Privacy policy

PRIVACY POLICY

Last modified: August 9, 2026

1. DATA CONTROLLER AND ROLES

The controller of personal data processed through NEKTIQA (nektiqa.com) is Mikita Klimuk, conducting business registered in the Central Register and Information on Economic Activity (CEIDG). Address: UL. GEN. TADEUSZA PEŁCZYŃSKIEGO 5/99, PL-01-471 WARSAW, POLAND. NIP: 5223245422 | REGON: 52404669200000. Contact: support@nektiqa.com.

NEKTIQA acts as controller for account, subscription, support, security, and system-log data. The Service is designed for testing publicly available pages only and does not offer a data-processing agreement under Article 28 GDPR.

2. CATEGORIES OF DATA WE PROCESS

  • Account and authentication data: name, email address, optional profile image, authentication method, and data needed to secure and operate sign-in.
  • Project and test data: project names, domains, tested URLs, release markers and notes, test results, reports, and summaries returned from testing publicly available pages.
  • Billing data: subscription status, plan, billing periods, purchase classification, and billing identifiers needed to operate the subscription. Payment-card details and tax IDs are handled by Stripe and are not stored by NEKTIQA.
  • Complimentary-access data: an optional recipient email and records needed to administer the access.
  • Support data: contact details and the information included in a support request.
  • Technical and security data: limited browser, device, and network-related information used to operate, secure, and protect the Service from abuse.

3. PURPOSES AND LEGAL GROUNDS

  • Performance of a contract (Article 6(1)(b) GDPR): creating and managing an account, authenticating users, delivering account verification and recovery messages, performing tests, maintaining projects and history, providing support requested by the user, and operating subscriptions.
  • Legal obligations (Article 6(1)(c) GDPR): invoicing, tax, accounting, and other legally required records.
  • Legitimate interests (Article 6(1)(f) GDPR): securing the Service, preventing fraud and abuse, enforcing rate limits, diagnosing failures, protecting legal claims, and maintaining reliable delivery and system records. These interests are assessed against users' rights and freedoms.

Support requests are not used to create marketing contacts. NEKTIQA does not currently send newsletters or marketing email through the support or authentication flows.

4. RECIPIENTS AND INTERNATIONAL TRANSFERS

NEKTIQA uses the following service providers where necessary:

  • Google: sign-in and performance testing.
  • Resend and Zoho Mail: transactional email and support correspondence.
  • Vercel, Upstash, and Cloudflare: hosting and technical infrastructure.
  • Stripe: payments, subscriptions, invoices, and refunds.

Some providers may process data outside the EEA. Where required, transfers rely on appropriate safeguards, such as Standard Contractual Clauses.

5. RETENTION AND DELETION

  • Account and project data: retained while the account is active. Following a deletion request, the account is disabled for a 14-day grace period and then deleted, subject to records that must be retained by law.
  • Full test reports: available for up to 30 days.
  • Test summaries: retained for up to 180 days.
  • Operational logs and security identifiers: up to 30 days.
  • Authentication tokens and abuse counters: until they are used or expire. Verification and recovery links expire after 30 minutes.
  • Support data: application metadata is retained for up to 7 days; correspondence may be retained where needed to handle a request, complaint, dispute, or legal claim.
  • Financial and accounting records: for the period required by applicable Polish tax and accounting law. Stripe may retain transaction records independently where required by law.

6. YOUR RIGHTS

Subject to the conditions in applicable law, you may request access, rectification, erasure, restriction, data portability, or object to processing based on legitimate interests. You may request a copy of available Account, project, and test data in JSON format by contacting support@nektiqa.com.

You may lodge a complaint with the President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warsaw, Poland.

7. SECURITY

NEKTIQA applies technical and organizational safeguards appropriate to the risk, including access controls, encrypted transmission, and data minimization. No Internet service can guarantee absolute security.

8. CHILDREN AND CHANGES TO THIS POLICY

The Service is not intended for persons under 16 years of age, and NEKTIQA does not knowingly collect their personal data. We may update this Policy when the Service, providers, or legal requirements change. The current version and modification date are published on this page.