Skip to content
nerlo.ai

Data processing register

This is a public summary of our record of processing activities under GDPR Article 30: the categories of personal data the Nerlo platform processes, the lawful basis for each, how long we keep it, who we share it with, and how to exercise your rights. It reflects the platform as actually built — where a subsystem is named in our design but not yet live, we say so rather than describe it as if it were.

What we process, and why

Each row lists a category of personal data, the fields it covers, and the GDPR Article 6 lawful basis we rely on.

Personal-data categories, the fields each covers, and the lawful basis for processing.
CategoryFieldsLawful basis
AuthenticationEmail, auth provider, and provider subject idArt. 6(1)(b) contract
Account identity (public)Opaque user id, display name, avatar, bioArt. 6(1)(b) contract
Localization preferencesTimezone, languageArt. 6(1)(b) contract
Email verification and sign-inEmail-verified state, and single-use SHA-256 token hashes for email-change and magic-link sign-in (short TTL)Art. 6(1)(b) contract
Consent recordsAnalytics and marketing opt-in flagsArt. 6(1)(a) consent
Demographics (opt-in)Country, role, company-size bucket, primary use caseArt. 6(1)(a) consent
ActivityLast-active timestamp, in-app notifications, dispatch logsArt. 6(1)(b) contract + Art. 6(1)(f) legitimate interest
Projects and saved contentProject names/notes, favorites, watchlist subscriptionsArt. 6(1)(b) contract
Notification preferencesPer-event-type channel settingsArt. 6(1)(a) consent + Art. 6(1)(b) contract
BillingStripe customer id (column present but not yet populated — the billing subsystem is not live)Art. 6(1)(b) contract + Art. 6(1)(c) legal obligation (once live)
Audit logs (autonomous AI decisions)Decision records referencing servers you authoredArt. 6(1)(c) legal obligation + Art. 6(1)(f) legitimate interest
Pseudonymized usage signalSHA-256 installer-token hash and country for install eventsArt. 6(1)(f) legitimate interest
Author identity (from public manifests)Author strings extracted from published package manifestsArt. 6(1)(f) legitimate interest

What we never process

How long we keep it

Data categories and their retention periods.
DataRetention
Account profile and demographicsUntil account deletion, plus a 14-day grace period
Magic-link and email-change tokensSingle-use, short TTL (email-change tokens expire in 24 hours)
In-app notifications90 days from creation
Audit records and AI decision logs24 months (audit-trail and evidence retention)
Pseudonymized install events24 months
Server-side HTTP access logs90 days

When you delete your account, audit records that reference your user id are retained per the schedule above with your email replaced by a non-recoverable placeholder, as permitted under Article 17(3) for legal obligations and the defence of legal claims.

Who we share it with

We rely on the sub-processors and separate controllers below. A complete and current sub-processor list will be published once our geo-IP provider is selected.

International transfers

Our compute and storage run on Google Cloud in the United States. Cross- border transfers are covered by the EU-U.S. Data Privacy Framework where the recipient is certified, together with Standard Contractual Clauses. UK data is handled under UK GDPR.

Your rights

You have the right to access, rectify, erase, restrict, and port your personal data, and to object to certain processing. Account settings let you edit your profile, change your email through a verified two-step flow, and request account deletion (with a 14-day grace period to cancel). For rights requests we cannot yet self-serve, contact us through the channel published in our privacy page.

This summary is maintained alongside our internal GDPR Article 30 register and updated as the platform changes. It describes current, verifiable practice; planned-but-unbuilt subsystems are labelled as such.