Privacy Policy

Last updated: June 6, 2026

Effective Date: June 6, 2026 | Version 2.0

1. Introduction

Nelieo ("Nelieo," "we," "us," or "our") is committed to protecting your privacy and ensuring transparency in how we collect, use, and safeguard your personal data. This Privacy Policy explains our practices regarding data collection and processing when you register for our waitlist and use our related services for the Nelieo Substrate Protocol (NSP) (collectively, the "Services").

NSP is designed to connect AI agents directly to application memory runtimes, converting legacy software and web applications into robust APIs. This policy outlines how we handle early access requests and waitlist participant data.

Key Principles:

  • Transparency: We clearly communicate what data we collect and why
  • Minimal Collection: We only collect data necessary for waitlist management
  • User Control: You have full control over your early-access profile
  • Security First: We employ industry-leading, zero-trust encryption measures
  • Compliance: We comply with GDPR, CCPA, and other global privacy regulations

2. Data Controller

The controller within the meaning of data protection laws, in particular the EU General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA), is:

Nelieo

Country: United States

Email: triunex.shorya@gmail.com

Data Protection Officer: triunex.work@gmail.com

Website: https://nelieo.com

For any questions regarding this Privacy Policy or our data processing practices, please contact our Data Protection Officer using the contact details above.

3. Data We Collect

During the current early access and waitlist phase, we collect minimal personal data to manage access requests:

3.1 Information You Provide

Data Type Examples Purpose
Waitlist Registration Full name, email address, company name (optional) Waitlist registration, authentication, communication, updates
Development Case Intended development focus, description of agents being built Early access screening, protocol optimization
Communication Data Support emails, feedback, survey responses Customer support, service improvement

3.2 Automatically Collected Information

  • Device Information: IP address, browser type, operating system, device identifiers
  • Usage Data: Pages visited, interaction patterns, session duration on our landing page
  • Location Data: General location based on IP address (country/region level)
  • Cookies & Tracking: See Section 9 for detailed information
  • Log Data: Server logs, performance metrics, and firewall events

3.3 Information from Third Parties

In our current waitlist-only configuration, we do not actively collect personal data from third-party APIs or social logins.

5. How We Use Your Data

We use the collected information for the following purposes:

Waitlist Operations

  • Manage early access registry
  • Screen developer use cases
  • Prevent bot submissions
  • Provide customer support

Communication

  • Send registration confirmation and updates
  • Notify users when early access is granted
  • Send updates regarding the Nelieo Substrate Protocol
  • Respond to inquiries and feedback

Improvement & Analytics

  • Analyze usage patterns and trends
  • Optimize landing page experience
  • Identify desired platform integrations
  • Conduct statistical research

Legal & Security

  • Comply with legal obligations
  • Protect against security threats and spam
  • Enforce our terms of service
  • Secure our Firestore/database backups

6. Data Sharing & Processors

We do not sell your personal data. We may share your information with the following categories of recipients:

6.1 Service Providers (Processors)

Provider Service Data Shared Location Safeguards
Google Cloud / Firebase Cloud hosting, Firestore database, infrastructure Waitlist details, device metadata USA, EU DPA, SCCs, ISO 27001, SOC 2
Resend Email delivery Email address, name, message body USA DPA, TLS encryption in transit
Sentry Error monitoring Error logs, client-side metadata USA DPA, automatic data scrubbing

6.2 Other Disclosures

  • Legal Requirements: When required by law, court order, or government request
  • Business Transfers: In connection with mergers, acquisitions, or asset sales
  • Protection: To protect our rights, privacy, safety, or property
  • With Consent: When you explicitly authorize disclosure

7. Data Retention

We retain your personal data only for as long as necessary to fulfill waitlist coordination and communications, unless a longer retention period is required by law.

Data Type Retention Period Rationale
Waitlist details Duration of beta + 12 months Early access screening, communications
Marketing / Update consent records 3 years after last interaction Compliance demonstration
Server & database logs 14 days (IP anonymized after 24h) Security monitoring, rate limiting
Support communications 3 years Quality assurance, legal protection

Upon deletion request, data is removed from active systems within 30 days and from database backups within 90 days.

8. Your Rights as a Data Subject

Depending on your location, you have the following rights regarding your personal data:

πŸ“‹

Right to Access (Art. 15 GDPR)

Request a copy of your personal data we hold and information about how we process it.

✏️

Right to Rectification (Art. 16 GDPR)

Correct any inaccurate or incomplete personal data we hold about you.

πŸ—‘οΈ

Right to Erasure (Art. 17 GDPR)

Request deletion of your personal data under certain circumstances ("right to be forgotten").

⏸️

Right to Restriction (Art. 18 GDPR)

Limit how we use your data if you contest its accuracy or object to processing.

πŸ“¦

Right to Data Portability (Art. 20 GDPR)

Receive your data in a structured, commonly used format and transmit it to another controller.

🚫

Right to Object (Art. 21 GDPR)

Object to processing based on legitimate interests, including profiling and direct marketing.

πŸ”„

Right to Withdraw Consent

Withdraw consent at any time where processing is based on consent (does not affect lawfulness of prior processing).

βš–οΈ

Right to Lodge a Complaint

File a complaint with your local data protection authority if you believe we've violated your rights.

8.1 How to Exercise Your Rights

To exercise any of these rights, please contact us at triunex.shorya@gmail.com with:

  • Your full name and email address associated with your account
  • Clear description of the right you wish to exercise
  • Any supporting information to verify your identity

Response Time: We will respond to your request within 30 days (GDPR) or 45 days (CCPA) of verification.

8.2 Supervisory Authorities

You have the right to lodge a complaint with your local supervisory authority:

10. International Data Transfers

As a global service, we may transfer your personal data to countries outside your jurisdiction, including to the United States where our primary servers are located.

10.1 Transfer Mechanisms

For transfers from the EU/EEA to third countries, we implement appropriate safeguards:

Recipient Country Safeguard Mechanism Description
United States Standard Contractual Clauses (SCCs) EU Commission-approved model clauses for data transfers
United Kingdom Adequacy Decision EU Commission has recognized UK's adequate protection level
Switzerland Adequacy Decision Recognized as providing adequate data protection

10.2 Additional Safeguards

  • Encryption: All data transfers are encrypted using TLS 1.3
  • Data Processing Agreements: Binding contracts with all processors
  • Security Measures: Technical and organizational measures meeting EU standards
  • Regular Audits: Compliance assessments of transfer mechanisms

You can request copies of the safeguards we have in place by contacting triunex.shorya@gmail.com.

9. Cookies & Tracking Technologies

We use cookies and similar tracking technologies to enhance your experience, analyze usage, and deliver personalized content.

9.1 Types of Cookies We Use

Category Purpose Examples Duration Legal Basis
Strictly Necessary Essential for website functionality Session ID, authentication tokens, security Session or 90 days Legitimate interest
Performance Analytics and site performance Google Analytics, page load times 14 months Consent (optional)
Functional Remember preferences and settings Language, theme, display preferences 12 months Consent (optional)
Targeting/Advertising Deliver relevant ads and marketing Advertising IDs, retargeting pixels 12 months Consent (optional)

9.2 Third-Party Cookies

We work with third-party services that may set their own cookies:

  • Google Analytics: Website analytics and user behavior tracking
  • Firebase: Security auditing, anti-bot analysis, and DDoS protection

9.3 Managing Cookie Preferences

You can control cookies through:

  • Cookie Consent Banner: Adjust preferences through our cookie consent tool
  • Browser Settings: Configure your browser to reject or delete cookies
  • Opt-Out Tools: Use industry opt-out mechanisms like DAA Opt-Out or Your Online Choices

⚠️ Note: Disabling certain cookies may limit functionality and prevent you from using some features of our Services.

11. Security Measures

We implement comprehensive technical and organizational measures to protect your personal data against unauthorized access, loss, destruction, or alteration.

11.1 Technical Safeguards

πŸ”’ Database Encryption

  • AES-256-GCM Encryption: All waitlist registration fields (name, email, company, developer focus) are encrypted on the server before write operations to the Firestore database.
  • TLS 1.3 Transmission: Secure SSL/TLS tunnels encrypt data in transit between browser clients and servers.

πŸ›‘οΈ Access Controls

  • Role-based access control (RBAC)
  • Multi-factor authentication (MFA)
  • API token validation for write requests

πŸ“Š Monitoring

  • Vulnerability tracking
  • Intrusion detection filters
  • Server logging (with scrubbed PII)

πŸ’Ύ Backup & Recovery

  • Regular encrypted database backups
  • Failover servers
  • Recovery testing

11.2 Organizational Measures

  • Data Minimization: We only collect what is necessary to manage waitlist registrations.
  • Access Logging: Detailed security logs are maintained.
  • Vendor Management: We verify the compliance of infrastructure providers like Google Cloud and Resend.
  • Incident Response: Documented data breach response protocols.

11.3 Certifications & Compliance

GDPR Compliant CCPA Compliant

⚠️ Data Breach Notification: In the event of a data breach affecting your personal data, we will notify you and relevant supervisory authorities within 72 hours as required by GDPR Article 33.

12. Third-Party Services

Our Services integrate with various third-party platforms. When you use these integrations, additional privacy policies may apply.

12.1 Analytics & Performance

Google Analytics

Provider: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA

Purpose: Website traffic analysis and landing page performance metrics

Data Collected: IP address (anonymized), device info, pages visited, session duration

Retention: 14 months (automatically deleted)

Opt-Out: Google Analytics Opt-out Browser Add-on

Privacy Policy: Google Privacy Policy

12.2 Communication & Email

Resend

Provider: Resend, Inc.

Purpose: Transactional waitlist notifications and onboarding updates

Data Shared: Name, email address, confirmation status

Privacy Policy: Refer to Resend's Privacy Policy on their official website.

12.3 Fonts & Typography

Google Fonts

Purpose: Display web fonts for consistent typography

Data Shared: IP address, browser information (to fetch font files)

Privacy Policy: Google Privacy Policy

13. Children's Privacy

Our Services are not intended for individuals under the age of 16 (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect personal data from children.

13.1 Age Verification

  • Waitlist registration is restricted to individuals 16 years or older
  • We require users to confirm they meet the minimum age requirement

13.2 Parental Rights

If you believe we have inadvertently collected data from a child:

  • Contact us immediately at triunex.shorya@gmail.com
  • We will delete the data within 48 hours of verification
  • Parents can request access to their child's data

COPPA Compliance (US): We comply with the Children's Online Privacy Protection Act and do not collect data from children under 13.

14. California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have specific rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA).

14.1 California Consumer Rights

  • Right to Know: Request disclosure of categories and specific pieces of personal information we collect
  • Right to Delete: Request deletion of your personal information (subject to exceptions)
  • Right to Correct: Request correction of inaccurate personal information
  • Right to Opt-Out: Opt-out of the "sale" or "sharing" of personal information
  • Right to Limit: Limit use of sensitive personal information
  • Right to Non-Discriminrimination: Not receive discriminatory treatment for exercising your rights

14.2 Categories of Personal Information

In the past 12 months, we have collected the following categories of personal information for waitlist coordination:

  • Identifiers (name, email address, company name, IP address)
  • Internet activity (interaction behavior with our landing page)

14.3 Sale of Personal Information

We do not sell your personal information. We do not and will not sell your personal data to third parties for monetary or other valuable consideration.

14.4 Exercising California Rights

To submit a request, contact us at:

  • Email: triunex.shorya@gmail.com
  • Subject Line: "California Privacy Rights Request"
  • Include: Your name, email, and specific right you wish to exercise

Verification: We will verify your identity before processing requests. Response within 45 days.

14.5 Authorized Agent

You may designate an authorized agent to make a request on your behalf. The agent must provide proof of authorization.

14.6 "Shine the Light" Law

California Civil Code Section 1798.83 permits California residents to request information about disclosures to third parties for direct marketing. We do not share personal information with third parties for their direct marketing purposes.

15. GDPR Compliance (EU/EEA/UK)

For individuals in the European Union, European Economic Area, and United Kingdom, we comply fully with the General Data Protection Regulation (GDPR).

15.1 Lawful Basis Summary

15.2 Data Protection Officer

You can contact our Data Protection Officer at: triunex.work@gmail.com

15.3 Representative in the EU

If required under GDPR Article 27, we will appoint an EU representative and provide contact details here.

15.4 Cross-Border Transfers

We use Standard Contractual Clauses (SCCs) approved by the European Commission for transfers outside the EU/EEA. See Section 10 for details.

15.5 Right to Lodge a Complaint

You have the right to lodge a complaint with a supervisory authority in your EU member state:

16. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.

16.1 Notification of Changes

  • Material Changes: We will notify you via email and/or prominent notice on our website at least 30 days before changes take effect
  • Minor Changes: Updated "Last Updated" date at the top of this policy
  • Version History: Available upon request

16.2 Your Continued Use

Your continued use of our Services after the effective date of changes constitutes acceptance of the updated policy. If you do not agree to changes, please discontinue use and contact us to delete your account.

16.3 Archived Versions

Previous versions of this Privacy Policy are archived and available upon request at triunex.shorya@gmail.com.

17. Contact Information

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

General Privacy Inquiries

Email: triunex.shorya@gmail.com

Response Time: Within 3 business days

Data Protection Officer

Email: triunex.work@gmail.com

For GDPR-related matters

Data Subject Rights Requests

Email: triunex.shorya@gmail.com

Subject: "Data Rights Request"

17.1 Request Response Time

  • GDPR (EU/UK): Within 30 days (may extend to 60 days for complex requests)
  • CCPA (California): Within 45 days (may extend to 90 days)
  • General Inquiries: Within 3 business days

Commitment to Privacy

At Nelieo, we believe privacy is a fundamental right. We are committed to protecting your personal data, providing transparency in our practices, and giving you control over your information. We continuously review and improve our privacy practices to ensure they meet the highest standards.

This Privacy Policy was last reviewed and updated on June 6, 2026. We conduct regular privacy impact assessments and maintain detailed records of processing activities as required by GDPR Article 30.