Nalvera ← Back to platform
Privacy Policy

Version 1.4  ·  Effective date: 13 July 2026

Summary: We store your imaging data to run AI models (segmentation, classification, image generation, and other inference tasks). On every tier, your data is used solely to deliver the AI result. It is never used for research or model improvement unless you explicitly opt in, per individual job, on the results page. Paid memberships and credit top-ups are handled by our payment processor, Stripe. You can delete your data at any time — the one exception is files from jobs you explicitly opted into research, which may be retained afterwards (see the research-use section below). We use essential cookies only — no advertising and no cross-site tracking — and measure site usage with Umami, a cookieless analytics service (Section 6). No third-party fonts.

1. Who We Are (Data Controller)

The data controller for Nalvera is Nalvera BV. Organisations that require a formal Data Processing Agreement (DPA) for their use of Nalvera can request one via our contact page.

Nalvera is a research-focused platform that runs peer-reviewed AI models on medical imaging data, including segmentation, classification, and image generation. The service is funded through paid memberships and credit top-ups, which sustain its research, education, and operational costs.

2. What Personal Data We Collect

Account data

Imaging data

Technical data

Billing data

Legal basis: Contract performance (Art. 6(1)(b) GDPR) to provide paid features; Legal obligation (Art. 6(1)(c) GDPR) to retain invoices for accounting and tax purposes.

3. How We Use Your Imaging Data

The same rule applies to every tier: no secondary use of your data without your explicit, per-job opt-in. By submitting data you confirm that you hold the rights to the imaging data and that it contains no human subject data or personal health information.

All accounts (Guest and paid memberships)

Your uploaded data and AI outputs are not used for any secondary purpose by default. Your data is processed solely to deliver the requested AI result and is not retained for model training, benchmarking, or publication.

Legal basis: Contract performance (Art. 6(1)(b) GDPR).

Optional per-job research opt-in

On the results page you can flag an individual job as available for research. The opt-in is never pre-selected, applies only to that job, and covers no other upload, past or future. Only for jobs you explicitly flag, you grant Nalvera BV (the Nalvera operator) a worldwide, royalty-free, non-exclusive licence to:

Files of an opted-in job may be retained for these purposes even after you delete the job. You can withdraw your consent at any time by contacting us (Section 10); withdrawal does not affect processing already carried out.

Legal basis: Consent (Art. 6(1)(a) GDPR).

Your responsibility

4. Data Retention

5. Your Rights Under GDPR

As an EU data subject you have the following rights.

Right of access (Art. 15)
Request a copy of all personal data we hold about you.
Right to rectification (Art. 16)
Correct inaccurate personal data.
Right to erasure (Art. 17)
Delete your account and all associated data. Use the platform's delete functions or email us.
Right to restrict processing (Art. 18)
Request we stop processing your data in specific ways while a dispute is resolved.
Right to data portability (Art. 20)
Receive your personal data in a machine-readable format.
Right to object (Art. 21)
Object to processing based on legitimate interest.
Right to withdraw consent
Withdraw consent at any time — for example a per-job research opt-in — by contacting us (Section 10).
Right to lodge a complaint
File a complaint with the Belgian DPA (GBA) or your national supervisory authority.

6. Cookies & Similar Technologies

Under the ePrivacy Directive (as implemented in Belgian law) and GDPR, we must inform you about all cookies and obtain your consent for non-essential ones.

Strictly necessary cookies do not require your consent under Art. 5(3) of the ePrivacy Directive. We set nalvera_session only when you log in and only store a cryptographic hash in the database; the plaintext token is never stored server-side.

Cookieless analytics (Umami)

Our public pages load Umami (script served from cloud.umami.is; page-view beacons are sent to gateway.umami.is), a privacy-focused analytics service, to give us aggregate page-view statistics. Umami sets no cookies and stores nothing in your browser — which is why it does not appear in the cookie table above — and it does not build cross-site profiles or advertising audiences. The data involved is limited to aggregate usage information such as the page URL, referrer, and coarse browser/device class. As with any web request, your IP address reaches Umami's servers in transit; there it is used only to derive coarse location statistics (country) and, per Umami's privacy policy, is not retained. The statistics never include your imaging data, account data, or anything you upload. See Umami's privacy policy for details.

7. Third-Party Services & Data Transfers

Imaging data and account data are hosted on servers within the European Economic Area (EEA). Routine transfers outside the EEA are limited to billing data sent to Stripe, which may be processed in the US under the EU-US Data Privacy Framework and Standard Contractual Clauses, and the aggregate, cookieless usage statistics processed by our analytics provider Umami (Section 6) — which never include imaging data, account data, or uploads. No imaging data is transferred outside the EEA.

8. Security Measures

9. Changes to This Policy

We may update this policy to reflect changes in law, our practices, or our services. Material changes will be communicated via email (if you have notifications enabled) and by updating the "Effective date" at the top. Continued use of the platform after notification constitutes acceptance of the updated policy.

10. Contact & Complaints

For all privacy-related queries, requests to exercise your rights, or to report a concern:

Back to Platform