Privacy Policy

How we collect, use and protect your data.

Last updated: June 2026

1. Who we are

NIS2Pathway is a SaaS compliance support platform operated by NIS2Pathway BV (in formation). We are the data controller for personal data processed through this platform. For questions, contact us at privacy@nis2pathway.com.

2. What data we collect

Account data: Name, email address and password (stored as a bcrypt hash). Collected when you register.

Organisation data: Organisation name, country, sector, employee count, IT management details and NIS2 preparation status. Provided during onboarding and assessment.

Assessment data: Answers to NIS2 readiness questions, scores and notes. Entered by you during the readiness scan.

Evidence files: Documents you upload to the Evidence Vault (PDF, images, spreadsheets etc.). Stored on EU-based servers.

Team data: Email addresses and roles of team members you invite. Invitation tokens are stored as cryptographic hashes.

Usage data: We may log server-side events for security and reliability purposes (e.g. login attempts, API errors). No tracking pixels or third-party analytics by default.

Billing data: If you subscribe to a paid plan, payment data is processed by Stripe. We do not store full card details. We may store your Stripe customer ID and subscription status.

3. How we use your data

  • To provide and operate the NIS2Pathway service.
  • To send transactional emails (account invitations, password resets, welcome emails).
  • To enforce plan limits and manage subscriptions.
  • To maintain an audit log of actions within your organisation (accessible to your team).
  • To investigate security incidents and comply with legal obligations.

We do not sell your personal data. We do not use your data for profiling or targeted advertising.

4. Legal basis (GDPR)

We process your data on the following legal bases:

  • Contract: Processing necessary to provide the service you signed up for.
  • Legitimate interest: Security logging, fraud prevention, service reliability.
  • Consent: Analytics (if configured); you can opt out by contacting us.

5. Data retention

We retain your data for as long as your account is active. If you delete your account, we will delete or anonymise your personal data within 30 days, except where we are required by law to retain it longer.

Audit log entries may be retained for up to 12 months for security purposes.

6. Data storage and security

All data is stored on EU-based servers. Data is encrypted in transit (TLS 1.2+) and at rest. Evidence files are stored in isolated per-organisation directories accessible only to authenticated members.

Passwords are stored as bcrypt hashes (12 rounds). We do not store plaintext passwords.

7. Third-party processors (sub-processors)

We use the following sub-processors to deliver the service:

Sub-processorPurposeData location
Resend (Resend Inc.)Transactional email delivery (invitations, password resets, welcome emails)United States (SCCs apply)
Stripe Inc.Payment processing (paid subscriptions only)United States / EU (SCCs apply)
Infrastructure provider (VPS)Hosting, database, file storageEU (France)
OpenAI (OpenAI, L.L.C.)NISMO AI assistant — processing user questions and limited dashboard contextUnited States (SCCs / DPA apply)

Each sub-processor is bound by a data processing agreement (DPA). Standard Contractual Clauses (SCCs) are in place for transfers outside the EU/EEA.

8b. NISMO AI Compliance Assistant

NISMO, the AI Compliance Assistant, may process your questions and limited dashboard context — such as control status, risk summaries, policy status and evidence metadata — to provide practical guidance. Uploaded evidence files are not sent to the AI model by default. NISMO is designed to support compliance work but does not provide legal advice.

NISMO questions and responses are stored in our database to provide conversation history and usage tracking. You can delete your conversation history at any time from the NISMO dashboard.

8. Cookies and local storage

NIS2Pathway uses the following cookies and browser storage:

  • Session cookie (necessary): A signed session token is set when you log in. It is required to use the platform and expires when you sign out or after 30 days of inactivity.
  • Language preference (functional): We store your language preference (EN/NL) in localStorage so the homepage displays in your chosen language on subsequent visits. No personal data is stored.

We do not use advertising cookies, tracking pixels, or third-party analytics cookies. If analytics are enabled in the future, this policy will be updated and consent will be requested.

9. Your rights

Under GDPR, you have the right to access, correct, export or delete your personal data. You can also object to processing or request restriction. To exercise these rights, email privacy@nis2pathway.com.

You have the right to lodge a complaint with your national data protection authority.

10. Changes to this policy

We may update this policy. Significant changes will be communicated by email or via an in-app notice. The "last updated" date at the top of this page indicates when the policy was last revised.