to Data Portability: Request transfer of your data
  • Right to Object: Object to certain types of processing
  • Right to Withdraw Consent: Withdraw consent for data processing

To exercise these rights, please contact us at support@nortilus.com with "GDPR Request" in the subject line.

14. Legal Basis for Processing (GDPR)

We process your personal data based on the following legal grounds under Italian and EU law:

  • Contract Performance: To provide our Services and fulfill our contractual obligations
  • Legitimate Interests: To improve our Services, prevent fraud, and conduct business operations
  • Consent: For marketing communications and optional features (where applicable)
  • Legal Compliance: To comply with applicable Italian and EU laws and regulations