Legal
Privacy Policy
Status: own-copy, published.
Last updated: 30 June 2026
This Privacy Policy explains how Noxlyt Systems P.S.A. processes personal data in connection with our website noxlyt.com, our application noxlyt.app, and the release-validation service we provide to business clients. It is written to meet the transparency requirements of Regulation (EU) 2016/679 (GDPR / RODO), in particular articles 13 and 14.
Data controller / our identity:
Noxlyt Systems prosta spółka akcyjna (Noxlyt Systems P.S.A.)
ul. Chęcińska 26B/44, 25-020 Kielce, Poland
KRS 0001245297 · Sąd Rejonowy w Kielcach, X Wydział Gospodarczy Krajowego Rejestru Sądowego
NIP 9592093594 · REGON 544903117 · Share capital: 1 000,00 PLN
Contact for privacy matters: privacy@noxlyt.com1. Who this policy is for
This policy applies to:
- Website visitors to noxlyt.com;
- People who contact us through the website contact form or by email;
- Authorised users of the noxlyt.app application at our business clients (Noxlyt is invite-only — there is no public self-sign-up).
It also explains, at a high level, how we handle personal data contained in our clients' test data, where we act as a processor on the client's behalf.
2. Controller and processor roles
Noxlyt processes personal data in two distinct capacities:
- As a controller — for data we decide the purposes of: your account data, contact enquiries, and operational/security data of our website and application.
- As a processor (GDPR art. 28) — for personal data that may be contained in aclient's test code, test data, and test results that we run and store on the client's instruction. Here the client is the controller and Noxlyt is theprocessor. That relationship is governed by a separate Data Processing Agreement(see our DPA and the Retention section below).
3. What personal data we process
| Category | Examples | Our role |
|---|---|---|
| Account data | Name, work email, organisation, role, authentication data | Controller |
| Contact-form data | Name, email, the message you send us | Controller |
| Application usage / security data | Sign-in session, audit/security logs, technical metadata needed to operate and secure the service | Controller |
| Client test data | Any personal data your test projects or test results happen to contain | Processor (on the client's behalf) |
| Website analytics | Aggregate, anonymised traffic metrics (cookieless — see §9) | Controller |
We do not intentionally collect special-category data (GDPR art. 9). Clients should not place special-category personal data in test artefacts without first agreeing appropriate safeguards with us under the DPA.
4. Why we process it, and our lawful bases (GDPR art. 6)
| Purpose | Lawful basis |
|---|---|
| Providing and operating the noxlyt.app service to a client | Performance of a contract (art. 6(1)(b)) and our legitimate interests / the client's instructions where we act as processor |
| Creating and managing user accounts (invite-based) | Performance of a contract and our legitimate interest in secure access management (art. 6(1)(b), (f)) |
| Responding to contact-form / email enquiries | Our legitimate interest in answering you (art. 6(1)(f)); steps prior to a contract (art. 6(1)(b)) |
| Securing the service (anti-bot, audit logging, abuse prevention) | Our legitimate interest in security and integrity (art. 6(1)(f)); legal obligation where applicable |
| Aggregate, cookieless website analytics | Our legitimate interest in understanding and improving the site (art. 6(1)(f)) |
| Complying with legal, tax and accounting obligations | Legal obligation (art. 6(1)(c)) |
Where we rely on legitimate interests, you have the right to object (see §10).
5. Where the data comes from (GDPR art. 14)
Most data we hold about you comes directly from you or from your use of the service. Some personal data, however, reaches us indirectly: where we act as a processor, the personal data inside a client's test data is provided to us by the client (the controller), not by the data subject. The categories of such data are determined by the client and are described, for that client, in the relevant Data Processing Agreement.
6. Sub-processors
To deliver the service we rely on a small set of sub-processors, each operating under a data-processing agreement (DPF-certified where applicable). This list mirrors our publicsub-processor page, which is the cross-reference of record:
| Sub-processor | Purpose | Location | Safeguards |
|---|---|---|---|
| Google Cloud (Google Ireland / Google LLC) | Hosting, database, storage, message queue, test execution | EU — europe-west1 (Belgium) | DPA/SCCs; DPF-certified |
| GitHub (GitHub Inc. / Microsoft) | Version control of client test-project source code | United States | DPA/SCCs; DPF (Microsoft) |
| Cloudflare | DNS, CDN, edge/TLS, anti-bot (Turnstile) and contact-form processing | Global edge | DPA/SCCs; DPF |
| Cloudflare Web Analytics | Aggregate, anonymised, cookieless website traffic metrics (no client-side state; no per-user tracking) | Global edge | DPA/SCCs; DPF |
| Resend (Plus Five Five, Inc.) | Transactional email delivery | Email sent via Ireland (eu-west-1); account data, metadata and logs stored in the United States | DPA/SCCs; DPF-certified (EU-U.S. DPF) |
A full Data Processing Agreement, including the sub-processor schedule, is available on request from privacy@noxlyt.com.
7. Where your data is stored and processed (international transfers)
Your test results and database are stored in the EU — Google Cloud, Belgium (europe-west1) — and your tests execute on EU-region infrastructure (Google Cloud, Belgium). Test-project source is version-controlled in GitHub (United States); web traffic is routed via Cloudflare's global network; and transactional email is sent via the Resend EU send-region while Resend's account data, metadata and logs are stored in the United States.
Where personal data is transferred outside the EEA (notably to GitHub and to Resend's US account infrastructure), the transfer is covered by appropriate safeguards — Standard Contractual Clauses and, where available, the EU-U.S. Data Privacy Framework. We re-verify these certifications at publication and periodically thereafter.
8. How long we keep data (retention) and erasure
- Account and user data — retained for the duration of the service relationship with your organisation. On a verified erasure request (see §10) we pseudonymise your personal identifiers (your name and email are overwritten) so that any historical validation records remain attributable to an anonymous reference rather than to you.
- Tenant / project data (your projects and their test results) — on off-boarding of a client or project, this data enters a defined retention window of up to 120 days, after which it is permanently deleted.
- Validation/execution records — for audit integrity, recorded validation runs are retained for the lifetime of the related project and are deleted (together with the project) when the client or project is removed; we do not silently alter historical run records.
- Contact-form enquiries — retained for as long as needed to handle your enquiry and, where relevant, to pursue a business relationship, then deleted or anonymised.
- Report retention beyond the above may vary with your plan — see your plan's terms.
We respond to erasure and other data-subject requests within the period required by law (one month under GDPR art. 12, extendable as that article allows).
9. Cookies and website analytics
Our website uses only strictly-necessary cookies and a cookieless analytics tool (Cloudflare Web Analytics), so we do not display a cookie consent banner. The Cloudflare analytics tool does not use cookies or other client-side state and does not track individuals over time; it produces only aggregate, anonymised metrics. Full detail, including the anti-bot and session cookies, is in our Cookie Policy.
10. Your rights
Subject to the conditions in the GDPR, you have the right to:
- access your personal data (art. 15);
- request rectification of inaccurate data (art. 16);
- request erasure ("right to be forgotten", art. 17);
- request restriction of processing (art. 18);
- data portability (art. 20);
- object to processing based on our legitimate interests (art. 21); and
- not be subject to solely automated decision-making — see §11 (art. 22).
Where we process personal data as a processor on a client's behalf, requests are directed to and decided by that client (the controller); we will assist the client in responding.
To exercise any right, contact privacy@noxlyt.com. We may need to verify your identity before acting. You also have the right to lodge a complaint with a supervisory authority — in Poland, the Prezes Urzędu Ochrony Danych Osobowych (UODO), ul. Stawki 2, 00-193 Warszawa.
11. Automated decision-making and profiling
We do not make decisions about you based solely on automated processing, and we donot carry out profiling within the meaning of GDPR art. 22.
12. Changes to this policy
We may update this policy from time to time. Material changes will be reflected in theLast updated date above and, where appropriate, communicated to affected clients.
13. Contact
For any privacy question or to exercise your rights: privacy@noxlyt.com, or write to the registered address above.