Legal
Privacy Policy
This page explains what personal data we collect on nlsys.io, why, where it goes, and what rights you have. It is written to match what this site actually does — nothing more.
Last updated: 9 September 2026 · OPS2.AI LTD, United Kingdom, Company No. 17081809, registered address 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom. Contact: nlsys.io@proton.me.
1. Who we are
OPS2.AI LTD ("we", "us") is a company registered in the United Kingdom. We are the data controller for the personal data described on this page. We are registered with the UK Information Commissioner's Office as a data controller, registration reference ZC106468. For anything privacy-related, write to nlsys.io@proton.me.
2. What we collect, and why
Contact forms. When you send a contact request, we receive the fields you submit and use them to answer the request. Standard products are purchased through the account; a contact form is not required to buy them.
Your account and usage. When you sign in to the customer account we process your email address, your sign-in and consent records, your platform API key, and your points ledger — points added with plans and top-ups, and points spent on traffic, compiles and reports. If you arrive via a marketing link, we also record the campaign tags (utm) and the referring site with your account — first-party attribution only; no third-party cookies are set for this. From your IP address we derive an approximate country at sign-up, to record where our users come from and to comply with sanctions and export rules; we do not store the raw IP for this purpose beyond the lookup. Our administrators can view these records in an internal dashboard. Legal bases: performing the contract with you; keeping accounting records required by law (kept up to 6 years in the UK); and our legitimate interest in securing the service and preventing misuse — including suspending access as described in the Terms. We do not sell this data and do not use it for third-party advertising.
Purchases and the billing portal. Payments are handled by our payment processor, Stripe. Card details go to Stripe directly and never touch our servers. NLSYS account authentication is handled separately by Auth0; NLSYS does not store your account password in the cabinet application. We see what the provider shows us: your name, email, purchases, invoices and subscription status (legal basis: performing the contract; keeping records required by law).
Product data. If you send signal streams, trajectory data or uploaded data files (for example CSVs) to our products, that data is processed on our servers for the sole purpose of providing the service you requested. Ownership of your data stays with you. Public browser checks. The CSV cost estimator and Battery file check read the selected file in your browser. Signal values are not sent to NLSYS unless you sign in and explicitly launch a product job.
Technical data. Hosting records may include IP address, request time and requested path for security and operations. Fonts are served from our domain. Some public pages include Cloudflare Web Analytics. The local file-check and CSV-estimator pages do not load this third-party analytics script.
Marketing. We do not send marketing emails. If that ever changes, it will be opt-in only.
3. Cookies and analytics
Some public pages use Cloudflare Web Analytics for aggregate page-view information. Our public navigation code also keeps campaign tags and entry paths in first-party sessionStorage for the current browser tab. This is browser storage, not a cookie. File contents are not included in those tags. The file-check and CSV-estimator pages omit third-party analytics; the estimator sends only size, counts and selected options to the public estimate API after file selection.
3a. Payments and card data
Checkout and card processing happen entirely on our payment providers' PCI DSS–compliant infrastructure. We never see or store card numbers.
4. Where your data goes (international transfers)
We are a UK company. Product and account data are processed on our own servers and by the processors listed below. Where personal data is transferred outside the UK, we rely on UK adequacy regulations or appropriate safeguards (such as the UK International Data Transfer Agreement or standard contractual clauses), as applicable. If you are in the EU/EEA, equivalent EU mechanisms apply to your data. Our processors: Stripe (payment processing), Auth0 (account authentication), Cloudflare (cookieless page-view analytics), our email provider (Proton — email you send us), and our hosting provider (site, account area and product infrastructure). Site forms are delivered to our own account server — no third-party form service. Each processor handles data under its own terms as our processor or an independent controller for their service.
5. How long we keep it
Contact correspondence is kept for as long as needed to handle the request and our relationship, then deleted. Billing records are kept for the period required by tax and company law. Product files and artifacts follow the retention displayed for the applicable product or account; you may also request deletion, subject to legal and security records we must retain.
6. Your rights
Under UK GDPR (and equivalent EU law) you can ask us for access to your personal data, correction, deletion, restriction of processing, portability, and you can object to processing based on legitimate interests. Write to nlsys.io@proton.me — we answer every message ourselves. You also have the right to complain to a supervisory authority: in the UK, the Information Commissioner's Office (ico.org.uk); in the EU, your local data protection authority.
7. Changes
If this policy changes, the new version appears on this page with an updated date. Material changes affecting existing customers will also be sent to the email we hold for you.