Privacy policy
This explains what personal data Noksaro collects when you use noksaro.com, why, who else handles it, how long it is kept, and the rights you have.
Who we are
Noksaro is responsible for your personal data (the "controller", in the words of the GDPR).
Noksaro
Koraalerf 24
6413 LV Heerlen
The Netherlands
Chamber of Commerce (KvK): 84806214
VAT: NL004250775B92
Email: contact@noksaro.com
What we collect
When you create an account
- Your email address, and your password, stored only as a one-way hash (bcrypt) so that we cannot read it.
- Your plan, whether your email address is confirmed, and your email preferences.
When you run checks
The websites you add, the business description Noksaro builds from their public pages, the questions asked, the answers the AI assistants gave, and the research, plan and alerts that follow. This is mostly information about businesses rather than about you, but it is linked to your account.
If you use the crawler report
When you paste or upload a server log, we read it to count visits from known AI crawlers. We keep only those counts: which crawler, which day, how many visits and errors, and the most-requested paths. The log itself, including any visitor IP addresses in it, is not stored.
If you pay
Payments are handled by Stripe. Your card details go to Stripe and never reach our servers. We store the identifiers Stripe gives us for your customer record and subscription, your plan's status, and its renewal or end date.
If you invite a teammate
The email address you invite, so that we can send the invitation and give them access.
When you email us
If you write to support@, contact@, admin@ or owner@noksaro.com, we keep your message, any attachments and our replies, so that we can answer and follow up. Mail sent to any other @noksaro.com address is not kept.
When you visit the site
Our web server logs each request: the IP address, the time, the page requested and the browser's user agent. We use these logs to keep the service secure and working, and they are deleted after 14 days.
Cookies
One cookie keeps you signed in. It cannot be read by scripts on the page and expires after 30 days. It is needed for the service to work, so it does not need your permission.
With your permission, and only after you click Accept, Google Analytics sets two more: _ga and _ga_…. They last up to two years and tell us how many people visit and which pages are useful. Google Signals and advertising features are switched off, so the data is not used to follow you across devices or to show you ads. If you click Reject, nothing is loaded from Google and no analytics cookie is set.
You can change your choice at any time with Cookie settings, linked at the bottom of the website's pages, in the app's sidebar and in Settings.
The site also keeps three small settings in your browser's storage: your cookie choice, that you dismissed an announcement, and a flag that reloads the page once if it fails to load after an update. There are no advertising cookies, and nothing is shared with advertisers.
Why we use it, and on what basis
- To provide the service you signed up for: your account, checks, reports, billing, and the emails that go with them, such as confirming your address or resetting a password. Basis: performing our contract with you.
- To report on your own sites: a digest when something has changed, and alerts. Basis: performing our contract with you. Every such email has a link to stop them.
- One follow-up after a check: if you ran a check, confirmed your email address and have not opted out, we send one email about it, once. Basis: our legitimate interest in following up with people who have used the service. It has an unsubscribe link.
- To answer your email: the messages you send us and our replies. Basis: our legitimate interest in answering the people who write to us, or performing our contract with you if you are a customer.
- To understand how the site is used: Google Analytics, only if you accept. Basis: your consent, which you can withdraw at any time with Cookie settings.
- To keep the service secure and working: server logs, and a record of the actions our staff take on accounts. Basis: our legitimate interest in running a safe service.
- To meet legal obligations: keeping billing records as Dutch tax law requires.
We do not sell personal data, and we do not use it for advertising. We make no automated decisions about you that have legal or similarly significant effects.
Who else handles it
We use a small number of service providers, each only for the purpose listed:
| Provider | What they do | Where |
|---|---|---|
| Vultr (The Constant Company, LLC) | Hosts our servers and database | Servers in Frankfurt, Germany |
| Stripe | Processes payments | Ireland and the United States |
| SendGrid (Twilio) | Sends our emails, and receives the ones sent to us | United States |
| Google (Google Analytics) | Measures visits to the site, only if you accept analytics cookies | United States |
| OpenAI, Anthropic, Perplexity and Google | AI models that analyse the website being checked and answer the questions a check asks | United States |
What we send the AI providers is the website's public content, the business description built from it, and the questions asked.
Some of these providers are based outside the European Economic Area. Where personal data is transferred there, it is protected by the safeguards the GDPR requires, such as the European Commission's Standard Contractual Clauses or the EU-US Data Privacy Framework.
If you share a report link, anyone with that link can open that report, so treat it like a password.
How long we keep it
- Your account and everything attached to it: until you delete your account. Deleting it in Settings removes your account, sites, checks and reports straight away.
- Billing records: seven years, as Dutch tax law requires.
- Server logs: 14 days.
- Emails you send us, and our replies: until the conversation is no longer needed, or sooner if you ask us to delete them.
- Analytics data: kept by Google for the retention period set in our Google Analytics account, at most 14 months.
Your rights
Under the GDPR you can ask to see the personal data we hold about you, have it corrected or deleted, restrict or object to how we use it, and receive it in a portable format. Two of these you can do yourself in Settings: download everything we hold as a file, and delete your account. For anything else, email contact@noksaro.com and we will reply within one month.
If you think we have handled your data wrongly, you can complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens. We would be glad of the chance to put it right first.
Security
The site is served only over HTTPS. Passwords are stored as one-way hashes. Access to our servers and database is limited to the people who run Noksaro.
Children
Noksaro is a business service and is not meant for anyone under 16.
Changes to this policy
If we change this policy, we update the date at the top. If a change affects how we use data you have already given us, we email you before it takes effect.