Privacy Policy
Last updated: July 2026
1. Data controller
Nupact GmbH
c/o Nitin Sahai, Ehrenbergstraße 2
10245 Berlin, Germany
Email: contact@nupact.ai
For full legal details see our Impressum.
2. What data we collect and why
Server logs. When you visit nupact.ai, our web server automatically records your IP address, browser type, referring URL, and the pages you request. This data is used solely to ensure technical operation and security of the website. Legal basis: Art. 6(1)(f) GDPR (legitimate interest). Log data is deleted within 30 days.
Contact by email. If you contact us at contact@nupact.ai, we store your email address and message content to respond to your enquiry. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in handling enquiries). Data is deleted once the enquiry is resolved, unless a contractual relationship follows.
Site analytics (on consent only). If you accept cookies, we use Google Analytics (via Google Tag Manager) to collect anonymised data about how visitors use this site — pages visited, session duration, and general location (country/city level). No advertising data is collected on this website. Legal basis: Art. 6(1)(a) GDPR. You can withdraw consent at any time via "Cookie Settings" in the footer.
Meeting bookings (Calendly, on consent only). If you accept cookies and click "Book a Call", you interact with the Calendly scheduling widget. Calendly, Inc. (USA) will collect your name, email address, and calendar availability to arrange a meeting. Legal basis: Art. 6(1)(a) GDPR. Calendly's privacy policy: calendly.com/privacy.
3. Third-party services
Google Tag Manager & Google Analytics (on consent only). Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland. Anonymised usage data may be transmitted to Google's servers in the USA. Google LLC participates in the EU–US Data Privacy Framework. Google's privacy policy: policies.google.com/privacy. GTM Consent Mode v2 is configured to prevent any data collection until consent is given.
Calendly (on consent only). Calendly, Inc., 271 17th St NW, Atlanta, GA 30363, USA. Loaded only after you accept cookies. Calendly participates in the EU–US Data Privacy Framework.
No other third-party services are used on this website. Fonts are served directly from nupact.ai (self-hosted). We do not use advertising trackers or social media pixels on this website.
4. Cookies
We use one first-party cookie (nupact_cookie_consent) to store your consent choice for 12 months.
If you accept, Google Analytics may set _ga and _ga_* cookies (up to 2 years), and
Calendly may set its own session cookies. You can review or change your choice at any time via "Cookie
Settings" in the footer.
5. Cyclops platform — processing of advertising data
Separate from this website, Nupact GmbH operates Cyclops, a campaign-management platform for advertisers. This section describes the data Cyclops processes for business clients. It does not apply to visitors of this website.
What we process. When a client connects its advertising accounts (for example, Meta or Google Ads) to Cyclops, we access — with the client's authorization, through the platforms' official interfaces (such as the Meta Marketing API and the Google Ads API) — the client's campaign configuration and settings, ad performance metrics (such as impressions, clicks, spend, conversions, and reach), and advertising account metadata.
Role and legal basis. We process this data on behalf of and at the direction of the client, to perform our contract with the client (Art. 6(1)(b) GDPR). A data processing agreement with the client governs the details.
Purposes. Providing the contracted services to that client: campaign management, reporting dashboards, performance monitoring, and optimization recommendations for the client's own campaigns.
Purpose limitation. Data from a client's advertising accounts is used only for that client, and only for that client's campaigns on the advertising platform the data came from. We do not:
- sell or license this data;
- use it to build or augment user profiles;
- use it for retargeting;
- combine one client's data with another client's;
- feed data obtained from one advertising platform into another platform's targeting or bidding systems.
Storage and security. Client data is stored in the European Union, segregated per client, and protected by administrative, physical, and technical safeguards. Access is limited to the client and persons acting on the client's behalf.
Jurisdiction and international government access. Nupact GmbH is established in Berlin, Germany, and is governed by the laws of the Federal Republic of Germany and the European Union. We do not voluntarily disclose this non-personal data to any government or public authority; we respond only to valid legal process under German and European Union law, we challenge requests that are unlawful or overbroad, and our agreements with data-ingestion sub-processors require them to process this data within the European Union.
Retention and deletion. We delete a client's advertising data when it is no longer needed to provide the services, when the client disconnects the relevant advertising account or terminates the contract, or upon a deletion request by the client, by the advertising platform (for example, Meta), or by a verified data subject. To request deletion, email contact@nupact.ai.
6. Reporting security vulnerabilities
If you believe you have found a security vulnerability in this website or in the Cyclops platform, please email security@nupact.ai. We acknowledge reports promptly and address confirmed issues with priority. See also security.txt.
7. Your rights under GDPR
You have the right to:
- Access the personal data we hold about you (Art. 15)
- Rectification of inaccurate data (Art. 16)
- Erasure ("right to be forgotten") (Art. 17)
- Restriction of processing (Art. 18)
- Data portability (Art. 20)
- Object to processing based on legitimate interest (Art. 21)
- Withdraw consent at any time without affecting the lawfulness of prior processing (Art. 7(3))
To exercise any of these rights, contact us at contact@nupact.ai.
8. Right to lodge a complaint
You have the right to lodge a complaint with a supervisory authority. The competent authority for Berlin is:
Berliner Beauftragte für Datenschutz und Informationsfreiheit (BlnBDI)
Friedrichstr. 219, 10969 Berlin
www.datenschutz-berlin.de