Security & privacy
Last updated: July 15, 2026
You trust Nidria to track your cases and those of your clients. Here is concretely where that data lives and how it is protected. This page is kept up to date.
Where your data is hosted
The app.nidria.com application and all of its data are hosted in France, in Paris: the application on Fly.io (servers in Paris) and the database on Supabase (servers in Paris). Your data is hosted exclusively in the European Union (Paris). Certain specific processing operations (sending emails, payment, automatic translation of templates) rely on subprocessors covered by transfer safeguards (SCCs/DPF).
The nidria.com marketing site is delivered by Cloudflare. The database benefits from Supabase's automatic backups.
Encryption
All exchanges with the application are encrypted over HTTPS/TLS. Data stored in the database is encrypted at rest by our database host (Supabase).
Access and authentication
- Two-factor authentication (2FA) available on accounts.
- You decide precisely what your client sees; your internal notes, costs and messages are never visible to them.
- Partitioned provider access: each external provider only accesses the case and step that concern them.
- Built for professions bound by confidentiality: you alone decide what is entered and what is shown to the client, and Nidria does not exploit the content of your cases.
Your data belongs to you
We do not sell your data, we do not share it for commercial purposes, and we do not use it to train artificial intelligence models. No advertising tracking inside the application. Your data is exportable at any time, and deleted at the end of the contract subject to legal obligations.
Reversibility: you are never locked in
Adopting a tool should not create dependency. Nidria is designed so you can leave as easily as you came in.
- Self-service export, anytime: you retrieve your cases and data in a standard format (CSV / Excel), without having to ask us.
- No dependency on the client side: your client only has a link to view, nothing to install, no account to keep.
- At the end of the contract: you export all of your data, then we delete it (subject to legal obligations).
- And if Nidria were to shut down? Your data stays yours (self-service export) and your clients only ever had a link: you resume your cases elsewhere without losing anything.
GDPR compliance
For the cases you manage on Nidria, you remain the data controller and Nidria acts as a processor. A data processing agreement (DPA) is accepted when your agency account is created; a copy is available on request at [email protected].
Our processors: Cloudflare (site delivery), Resend (transactional emails), Fly.io (application hosting, Paris), Supabase (database, Paris), Paddle (payments, Merchant of Record), Z.ai (automatic translation of journey templates, Singapore; no case data; content not retained). Transfers outside the European Union, where applicable, are governed by standard contractual clauses or the Data Privacy Framework.
You have the rights of access, rectification, erasure, objection, restriction and portability, and may lodge a complaint with your supervisory authority (in France, the CNIL). Full details in the legal notice and privacy policy.
Platform security
Nidria's security is overseen in-house by one of our co-founders, a cybersecurity engineer, who reviews the platform's architecture, access and dependencies.
Our infrastructure runs on providers recognized for their security standards and certified in their own right: Cloudflare (site delivery), Supabase (database) and Fly.io (application), several holding SOC 2 and ISO 27001 certifications. Your data therefore benefits from these guarantees at the hosting level.
Certifications
Nidria applies GDPR principles and the best practices above. Nidria is not yet certified in its own right against an external standard (such as ISO 27001); a certification process may be undertaken as we grow. In all honesty, we display no label we have not obtained, but our infrastructure components do hold them.
A security question?
Email us at [email protected], we will respond.