Nimbus Tech — Privacy Policy
Effective Date: 22.09.2026
1. Introduction
Nimbus Tech ("Nimbus Tech," "we," "our," or "us") respects the privacy of everyone who visits our website, contacts us, or uses our services. This Privacy Policy explains what personal data we collect, why we collect it, how we protect it, and what rights you have in relation to it.
By using our website or otherwise interacting with us, you acknowledge the practices described in this Privacy Policy. If you do not agree with any part of it, please discontinue use of our website and services.
2. Who We Are
Nimbus Tech d.o.o., with its registered seat at Heroja Pinkija 18, Republic of Serbia, registration number 21694002 ("Nimbus Tech," "we," "us"), is the data controller responsible for the personal data described in this Privacy Policy.
For any privacy-related question, request, or concern, contact us at privacy@nimbus-tech.io.
3. Definitions
- Personal Data — any information relating to an identified or identifiable natural person.
- Processing — any operation performed on personal data, automated or not (collection, storage, use, disclosure, deletion, etc.).
- Controller — the entity that determines the purposes and means of processing personal data; in this case, Nimbus Tech.
- Processor — any third party that processes personal data on our behalf.
- GDPR — the EU General Data Protection Regulation (Regulation (EU) 2016/679).
- PDPA — the Serbian Law on Personal Data Protection ("Official Gazette of the RS," No. 87/2018).
- Cookies — small data files stored on your device to enable website functionality and analytics.
- You / User / Data Subject — any natural person whose personal data we process.
4. Who This Policy Applies To
This Privacy Policy applies to:
- visitors to our website;
- individuals who contact us via our website, email, or other channels;
- individuals who engage us as clients, partners, or suppliers, in their individual capacity;
- individuals who subscribe to our newsletter or marketing communications.
This Policy does not cover our processing of employee or job applicant data, which is addressed in a separate internal policy available upon request.
5. Information We Collect
5.1 Information You Provide Directly
Name, email address, phone number, company name, job title, and any other information you submit through contact forms, email, or during the course of a business relationship.
5.2 Information Collected Automatically
IP address, browser type and version, device information, operating system, referring website, pages visited, and general usage data, collected via cookies and similar technologies when you visit our website.
5.3 Information From Cookies
See Section 7 (Cookies) below.
6. How We Use Your Information and Legal Basis
We use personal data for the following purposes, on the legal bases indicated:
| Purpose | Legal Basis |
|---|---|
| Respond to inquiries and requests | Consent / pre-contractual steps |
| Provide, maintain, and support our services | Performance of a contract |
| Communicate with clients, partners, and prospects | Legitimate interest / Consent |
| Send newsletters and marketing communications | Consent |
| Improve our website and services (analytics) | Consent / Legitimate interest |
| Maintain security and prevent fraud or misuse | Legitimate interest |
| Comply with legal and regulatory obligations | Legal obligation |
We do not use personal data for any purpose incompatible with those listed above without first informing you and, where required, obtaining your consent.
7. Cookies
Our website uses cookies and similar technologies, including:
- Strictly necessary cookies, required for the website to function, which do not require consent.
- Analytics cookies, which help us understand how visitors use our website (e.g., Google Analytics).
- Marketing cookies, used to measure the effectiveness of our communications.
Non-essential cookies are only set after you provide consent through our cookie banner. You may withdraw consent or change your preferences at any time via the cookie settings link in our website footer, or through your browser settings. Disabling certain cookies may affect the functionality of our website.
8. What We Do Not Do
Nimbus Tech will never:
- sell your personal data;
- use your personal data for purposes other than those described in this Privacy Policy without your knowledge;
- share your personal data with third parties except as described in Section 9 below.
9. Sharing of Your Information
We do not sell personal data. We may share it with the following categories of recipients, each bound by appropriate data protection agreements:
| Category | Example / Purpose |
|---|---|
| Cloud hosting & infrastructure providers | Hosting our website and business systems |
| Business software providers | Email, CRM, and collaboration tools used to communicate with you and run our operations |
| Analytics providers | Understanding website usage (e.g., Google Analytics) |
| Professional advisors | Legal, accounting, and audit services |
| Regulatory or law enforcement authorities | When required by applicable law |
Our current processors (sub-processors), as recorded in our NT-REG-16 Approved Software List and the Drata vendor register, are: Google Workspace, Slack, Nuclino, 1Password, AWS, GitHub, Figma, Linear, Drata, Lovable (website host), and Claude Team.
10. International Data Transfers
Personal data may be transferred to and processed in countries outside the Republic of Serbia and the European Economic Area (EEA), including the United States, through our service providers and cloud platforms. Where such transfers occur, we ensure appropriate safeguards are in place, such as adequacy decisions, Standard Contractual Clauses, or equivalent mechanisms recognized under the GDPR and the Serbian PDPA.
11. Data Retention
We retain personal data only for as long as necessary to fulfill the purposes described in this Privacy Policy, comply with legal obligations, resolve disputes, and enforce our agreements. Retention periods vary by data type and purpose (for example, contact form inquiries are retained for 12 months; newsletter data is retained until you unsubscribe). When no longer needed, data is securely deleted or anonymized.
12. Security
We implement administrative, technical, and organizational measures designed to protect personal data against unauthorized access, disclosure, alteration, or destruction, including:
- access controls and role-based permissions;
- multi-factor authentication;
- encryption of data in transit and, where appropriate, at rest;
- audit logging and monitoring;
- use of vetted, secure cloud service providers.
No method of transmission or storage is completely secure. While we work to protect your data, we cannot guarantee absolute security.
13. Your Privacy Rights
Depending on applicable law (including the GDPR and the Serbian PDPA), you may have the right to:
- Access — request a copy of the personal data we hold about you.
- Rectification — request correction of inaccurate or incomplete data.
- Erasure — request deletion of your personal data in certain circumstances.
- Restriction — request that we limit how we process your data.
- Objection — object to processing based on legitimate interest or for direct marketing.
- Portability — receive your data in a structured, commonly used, machine-readable format.
- Withdraw consent — where processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing.
- Lodge a complaint — with the Serbian Commissioner for Information of Public Importance and Personal Data Protection (Poverenik, poverenik.rs) or, where applicable, your local EU/UK supervisory authority.
To exercise any of these rights, contact us at privacy@nimbus-tech.io. We may ask you to verify your identity before processing your request. We will respond within 30 days; this period may be extended by up to two additional months for complex requests, and we will notify you if an extension is needed.
14. Children's Privacy
Our website and services are not directed at children, and we do not knowingly collect personal data from individuals under the age of 15. If you believe a child has provided us with personal data, please contact us so that we can delete it.
15. Marketing Communications
If you receive marketing communications from us and no longer wish to, you may unsubscribe at any time using the link in the email or by contacting privacy@nimbus-tech.io. We will not use your data for marketing purposes beyond what you have consented to.
16. Links to Other Websites
Our website may contain links to third-party websites. We are not responsible for the privacy practices of those websites and encourage you to review their respective privacy policies.
17. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. Updates will be posted on this page with a revised effective date. Continued use of our website after changes are posted constitutes acceptance of the updated Policy.
18. Governing Law
This Privacy Policy is governed by the laws of the Republic of Serbia, without prejudice to any mandatory data protection rights you may have under the GDPR or other applicable local law.
19. Contact Us
For privacy-related inquiries, requests, or concerns, please contact:
Nimbus Tech