01Introduction
NIXFEO is committed to protecting your personal data and complying with the General Data Protection Regulation (GDPR) and all applicable European data protection laws.
This privacy policy describes how we collect, use, store, and protect your personal information when you use our website and services. As a European company based in Estonia, data protection is at the core of our architecture and operations.
02Data collection
We collect the following categories of personal data:
Identity information
First name, last name, and job title provided when creating an account or booking a consultation.
Contact information
Email address, phone number, and company name used for communication and service delivery.
Professional information
Company name, industry, role, and project details shared during onboarding or consultations.
Technical data
IP address, browser type, device information, pages visited, and interaction data collected automatically for analytics and security purposes.
Playground data
The interactive playground on our home page works without any account or personal data: the idea you type is sent to our servers, used once to generate an architecture proposal, and is not stored. The generation itself runs on a European AI provider (Mistral AI, France), so your request is not transferred outside the EU.
To protect that free service from automated abuse, we keep a salted, irreversible fingerprint of your IP address — never the address itself — together with a timestamp. These records are deleted after 7 days and are used for nothing else.
If, and only if, you ask us to e-mail you the detailed version, we store your e-mail address, the idea you described and the proposal generated for it, so we can send the document and answer any follow-up. Whether you agree to be contacted about your project is a separate, optional choice. We never sell this data, never add you to a mailing list without asking, and delete it on request — see "Your rights" below.
Chat assistant
Our chat assistant loads only after you have answered the cookie banner, and opens no connection until you click it. Before your first message it tells you what it does and asks you to agree. If you never open it, nothing is sent and nothing is stored.
Once you start a conversation, your messages are sent to a European AI provider (Mistral AI, France) to produce an answer, so the exchange is not transferred outside the EU. If you give the assistant your name, e-mail or phone number, we keep them so we can reply.
The assistant sets no cookies. It stores three things in your own browser, on this domain: a conversation identifier for the session, your last 50 messages, and the date you agreed — plus your contact details if you provided any. The conversation history and those contact details expire after 30 days and are then discarded automatically. There is no advertising or third-party tracking in it of any kind.
You can erase all of it right now, without hunting through your browser settings. This clears what is stored on this device only — to have the conversation itself deleted on our side, write to hello@nixfeo.com and a person will handle it.
The assistant has stored nothing in this browser.
03Data usage
We use your personal data for the following purposes:
- Service provision and improvement: to deliver, maintain, and improve our AI agents, automations, and related services.
- Communication: to respond to your inquiries, send service updates, and provide technical support.
- Personalization: to customize your experience and provide relevant recommendations based on your usage patterns.
- Legal compliance: to comply with legal obligations, resolve disputes, and enforce our agreements.
04Hosting and security
All data is hosted exclusively in Estonia and the European Union, in secure, certified data centers operated by NIXFEO.
We implement the following security measures to protect your data:
- Encryption: end-to-end encryption for data in transit (TLS 1.3) and at rest (AES-256).
- Access controls: role-based access control (RBAC) with multi-factor authentication for all administrative access.
- Monitoring: continuous security monitoring, intrusion detection, and automated alerting systems.
- Backups: regular encrypted backups with geographic redundancy within the EU.
05Your rights
Under the GDPR, you have the following rights regarding your personal data:
- Right of access (Article 15): you have the right to obtain confirmation that personal data concerning you is being processed and to access that data.
- Right to rectification (Article 16): you have the right to request correction of inaccurate personal data.
- Right to erasure (Article 17): you have the right to request deletion of your personal data ("right to be forgotten"). We provide one-click deletion.
- Right to restriction (Article 18): you have the right to request restriction of processing of your personal data under certain conditions.
- Right to portability (Article 20): you have the right to receive your personal data in a structured, commonly used format and to transfer it to another controller.
- Right to object (Article 21): you have the right to object to the processing of your personal data for direct marketing or based on legitimate interest.
To exercise any of these rights, contact us at hello@nixfeo.com. We will respond within 30 days.
06Cookies
Necessary cookies
These cookies are essential for the website to function properly. They include session cookies, security tokens, and preferences. These cookies cannot be disabled.
Analytics cookies
We use analytics tools to understand how visitors interact with our site. These cookies collect information such as pages visited, time spent on the site, and referral sources. All data is anonymized.
You can manage your cookie preferences at any time through our consent banner displayed on your first visit. You can also configure cookie settings in your browser.
07Data transfer
Your personal data is processed and stored exclusively in Estonia and the European Union. We do not transfer personal data to countries outside the EU/EEA.
All our infrastructure, including servers, databases, and backup systems, is located in EU data centers. This ensures full compliance with GDPR data transfer requirements.
08Contact
For any questions about this privacy policy or to exercise your rights, contact our Data Protection Officer (DPO):
DPO contact: hello@nixfeo.com
Address: NIXFEO OÜ, Harju maakond, Kesklinna linnaosa, Pärnu mnt 139e/2-8, 11317 Tallinn, Estonia
Phone: +33 9 70 40 19 50
09Supervisory authority
If you believe your data protection rights have been violated, you have the right to lodge a complaint with the Estonian Data Protection Authority:
Andmekaitse Inspektsioon (Estonian Data Protection Authority)
Tatari 39, 10134 Tallinn, Estonia
Website: www.aki.ee
Email: info@aki.ee