Privacy Policy
Last modified: 23 July 2026 · Version 1.0
1. Who we are
Nodge is a trade name of CoreCubes B.V., a company incorporated in the Netherlands (KvK 94074542), with its registered office at Winklerlaan 363-41, 3571 KE Utrecht, the Netherlands. For anything in this policy, contact us at info@nodge.ai.
CoreCubes B.V. is the controller of the personal data described here.
2. What this policy covers, and what it does not
This policy explains how we handle personal data about you, our account holders and prospective customers: the data you give us to create an account, use, and pay for the Service.
It does not cover the personal data that may sit inside the applications and agents you build and run on Nodge. For that data, you are the controller and we act as your processor, and our handling is governed by the Data Processing Agreement, not this policy.
3. What we collect and why
We keep data collection deliberately minimal. We collect:
| Category | Examples | Why (lawful basis) |
|---|---|---|
| Account data | Name, email, login credentials/identifiers | To create and operate your account. Performance of our contract (Art. 6(1)(b) GDPR) |
| Billing & tax data | Company name, VAT ID, country, payment details, invoices | To take payment and meet tax/invoicing law. Contract and legal obligation (Art. 6(1)(b), (c)) |
| Support data | Messages and information you send us for support | To help you. Contract and our legitimate interest in supporting users (Art. 6(1)(b), (f)) |
| Security & access logs | Sign-in events, actions in the platform, IP address | To keep the Service and your account secure. Legitimate interest and legal obligation (Art. 6(1)(f), (c)) |
| Consent records | Which terms version you accepted, when, and how | To evidence our agreement. Legitimate interest and legal obligation (Art. 6(1)(f), (c)) |
| Website enquiries | Name, email, optional company, and your message from the contact form or an email to us | To respond to you and, where relevant, take steps at your request before entering a contract. Legitimate interest and pre-contract steps (Art. 6(1)(f), (b)) |
We use the details you send through the website contact form only to respond to you. We do not use them for marketing without your consent, and we do not carry out any solely automated decision-making that produces legal or similarly significant effects (Art. 22 GDPR).
What we do not do: we do not run product telemetry or usage tracking, we do not sell your personal data, and we do not use your personal data, your code, prompts, or agent interactions to train any model.
4. Cookies
The Service uses only strictly necessary cookies and equivalent storage required to run it, for example, to keep you signed in and to protect against cross-site request forgery. These are exempt from consent, so we do not use a cookie banner. We set no analytics, advertising, or tracking cookies. If this ever changes, we will ask for your consent first.
5. Who we share data with
We share personal data only with:
- Sub-processors that help us run the Service (such as hosting, backup, email, and billing). Our current list, with each provider's location, is at https://nodge.ai/sub-processors. Contact-form messages are delivered by AhaSend B.V. (Netherlands) and received in our Proton email (Proton AG, Switzerland).
- Authorities or advisers where we are legally required to, or to establish or defend legal claims.
We do not share your personal data with anyone else.
6. Where your data is: no transfers outside the EU
The account, billing, and enquiry data covered by this policy is processed and stored within the European Union, on our platform in the Netherlands. The one exception is our email: messages to and from us are handled in Proton (Proton AG, Switzerland). Switzerland has an EU adequacy decision, so no Standard Contractual Clauses are required, and we use no sub-processor for this data outside the EEA or such an adequacy-decision country.
This is separate from where the data inside the apps you build is stored. If you provision compute, you choose your cluster location, which may be outside the EEA; that data is governed by the Data Processing Agreement, where you are the controller, not by this policy.
If you configure your own third-party model provider using your own LLM keys, or connect your projects to any other third-party tool you choose (for example a code host, a chat or paging tool, or an external endpoint), any data you send to that provider or tool is governed by your relationship with them, not by this policy. Any transfer outside the EEA that results from an integration you configure is your choice.
7. How long we keep it
We keep personal data only as long as needed for the purpose it was collected:
- Account data: kept while your account is active. If you request account deletion, we delete or anonymise it within 30 days. If an account and its environments stay inactive for 90 days, we delete it after sending a prior warning by email. In each case, unless we must keep it longer.
- Billing and invoice data: for the statutory tax-retention period (in the Netherlands generally 7 years).
- Security and consent logs: for 12 months, proportionate to their security and evidential purpose.
- Audit logs within an organisation: where you are a member of an organisation, that organisation keeps an audit log of the actions taken in its account. This log is a record of the organisation's activity, not of you as an individual. It is retained for the organisation's configured audit-retention period (by default, records are queryable in the platform for 3 months, then archived and kept for a further 365 days), after which it is removed. While the log is retained, deleting your account removes your personal account data, but the name attached to actions you took stays in the log for the remainder of that period, because a record of who did what would lose its meaning and integrity without it. We keep no more than that name and the record of the action; we rely on our and the organisation's legitimate interest in an accurate, tamper-evident record. The organisation is the controller for its own audit log; we process it on its behalf under the DPA.
- Website enquiries: for as long as needed to handle your request and any follow-up, and to keep a reasonable record of the correspondence, then deleted.
8. Your rights
Under the GDPR you have the right to access your personal data, to rectify it, to erase it, to restrict or object to processing, and to data portability. Where we rely on consent, you may withdraw it at any time.
To exercise any of these, email info@nodge.ai. We will respond within the statutory time limit. When we act on an erasure request we remove your personal account data, but the name attached to your past actions remains in an organisation's audit log until that log reaches the end of its retention period, on the legitimate-interest basis described in Section 7. You also have the right to lodge a complaint with the Dutch supervisory authority, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl), or with the authority in your EU country of residence.
9. How we protect your data
We apply appropriate technical and organisational measures, including encryption at rest, TLS in transit, access controls, and full audit logging, and we are certified to ISO/IEC 27001:2022. More detail is on our security page.
10. Marketing communications
We send service and security messages that are necessary to operate your account. We send marketing emails only where you have opted in or where permitted by law, and you can unsubscribe at any time.
11. Data Protection Officer and representative
We have appointed a Data Protection Officer, who you can reach at koen@nodge.ai for any question about how we handle your personal data or to exercise your rights. As an EU-established controller, no Article 27 EU representative is required.
12. Changes to this policy
We may update this policy from time to time. We will post the new version here with an updated date and version number, and for material changes we will notify you (for example, by email or in-product notice). Previous versions remain available.
Contact
CoreCubes B.V. (Nodge), Winklerlaan 363-41, 3571 KE Utrecht, the Netherlands. KvK 94074542 · BTW NL866626402B01. Reach us at info@nodge.ai.