Privacy Policy
Privacy Policy
Last updated: 8 July 2026
Nentis AI respects your privacy and is committed to protecting your personal data. This Privacy Policy explains what personal data we collect, why we collect it, how we use it, and the rights you have under the EU General Data Protection Regulation (GDPR) and Belgian data protection law.
This policy applies to our website nentisai.com and to the personal data we process when you contact us, request a proposal, or engage our services.
1. Who we are (data controller)
The controller responsible for your personal data is:
- Nentis AI — SRL in formation under Belgian law
- Email: contact@nentisai.com
Nentis AI is currently completing its incorporation. Its enterprise number (BCE/KBO), VAT number, and registered office will be published here as soon as registration is complete.
For any question about this policy or about how we handle your data, contact us at contact@nentisai.com.
2. Personal data we collect
We only collect the personal data we need for the purposes described below. Depending on how you interact with us, this may include:
Data you provide directly
- Identity and contact data: name, company, email address, phone number (when you complete a form or email us).
- Content of your message: the workflow, project, budget or other information you choose to share when contacting us or requesting a proposal or discovery call.
- Client and project data: information exchanged during an engagement, governed by the applicable service agreement and, where relevant, a Data Processing Agreement.
Data collected automatically
- Technical data: IP address, browser type, device information, and pages visited, collected through cookies and similar technologies (see our Cookie Policy).
- Analytics data: aggregated, statistical information about how visitors use the site, collected only where you have consented to non-essential cookies.
We do not intentionally collect special categories of personal data (such as health, biometric, or political data) through this website. Please do not send us such data through our contact channels.
3. How we use your data and legal bases
We process personal data only where we have a valid legal basis under Article 6 GDPR:
- To respond to your enquiries and requests — legal basis: our legitimate interest in answering you, or steps taken at your request before entering into a contract.
- To prepare proposals, quotes, and discovery calls — legal basis: pre-contractual steps at your request.
- To provide our services and manage client relationships — legal basis: performance of a contract.
- To operate, secure, and improve our website — legal basis: our legitimate interest in running a safe, functional website.
- To use analytics and marketing cookies — legal basis: your consent, which you can withdraw at any time.
- To comply with legal obligations (for example accounting and tax) — legal basis: legal obligation.
Where we rely on legitimate interests, we balance those interests against your rights and freedoms, and you may object at any time (see Your rights).
5. Who we share your data with
We do not sell your personal data. We share it only where necessary, with:
- Service providers (processors) who help us operate our business — for example hosting, email, scheduling, and analytics providers. They act on our instructions under a data processing agreement.
- Professional advisers such as accountants and lawyers, where necessary.
- Public authorities, where we are legally required to disclose data.
When a provider processes personal data on our behalf, we put in place a data processing agreement that meets the requirements of Article 28 GDPR.
6. International data transfers
We aim to keep personal data within the European Economic Area (EEA). Some of our providers may process data outside the EEA. Where that happens, we ensure an appropriate safeguard is in place, such as an adequacy decision by the European Commission or the European Commission's Standard Contractual Clauses, together with any additional measures required.
You can request more information about the safeguards we use by contacting us at contact@nentisai.com.
7. How long we keep your data
We keep personal data only for as long as necessary for the purposes for which it was collected, and to meet our legal obligations.
- Enquiry and contact data: kept for as long as needed to handle your request and for a reasonable period afterwards, then deleted or anonymised.
- Client and project data: kept for the duration of the engagement and for the retention periods required by Belgian law (for example, accounting records are generally kept for the legally required period).
- Cookie and analytics data: kept for the retention periods set out in our Cookie Policy.
8. How we protect your data
We apply appropriate technical and organisational measures to protect personal data against loss, misuse, and unauthorised access, including access controls, secure connections, and limiting access to authorised people. No system can be guaranteed fully secure, but we work to protect your data proportionately to the risk.
9. Your rights
Under the GDPR, you have the following rights regarding your personal data:
- Access — obtain a copy of the personal data we hold about you.
- Rectification — correct inaccurate or incomplete data.
- Erasure — ask us to delete your data in certain circumstances.
- Restriction — ask us to limit how we use your data.
- Portability — receive your data in a structured, machine-readable format.
- Objection — object to processing based on our legitimate interests, and to direct marketing at any time.
- Withdraw consent — where processing is based on consent, withdraw it at any time without affecting prior processing.
To exercise any of these rights, contact us at contact@nentisai.com. We will respond within the time limits set by the GDPR (normally within one month). We may ask you to confirm your identity before acting on a request.
10. Automated decision-making
We do not make decisions that produce legal or similarly significant effects about you based solely on automated processing through this website. Where AI supports our work, human oversight applies as described in our AI Policy.
11. Third-party links
Our website may contain links to third-party websites and services (for example a scheduling tool). This Privacy Policy does not apply to those websites. We encourage you to read their own privacy policies.
12. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. The updated version will be published on this page with a new “Last updated” date.
13. Contact and complaints
For any question or request regarding your personal data, contact us at contact@nentisai.com.
If you believe we have not handled your data properly, you have the right to lodge a complaint with the Belgian Data Protection Authority:
- Gegevensbeschermingsautoriteit / Autorité de protection des données (APD-GBA)
- Rue de la Presse 35 / Drukpersstraat 35, 1000 Brussels, Belgium
- contact@apd-gba.be — www.dataprotectionauthority.be
Questions about this document? Contact us at contact@nentisai.com