Legal
Privacy policy
Last updated:
Note: All legal pages refer to Nokofy, a SaaS platform owned by UMS Solutions d.o.o., Belgrade 11050, Serbia — VAT ID (PIB) 114522183, company number 22034588. Responsible person: Marko Uljarević.
1. Who processes your data
The data controller is UMS Solutions d.o.o., Belgrade 11050, Serbia — VAT ID (PIB) 114522183, company number 22034588, the company providing the Nokofy service available at nokofy.com and tools.nokofy.com.
Nokofy is a SaaS platform owned by UMS Solutions d.o.o., Belgrade 11050, Serbia — VAT ID (PIB) 114522183, company number 22034588.
Responsible person: Marko Uljarević.
Contact for all questions about data protection: podrska@nokofy.com. A data protection officer (DPO) has not been appointed for now — there is no legal obligation to do so yet; if that changes, we will publish the contact here.
This policy explains what we do with the data of users of the Nokofy service and of visitors to nokofy.com.
2. What data we collect
Account data
Name, email address, password (stored encrypted; we do not see it), company name and billing details if you use a paid plan, language and interface settings.
Service usage data
The sites you add and analyse, the keywords you track, the searches and research you run, the texts you generate and edit, the reports you build, the team members you invite, and the history of API calls and limit usage.
Technical data
IP address, device and browser type, operating system, access time, the pages you opened in the application and any errors that occurred. This data arises automatically and serves security and fault fixing.
Cookies and similar technologies
These are described in detail on the Cookiespage.
Communication
Messages you send us through the contact form or by email, and our correspondence with you.
What we don't ask for: we do not ask for and do not want special categories of data — health, religion, political opinions, biometrics. Please don't enter them into free-text fields.
3. Why we process data and on what basis
| What we do | Why | Legal basis |
|---|---|---|
| Opening and running an account, access to the application | Without it there is no service | Performance of a contract |
| Analyses, research and content writing | It is the service you asked for | Performance of a contract |
| Billing, invoices, accounting | To bill you and meet tax obligations | Performance of a contract and legal obligation |
| Support and answers to questions | So you get help when you're stuck | Performance of a contract / legitimate interest |
| Security, abuse prevention, access logs | To keep the service safe | Legitimate interest |
| Product improvement and aggregate usage statistics | So we know what to fix | Legitimate interest |
| Newsletter and announcements | So you hear what's new | Consent (unsubscribe in one click) |
When we rely on legitimate interest, we assess that the interest does not override your rights — and we can show you that assessment on request.
4. How long we keep data
- Account data and the content in the account — for as long as you have an account. After the account is deleted: 30 days in which you can restore it, then permanent deletion.
- Billing data and invoices — as long as tax law requires — in Serbia that is 10 years.
- Position history and data from connected tools — for as long as the account and the site it relates to exist; deleted together with the site.
- Technical logs — 7 days.
- Support correspondence — 24 months.
- Newsletter data — until you unsubscribe, then a short while longer so we can prove that you did.
Backups are deleted in the ordinary rotation cycle, at the latest 90 days after deletion from production.
5. Who we pass data to
We do not sell your data. To anyone, ever.
We share it only with processors who help us run the service, and only to the minimum extent needed. We have a data processing agreement with each of them. Categories of processor:
- Hosting and infrastructure — servers and databases are located in the European Union, in Germany.
- Email service provider — sending transactional messages (registration confirmation, password reset, notifications) and the newsletter.
- Payment processor — Paddle. Payments are processed by Paddle as the Merchant of Record: Paddle issues the invoice and processes the payment. We never see or store card data — it stays with Paddle. Paddle privacy policy: paddle.com/legal.
- AI text processing provider — processing text in order to produce content and suggestions. Only what is needed to produce the text is passed on (topic, keywords, given instructions), not your personal data from the account.
- Search data provider — obtaining data on volumes, competitors and positions for the keywords you track.
- Error and stability monitoring tools — technical data about errors in the application.
We may also disclose data to a competent authority where the law requires it — and in that case we ask for the legal basis and, where permitted, inform you.
Transfers outside the EU and EEA: we make every effort to keep data within the EU. If a processor processes data outside that area, it is done on the basis of standard contractual clauses or an adequacy decision.
6. Data from Google Search Console and similar tools
If you connect your Google Search Console or Bing Webmaster account, the following applies — and it is deliberately written more strictly than the law requires:
Access is read-only. We change nothing in your account, add and remove no sites, send nothing back. We share the data we retrieve with nobody.
- The data we retrieve — queries, clicks, impressions, positions and pages — is used solely to display it to you in your own account and to cross-check it with the other analyses you ran yourself.
- We do not use it for anyone else's account, do not include it in aggregate statistics anybody else would see, and do not sell it.
- You can break the connection at any time from the site's settings. We then stop retrieving new data, and the history already retrieved is deleted together with the site.
The same applies to any other account you connect yourself.
What permissions we ask for
When you connect a Google account, Google's consent screen shows exactly this — nothing more is requested:
- openid and email — so we know which account is connected and can tie it to your account with us.
- Search Console, read-only (`webmasters.readonly`) — the list of sites you have in Search Console and their search data: queries, clicks, impressions, positions and pages.
We do not request write permission and cannot obtain it silently — Google would show it on that same screen.
Google API Services User Data Policy
Nokofy's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy , including the Limited Use requirements. Concretely, that means:
- we use the data solely to show you what you connected the account for — positions, clicks, impressions and analyses inside your own account;
- we do not transfer it to third parties, except where necessary to run the service, for security purposes, or where the law requires it;
- we do not use it for advertising, ours or anyone else's;
- no human reads it, unless you ask us to while reporting a problem, it is necessary for security, or the law requires it;
- we do not use it to train artificial intelligence models.
7. Your rights
Under the GDPR and the Serbian Personal Data Protection Act you have the right to:
- access — to find out what data we hold about you and to receive a copy;
- rectification — to correct inaccurate or incomplete data; most of it you can correct yourself, in the account settings;
- erasure — to ask us to delete you, other than what we must keep by law;
- restriction of processing — to “freeze” processing temporarily while something is clarified;
- portability — to receive your data in a common, machine-readable format; an export also exists in the application itself;
- objection — to object to processing based on legitimate interest, including direct marketing;
- withdrawal of consent — at any time, without affecting processing that has already taken place;
- a complaint to a supervisory authority — in Serbia that is the Commissioner for Information of Public Importance and Personal Data Protection; if you are in the EU, the supervisory authority of your country.
You send the request to podrska@nokofy.com . We reply within 30 days at the latest; if the request is complex the deadline may be extended, but we will tell you. The request is free of charge unless it is manifestly unfounded or repeated without reason.
We do not make automated decisions about you that would have legal consequences for you.
8. Security
What we concretely do:
- an encrypted connection (HTTPS) on every page and for every call;
- passwords are stored in a form that cannot be turned back into readable text;
- access to data is limited to those who need it for their work, with an access record;
- regular backups, kept separate from production;
- regular updating of components and monitoring of security advisories.
No system is impenetrable. If a data breach does occur that could endanger your rights, we notify the supervisory authority within 72 hours, and you without delay if the risk is high.
9. Children
The service is not intended for persons under 18 and we do not knowingly collect their data. If we learn that a child opened an account without parental consent, we delete it.
10. Changes to this policy
We update the policy when the way we work or the law changes. The date of the last change is always at the top of the page. We announce significant changes by email and by a message in the application, at least 15 days in advance.
11. Data protection contact
- Support: podrska@nokofy.com
- Nokofy is a SaaS platform owned by UMS Solutions d.o.o., Belgrade 11050, Serbia — VAT ID (PIB) 114522183, company number 22034588.
- Responsible person: Marko Uljarević.
- Supervisory authority in Serbia: Commissioner for Information of Public Importance and Personal Data Protection, Bulevar kralja Aleksandra 15, Belgrade.
Other legal pages: Terms of service · Cookies