Privacy policy

Last updated: September 2026

This Privacy Policy describes how Naykora collects, uses, shares, and protects your personal data when you use naykora.ai and the Naykora service. We are committed to respecting your privacy and complying with the Swiss Federal Act on Data Protection (FADP) as well as the General Data Protection Regulation (GDPR - EU 2016/679) for persons residing in the European Union.

1. Data controller

The data controller within the meaning of the FADP and the GDPR is the operator of the Naykora service, identified in the Legal notice. Its full contact details are provided on written request to contact@naykora.ai, which is also the dedicated address for data protection matters. At the current scale of processing, Naykora is not required to appoint a data protection officer and reassesses this obligation at each growth milestone.

2. Data collected and legal bases

• Account data (first name, last name, email, date of birth, language) - contract performance (art. 6.1.b GDPR). • Authentication data: one-time codes, magic links, encrypted password, session tokens, Google identifiers when you sign in with OAuth, encrypted two-factor authentication secret if you enable it (mandatory for administrators) - contract performance and security obligation (art. 6.1.b and 6.1.c). • Payment data (Stripe customer ID, billing history, subscription status) - contract performance and accounting obligation. • Referral data (code, referrer-referral relationships, IBAN/BIC, earnings history) - contract performance and anti-money-laundering obligations. • Technical monitoring data, collected by the Naykora Dragon Shield application: device identification (hostname, manufacturer, model, serial number, operating system and version, agent version); security status (installed and pending patches, antivirus status, available updates, system alerts); operating status (last contact, uptime, processor, memory and disk usage); network (public IP address, MAC address, gateway, domain); name of the user account signed in on the machine; installed software inventory, hidden by default in your dashboard. We do not access files, emails, documents, photos, browsing history or any personal content: no screenshots, no activity recording - contract performance. • Communication data (built-in messaging, notifications) - contract performance. • Gift journey: the recipient's first name and, if you choose the guardian-led setup, a way to reach them, used solely to schedule the setup with their consent and erased afterwards - contract performance. • Connection and usage data (IP address, browser, pages visited, dashboard actions, currency preference) - legitimate interest (security, fraud prevention, Service improvement). • Essential cookies (session, preferences) - strictly necessary; Meta Pixel marketing cookie placed only after your agreement - consent (art. 6.1.a).

3. Processing purposes

Your data is used to: • provide the Service: monitor device health, alert, manage the subscription; • bill and collect payments; • operate the referral program and prevent fraud; • contact you: alerts, transactional emails, support, product information; • secure the Service: intrusions, brute force, access auditing; • comply with our legal obligations: accounting, judicial requests; • improve the Service through aggregated, anonymous analytics; • measure our advertising campaigns, only if you accepted marketing cookies.

4. Subprocessors and recipients

Each subprocessor is bound by a data processing agreement or an equivalent contractual commitment: • Supabase (USA, EU instances): database, authentication, storage. Data: account, referral, monitoring, messages. Transfer: Standard Contractual Clauses (SCCs). • Stripe (Ireland / USA): payments, billing, taxes. Data: name, email, customer ID, transactions, country, IBAN where applicable. SCCs. • SuperOps Inc. (USA): device supervision infrastructure used by the Naykora Dragon Shield application. Data: technical metrics, alerts, software inventory. SCCs. • Resend (USA): transactional email delivery. Data: email address, email content. • Vercel (USA): website and API hosting, anonymous audience measurement and performance. Data: server logs, technical IP addresses; no third-party cookie. SCCs. • Sentry (USA): technical error monitoring. Data: error trace, request context, user identifier when relevant. SCCs. • Upstash (Ireland / USA): rate limiting. Anonymized technical data. • ipapi.co and frankfurter.dev: geolocation and exchange rates for price display. No personal data stored. • Discord Inc. (USA): our team's internal alert channel. Data: first name and name of the device concerned, never email or payment data. SCCs. • Meta Platforms Ireland Ltd (Ireland / USA): advertising measurement (Pixel and Conversions API), only with your consent. Data: browsing and conversion events, hashed identifiers; never your monitoring data. SCCs and DPF. We never sell your data. The up-to-date list can be requested at contact@naykora.ai.

5. International transfers

Some subprocessors are located in the United States. These transfers are governed by the European Commission's Standard Contractual Clauses (2021 version), by the EU-US Data Privacy Framework for certified providers, and by additional technical measures (encryption, access controls, administrative access logging).

6. Data security

Naykora applies technical and organizational measures proportionate to the risk. To preserve their effectiveness, we do not publish the details of our configurations. Our commitments: • encryption of data in transit and at rest; • strong authentication and strict session management; • data isolation down to the database level: each user can only access their own information; • protection against brute force and automated abuse; • integrity verification of exchanges with our providers (payment, authentication, supervision); • strict browser-side security headers; • restricted, audited and logged administrative access; • dependency monitoring and rapid security patches; • code review before each deployment. A detailed technical write-up can be provided under a confidentiality agreement, on request to contact@naykora.ai.

7. Data retention

• Account data: for the duration of the relationship; anonymized immediately upon account deletion. • Accounting and tax data (invoices, Stripe history): 10 years, legal obligation. • Monitoring data (devices, alerts, alert episodes): for the duration of the subscription, deleted with the account. Live metrics (processor, memory, disks) are not stored, they are read at display time. • Sent email log (recipient, type, subject, status): 180 days, then automatic daily purge. • Anonymous internal measurement of the purchase journey: 365 days, then automatic purge. • Messaging data: for the duration of the relationship; archive available once a conversation is resolved; deletion on request. • Referral data (earnings, IBAN, payouts): 10 years, accounting and AML obligations. • Security logs (sign-ins, administrative actions): for the duration of the relationship, for security and audit purposes. After these periods, data is irreversibly deleted or anonymized.

8. Your rights

You have the following rights: • access: obtain a copy of your data; • rectification of inaccurate data; • erasure, subject to legal retention obligations; • portability in a structured format (JSON); • objection to processing based on legitimate interest; • restriction of processing while a dispute is examined; • withdrawal of consent at any time, without retroactive effect; • post-mortem directives on the fate of your data; • not to be subject to a fully automated decision producing legal effects: Naykora makes none. To exercise them, write to contact@naykora.ai: acknowledgement within 7 days, response within one month (three months for complex requests, with prior notice). You may also lodge a complaint with the supervisory authority of your country of residence: • Switzerland: Federal Data Protection and Information Commissioner (FDPIC, PFPDT) - edoeb.admin.ch • France: CNIL - cnil.fr • Portugal: CNPD - cnpd.pt • Belgium: APD - autoriteprotectiondonnees.be • Other EU countries: national data protection authority.

9. Cookies and local storage

Essential cookies, exempt from consent: • logged-in session (Supabase Auth): about 7 days, renewed automatically; • currency preference (CHF/EUR): 1 year; • language (FR/EN/PT): 1 year; • trusted device for two-factor authentication, if you enable it: 30 days; • technical cookie for Google sign-in: 10 minutes. Marketing cookie, subject to your consent in the banner: the Meta Pixel measures our advertising campaigns and only loads if you click "Accept all"; with "Essential only", no marketing tracker is loaded. Your choice is stored in the browser and can be changed at any time with the "Manage my cookies" button at the bottom of this page. A few display preferences (theme, interface state) are stored locally without being sent to our servers. We also count, anonymously, without cookies, IP address or identifier, the key steps of the purchase journey (visit, click, checkout started).

10. Minors

Only adults may create an account. Monitoring may cover devices used by minors in the household, under the responsibility of the account holder. We do not collect any data directly from children; if you believe a minor has transmitted data to us without parental consent, write to contact@naykora.ai for immediate deletion.

11. Data breach notification

In case of a data breach likely to result in a high risk to your rights, we notify the competent supervisory authority within 72 hours and inform you by email as soon as possible of the nature of the incident, the data concerned and the measures taken or recommended. An internal incident register is kept.

12. Automated decisions and profiling

Monitoring alerts rely on deterministic technical rules (for example critical security patches pending) and do not constitute profiling within the meaning of Article 22 of the GDPR. Referral fraud detection is automatic, but any account suspension is subject to prior human review and can be contested at any time.

13. Changes to this policy

We may update this policy to reflect legal or technical changes or new subprocessors. Any substantial change is notified to you by email at least 30 days before it enters into force. The last update date appears at the top of the page; the previous version can be obtained on request.

14. Contact

Email: contact@naykora.ai (recommended subject: "Personal data") Built-in messaging: from your dashboard, Messages section. Postal address: available on request to contact@naykora.ai.
Clears your current choice and shows the consent banner again.