Privacy Policy

Last updated: 2 September 2026

This Privacy Policy explains what personal data Nerva IR collects, why, and what rights you have. The data controller is HardSoft Security. We handle personal data in line with the EU General Data Protection Regulation (GDPR) and Spanish data-protection law.

1. Data we collect

  • Account data: your email address, a hashed (never plaintext) password, email-verification and password-reset state, your plan, and organization membership if you belong to a team.
  • Content you submit for analysis: the text, URLs, or screenshots you send us to check, plus any details you provide while working through an incident. Screenshots are processed in memory and are not retained after processing. We store a one-way hash of submitted content for de-duplication, along with the analysis result and the guidance produced.
  • Monitoring data: email addresses you add to breach monitoring, and the breach records matched against them.
  • Usage and technical data: request logs, approximate timing, rate-limit counters, a coarse device fingerprint for anonymous abuse-prevention, and basic diagnostics needed to run and secure the Service.
  • Payment data: if you buy a paid plan, our third-party payment processor collects and processes your payment details. We receive only a customer and subscription identifier and your plan status — never your full card number.

2. How we use it

  • To provide the Service: analyse what you submit, generate guidance, track your incidents, run breach monitoring, and manage your account and any team.
  • To keep the Service secure and reliable: authentication, rate limiting, abuse prevention, debugging, and fraud prevention.
  • To communicate with you: verification, password reset, security or breach alerts you have opted into, and replies to messages you send us.
  • To handle billing for paid plans.
  • To meet legal obligations and to establish, exercise, or defend legal claims.

3. Legal bases

We rely on: performance of our contract with you (providing the Service you signed up for); our legitimate interests (securing the Service, preventing abuse, improving reliability); your consent where we ask for it (for example, optional monitoring of a specific address); and compliance with legal obligations.

4. Sharing and sub-processors

We do not sell your personal data and we do not use it for advertising.

We share the minimum necessary data with service providers who process it on our behalf:

  • Payment processing: our third-party payment processor.
  • Threat intelligence and reputation lookups: third-party threat-intelligence and reputation providers. URLs and domains are checked against these services; we strip credentials and tokens from URLs before any external lookup.
  • Breach monitoring: a third-party breach-monitoring provider, queried with the email addresses you ask us to monitor.
  • Email delivery: our own mail infrastructure.
  • Hosting and infrastructure providers that run our servers and database.

We may also disclose data if required by law or to protect the rights, safety, or property of users, the public, or us.

5. What we deliberately avoid

  • We do not retain screenshots after processing.
  • We do not send unnecessary personal data to third-party scanners, and we strip secrets from URLs before external checks.
  • Password-reset and verification endpoints never reveal whether an account exists.

6. Retention

We keep account data for as long as your account is active. Incident and analysis history is kept while your account exists so you can refer back to it; you can delete individual items where the Service offers that option. Rate-limit counters and short-lived security data expire automatically. When you close your account we delete or anonymise your personal data within a reasonable period, except where we must retain certain records to comply with the law or resolve disputes.

7. Security

Passwords are hashed with bcrypt. Access uses signed, expiring tokens. Traffic is encrypted in transit. Access to production data is limited to what is needed to operate the Service. No system is perfectly secure, and we cannot guarantee absolute security.

8. International transfers

Some sub-processors may process data outside the European Economic Area. Where that happens, we rely on an adequacy decision or on appropriate safeguards such as the European Commission's Standard Contractual Clauses.

9. Cookies and local storage

We use strictly necessary storage only: an authentication session, an anonymous-session identifier used for abuse-prevention on public endpoints, and local preferences such as your language and theme. We do not use advertising or third-party tracking cookies.

10. Your rights

Subject to the conditions in the GDPR, you can request access to your data, correction, deletion, restriction or objection to processing, and portability, and you can withdraw consent at any time where processing is based on consent. To exercise these rights, contact us through the contact page. You also have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD) or your local supervisory authority.

11. Children

The Service is not directed to children. You must be at least 18, or the age of majority where you live, to use it.

12. Changes

We may update this Policy. If a change is material we will take reasonable steps to notify you. The "last updated" date above always reflects the current version.

13. Contact

For any privacy question or request, use the contact page on this site.