Privacy Policy
Last updated: 17 June 2026
This Privacy Policy explains how Nair Development Hub SRL ("Triagely", "we", "us", or "our") collects, uses, and protects personal data in connection with the Triagely service available at https://www.triagely.net (the "Service").
We take privacy seriously and aim to comply with the EU General Data Protection Regulation (GDPR) and applicable Romanian data-protection law.
1. Who we are
The data controller (where we act as controller — see Section 3) is:
- Company: Nair Development Hub SRL
- Registered address: Str. Tineretului 63, Chiajna, Ilfov County, Romania
- Company registration number / CUI: 48366031
- Contact for privacy matters: contact@triagely.net
If you have any questions about this Policy or how we handle your data, email us at the address above.
2. Who this Policy applies to
This Policy applies to:
- Account holders — the developers and businesses who sign up for and use Triagely; and
- Visitors to our website; and
- End users of our customers — the people who submit feedback that our customers collect and send into Triagely.
Please read Section 3 carefully, because our role (and your rights) differ depending on which category applies.
3. Our two roles: controller and processor
Triagely handles personal data in two distinct roles.
3.1 We are the controller of account-holder and website data
For data about our account holders and website visitors, we decide why and how the data is processed. This includes account details, billing information, and analytics. Sections 4–11 of this Policy apply to this data.
3.2 We are a processor of end-user feedback content
The feedback that our customers collect from their own users and send into Triagely (via our API, widget, or email forwarding) is processed by us on behalf of, and under the instructions of, the customer. In this context:
- The customer is the data controller of that feedback content.
- Triagely is the data processor, handling it only to provide the Service.
- The customer is responsible for having a lawful basis to collect that data and to send it to us, and for informing their own users appropriately.
If you are an end user who submitted feedback and you want to access or delete your data, please contact the business you originally gave the feedback to — they control it. We will assist that business as their processor. Our Data Processing Agreement (DPA), which governs how we process feedback data on our customers' behalf, is available at https://www.triagely.net/dpa.
4. What data we collect, and why (account holders & visitors)
| Data | Examples | Why we process it | Legal basis |
|---|---|---|---|
| Account & identity | Email address; authentication identity (magic-link or Google sign-in) | To create and operate your account; to log you in; to communicate about the Service | Performance of a contract (Art. 6(1)(b) GDPR) |
| Billing data | Email, optional company name, optional tax ID, billing address (card details are handled by Stripe — see Section 6 — and are never stored or seen by us) | To process subscriptions, payments, trials, and refunds | Performance of a contract; legal obligation, e.g. accounting (Art. 6(1)(b); Art. 6(1)(c) GDPR) |
| Product & usage analytics | Pages viewed, clicks/interactions, and (once you give us your email) behaviour tied to that email | To understand and improve the Service | Consent for non-essential analytics cookies, and/or our legitimate interest in improving the Service (Art. 6(1)(a); Art. 6(1)(f) GDPR) |
| Website & technical data | IP address, device/browser information, performance metrics, log data | To deliver, secure, and maintain the website | Legitimate interest in operating a secure, reliable service (Art. 6(1)(f) GDPR) |
| Waitlist / marketing | Email and signup source | To send you product updates and launch information if you join our waitlist | Consent — you can unsubscribe at any time (Art. 6(1)(a) GDPR) |
| Support communications | The content of emails you send us | To respond to and resolve your request | Legitimate interest; performance of a contract (Art. 6(1)(f); Art. 6(1)(b) GDPR) |
5. Feedback content we process for customers (processor data)
When a customer uses Triagely, the following may be captured and stored as feedback:
- A free-form message;
- Optionally an email address, name, and URL;
- For forwarded emails, also the subject and message identifiers; and
- The source channel (API, widget, or email).
Because this content is free-form, it can contain any information the end user chooses to type, including personal data. We do not control what end users submit. Customers must not configure the Service to collect special-category (sensitive) personal data, and are responsible for instructing their users accordingly (see our Terms and our DPA).
We use this content only to provide the Service: to split, deduplicate, group, summarise, rank, and display feedback to the customer. We do not sell it, and we do not use it to train AI models (see Sections 8 and 9).
6. Cookies and analytics
We use a limited set of cookies and similar technologies:
- Strictly necessary technologies that make the Service work (for example, keeping you logged in). These do not require consent.
- Analytics and experimentation technologies — including PostHog (product analytics) and local storage used to remember experiment variants. These are non-essential and are only set after you give consent through our cookie-consent banner. You can change or withdraw your consent at any time via the banner.
- Privacy-friendly, cookieless website analytics (aggregate traffic and performance metrics) provided through our hosting platform.
For more detail on individual cookies, contact us at contact@triagely.net.
7. Service providers (sub-processors)
We rely on the following third-party providers to operate the Service. Each receives only the data needed for its function. We maintain agreements with these providers and, where they are located outside the European Economic Area (EEA), we rely on appropriate safeguards (see Section 10).
| Provider | Purpose | Data it receives | Location |
|---|---|---|---|
| Supabase | Database & authentication (primary data store) | All stored data; authentication identities (email, Google sign-in identifier) | EU (Ireland) |
| Vercel | Hosting / CDN, website analytics, performance metrics | HTTP request data, IP address, performance metrics | EU (Frankfurt) |
| PostHog | Product analytics (consent-based) | Pageviews, interactions, custom events; email after signup | EU |
| Stripe | Payments & subscriptions | Billing email, name, address, tax ID, card data (card data handled solely by Stripe) | US / global (PCI-compliant) |
| OpenRouter (routing to OpenAI and Anthropic) | AI analysis of feedback (split, match, summarise) | Feedback content | US |
| Postmark | Inbound email parsing / forwarding | Full forwarded support emails (sender, subject, body) | US |
| Loops | Waitlist email marketing | Email and signup source | US |
| Reddit Ads | Conversion measurement (waitlist only) | A SHA-256 hash of the email (never the raw email) and the event | US |
| Optional OAuth sign-in | Standard OAuth profile (email, basic profile) | US / global |
We keep this list current. We will update it when we add, remove, or change a material sub-processor.
8. AI processing of feedback
To provide the Service, feedback content is sent to AI providers (via OpenRouter, which routes to OpenAI and Anthropic) solely to categorise, deduplicate, and summarise that feedback.
We select AI providers whose API terms state that they do not use data submitted through their API to train their models. These providers may retain content briefly — typically for up to 30 days — solely to monitor for and prevent abuse and to keep the service safe, after which it is deleted, unless they are legally required to retain it for longer. The behaviour of these third-party providers is governed by their own policies and is ultimately outside our direct control, and we cannot guarantee it. We do not, ourselves, use feedback or customer content to train any AI models.
9. How we use feedback content — our commitments
We make the following commitments regarding the feedback content we process on customers' behalf:
- We do not routinely read it. Our staff will not access, read, or browse through customer feedback content in the ordinary course of business.
- We do not sell it. We never sell customer data or end-user data.
- We do not train on it. We do not use customer or end-user content to train AI models.
- Access only with agreement. We will access specific feedback content only with the customer's request or agreement — for example, when a customer asks us to investigate or debug an issue.
- Limited exceptions. We may also access, retain, or disclose content where we are legally required to do so, or where strictly necessary to secure the Service or prevent abuse or fraud.
10. International data transfers
Our primary data store, application hosting, and product analytics are hosted within the EEA (Ireland, Frankfurt, and the EU respectively). Some of our other providers are located outside the EEA (notably in the United States). Where personal data is transferred outside the EEA, we rely on appropriate safeguards under the GDPR — primarily the European Commission's Standard Contractual Clauses (SCCs), certification under the EU–U.S. Data Privacy Framework where a provider participates, and each provider's own data-protection commitments — to ensure your data receives an adequate level of protection. You can request more information about these safeguards by emailing us.
11. How we protect your data
We apply technical and organisational measures appropriate to the risk, including:
- Row-Level Security on all database tables: a client can only read its own data and can never write directly — every write passes through our server after an ownership check.
- AI-derived data, billing records, and internal counters are accessible only to privileged server processes, never to client applications.
- API keys are stored only as a one-way SHA-256 hash plus a short display prefix; the raw key is shown to you once and never stored.
- The feedback widget uses a separate public key, an origin allowlist, rate limiting, size limits, and input sanitisation.
- Webhooks are authenticated and signature-verified.
No system can be guaranteed perfectly secure, but we work to protect your data and to limit who can access it.
12. How long we keep data
We keep your data for as long as your account or projects exist. When you delete a project or your account, the associated data is deleted; there is no fixed time-based retention period.
After deletion, we retain a small non-personal record (project name, feedback/ticket counts, owner identifier, and dates) for support, billing, and anti-abuse audit purposes. This record does not contain feedback content or end-user personal data.
We may retain certain billing and transaction records for longer where required by law (for example, accounting and tax rules).
13. Your rights
Under the GDPR, you have the right to:
- Access the personal data we hold about you;
- Rectify inaccurate data;
- Erase your data ("right to be forgotten");
- Restrict or object to certain processing;
- Data portability — receive your data in a structured, machine-readable format;
- Withdraw consent at any time, where processing is based on consent (this does not affect prior processing).
Account holders can exercise access and deletion rights through in-product tools where available, or by emailing contact@triagely.net. We will respond within the timeframes required by law.
You also have the right to lodge a complaint with the Romanian supervisory authority:
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP) B-dul G-ral. Gheorghe Magheru 28–30, Sector 1, Bucharest, Romania Website: https://www.dataprotection.ro
14. Children
The Service is intended for businesses and is not directed at children. We do not knowingly allow anyone under the age of 16 to create an account. If you believe a minor has provided us with personal data, please contact us and we will delete it.
15. Changes to this Policy
We may update this Policy from time to time. When we make material changes, we will update the "Last updated" date above and, where appropriate, notify you. Your continued use of the Service after changes take effect means you accept the updated Policy.
16. Contact
For any privacy question or request, contact us at contact@triagely.net.