Privacy Policy
Last updated: 20 September 2026
1. Data controller
- Controller
- Matikus, Lda.
- Address
- Startup Madeira – EV 289, Campus da Penteada, 9020-105 Funchal, Madeira, Portugal
- NIPC
- 519 513 630
- tech@matikus.com
This policy explains how Matikus, Lda. processes personal data when people visit or use Nodify, create an account, configure buttons and notification channels, interact with a Nodify button, submit a contact request, or purchase a subscription.
2. Our role and the account holder’s role
Matikus, Lda. is the controller for account administration, service security, billing administration, and its own operational records. An account holder decides where a Nodify button is placed, which notification channels receive alerts, and whether a contact form is enabled. For personal data collected through those customer-configured features, the account holder may be an independent controller and is responsible for providing any additional notices and having an appropriate legal basis.
3. Account and authentication data
- Name and email address.
- Password hash and authentication records; Nodify does not store the plain-text password.
- Session identifiers, session expiry, IP address, and browser user-agent information used to secure signed-in sessions.
- Account creation and update timestamps.
- Subscription plan, status, billing period, trial start and end dates, reminder delivery status, existing Free-plan eligibility, and identifiers returned by Creem.
4. Workspace and channel data
- Button labels, descriptions, appearance, language, active dates, and public messages configured by the account holder.
- Notification-channel names, status, delivery history, and failure information.
- Credentials and destination details for email, Telegram, Slack, Discord, or customer-defined webhooks. Sensitive channel configuration is encrypted at rest and is not returned in plain text through the product interface.
5. Button interactions and contact requests
- The button tracking identifier, view time, confirmation time, status, and a shortened browser user-agent string.
- A salted, keyed hash of the visitor’s IP address for abuse prevention. The plain IP address is not stored in the click-event record.
- If a contact form is enabled: email address and message, plus optional name, subject, and urgency.
- Delivery jobs and daily aggregate counts for views, confirmations, quota blocks, and contact-form submissions.
Nodify does not place a tracking pixel in email signatures and does not use button activity to build cross-customer advertising profiles. Opening a Nodify URL and explicitly confirming an action are recorded as separate events; a notification is triggered only after confirmation.
6. Purposes and legal bases
- Account, buttons, notifications, and subscriptions
- Performance of a contract or steps requested before entering into a contract — Article 6(1)(b) GDPR.
- Contact requests sent through a customer’s button
- Taking steps at the sender’s request and the legitimate interests of the sender and account holder in communicating — Articles 6(1)(b) and 6(1)(f) GDPR, depending on the context.
- Security, abuse prevention, rate limits, and reliable delivery
- Our legitimate interest in protecting Nodify, its users, and visitors — Article 6(1)(f) GDPR.
- Accounting, tax, fraud-prevention, and regulatory records
- Compliance with legal obligations — Article 6(1)(c) GDPR.
8. Recipients and service providers
- Hetzner Online GmbH
- EU-based infrastructure hosting for the Nodify application and database.
- Brevo / Sendinblue SAS
- Transactional email delivery. Recipient address and notification content are sent to Brevo when an email channel or system email is used.
- Creem / Armitage Labs OÜ
- Merchant of record for paid subscriptions. Creem hosts checkout, processes payment and billing details, handles applicable taxes and invoices, and returns subscription identifiers and status to Nodify.
- Customer-configured destinations
- Telegram, Slack, Discord, and customer-defined webhook endpoints receive notification content only when an account holder configures and activates the relevant channel.
We do not use an external analytics, error-reporting, log aggregation, or uptime-monitoring provider at present. Operational request logs are produced within our own hosted environment and do not contain contact-form content.
9. International transfers
Our primary application infrastructure is located in the European Union. Some service providers or customer-selected notification destinations may process data outside the European Economic Area. Where Matikus, Lda. is responsible for such a transfer, it relies on an adequacy decision or appropriate safeguards under Chapter V GDPR, such as the European Commission’s standard contractual clauses. Customer-selected destinations are also subject to the account holder’s configuration and responsibilities.
10. Retention
- Click events and associated contact requests
- Retained for six months from the view, then deleted. Non-personal daily aggregate counts remain available for analytics.
- Account, workspace, and channel data
- Retained while the account or relevant item exists. Account deletion removes account-linked operational data immediately from the active database, subject to backups and records that must be retained by law.
- Authentication sessions and verification records
- Retained until expiry or deletion in accordance with their security purpose.
- Billing and transaction records
- Retained for the periods required by applicable accounting, tax, fraud-prevention, and legal obligations. Creem applies its own retention periods as merchant of record.
- Operational logs
- Retained only for as long as reasonably necessary for security, reliability, and incident investigation.
- First-party website and product event totals
- Retained as daily aggregate counts for product-performance trend analysis. They are not linked to visitors or account holders.
11. Your data-protection rights
- Access to your personal data — Article 15 GDPR.
- Correction of inaccurate data — Article 16 GDPR.
- Erasure — Article 17 GDPR.
- Restriction of processing — Article 18 GDPR.
- Data portability — Article 20 GDPR.
- Objection to processing based on legitimate interests — Article 21 GDPR.
- Withdrawal of consent at any time where processing relies on consent, without affecting earlier lawful processing.
Account holders can download a machine-readable account export and delete their account from the account area. Other requests, including requests from people who interacted with a button or submitted a contact form, may be sent to tech@matikus.com. We may need information that allows us to identify the relevant account or interaction.
12. Complaints
You may lodge a complaint with the Portuguese supervisory authority, Comissão Nacional de Proteção de Dados (CNPD), or with another competent supervisory authority in the EU or EEA.
13. Changes to this policy
We may update this policy when Nodify, its providers, or legal requirements change. The current version and its update date are always published on this page. Material changes will be communicated through the service when appropriate.