Privacy Policy

Last updated: February 2026

1. Data Controller

Nomado Innovations EOOD, a company registered in the Republic of Bulgaria (UIC: XXXXXXXXXX), with its registered office at Sofia, Bulgaria, is the data controller for personal data collected through this website and our platform services. We are committed to protecting your privacy in accordance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and applicable Bulgarian data protection laws, including the Personal Data Protection Act.

2. Data We Collect

We collect the following categories of personal data depending on how you interact with our platform:

2.1 Account Data

  • Registration information: name, email address, chosen role (Customer or Talent), and hashed password when you create an account.
  • Profile data: additional information you may provide, such as company name, job title, or professional skills.

2.2 Brief and Project Data

  • Customer briefs: answers to brief questionnaires including text responses, selected options, and uploaded files (such as brand books, specification documents, or reference materials).
  • Brief templates: structural data created by moderators including section names, question titles, and answer types.

2.3 Career Application Data

  • CV/Resume: uploaded curriculum vitae files submitted as part of job applications.
  • Cover letter: text content submitted alongside job applications.

2.4 Contact and Communication Data

  • Contact form submissions: name, email, company name, and message content.

2.5 Technical Data

  • Usage data: anonymized analytics data including page views, browser type, device information, and IP address (truncated) collected through Vercel Analytics.
  • Cookies and local storage: session tokens, theme preferences, and authentication state.

3. How We Use Your Data

Personal data is processed for the following purposes:

  • Account management: creating and maintaining your user account, authenticating your identity, and managing role-based access to platform features.
  • Service delivery: facilitating brief creation, template management, and project requirement gathering between customers and our team.
  • Recruitment: processing job applications, evaluating candidates, and communicating about career opportunities.
  • Communication: responding to your inquiries, providing project updates, and sending service-related notifications.
  • Platform improvement: analyzing usage patterns to improve our website, services, and user experience.
  • Legal compliance: fulfilling our obligations under applicable laws and regulations.

We do not sell, rent, or share your personal data with third parties for marketing purposes.

4. Legal Basis for Processing

We process your personal data based on the following legal grounds under GDPR Article 6(1):

  • Contract performance (Art. 6(1)(b)): processing necessary to provide our platform services, manage your account, and deliver agreed-upon services.
  • Consent (Art. 6(1)(a)): where you have given explicit consent, such as submitting a contact form, uploading a CV, or opting into communications.
  • Legitimate interest (Art. 6(1)(f)): processing necessary for our legitimate business interests, such as improving our services, preventing fraud, and ensuring platform security, provided these interests do not override your fundamental rights.
  • Legal obligation (Art. 6(1)(c)): processing required to comply with applicable laws, such as tax reporting or responding to legal requests.

5. Data Sharing and Processors

We may share your personal data with the following categories of recipients:

  • Hosting and infrastructure: Vercel Inc. (United States) for website hosting and serverless functions, operating under appropriate data protection safeguards.
  • Internal team members: authorized moderators and administrators who require access to brief data and applications to deliver our services.
  • Legal and regulatory authorities: where required by law or to protect our legal rights.

We do not share your personal data with any third parties for their own marketing or commercial purposes.

6. International Data Transfers

Your personal data may be transferred to and processed in countries outside the European Economic Area (EEA), specifically the United States, where our hosting provider Vercel operates. Such transfers are protected by:

  • EU adequacy decisions where available (e.g., EU-US Data Privacy Framework).
  • Standard Contractual Clauses (SCCs) approved by the European Commission.
  • Additional technical and organizational safeguards, including encryption and access controls.

7. Data Retention

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected:

  • User accounts: retained for the duration of your active account. Data is deleted within 30 days of account deletion request.
  • Customer briefs: retained for the duration of the associated project engagement, plus 24 months for reference and dispute resolution.
  • Job applications and CVs: retained for 12 months from the date of submission, unless you request earlier deletion or consent to longer retention.
  • Contact form submissions: retained for 24 months from the date of submission.
  • Usage analytics: anonymized and retained indefinitely for trend analysis.

8. Cookies and Local Storage

Our platform uses the following storage mechanisms:

NamePurposeDurationType
next-auth.session-tokenAuthentication sessionSessionEssential
next-auth.csrf-tokenCSRF protectionSessionEssential
themeDark/light mode preference1 yearFunctional

No third-party tracking cookies or advertising cookies are used on this platform.

9. Your Rights Under GDPR

Under the General Data Protection Regulation, you have the following rights regarding your personal data:

  • Right of access (Art. 15): request a copy of the personal data we hold about you.
  • Right to rectification (Art. 16): request correction of inaccurate or incomplete data.
  • Right to erasure (Art. 17): request deletion of your personal data (“right to be forgotten”).
  • Right to restriction (Art. 18): request restriction of processing in certain circumstances.
  • Right to data portability (Art. 20): receive your data in a structured, machine-readable format.
  • Right to object (Art. 21): object to processing based on legitimate interests.
  • Right not to be subject to automated decisions (Art. 22): we do not make solely automated decisions that produce legal effects concerning you.

To exercise any of these rights, contact us at privacy@inomado.com. We will respond within 30 days. If you are not satisfied with our response, you have the right to lodge a complaint with the Commission for Personal Data Protection of the Republic of Bulgaria (CPDP).

10. Children's Privacy

Our platform and services are not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child under 16, please contact us immediately and we will delete such data without undue delay.

11. Security Measures

We implement appropriate technical and organizational measures to protect your personal data, including:

  • Encryption in transit (TLS 1.3) for all data transmissions
  • Password hashing using industry-standard algorithms
  • Role-based access controls limiting data access to authorized personnel
  • Regular security reviews and vulnerability assessments
  • Secure session management with HTTP-only, encrypted tokens

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify registered users of material changes via email or through a prominent notice on our platform. The “Last updated” date at the top of this policy indicates when the latest revision was made.

13. Contact and Data Protection

For questions about this privacy policy, to exercise your data protection rights, or for any privacy-related concerns, contact us at:

Nomado Innovations EOOD

Data Protection Contact

Email: privacy@inomado.com

General: contact@inomado.com

Sofia, Bulgaria, European Union