Effective date: 1 August 2026
Controller/operator: Nibit AI, a sole proprietorship (eenmanszaak) registered in the Netherlands, with its business address at Staten Bolwerk 54, 2011 MN Haarlem, Netherlands. A sole proprietorship has no separate legal personality, so the controller is the individual who owns the business, trading as Nibit AI.
- Chamber of Commerce (KVK): 42135507
- Establishment number: 000066399580
- Telephone: +31 6 23033951
- Privacy contact: privacy@nibit.ai
1. Scope
This Privacy Policy explains how Nibit collects, uses, discloses, stores, and protects personal information when you use Nibit's applications, websites, notebook and learning tools, AI features, collaboration and chat features, support channels, and related Services.
It does not govern independent third-party services you choose to access through links or integrations.
2. Summary
- Nibit processes account information and the content you choose to create, import, upload, record, share, or send.
- AI features may send relevant content to an AI provider to perform the action you request.
- Collaboration and sharing disclose content and profile information to the people you select.
- Infrastructure, storage, email, security, media, and support providers process limited data to operate the Services.
- Nibit provides account deletion, but some information may remain temporarily or where retention is legally or operationally necessary.
Nibit does not sell personal information, does not share it for cross-context behavioural advertising, and does not run targeted advertising. There are no advertising networks, ad SDKs, or advertising pixels in the Services, and no third-party product analytics. The Subprocessors list names every third party that receives data and says what each one sees.
3. Information we collect
3.1 Account and profile information
This may include:
- email address, username, profile or display name, avatar, and preferences;
- password hash and account-verification status;
- verification, password-reset, and security records;
- the date you accepted these policies, which versions you accepted, and the IP address the acceptance came from;
- your date of birth, the country you signed up from, and the minimum age we applied to the account;
- subscription tier and account status; and
- support and administrative account history.
Nibit should never store your plaintext password.
3.2 Notes, learning material, and uploaded content
We process content you provide, including:
- notebooks, chapters, pages, titles, text, formatting, comments, bookmarks, flashcards, quizzes, attempts, and generated study material;
- imported PDFs, presentations, documents, Markdown, HTML, images, and related extracted text;
- material retrieved from web pages and YouTube links you ask us to import, including video details and transcripts;
- drawings, diagrams, equations, links, citations, and source material;
- attachments, profile images, recordings, audio, transcripts, and file metadata; and
- exports and copies you ask us to create.
Content can include personal or sensitive information depending on what you choose to submit. Do not submit information you are not authorised to use or that requires protections the Services do not provide.
3.3 AI information
When you use an AI feature, we may process:
- your prompt or instruction;
- text, files, images, audio, notes, selections, conversation history, or context needed for the request;
- generated output;
- model, token, cost, quota, timing, safety, and error information; and
- your decision to save, replace, reject, or otherwise use output where the feature records that action.
Relevant request content is transmitted to Nibit's AI provider to perform the requested processing.
Nibit's AI provider is OpenAI, accessed through its API on a business account governed by the OpenAI Services Agreement and its data processing addendum. What OpenAI itself does with the data it receives is described in OpenAI's privacy policy. Under those terms:
- content you submit through an AI feature is not used to train or improve OpenAI's models, and is not used to train any model of Nibit's;
- OpenAI may retain the request and its output for up to 30 days for abuse and misuse monitoring, after which it is deleted;
- processing takes place in the United States.
We state the 30-day abuse-monitoring window rather than claiming nothing is retained, because the second claim would not be accurate. If we move to a zero-retention arrangement, this paragraph changes before the architecture does.
Which kind of model serves which feature, and OpenAI's published source for the three statements above, are set out in Subprocessors section 3.
3.4 Collaboration, sharing, social, and communication information
This may include:
- friends, requests, groups, memberships, roles, invitations, and sharing permissions;
- direct and group messages, mentions, reactions, GIF or sticker selections, attachments, and timestamps;
- shared notebook, chapter, page, or generated-output access;
- comments, edits, presence, cursors, collaboration updates, and version checkpoints; and
- reports, moderation decisions, appeals, and abuse-prevention records.
The people you share with receive the content and profile information needed for the feature. Their own copying or disclosure may be outside Nibit's control.
3.5 Usage, device, and security information
We may collect:
- IP address and a coarsened form displayed in device-management interfaces;
- user agent, browser, operating system, device and application information;
- session identifiers, authentication tokens, session creation, expiry, and last-seen time;
- requests, feature interactions, timestamps, errors, performance, rate-limit, and quota records;
- security events, suspected abuse, failed logins, and fraud indicators; and
- cookies, browser storage, IndexedDB, local application storage, cache, and preferences required for authentication, offline behaviour, sync, and user settings.
Everything Nibit stores on your device is strictly necessary to run the Services. There is no advertising, analytics, or marketing technology, so there is no consent banner to click through:
| What | Where | Purpose | Lifetime |
|---|---|---|---|
| Session token | Cookie (HTTP-only, Secure) | Keeps you signed in | 30 days, or until you sign out |
| CSRF token | Cookie | Prevents cross-site request forgery | The browser session |
| Device record | Cookie | Identifies this device in the device-management screen so you can sign it out remotely | 30 days |
| Preferences | Local storage | Theme, editor and layout settings | Until you clear it |
| Offline notebook cache | IndexedDB | Lets you read and write notes without a connection, and syncs when you reconnect | Until you sign out or clear it |
| Draft and undo state | Local storage | Prevents work being lost on a crash or reload | Until the draft is saved |
Signing out clears the session and device cookies. Clearing site data in your browser clears the rest; on the desktop app, "Sign out" clears the local cache. Blocking these will stop the Services working.
3.6 Support and communications
We process support-ticket details, name and email, messages, attachments, replies, delivery events, and related troubleshooting information. We also process security, verification, reset, service, policy, billing, and optional marketing communications.
3.7 Billing and transaction information
Payments are processed by Stripe. When you buy a paid Service, we process:
- plan, amount, currency, tax, status, dates, renewal and cancellation state;
- purchase and credit records;
- payment-provider customer and transaction references; and
- limited billing details supplied by the payment provider; and
- where a parent or legal guardian pays for an account holder under 18, their name, billing address and country, the email address they give us for receipts, and a record of the confirmations they gave at the point of purchase.
Payment-card and bank details are collected directly by the payment provider. Nibit does not receive or store your full card number; we receive a provider-side customer reference, the last four digits, the card brand, the expiry, and the country, which is what we need to show you your billing history and to apply tax correctly.
The payment provider is named in the Subprocessors list from the day it first processes a payment, and no provider processes a payment before its row appears there. Billing records are kept for seven years, because tax law requires it - see section 7.
3.8 Information from other sources
We may receive information from:
- collaborators, group members, people who report content, and support contacts;
- authentication, payment, cloud, security, email, and media providers;
- imported files and links you direct us to process; and
- public sources where a feature clearly asks us to retrieve public material.
4. Why we process information
We process information to:
- create and secure accounts;
- provide notebooks, storage, import/export, search, sync, offline support, collaboration, chat, AI, recordings, quizzes, and support;
- carry out your sharing and processing instructions;
- calculate usage, enforce quotas, administer subscriptions, and process purchases;
- maintain, troubleshoot, measure, and improve reliability and usability;
- detect, investigate, prevent, and respond to fraud, abuse, security incidents, illegal content, and policy violations;
- communicate about accounts, security, support, payments, and policy changes;
- comply with law, court orders, regulatory duties, and enforceable requests;
- establish, exercise, or defend legal claims; and
- perform other purposes with your consent.
5. Legal bases under the GDPR
Nibit is established in the Netherlands, so the GDPR governs this processing directly. It is worth being precise about how far that reaches, because it is wider than people expect: Article 3(1) turns on where the controller is established, not on where you are. Everything we do with your personal information is therefore processed under the GDPR and the Dutch implementing act, the Uitvoeringswet AVG, whichever country you live in and whether or not you are in Europe. The UK GDPR applies on top of that to people in the United Kingdom. Section 12 sets out who supervises us and how to complain.
Every purpose in section 4 rests on one of these legal bases:
- Contract: account management and features you request.
- Legitimate interests: security, fraud prevention, service integrity, support, limited product improvement, and enforcing rights, balanced against your rights.
- Legal obligation: tax, accounting, lawful requests, safety, and regulatory compliance.
- Consent: optional marketing, non-essential device storage, and processing that specifically requires consent. You may withdraw consent prospectively.
- Vital interests: exceptional situations involving an immediate threat to life or safety.
Where we rely on legitimate interests, we have assessed in each case whether the interest is real, whether the processing is necessary to serve it, and whether it is outweighed by your rights. You can ask us for a summary of that assessment for any specific purpose at privacy@nibit.ai, and you can object to processing based on legitimate interests under section 10.
6. How we disclose information
6.1 At your direction
We disclose content and relevant profile details when you share, collaborate, message, join a group, contact support, connect a third-party service, or otherwise direct us.
6.2 Service providers
We use these providers:
- Railway for application and service hosting;
- Neon for managed PostgreSQL database services;
- Tigris for object storage;
- Cloudflare for web delivery, workers, DNS, proxying, and security;
- OpenAI for AI, transcription, and text-to-speech processing;
- Resend, through Nibit's email service, for transactional email;
- Klipy for GIF and sticker search or retrieval;
- Google, through the YouTube Data API, for video details when you import a YouTube link; and
- Supadata for the transcript of a YouTube video you import.
The last two are contacted by Nibit's servers rather than by your device, and the request carries only the video identifier taken from the link you supplied. Your account identity and your IP address are not sent to them.
See the Subprocessors list for each provider's contracting entity, processing location, and retention period, and for the two things worth knowing beyond the category: what OpenAI may and may not do with an AI request, and what the GIF picker sends to an advertising-supported service.
6.3 Legal, safety, and rights
We may disclose information where reasonably necessary to comply with law or valid legal process; protect people from serious harm; investigate fraud, abuse, security, or illegal conduct; enforce our agreements; or establish and defend legal claims.
6.4 Corporate transactions
Information may be disclosed during a financing, merger, acquisition, restructuring, insolvency, or sale of all or part of the business, subject to confidentiality and applicable notice requirements.
6.5 Aggregated or de-identified information
We may use and disclose information that cannot reasonably identify you. We will not attempt to re-identify information treated as de-identified except to test whether de-identification works or where law permits.
7. Data retention
We retain information only for as long as reasonably necessary for the purposes described above, including legal, accounting, fraud, security, dispute, backup, and continuity needs.
Deleting your account starts a 24-hour cancellation period, so that an account deleted in anger or by accident can be recovered. After that window the purge runs and is not reversible.
| Record | Kept for |
|---|---|
| Account and profile | Until you delete the account |
| Deleted account | Purged 24 hours after the deletion request; residual copies clear on the schedule below |
| Notes, notebooks, attachments, recordings | Until you delete them, or until the account is purged |
| Trash | 30 days, then permanently deleted |
| Page version history | 90 days |
| Sessions and device records | 30 days from last use, or until you sign the device out |
| Verification and password-reset codes | 1 hour |
| Chat messages and collaboration updates | Until deleted by a participant, or until the account is purged |
| AI prompts and outputs held by Nibit | Deleted with the note or conversation they belong to |
| AI prompts and outputs held by OpenAI | Up to 30 days for abuse monitoring - see section 3.3 |
| AI usage and quota counters | 13 months, for billing and quota disputes |
| Support tickets | 24 months from closure |
| Security and audit logs | 12 months |
| Abuse, moderation, and appeal records | 24 months |
| Billing and tax records | 7 years, as tax law requires |
| Backups | Overwritten on a rolling 35-day cycle |
| Orphaned objects in storage | Collected within 7 days |
A legal hold overrides this table. If we are required to preserve records for a legal claim, an investigation, or a court order, we keep those records until the hold lifts, and we do not delete them on request in the meantime.
Deletion may not remove:
- content another user lawfully copied or retained;
- records required for billing, tax, security, fraud prevention, legal claims, or legal obligations;
- de-identified information; or
- backup copies until their scheduled overwrite.
8. Security
We use technical and organisational safeguards intended to protect information, including access controls, password hashing, transport encryption, session controls, input and file validation, rate limiting, and security logging.
No service can guarantee absolute security. You are responsible for protecting your credentials and devices and for promptly reporting suspected compromise.
Specifically:
- data is encrypted in transit and at rest;
- passwords are never stored in plaintext or in any reversible form;
- access to production data is limited to the people who need it for their work, and is reviewed regularly;
- providers are assessed before they process user data, and each one is listed in the Subprocessors list.
If something goes wrong. We investigate suspected incidents on receipt. Where a breach is likely to put you at risk, we will tell you and the relevant regulators without undue delay, and within any deadline the law sets - 72 hours to the Autoriteit Persoonsgegevens under the GDPR, and the timelines set by the CERT-In directions and the DPDP Act for users in India. We will tell you what happened, what was affected, and what to do about it. Report a suspected vulnerability or compromise to security@nibit.ai; the Acceptable Use Policy section 3 sets out the safe harbour for researchers.
9. International transfers
Nibit is established in the Netherlands, and most of the infrastructure the Services run on is in the United States. That combination is the thing to understand here: we are a European controller sending personal information out of the European Economic Area, so Chapter V of the GDPR governs every one of those transfers and we have to name a lawful basis for each.
Where your information goes. Our own operations are in the Netherlands. The providers that host the application, the database, and object storage are in the United States, so account data, note content, and attachments are transferred there and processed there. Cloudflare serves traffic from the edge location nearest you, so request metadata is handled in your own region before it reaches that infrastructure. One provider sits inside the EEA: Supadata, operated by Dumpling Software UG in Germany, which returns the transcript of a YouTube video you import and receives only a video identifier, never your identity or IP address. The Subprocessors list gives the location of each provider individually.
How each transfer is made lawful. Each provider is engaged under its published data processing terms, which we accept as part of our account with it, and those terms incorporate the European Commission's standard contractual clauses. The clauses are our baseline safeguard under Article 46(2)(c) for every transfer out of the EEA, and they apply to every provider without exception. Where a US provider is separately certified under the EU-US Data Privacy Framework, that certification adds an Article 45 adequacy basis on top; it never replaces the clauses underneath. Certification is a per-company fact rather than a general property of US providers, so we check it against the Department of Commerce's published list when we take a provider on and again when we review the list. The position for each one, with the date it was last checked, is recorded in Subprocessors section 2.1.
It is worth stating the result rather than leaving it in a table. Three of our providers, including the one that processes what you write when you use an AI feature, are not certified under the Framework at all. For those, the contractual clauses and the assessment below are the whole of the safeguard. For the UK, the international data transfer addendum applies alongside the clauses.
What sits on top of the paperwork. Standard contractual clauses are not self-executing, so we also assess whether the law of the destination country actually lets the provider honour them, and what would happen to your information if a public authority there demanded access. Where that assessment calls for more than the clauses give us, we look to the measures already described in section 8: encryption in transit and at rest, and access limited to the people who need it. If we conclude a transfer cannot be made safe, we will not make it. You can ask us for the assessment behind any particular provider at privacy@nibit.ai.
India. If you are in India, your information is transferred to and processed in the Netherlands and the United States. The Digital Personal Data Protection Act permits transfers outside India except to countries the Central Government restricts; neither is restricted, and we will stop transferring to any country that becomes so.
10. Your choices and rights
Depending on location, you may have rights to:
- access or obtain a copy of personal information;
- correct inaccurate information;
- delete information;
- restrict or object to processing;
- receive portable data;
- withdraw consent;
- opt out of marketing;
- opt out of sale, sharing, or targeted advertising where applicable;
- limit use of sensitive personal information where applicable;
- appeal a denied privacy request; and
- complain to a regulator.
Account settings cover most of these directly: you can edit your profile, export your notebooks, and delete your account without asking us. For anything else, email privacy@nibit.ai with what you want and the address on your account.
How we handle a request.
- We acknowledge it within 5 business days and respond substantively within 30 days. If a request is complex we may take up to 60 days in total, and we will tell you before the first 30 days are up.
- We verify identity before acting - normally by confirming you control the account email, and by asking for more where the request is high-risk. We ask for the least we can.
- An authorised agent must provide written authority signed by you, and we may still confirm the request with you directly.
- Requests are free. If one is manifestly unfounded or repetitive we may charge a reasonable fee or decline it, and we will explain which and why.
- If we refuse, we tell you the reason and how to appeal. To appeal, reply to our decision with "Appeal" in the subject line; a different person reviews it and responds within 30 days.
- We keep a record of each request and its outcome for 24 months.
We will not discriminate against you for exercising a privacy right - no degraded service, no different price.
11. United States and California
Nibit does not currently meet the thresholds that make a business subject to the California Consumer Privacy Act.
We do not rely on that. The rights in section 10 are offered to everyone, in every US state, whether or not a statute compels them: access, a copy of your data, correction, deletion, and portability. If Nibit later crosses a statutory threshold, this section will be updated before the obligation attaches rather than after.
Two representations that hold regardless of applicability:
- No sale, no sharing. Nibit does not sell personal information and does not share it for cross-context behavioural advertising, as those terms are defined in the CCPA. No disclosure to a provider in the Subprocessors list is a sale or a share - each one processes data on our instructions, for our purposes, under contract.
- Global Privacy Control. We honour the GPC signal. Since we do not sell or share, the signal has nothing to opt you out of; we honour it anyway so that the answer does not change quietly if our practices do.
Sensitive personal information. Account credentials are the only category of sensitive personal information we handle, and we use them solely to authenticate you. We do not use or disclose sensitive personal information to infer characteristics about you, so the right to limit its use has no application here.
Statutory categories. Under the CCPA's classification, we collect identifiers, customer records, commercial information, internet and network activity, audio and visual information (recordings you make), and the contents of your notes and messages. Section 3 says what each of these is, section 4 why we collect it, section 6 who receives it, and section 7 how long we keep it.
Notice at collection. This Policy is that notice. We do not collect personal information from a California resident for any purpose not described in section 4.
12. The Netherlands, the EU, and the United Kingdom
Nibit is established in the Netherlands. Everything in this section follows from that one fact, and several of the answers below are the opposite of what an earlier version of this Policy said, because that version described a company established in the United States.
- Controller: the individual trading as Nibit AI, a sole proprietorship registered in Haarlem, the Netherlands, privacy@nibit.ai. Business address and telephone in section 16. To completedecide whether to name the owner here. A controller must be identifiable under Article 13, and for a sole proprietorship that points at the natural person rather than at a trade name.
- Lead supervisory authority: the Autoriteit Persoonsgegevens, in The Hague, because our main establishment is in the Netherlands. You can complain to it. You can equally complain to the supervisory authority of the country where you live, where you work, or where you think something went wrong, and you do not have to raise it with us first - though we would rather you did, because we can usually fix it faster than a regulator can.
- EU representative: not required, and none appointed. Article 27 obliges a controller established outside the Union to appoint a representative inside it. We are inside it, so the article does not reach us. The previous version of this Policy also said none was appointed; the reason has changed completely, and the reason is the part that matters.
- UK representative: none appointed. Article 27 of the UK GDPR requires one from a controller outside the UK that offers goods or services to people in the UK or monitors their behaviour there. The Services are offered in the European Union, the United States, and India, and the United Kingdom is not among them, so the article does not apply. If that changes, we will appoint a UK representative and name them here before we begin offering the Services there.
- Data protection officer: none appointed. Article 37 requires one where a controller's core activities consist of large-scale regular and systematic monitoring, or large-scale processing of special-category data. A private notebook is neither. We do not profile users, we serve no advertising, and we do not routinely inspect the content of private notes. We keep that assessment under review and will appoint a data protection officer and name them here if it stops holding. Privacy questions sent to privacy@nibit.ai reach a person who can answer them.
- Records of processing: we maintain the record Article 30 requires and will produce it to the Autoriteit Persoonsgegevens on request.
Your rights under section 10 are given to everyone, everywhere, and always were. What changes now is that for people in the EU they are backed by a regulator with jurisdiction over us rather than offered voluntarily.
13. India
Nibit offers the Services in India and acts as a data fiduciary under the Digital Personal Data Protection Act, 2023. The Act and its Rules have phased commencement, and we update this Policy and our operations as provisions enter into force. Nibit has not been notified as a significant data fiduciary; if it is, the additional duties that follow will be reflected here.
Notice and consent. This Policy is the notice the Act requires. Where we rely on your consent, we record what you agreed to and when, and you can withdraw it at any time in account settings or by writing to privacy@nibit.ai - withdrawal is as easy to give effect to as the consent was to give. Withdrawing consent does not undo processing already carried out lawfully, and some features stop working without it.
Your rights. Access, correction, completion, updating, and erasure of your personal data, the right to nominate someone to exercise your rights if you die or become incapacitated, and the right to grievance redressal. Section 10 explains how to exercise them and how long we take. Nomination requests go to privacy@nibit.ai.
Grievance Officer. Under the DPDP Act and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules:
- Designation: Grievance Officer, Nibit AI
- Email: privacy@nibit.ai
- Address: Staten Bolwerk 54, 2011 MN Haarlem, Netherlands
We acknowledge a grievance within 24 hours and dispose of it within 15 days. Where a court order or an authorised government agency directs us to remove unlawful material, we act within 36 hours. The same officer and timelines are stated in Copyright and DMCA section 7. If you are not satisfied with the outcome, you may complain to the Data Protection Board of India.
Transfers and breaches. Your data is processed in the Netherlands and the United States - see section 9. Personal-data breaches are reported to the Data Protection Board and to affected users as the Act requires, and to CERT-In within the timelines its directions set.
14. Children
The minimum age for a Nibit account is 13, everywhere the Services are offered. Signup asks for your date of birth and the country you are signing up from, and records both with the account together with the minimum age we applied. We do not otherwise verify either.
Users aged 13 to 17 may hold an account, and holding one needs no guardian-consent step. Buying a paid subscription does, because an adult has to be the purchaser: Terms of Service section 8.2 and the Parental and Guardian Consent document set that out. What the account-level position does and does not mean in practice:
- we serve no advertising to anyone of any age, and we do not profile anyone for advertising;
- we do not sell or share personal information;
- there is no public profile directory and no way for a stranger to find a user by browsing - sharing, groups, and chat connect only people who have deliberately connected;
- new notebooks are private by default and stay that way until their owner shares them.
Paid subscriptions. A subscription is a contract, and a minor cannot reliably enter one, so the person who pays has to be 18 or over. Where a parent or legal guardian subscribes for an account holder aged 13 to 17, we collect their confirmations on the payment page and keep a record of what they confirmed and when. Section 3.7 lists what we then hold about them, and the Parental and Guardian Consent document explains the arrangement in full.
Parents and guardians. If you are the parent or legal guardian of a user under 18 and want to see what we hold about them, correct it, or have the account deleted, write to privacy@nibit.ai from an address we can verify against the account. We will act on it, and we will not ask you for a court order first.
The Netherlands and the EU. Article 8 of the GDPR sets a consent age for online services and lets each country pick a figure between 13 and 16. The Netherlands did not lower it: under the Uitvoeringswet AVG the age is 16. That rule bites on processing we base on consent, not on the whole account - the account itself, and the features you ask for, run on contract rather than consent under section 5, and Article 8 does not reach those. What it does reach is the consent-based processing listed in section 5: optional marketing and non-essential device storage. For a user under 16 in the Netherlands or in another EU country with the same threshold, we do not rely on their consent for those things, and we will not until a parent or guardian authorises it.
The account minimum age stays 13, in the EU as in the other two markets, because the account runs on contract rather than consent. What changes for a user aged 13 to 15 in the EU is narrower and specific: their own consent is not a valid basis for optional marketing or for non-essential storage on their device, and we do not treat it as one.
To completeengineering - recording a date of birth and a country at signup is what makes the paragraph above enforceable, and the enforcement itself is still unbuilt. Before the EU launch, an EU user under 16 must not have their own consent relied on for optional marketing or non-essential device storage, either by not offering those options at all or by routing them through a guardian.
India. The Digital Personal Data Protection Act treats everyone under 18 as a child, requires verifiable consent from a parent or guardian, and prohibits tracking and behavioural advertising directed at children. Nibit does not track or behaviourally advertise to anyone of any age. We will collect verifiable guardian consent when the Act's provisions on children commence; until then, a guardian can exercise the controls above at any time.
If you believe someone under 13 has created an account, tell us at privacy@nibit.ai and we will delete it.
15. Changes
We may update this Policy to reflect changes in law, providers, or the Services. We will identify the effective date and provide additional notice where a material change or applicable law requires it.
Archived versions are published at a permanent, dated URL. The version you accepted is recorded with your account and remains reachable at nibit.ai/legal/privacy/<version> - for example, /legal/privacy/2026-08-01.
16. Contact
- Privacy requests: privacy@nibit.ai
- Grievance Officer (India): privacy@nibit.ai - see section 13
- Security and breach reports: security@nibit.ai
- Legal notices: legal@nibit.ai
- Postal address: Nibit AI, Staten Bolwerk 54, 2011 MN Haarlem, Netherlands
- Telephone: +31 6 23033951
Nibit has not appointed a data protection officer, for the reason given in section 12. Privacy questions sent to privacy@nibit.ai reach a person who can answer them.