Boring, in the
best way.
No badges, no certification logos we did not earn. Just a plain description of where your files live, who can reach them, and how long we keep them.
How your files are protected.
Your files are yours.
- We do not train AI models on your files, documents or form responses.
- We do not sell your data, and we do not show advertising.
- We do not read, index or profile the contents of your files.
- We do not load third-party analytics or advertising scripts, and web fonts come from our own servers.
- We do not send your files to an AI provider unless you connect an assistant yourself, which you can revoke at any time.
A short list, published.
These are every provider that touches data on our behalf. If we ever add one, we announce it here 30 days in advance and you can object.
| Provider | What it does | Where |
|---|---|---|
| Wasabi | File and document storage, AES-256 at rest | EU, Amsterdam |
| AWS SES | Email delivery | EU, Frankfurt |
| Stripe | Subscription payments | EU/US, Data Privacy Framework and SCCs |
| Sign-in with Google | EU/US, Data Privacy Framework and SCCs | |
| GuusLab | Application servers, conversion, compression, malware scanning, database backups | Netherlands, our own hardware |
Wasabi, where your files live, is ISO 27001 certified and its data centers are SOC 2 audited, and it encrypts every object at rest with AES-256. Those are their certifications, not ours: the compliance section further down says exactly what we do and do not hold.
The formal version, with the notice period and your right to object, is Annex 3 of our Data Processing Agreement.
Deleted means deleted.
We back up the database, so your account, workspaces and documents survive a failure. We do not back up uploaded files: storage holds one copy. Nobody can quietly restore a file after you remove it, not even us. The other side of that deal is that Nemi is not your backup either, so keep your own copy of anything you cannot lose. Documents and spreadsheets do have version history inside the app, which is a different thing.
What we have, and what we do not.
Nemi is built and run in the Netherlands under the GDPR. You get a Data Processing Agreement under Article 28 that applies automatically to business use, with a published sub-processor list, breach notification within 48 hours, audit rights and deletion when you leave. Our Privacy Policy covers your own rights of access, correction, export and erasure, and support@nemilab.com is also our point of contact under the EU Digital Services Act.
We are not SOC 2 audited, not ISO 27001 certified, and not built for HIPAA, the Dutch Wgbo or NEN 7510. We do not sign business associate agreements. Because of that, Nemi may not be used for special categories of personal data under Article 9 GDPR, such as health data or biometrics, or for patient records. That rule is in Section 7 of our Terms of Service, and it applies to the questions you ask in a Nemi form too.
If a data breach puts your rights at risk, we notify the Dutch supervisory authority within 72 hours and affected users without undue delay. For data we process on your behalf as a processor, you hear from us within 48 hours.
Tell us, we will answer.
Report a vulnerability to support@nemilab.com with "security" in the subject. Include the steps to reproduce it and what you think the impact is. You get a reply within two business days, we keep you posted while we fix it, and we credit you if you want.
Please test only against your own account, do not access other people's data, and give us a reasonable window to fix things before publishing. We will not pursue researchers who follow that. We do not run a paid bug bounty.
Illegal content or abuse goes to the same address and is handled under Section 8 of our Terms of Service.
Free to start, no credit card.
Files, safely done.
15 GB free, stored in the EU, never trained on.