Legal

    Privacy Policy

    Last updated: 17/07/2026

    1. Data controller

    The controller of personal data is NelcoLabs by Bilos, a sole proprietorship registered in the Swiss Confederation ("NelcoLabs", "we"). Contact for all data protection matters: abilos@nelco-labs.com. NelcoLabs is not required to appoint a Data Protection Officer (DPO) pursuant to art. 37 GDPR, but all questions and requests may be sent to the above address.

    2. Applicable law

    The processing of personal data is carried out in accordance with Regulation (EU) 2016/679 (GDPR), the Swiss Federal Act on Data Protection (FADP/nFADP) and any other applicable law of the country of the user's habitual residence.

    3. What data we collect

    • Contact data: first and last name, email address, phone number (if provided), company name and position (for business inquiries).
    • Communication content: subject, message, and correspondence via email and other channels.
    • Booking data: selected slot, type of service, optional notes.
    • Technical data: IP address, device and browser type, language, timestamp, referer URL — collected for security and statistical purposes.
    • Billing data: in case of invoicing, name, address, VAT/UID and other legally required information. Payment card data itself is not stored on our systems.

    4. Purposes of processing and legal bases

    • Responding to inquiries and communicating with prospective clients — legal basis: consent and pre-contractual measures (art. 6(1)(a) and (b) GDPR).
    • Conclusion and performance of service contracts — legal basis: performance of a contract (art. 6(1)(b) GDPR).
    • Issuing invoices and complying with accounting and tax obligations — legal basis: legal obligation (art. 6(1)(c) GDPR).
    • Website security, prevention of abuse and usage statistics — legal basis: legitimate interest (art. 6(1)(f) GDPR).
    • Defence against potential legal claims — legal basis: legitimate interest (art. 6(1)(f) GDPR).

    5. Retention period

    • Contact-form data and correspondence are kept for a maximum of 24 months from the last communication, after which they are deleted or anonymised.
    • Contract documentation is kept for the duration of the contractual relationship and additionally for statutory limitation periods (generally 5–10 years).
    • Accounting documentation is kept for the periods prescribed by applicable tax and accounting law (up to 11 years).
    • Technical logs are kept for a maximum of 90 days, except in the case of security incident investigations.

    6. Recipients and processors

    We do not sell personal data and do not share it for marketing purposes. We use verified technical providers acting as processors under contracts pursuant to art. 28 GDPR:

    • Supabase (database and authentication hosting) — EU region where available.
    • Resend (transactional email delivery).
    • Lovable / Vercel-class hosting (website hosting and CDN).
    • Accounting and legal advisors, banks and tax authorities, where required by law.

    For transfers of data outside the EU/EEA, transfers rely on adequacy decisions (e.g. Switzerland, UK, EU-US Data Privacy Framework) or Standard Contractual Clauses (SCC) of the European Commission, with additional technical and organisational measures where necessary.

    7. Your rights

    • Right of access to your data (art. 15 GDPR)
    • Right to rectification of inaccurate or incomplete data (art. 16)
    • Right to erasure, so-called "right to be forgotten" (art. 17)
    • Right to restriction of processing (art. 18)
    • Right to data portability (art. 20)
    • Right to object to processing based on legitimate interest (art. 21)
    • Right to withdraw consent at any time, without affecting the lawfulness of prior processing
    • Right to lodge a complaint with a supervisory authority: in Croatia AZOP, in Switzerland EDÖB/FDPIC, or the authority in your country of habitual residence.

    Requests to exercise your rights should be sent to abilos@nelco-labs.com. We respond without undue delay and no later than within 30 days. To verify the requester's identity we may ask for additional information.

    8. Cookies

    The website uses only strictly necessary technical cookies and local storage required for proper operation (e.g. language selection, session security markers). We do not use third-party marketing or profiling cookies without your prior consent. If we introduce analytics or marketing cookies in the future, we will request your explicit consent via a cookie banner.

    9. Security and confidentiality

    We apply appropriate technical and organisational safeguards: encryption in transit (TLS/HTTPS), encryption at rest where available, access restriction on a "need-to-know" basis, regular system updates and security reviews. We are aware that no system is absolutely secure and we cannot guarantee the complete security of data transmission over the internet.

    10. Automated decision-making and AI

    We do not carry out automated decision-making producing legal effects within the meaning of art. 22 GDPR. If, as part of a specific service, we use AI tools (e.g. ChatGPT, Claude, Gemini, Midjourney), we will inform you in advance and will not enter confidential or personal data into those tools without your consent.

    11. Minors

    Our services are not intended for persons under the age of 16. We do not knowingly collect data from minors without parental or guardian consent. If you are a parent/guardian and believe a child has provided us with their data, please contact us and we will remove the data.

    12. Policy changes

    We reserve the right to amend this Privacy Policy. The version in force is the one published on this page with the noted last-modified date. For significant changes we will notify users by email or a prominent notice on the website.