Nimbus Tech — Privacy Policy

Effective Date: 22.09.2026

1. Introduction

Nimbus Tech ("Nimbus Tech," "we," "our," or "us") respects the privacy of everyone who visits our website, contacts us, or uses our services. This Privacy Policy explains what personal data we collect, why we collect it, how we protect it, and what rights you have in relation to it.

By using our website or otherwise interacting with us, you acknowledge the practices described in this Privacy Policy. If you do not agree with any part of it, please discontinue use of our website and services.

2. Who We Are

Nimbus Tech d.o.o., with its registered seat at Heroja Pinkija 18, Republic of Serbia, registration number 21694002 ("Nimbus Tech," "we," "us"), is the data controller responsible for the personal data described in this Privacy Policy.

For any privacy-related question, request, or concern, contact us at privacy@nimbus-tech.io.

3. Definitions

  • Personal Data — any information relating to an identified or identifiable natural person.
  • Processing — any operation performed on personal data, automated or not (collection, storage, use, disclosure, deletion, etc.).
  • Controller — the entity that determines the purposes and means of processing personal data; in this case, Nimbus Tech.
  • Processor — any third party that processes personal data on our behalf.
  • GDPR — the EU General Data Protection Regulation (Regulation (EU) 2016/679).
  • PDPA — the Serbian Law on Personal Data Protection ("Official Gazette of the RS," No. 87/2018).
  • Cookies — small data files stored on your device to enable website functionality and analytics.
  • You / User / Data Subject — any natural person whose personal data we process.

4. Who This Policy Applies To

This Privacy Policy applies to:

  • visitors to our website;
  • individuals who contact us via our website, email, or other channels;
  • individuals who engage us as clients, partners, or suppliers, in their individual capacity;
  • individuals who subscribe to our newsletter or marketing communications.

This Policy does not cover our processing of employee or job applicant data, which is addressed in a separate internal policy available upon request.

5. Information We Collect

5.1 Information You Provide Directly

Name, email address, phone number, company name, job title, and any other information you submit through contact forms, email, or during the course of a business relationship.

5.2 Information Collected Automatically

IP address, browser type and version, device information, operating system, referring website, pages visited, and general usage data, collected via cookies and similar technologies when you visit our website.

5.3 Information From Cookies

See Section 7 (Cookies) below.

6. How We Use Your Information and Legal Basis

We use personal data for the following purposes, on the legal bases indicated:

PurposeLegal Basis
Respond to inquiries and requestsConsent / pre-contractual steps
Provide, maintain, and support our servicesPerformance of a contract
Communicate with clients, partners, and prospectsLegitimate interest / Consent
Send newsletters and marketing communicationsConsent
Improve our website and services (analytics)Consent / Legitimate interest
Maintain security and prevent fraud or misuseLegitimate interest
Comply with legal and regulatory obligationsLegal obligation

We do not use personal data for any purpose incompatible with those listed above without first informing you and, where required, obtaining your consent.

7. Cookies

Our website uses cookies and similar technologies, including:

  • Strictly necessary cookies, required for the website to function, which do not require consent.
  • Analytics cookies, which help us understand how visitors use our website (e.g., Google Analytics).
  • Marketing cookies, used to measure the effectiveness of our communications.

Non-essential cookies are only set after you provide consent through our cookie banner. You may withdraw consent or change your preferences at any time via the cookie settings link in our website footer, or through your browser settings. Disabling certain cookies may affect the functionality of our website.

8. What We Do Not Do

Nimbus Tech will never:

  • sell your personal data;
  • use your personal data for purposes other than those described in this Privacy Policy without your knowledge;
  • share your personal data with third parties except as described in Section 9 below.

9. Sharing of Your Information

We do not sell personal data. We may share it with the following categories of recipients, each bound by appropriate data protection agreements:

CategoryExample / Purpose
Cloud hosting & infrastructure providersHosting our website and business systems
Business software providersEmail, CRM, and collaboration tools used to communicate with you and run our operations
Analytics providersUnderstanding website usage (e.g., Google Analytics)
Professional advisorsLegal, accounting, and audit services
Regulatory or law enforcement authoritiesWhen required by applicable law

Our current processors (sub-processors), as recorded in our NT-REG-16 Approved Software List and the Drata vendor register, are: Google Workspace, Slack, Nuclino, 1Password, AWS, GitHub, Figma, Linear, Drata, Lovable (website host), and Claude Team.

10. International Data Transfers

Personal data may be transferred to and processed in countries outside the Republic of Serbia and the European Economic Area (EEA), including the United States, through our service providers and cloud platforms. Where such transfers occur, we ensure appropriate safeguards are in place, such as adequacy decisions, Standard Contractual Clauses, or equivalent mechanisms recognized under the GDPR and the Serbian PDPA.

11. Data Retention

We retain personal data only for as long as necessary to fulfill the purposes described in this Privacy Policy, comply with legal obligations, resolve disputes, and enforce our agreements. Retention periods vary by data type and purpose (for example, contact form inquiries are retained for 12 months; newsletter data is retained until you unsubscribe). When no longer needed, data is securely deleted or anonymized.

12. Security

We implement administrative, technical, and organizational measures designed to protect personal data against unauthorized access, disclosure, alteration, or destruction, including:

  • access controls and role-based permissions;
  • multi-factor authentication;
  • encryption of data in transit and, where appropriate, at rest;
  • audit logging and monitoring;
  • use of vetted, secure cloud service providers.

No method of transmission or storage is completely secure. While we work to protect your data, we cannot guarantee absolute security.

13. Your Privacy Rights

Depending on applicable law (including the GDPR and the Serbian PDPA), you may have the right to:

  • Access — request a copy of the personal data we hold about you.
  • Rectification — request correction of inaccurate or incomplete data.
  • Erasure — request deletion of your personal data in certain circumstances.
  • Restriction — request that we limit how we process your data.
  • Objection — object to processing based on legitimate interest or for direct marketing.
  • Portability — receive your data in a structured, commonly used, machine-readable format.
  • Withdraw consent — where processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing.
  • Lodge a complaint — with the Serbian Commissioner for Information of Public Importance and Personal Data Protection (Poverenik, poverenik.rs) or, where applicable, your local EU/UK supervisory authority.

To exercise any of these rights, contact us at privacy@nimbus-tech.io. We may ask you to verify your identity before processing your request. We will respond within 30 days; this period may be extended by up to two additional months for complex requests, and we will notify you if an extension is needed.

14. Children's Privacy

Our website and services are not directed at children, and we do not knowingly collect personal data from individuals under the age of 15. If you believe a child has provided us with personal data, please contact us so that we can delete it.

15. Marketing Communications

If you receive marketing communications from us and no longer wish to, you may unsubscribe at any time using the link in the email or by contacting privacy@nimbus-tech.io. We will not use your data for marketing purposes beyond what you have consented to.

16. Links to Other Websites

Our website may contain links to third-party websites. We are not responsible for the privacy practices of those websites and encourage you to review their respective privacy policies.

17. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. Updates will be posted on this page with a revised effective date. Continued use of our website after changes are posted constitutes acceptance of the updated Policy.

18. Governing Law

This Privacy Policy is governed by the laws of the Republic of Serbia, without prejudice to any mandatory data protection rights you may have under the GDPR or other applicable local law.

19. Contact Us

For privacy-related inquiries, requests, or concerns, please contact:

Nimbus Tech

privacy@nimbus-tech.io