Legal

Privacy Policy

How we handle personal data across our website and platform — and the rights you have over it.

Last updated: 17 July 2026

This Privacy Policy explains how Nirvet Ltd ("Nirvet", "we", "us") collects, uses, discloses, and safeguards personal data when you visit our website, contact us, or use the Nirvet platform. We act as a data controller for personal data we collect directly, and as a data processor for personal data our customers process through the platform under their own agreements.

Data we collect

We collect only what we need to provide and improve our services:

  • Contact data — name, email, company, and the content of any message you send us through the site or by email.
  • Account data — for platform users: identity, role, and authentication metadata (we never store passwords in plain text).
  • Usage & technical data — IP address, device/browser type, and audit logs of actions taken within the platform, for security and accountability.
  • Customer telemetry — security data our customers ingest is processed strictly on their behalf, under their control and their retention rules.

How we use it

We use personal data to respond to enquiries, provide and secure the platform, meet legal and regulatory obligations, and improve our services. We do not sell personal data, and we do not use customer telemetry to train models.

Legal bases

Where the GDPR or comparable law applies, we rely on: performance of a contract (providing the service), legitimate interests (securing and improving it), consent (where required, e.g. optional communications), and legal obligation (compliance and record-keeping).

Sharing & sub-processors

We share personal data only with vetted sub-processors that support our operations (e.g. hosting and infrastructure), bound by contractual data-protection terms; when required by law or to protect rights and safety; and with your direction. A current list of sub-processors is available to customers on request.

International transfers

Where data is transferred across borders, we use appropriate safeguards such as Standard Contractual Clauses. For customers with data-residency requirements, the platform supports regional, private-cloud, on-premises, and air-gapped deployment so data can stay within your chosen jurisdiction.

Retention

We keep personal data only as long as necessary for the purposes above or as required by law. Customer telemetry is retained per the retention rules the customer configures, and deletion is enforced and auditable.

Security

Data is encrypted in transit (TLS 1.3) and at rest (AES-256). Access is authorised against policy with a full audit trail, and enterprise tenants may use customer-managed keys. We apply the same security posture to our own operations that we help customers enforce.

Your rights

Subject to applicable law, you may request access to, correction of, deletion of, or restriction of your personal data, and object to certain processing or request portability. To exercise any right, contact us at privacy@nirvet.com. You also have the right to lodge a complaint with your local data-protection authority.

Changes

We review this policy periodically and will update the date above when we make material changes. Significant changes will be communicated to affected customers.

Contact

For privacy questions or to reach our data-protection contact, email privacy@nirvet.com, or reach us via our contact page. General enquiries: contact@nirvet.com.