Privacy Policy
Effective date: 13 August 2026
This Privacy Policy describes how Nilo Collaborations AB, org. no. 559273-2241, Bytaregatan 4D, 222 21 Lund, Sweden ("Nilo", "we", "us"), processes personal data in connection with the website nilocollab.com (the "Site").
Nilo is the data controller for the processing described in this policy. The policy covers your use of the Site, enquiries you send us through the Site or directly by email, and our handling of privacy requests. Processing of personal data in the Nilo workshop product (nilomeeting.com) is described in that product's own privacy documentation.
1. What data we process
Hosting and security data. The Site is hosted by Cloudflare. When you visit any page, Cloudflare processes technical request data – such as your IP address, browser user agent, and requested URL – on our behalf to deliver the Site and protect it against attacks. We do not store this data in our own systems and we use no analytics or advertising tools.
Contact form. When you contact us or book a demo through the form on the Site, we process the information you submit: your name, email address, and company name (required – the form cannot be submitted without them), and any message you write (optional).
Security verification (Cloudflare Turnstile). The contact page includes Cloudflare Turnstile, which protects the form against spam and automated abuse. Turnstile runs as soon as the contact page loads and processes signals from your browser – including your IP address, user agent, and other device and connection characteristics – to distinguish humans from bots. When you submit the form, the resulting verification token and your IP address are checked against Cloudflare's verification service. We do not store these signals in our own systems.
Direct correspondence. If you email us directly, or contact us to exercise your privacy rights, we process the personal data contained in that correspondence.
2. Why and on what legal basis
| Purpose | Legal basis |
|---|---|
| Responding to your enquiry or demo request, and proportionate follow-up on that enquiry | Legitimate interest (Art. 6(1)(f) GDPR) in responding to enquiries addressed to us |
| Delivering the Site and protecting it and the contact form against abuse (hosting data, Turnstile) | Legitimate interest (Art. 6(1)(f) GDPR) in operating a secure website |
| Handling privacy-rights requests | Legal obligation (Art. 6(1)(c) GDPR) |
We use contact details only to handle the enquiry they were submitted with. We do not add you to recurring marketing campaigns or newsletters based on a contact-form submission.
3. How long we keep it
- Contact-form submissions and related correspondence are delivered to us as email. We keep them for as long as needed to handle your enquiry and any follow-up, and delete them no later than 24 months after our last contact with you. If the enquiry leads to a customer relationship, related correspondence is retained for the duration of that relationship and deleted no later than 24 months after it ends, unless a longer period is required by law (for example accounting rules).
- Hosting and Turnstile data is stored by Cloudflare on our behalf and retained in accordance with Cloudflare's privacy policy; we do not receive or keep copies of it.
- Records of privacy-rights requests are kept to demonstrate compliance and deleted no later than 3 years after the request was closed.
4. Who receives your data
We do not sell personal data. The following service providers process personal data in connection with the Site:
- Cloudflare, Inc. (USA) – hosts the Site, provides the Turnstile security verification, and delivers contact-form submissions to us by email. Cloudflare acts as our processor for this data. Cloudflare additionally acts as an independent controller for certain security signals it uses to maintain and improve its own services – for Turnstile, see the Cloudflare Turnstile Privacy Notice, and for aggregated network and threat data derived from traffic to the services it provides, see Cloudflare's privacy policy.
- Microsoft (Microsoft 365) – our mailbox provider; we contract with Microsoft's EEA entity (Microsoft Ireland Operations Ltd), which stores the contact-form emails and other correspondence we receive.
Data may be transferred to the United States. Where it is processed by Cloudflare, Inc. or by US Microsoft entities covered by the EU–US Data Privacy Framework, the transfer relies on their DPF certification, which the European Commission has recognised as providing adequate protection. For transfers outside the framework's scope, the European Commission's Standard Contractual Clauses apply; a copy can be requested from us at the address below.
Beyond this, we disclose personal data only if required by law or to protect our legal rights.
5. Your rights
Under the GDPR you have the right to:
- request access to the personal data we hold about you;
- request rectification of inaccurate data;
- request erasure of your data;
- request restriction of processing;
- object to processing based on legitimate interest;
- receive your data in a portable format, where applicable.
To exercise any of these rights, contact us at henrik.akej@nilocollab.com. You also have the right to lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY), www.imy.se, or the supervisory authority in your EU member state.
6. Changes to this policy
We may update this policy from time to time. The current version, with its effective date, is always available on this page.
7. Contact
Nilo Collaborations ABBytaregatan 4D, 222 21 Lund, Sweden
Email: henrik.akej@nilocollab.com