Nalvera.AI ← Back to platform
Privacy Policy

Version 1.5  ·  Effective date: 30 July 2026

1. Who We Are (Data Controller)

The data controller for Nalvera is Nalvera BV. Organisations that require a formal Data Processing Agreement (DPA) for their use of Nalvera can request one via our contact page.

Nalvera is a research-focused platform that runs peer-reviewed AI models on medical imaging data, including segmentation, classification, and image generation. The service is funded through paid plans and credit top-ups, which sustain its research, education, and operational costs.

2. What Personal Data We Collect

Account data

Imaging data

Technical data

Billing data

Legal basis: Contract performance (Art. 6(1)(b) GDPR) to provide paid features; Legal obligation (Art. 6(1)(c) GDPR) to retain invoices for accounting and tax purposes.

3. How We Use Your Imaging Data

The same rule applies to every tier: no secondary use of your data without your explicit, per-job opt-in. By submitting data you confirm that you hold the rights to the imaging data and that it contains no human subject data or personal health information.

All accounts (Guest and paid plans)

Your uploaded data and AI outputs are not used for any secondary purpose by default. Your data is processed solely to deliver the requested AI result and is not retained for model training, benchmarking, or publication.

Legal basis: Contract performance (Art. 6(1)(b) GDPR).

Optional per-job research opt-in

On the results page you can flag an individual job as available for research. The opt-in is never pre-selected, applies only to that job, and covers no other upload, past or future. Only for jobs you explicitly flag, you grant Nalvera BV (the Nalvera operator) a worldwide, royalty-free, non-exclusive licence to:

Files of an opted-in job may be retained for these purposes even after you delete the job. You can withdraw your consent at any time by contacting us (Section 11); withdrawal does not affect processing already carried out.

Legal basis: Consent (Art. 6(1)(a) GDPR).

Your responsibility

4. How We Use Your Account Data

Section 3 covers the imaging data you submit. This section covers everything else we do with your account data, the data each purpose uses, and the legal basis we rely on for it.

Purposes and legal bases

PurposeData usedLegal basis
Creating and operating your account Email address, password hash, account and verification status, plan Contract — Art. 6(1)(b)
Email verification and essential account messages Email address, verification and password-reset codes Contract — Art. 6(1)(b)
Running AI models on the data you submit Imaging files, AI outputs, job metadata (Section 3) Contract — Art. 6(1)(b)
Optional per-job research use of imaging data The scans and outputs of jobs you individually flag (Section 3) Consent — Art. 6(1)(a)
Security, abuse prevention and account lockout Login history, IP address, server and technical logs Legitimate interests — Art. 6(1)(f): keeping the platform and its accounts secure
Security and compliance audit trail Records of administrative and security-relevant actions Legal obligation — Art. 6(1)(c); legitimate interests — Art. 6(1)(f): meeting our ISO 27001 (A.12.4) obligations
Aggregate usage statistics Country, derived once from your IP address at sign-up Legitimate interests — Art. 6(1)(f): understanding, in aggregate, where the platform is used
Job notification emails Email address, job status Consent — Art. 6(1)(a), per event, switched on under Settings → Notifications
Onboarding and user-experience research Email address, account-creation date, verification status, whether any job has been submitted, last sign-in Legitimate interests — Art. 6(1)(f): understanding barriers to account activation and improving Nalvera's onboarding and user experience
Newsletter and product announcements Email address Consent — Art. 6(1)(a)
Taking payment for memberships and credit top-ups Billing data, transaction history Contract — Art. 6(1)(b)
Keeping invoices and accounting records Invoices and transaction records Legal obligation — Art. 6(1)(c)

Where a purpose above relies on legitimate interests, you have the right to object to that processing at any time under Art. 21 GDPR (Section 6). Where it relies on consent, you can withdraw that consent at any time, without affecting processing already carried out.

Onboarding and user-experience research

We work continuously to improve Nalvera's registration and onboarding experience. Where an account has been created but no job has subsequently been submitted, we may contact the account holder to establish what prevented activation, so that we can remove the obstacle.

Selection criteria. Recipients are determined solely from five account attributes: your email address, the date the account was created, its verification status, whether any job has been submitted on the account, and the date of last sign-in. On that basis:

Frequency. A maximum of two messages in total, for the lifetime of the account: one reminder and one research invitation. No further contact is made for this purpose thereafter, irrespective of whether you respond or object.

Exclusions. We do not use your imaging data, filenames or any detailed behavioural profiling to determine who is contacted. These messages contain no advertising, no offers or discounts, no promotion of products or features, and no upselling. Information you provide is not used to target marketing, nor for automated decision-making or profiling. Participation is voluntary and has no bearing on your account, your credit balance, or the service you receive.

Handling of responses. Responses are received and reviewed by our staff. They remain associated with your account while the feedback is being addressed, and are erased or irreversibly anonymised within 12 months. Please do not include patient data, health information or imaging files in your response; such material is not required and we ask that it not be submitted.

Right to object. Every message sent for this purpose contains a one-click link that discontinues further contact without requiring you to sign in. You may also disable it at any time under Settings → Notifications, or by contacting us (Section 11). This control operates independently of the newsletter: disabling research invitations does not alter your newsletter preference, and unsubscribing from the newsletter does not in itself discontinue these messages. Where you object, we retain a minimal record of the objection solely in order to continue giving effect to it.

Legal basis: Legitimate interests (Art. 6(1)(f) GDPR). The interest pursued is understanding barriers to account activation and improving Nalvera's onboarding and user experience. We have balanced this against your interests and fundamental rights: the processing is limited to basic account attributes, no imaging or health data is involved, the messages are non-promotional, the volume is capped at two messages for the lifetime of the account, and contact can be discontinued in one click.

5. Data Retention

6. Your Rights Under GDPR

As an EU data subject you have the following rights.

Right of access (Art. 15)
Request a copy of all personal data we hold about you.
Right to rectification (Art. 16)
Correct inaccurate personal data.
Right to erasure (Art. 17)
Delete your account and all associated data. Use the platform's delete functions or email us.
Right to restrict processing (Art. 18)
Request we stop processing your data in specific ways while a dispute is resolved.
Right to data portability (Art. 20)
Receive your personal data in a machine-readable format.
Right to object (Art. 21)
Object to any processing we base on legitimate interests — see the table in Section 4 for which purposes those are. For onboarding-research messages, use the one-click link in the message itself or the switch under Settings → Notifications; for anything else, contact us (Section 11).
Right to withdraw consent
Withdraw consent at any time — for example a per-job research opt-in — by contacting us (Section 11).
Right to lodge a complaint
File a complaint with the Belgian DPA (GBA) or your national supervisory authority.

7. Cookies & Similar Technologies

Under the ePrivacy Directive (as implemented in Belgian law) and GDPR, we must inform you about all cookies and obtain your consent for non-essential ones.

Strictly necessary cookies do not require your consent under Art. 5(3) of the ePrivacy Directive. We set nalvera_session only when you log in and only store a cryptographic hash in the database; the plaintext token is never stored server-side.

Cookieless analytics (Umami)

Our public pages load Umami (script served from cloud.umami.is; page-view beacons are sent to gateway.umami.is), a privacy-focused analytics service, to give us aggregate page-view statistics and aggregate interaction events — counts of things like “a sign-up button was clicked”, “an account was created”, or “the contact form was submitted”, together with a fixed label describing which button or enquiry category it was. These are counters: they carry no name, e-mail address, file name, scan metadata, or anything you typed, and they are not linked to your account. Umami sets no cookies and stores nothing in your browser — which is why it does not appear in the cookie table above — and it does not build cross-site profiles or advertising audiences. The data involved is limited to aggregate usage information such as the page URL, referrer, coarse browser/device class, and the interaction counters described above. Pages that carry a secret in their URL — account-activation and password-reset links — are deliberately excluded from analytics entirely. As with any web request, your IP address reaches Umami's servers in transit; there it is used only to derive coarse location statistics (country) and, per Umami's privacy policy, is not retained. The statistics never include your imaging data, account data, or anything you upload. See Umami's privacy policy for details.

8. Third-Party Services & Data Transfers

Imaging data and account data are hosted on servers within the European Economic Area (EEA). Routine transfers outside the EEA are limited to three things: billing data sent to Stripe, which may be processed in the US under the EU-US Data Privacy Framework and Standard Contractual Clauses; the aggregate, cookieless usage statistics processed by our analytics provider Umami (Section 7); and the single sign-up IP lookup described above, which may be answered outside the EEA. None of these include imaging data or uploads. No imaging data is transferred outside the EEA.

9. Security Measures

10. Changes to This Policy

We may update this policy to reflect changes in law, our practices, or our services. Material changes will be communicated via email (if you have notifications enabled) and by updating the "Effective date" at the top; where a change is significant we will ask you to review it again the next time you sign in.

This document is a privacy notice: it tells you what we do and why. Creating an account, or continuing to use the platform, means you acknowledge you have received it — it is not itself the legal basis for anything described here. Each purpose stands on the basis named for it in Section 4, and the purposes that require your consent (the newsletter, job notification emails, and the per-job research opt-in) are always asked for separately and can be withdrawn without affecting your account.

11. Contact & Complaints

For all privacy-related queries, requests to exercise your rights, or to report a concern:

Back to Platform