Skip to content
NNodify
ProductUse casesIntegrationsGuidesPricing
Sign inStart 14-day trial

Privacy Policy

Last updated: 20 September 2026

  1. 1. Data controller
  2. 2. Our role and the account holder’s role
  3. 3. Account and authentication data
  4. 4. Workspace and channel data
  5. 5. Button interactions and contact requests
  6. 6. Purposes and legal bases
  7. 7. Cookies and analytics
  8. 8. Recipients and service providers
  9. 9. International transfers
  10. 10. Retention
  11. 11. Your data-protection rights
  12. 12. Complaints
  13. 13. Changes to this policy

1. Data controller

Controller
Matikus, Lda.
Address
Startup Madeira – EV 289, Campus da Penteada, 9020-105 Funchal, Madeira, Portugal
NIPC
519 513 630
Email
tech@matikus.com

This policy explains how Matikus, Lda. processes personal data when people visit or use Nodify, create an account, configure buttons and notification channels, interact with a Nodify button, submit a contact request, or purchase a subscription.

2. Our role and the account holder’s role

Matikus, Lda. is the controller for account administration, service security, billing administration, and its own operational records. An account holder decides where a Nodify button is placed, which notification channels receive alerts, and whether a contact form is enabled. For personal data collected through those customer-configured features, the account holder may be an independent controller and is responsible for providing any additional notices and having an appropriate legal basis.

3. Account and authentication data

  • Name and email address.
  • Password hash and authentication records; Nodify does not store the plain-text password.
  • Session identifiers, session expiry, IP address, and browser user-agent information used to secure signed-in sessions.
  • Account creation and update timestamps.
  • Subscription plan, status, billing period, trial start and end dates, reminder delivery status, existing Free-plan eligibility, and identifiers returned by Creem.

4. Workspace and channel data

  • Button labels, descriptions, appearance, language, active dates, and public messages configured by the account holder.
  • Notification-channel names, status, delivery history, and failure information.
  • Credentials and destination details for email, Telegram, Slack, Discord, or customer-defined webhooks. Sensitive channel configuration is encrypted at rest and is not returned in plain text through the product interface.

5. Button interactions and contact requests

  • The button tracking identifier, view time, confirmation time, status, and a shortened browser user-agent string.
  • A salted, keyed hash of the visitor’s IP address for abuse prevention. The plain IP address is not stored in the click-event record.
  • If a contact form is enabled: email address and message, plus optional name, subject, and urgency.
  • Delivery jobs and daily aggregate counts for views, confirmations, quota blocks, and contact-form submissions.

Nodify does not place a tracking pixel in email signatures and does not use button activity to build cross-customer advertising profiles. Opening a Nodify URL and explicitly confirming an action are recorded as separate events; a notification is triggered only after confirmation.

6. Purposes and legal bases

Account, buttons, notifications, and subscriptions
Performance of a contract or steps requested before entering into a contract — Article 6(1)(b) GDPR.
Contact requests sent through a customer’s button
Taking steps at the sender’s request and the legitimate interests of the sender and account holder in communicating — Articles 6(1)(b) and 6(1)(f) GDPR, depending on the context.
Security, abuse prevention, rate limits, and reliable delivery
Our legitimate interest in protecting Nodify, its users, and visitors — Article 6(1)(f) GDPR.
Accounting, tax, fraud-prevention, and regulatory records
Compliance with legal obligations — Article 6(1)(c) GDPR.

7. Cookies and analytics

Nodify uses only technically necessary authentication and security mechanisms needed to keep users signed in and protect requests. We do not currently use advertising cookies, third-party analytics, tracking pixels, or behavioural advertising. Because no optional tracking technologies are used, Nodify does not display a consent banner.

To understand whether the website and onboarding flow work, Nodify counts a fixed set of first-party product events as daily totals. These totals include actions such as viewing the landing page, starting the demo, beginning signup, creating a button, or connecting a channel. The event counter does not store a visitor or account identifier, IP address, browser user-agent, page URL, referrer, campaign parameter, free-text value, cookie, or local-storage identifier. It cannot be used to reconstruct an individual journey or calculate unique visitors.

8. Recipients and service providers

Hetzner Online GmbH
EU-based infrastructure hosting for the Nodify application and database.
Brevo / Sendinblue SAS
Transactional email delivery. Recipient address and notification content are sent to Brevo when an email channel or system email is used.
Creem / Armitage Labs OÜ
Merchant of record for paid subscriptions. Creem hosts checkout, processes payment and billing details, handles applicable taxes and invoices, and returns subscription identifiers and status to Nodify.
Customer-configured destinations
Telegram, Slack, Discord, and customer-defined webhook endpoints receive notification content only when an account holder configures and activates the relevant channel.

We do not use an external analytics, error-reporting, log aggregation, or uptime-monitoring provider at present. Operational request logs are produced within our own hosted environment and do not contain contact-form content.

  • Brevo privacy policy
  • Creem privacy notice
  • Hetzner privacy policy

9. International transfers

Our primary application infrastructure is located in the European Union. Some service providers or customer-selected notification destinations may process data outside the European Economic Area. Where Matikus, Lda. is responsible for such a transfer, it relies on an adequacy decision or appropriate safeguards under Chapter V GDPR, such as the European Commission’s standard contractual clauses. Customer-selected destinations are also subject to the account holder’s configuration and responsibilities.

10. Retention

Click events and associated contact requests
Retained for six months from the view, then deleted. Non-personal daily aggregate counts remain available for analytics.
Account, workspace, and channel data
Retained while the account or relevant item exists. Account deletion removes account-linked operational data immediately from the active database, subject to backups and records that must be retained by law.
Authentication sessions and verification records
Retained until expiry or deletion in accordance with their security purpose.
Billing and transaction records
Retained for the periods required by applicable accounting, tax, fraud-prevention, and legal obligations. Creem applies its own retention periods as merchant of record.
Operational logs
Retained only for as long as reasonably necessary for security, reliability, and incident investigation.
First-party website and product event totals
Retained as daily aggregate counts for product-performance trend analysis. They are not linked to visitors or account holders.

11. Your data-protection rights

  • Access to your personal data — Article 15 GDPR.
  • Correction of inaccurate data — Article 16 GDPR.
  • Erasure — Article 17 GDPR.
  • Restriction of processing — Article 18 GDPR.
  • Data portability — Article 20 GDPR.
  • Objection to processing based on legitimate interests — Article 21 GDPR.
  • Withdrawal of consent at any time where processing relies on consent, without affecting earlier lawful processing.

Account holders can download a machine-readable account export and delete their account from the account area. Other requests, including requests from people who interacted with a button or submitted a contact form, may be sent to tech@matikus.com. We may need information that allows us to identify the relevant account or interaction.

12. Complaints

You may lodge a complaint with the Portuguese supervisory authority, Comissão Nacional de Proteção de Dados (CNPD), or with another competent supervisory authority in the EU or EEA.

  • CNPD — Portuguese Data Protection Authority

13. Changes to this policy

We may update this policy when Nodify, its providers, or legal requirements change. The current version and its update date are always published on this page. Material changes will be communicated through the service when appropriate.

Legal noticeTerms of service
NNodify

Small button. Big possibilities.

Product

ProductPricingSign inStart 14-day trial

Use cases

Email signaturesProposal follow-upOut-of-office repliesGuides

Legal

About NodifySecurity and privacyLegal noticePrivacy policyTerms of service
© 2026 Nodify. All rights reserved. Nodify is operated by Matikus, Lda. SupportMake every email an opening.