Back to home

Security & privacy

Last updated: July 15, 2026

You trust Nidria to track your cases and those of your clients. Here is concretely where that data lives and how it is protected. This page is kept up to date.

Where your data is hosted

The app.nidria.com application and all of its data are hosted in France, in Paris: the application on Fly.io (servers in Paris) and the database on Supabase (servers in Paris). Your data is hosted exclusively in the European Union (Paris). Certain specific processing operations (sending emails, payment, automatic translation of templates) rely on subprocessors covered by transfer safeguards (SCCs/DPF).

The nidria.com marketing site is delivered by Cloudflare. The database benefits from Supabase's automatic backups.

Encryption

All exchanges with the application are encrypted over HTTPS/TLS. Data stored in the database is encrypted at rest by our database host (Supabase).

Access and authentication

Your data belongs to you

We do not sell your data, we do not share it for commercial purposes, and we do not use it to train artificial intelligence models. No advertising tracking inside the application. Your data is exportable at any time, and deleted at the end of the contract subject to legal obligations.

Reversibility: you are never locked in

Adopting a tool should not create dependency. Nidria is designed so you can leave as easily as you came in.

GDPR compliance

For the cases you manage on Nidria, you remain the data controller and Nidria acts as a processor. A data processing agreement (DPA) is accepted when your agency account is created; a copy is available on request at [email protected].

Our processors: Cloudflare (site delivery), Resend (transactional emails), Fly.io (application hosting, Paris), Supabase (database, Paris), Paddle (payments, Merchant of Record), Z.ai (automatic translation of journey templates, Singapore; no case data; content not retained). Transfers outside the European Union, where applicable, are governed by standard contractual clauses or the Data Privacy Framework.

You have the rights of access, rectification, erasure, objection, restriction and portability, and may lodge a complaint with your supervisory authority (in France, the CNIL). Full details in the legal notice and privacy policy.

Platform security

Nidria's security is overseen in-house by one of our co-founders, a cybersecurity engineer, who reviews the platform's architecture, access and dependencies.

Our infrastructure runs on providers recognized for their security standards and certified in their own right: Cloudflare (site delivery), Supabase (database) and Fly.io (application), several holding SOC 2 and ISO 27001 certifications. Your data therefore benefits from these guarantees at the hosting level.

Certifications

Nidria applies GDPR principles and the best practices above. Nidria is not yet certified in its own right against an external standard (such as ISO 27001); a certification process may be undertaken as we grow. In all honesty, we display no label we have not obtained, but our infrastructure components do hold them.

A security question?

Email us at [email protected], we will respond.