itsaura.ai
Home About Let’s talk Contact
Legal

Privacy Policy

Last updated: 28 July 2026

We handle a good deal of material that our clients would not want anywhere else, so we would rather be plain about what we do with data than reassuring about it. This policy covers our website and each of our three services in turn.

1Who we are

Nimbostratus B.V., operating under its registered trademark itsaura, is the controller for the personal data described in sections 2 and 3. We are registered in the Netherlands under KvK number 59740086 and we work from Amsterdam.

You can reach us through the contact form on this site. We have not appointed a Data Protection Officer; we are not required to, and correspondence goes directly to the people responsible for the work.

2This website

The contact form collects your name, organisation, email address, telephone number, the service you say you are interested in, and whatever you write in the message field. We use it to answer you and, if an engagement follows, to run it. The lawful basis is our legitimate interest in responding to an approach, and thereafter the performance of a contract.

This site sets no analytics cookies, no advertising cookies and no third-party trackers. There is no consent banner because there is nothing to consent to.

The fonts are served from our own servers rather than from a font provider, so visiting this site does not disclose your IP address to a third party for the sake of a typeface. All scripts and stylesheets are likewise served from this domain, and the site's content security policy blocks anything else from loading.

The site stores nothing in your browser — no cookies, and nothing in local storage.

Our web server keeps standard access logs — IP address, timestamp, requested page, user agent — for security and troubleshooting, on the basis of our legitimate interest in keeping the site available and unmolested. Logs are kept for 30 days and then deleted.

3Prospective and current clients

Where you are or may become a client, we process business contact details, correspondence, and the records of the engagement itself. The lawful basis is the performance of a contract, or our legitimate interest in developing a professional relationship before one exists.

We keep enquiries that do not lead to an engagement for 12 months. Engagement records are kept for the duration of the engagement and for 7 years afterwards, which is the retention period required by Dutch tax and administration law for the underlying financial records. Where a record is not caught by that obligation, we delete it once the engagement is closed.

We do not sell data, we do not share it for anyone else's marketing, and we do not build profiles. We send no newsletter.

4Projects

Building a system means seeing the data it will run on. Where that data includes personal data, you are the controller and we act on your documented instructions as processor, under the Article 28 agreement that forms part of the engagement.

We ask for test data rather than production data wherever a system can be built and proven without the real thing, and for the minimum where it cannot. Access is limited to the people actually working on the engagement.

At the end of a project we hand over the system and delete the working copies we hold, unless you have asked us to keep a copy for a maintenance arrangement. We confirm the deletion in writing.

5Advice

Advisory work rarely needs personal data at all, and we prefer to keep it that way. Ordinarily we process nothing beyond the business contact details of the people we are working with.

Where an engagement requires us to review documents that contain personal data — a set of contracts, an incident file, a register of processing — we hold them only for the duration of the engagement and return or destroy them when it ends. Where we act as processor for that material, an Article 28 agreement is in place before we receive it.

6Knowhow

A Knowhow system indexes your documents so that your people can ask questions of them. You remain the controller of everything in it. We act as processor, and only to the extent needed to run, support and repair the system.

Your documents and the index built from them stay within the environment agreed with you. The models that answer questions run in that same environment. No document, no question and no answer is sent to an external AI service.

We do not use your content to train models — not for ourselves, and not for another client. Your material improves your system and nothing else.

Query logs are kept only as long as needed to operate and troubleshoot the system, and are covered by the same confidentiality obligations as the documents themselves.

When a subscription ends, we hand the data back in a structured, machine-readable format or destroy it, at your choice, and confirm in writing which we did.

7Sub-processors

For this website and the correspondence it generates, we rely on:

  • Cloudflare, Inc. — content delivery and protection against denial-of-service attacks. Requests to this site transit Cloudflare's network.
  • STRATO AG — mail delivery, which carries the notification generated when you submit the contact form.

Sub-processors used in the delivery of a service to a client are named in that client's Article 28 agreement. We add none without telling the client first, so that they have a real opportunity to object.

8International transfers

Our own processing takes place within the European Economic Area, and a Knowhow system stays within the environment agreed with the client.

The one routine exception is the website: Cloudflare operates a global network, so a request may be handled outside the EEA. That transfer is covered by the EU–US Data Privacy Framework and, where the framework does not apply, by Standard Contractual Clauses.

9Security

We encrypt data at rest and in transit, authenticate access with keys rather than passwords wherever the system allows it, isolate client environments from one another and from the public network, and grant each person the least access their work requires.

We keep the number of copies of client material as low as the work permits, on the view that data you never made a second copy of is data you cannot lose twice.

If a breach affects your personal data we will tell you without undue delay, and within 24 hours of becoming aware where you are a client, so that you can meet your own obligations. Where we are the controller, we notify the Autoriteit Persoonsgegevens within 72 hours if the breach meets the threshold.

10Your rights

Where we are the controller, you may ask us to:

  • give you a copy of the personal data we hold about you, and tell you what we do with it;
  • correct it if it is wrong or incomplete;
  • erase it, where we have no continuing obligation or legitimate ground to keep it;
  • restrict what we do with it while a dispute about it is resolved;
  • hand it over in a portable format, or send it to someone else;
  • stop processing it where we rely on legitimate interest, unless we have compelling grounds that override yours.

Write to us through the contact form and we will answer within one month. There is no charge. Where we hold your data as a processor for one of our clients, we will pass your request to that client, who is the one able to act on it, and tell you that we have done so. You may also complain to the Autoriteit Persoonsgegevens, the Dutch supervisory authority, at autoriteitpersoonsgegevens.nl.

11Changes to this policy

We update this policy when what we do changes. The date at the top of the page tells you which version you are reading. Where a change materially affects a client engagement, we notify the client directly rather than relying on your noticing a new date.

12Contact

Nimbostratus B.V., operating under its registered trademark itsaura. Registered in the Netherlands, KvK 59740086. The quickest route to us is the contact form at itsaura.ai. Our General Terms & Conditions set out how we engage.

itsaura.ai

Projects delivered, advice you can act on, and knowledge your people can simply ask. Your data stays where it belongs.

Navigation
Projects Advice Knowhow About
Legal & Contact
General Terms & Conditions Privacy Policy Contact

© 2026 Nimbostratus B.V. — itsaura® is a registered trademark of Nimbostratus B.V., registered in the Netherlands (KvK 59740086)

Get AI right, on your data

Contact

Get to know you.

Tell us whether you're after a project, advice, a knowledge system, or some combination. We will respond shortly.

Your information is treated in confidence — see our Privacy Policy.

That did not send. Please try again, or write to us directly.

Prefer to call? +31 20 334 2338

Thank you.

Your inquiry has been received. We will be in touch shortly.