Privacy and Cookie Policy
Introduction
Protecting your privacy is very important to us. This Privacy Notice (“Notice”) explains how we collect, use, and disclose the information we process during the operation of our business. We regularly review our compliance with this Notice and may update it from time to time.
1. What is personal data
According to Article 4 of the General Data Protection Regulation (GDPR), “personal data” refers to any information that relates to an identified or identifiable individual (“data subject”).
In this document, “personal data” and “personal information” mean the same thing. Our Clients are considered “data subjects” under GDPR.
2. Who we are
We are NovaBridge Tech OÜ, incorporated under Estonian law with registry code 17390133 and registered address Harju maakond, Tallinn, Lasnamäe linnaosa, Võru tn 11, 13612, Estonia. We act both as the Controller and the Processor of personal information.
NovaBridge Tech OÜ operates the brand Nodomono and manages the website http://nodomono.com (“Website”, “us”, “we”, “our”, “Nodomono”).
3. What we do
Nodomono is an online platform offering digital gift cards and mobile top-up vouchers.
We use personal information only for the purposes described in this Notice. We share Client data with third parties exclusively when needed to deliver our services and only with the Client’s explicit consent.
We do not collect or process special categories of personal data (as defined in Article 9 GDPR).
4. How to contact us
If you have questions, comments, or requests related to this Privacy Notice, please contact us at: [email protected]
5. Voluntary nature of data provision
Clients are not obligated to provide personal data. However, some services cannot be offered unless the necessary information is provided. You may share data with us while creating an account, making purchases, completing forms on our Site, or communicating with us.
6. Types of personal data
We classify personal information into three main categories:
Directly Provided Data (D)
Information you supply yourself (e.g., form entries).
Indirectly Collected Data (I)
Information related to you but not supplied directly by you (e.g., IP address).
Automatically Generated Data (A)
Information created by our system. Under GDPR Article 4(1), this is considered personal data even if you did not provide it.
Subtypes:
• Static A (SA): does not change after generation (e.g., internal user ID).
• Dynamic A (DA): changes based on user activity.
We use the abbreviations D, I, SA, and DA when referring to these data types.
7. What information we collect, when, and why
Personal information is collected at several stages of interaction with the Company:
7.1 Sign Up (Registration)
The following may be requested or generated during registration:
1) Email address (D) – used as login, for alerts and notifications.
2) IP address (I) – used for identification, AML/CFT compliance, contractual obligations, fraud prevention.
If you hide or alter your IP, we are not responsible for displaying irrelevant information.
3) Internal user ID (SA) – used for internal identification.
4) Registration date (SA) – used for statistics.
5) Verification indicator (DA) – internal use.
6) Status (DA) – indicates the Client’s activity level.
7.2 First Log In
During the first login, the Client is asked to provide:
Citizenship (D), Country of residence (D), City (D) – used for statistics.
7.3 Verification
Under our AML/CFT Policy, we may request:
First name, last name, phone number, date of birth, country of birth, gender, identification document, address, proof of address – all (D).
7.4 Ongoing collection of information
We may also collect:
1) Survey responses (D) – to improve services.
2) Records of correspondence (D) – to fulfill contractual obligations, handle disputes, or support communication.
3) Technical data like browser type, version, time zone, OS, platform (I) – to enhance our services.
4) Risk behavior indicators (DA) – monitored to detect potentially harmful usage patterns.
This list is not exhaustive but illustrates the types of fundamental data we process.
8. Lawfulness of Processing and Disclosure
When a Client enters into cooperation with us, data processing is necessary for performing the agreement, making it lawful under GDPR Article 6(b).
In other cases, Clients must provide explicit consent prior to data collection or processing. We do not use pre-ticked boxes; all consent is freely given.
We may lawfully disclose personal data to:
• Law enforcement, regulators, government agencies, fraud-prevention bodies, identity verifiers, payment processors, credit agencies, banks, courts.
• Third parties you authorize us to introduce you to.
• Service providers and contractors (e.g., IT support, marketing providers, communication platforms, auditors, legal advisors).
We must disclose information when:
• Required by public authorities, national security, or legal obligations.
• Needed to defend legal claims, comply with court orders or subpoenas.
• Necessary to prevent financial harm, fraud, or illegal activities.
• Related to business transfers such as mergers, restructurings, or asset sales.
9. Third Parties
We may share personal data with the following third parties (only the minimum required amount):
1) Verification service providers.
2) SMS-notification providers – only your phone number and the message content are shared (messages do not contain personal data).
3) Email/mailing service providers – to communicate with Clients.
10. Where we store personal data
We store data in AWS data centers. Data may also be stored by verification providers like SumSub, Shafti, or Onfido. These entities act strictly as data processors and only maintain server infrastructure – they do not access or process personal data directly.
11. How long we store personal data
We retain personal data as long as required to deliver our services or until consent is withdrawn (see section 12.5). Regardless of withdrawal, AML regulations require us to store certain data for 5 years after service termination.
12. Rights of the Client
Clients have a wide range of rights under GDPR:
12.1 Obtain confirmation
You may ask whether we are processing your personal data.
12.2 Access personal data
You may request a copy of your processed data.
12.3 Demand additional information
You may request the purposes of processing, categories of data, recipients, and retention timelines.
12.4 Request rectification
You may request correction or completion of inaccurate or incomplete data.
12.5 “Be Forgotten” (Erasure)
You may withdraw consent and request deletion of your data.
However, due to legal obligations (AML), we must retain certain information for 5 years after account closure.
12.6 Restrict processing
You may request that processing be paused while data accuracy is assessed.
12.7 Receive personal data
You may request your data in a machine-readable format.
12.8 Have personal data transmitted
You may request transfer of your data between controllers when feasible.
12.9 Object
You may object to processing based on your particular situation.
13. Communications
You may receive the following types of communication if you opt in:
• Emails
• Phone messages
• Push notifications
• Account messages
You may unsubscribe at any time via the opt-out link or by emailing [email protected].
14. Cookies
We may use cookies to ensure proper Website operation, understand user behavior, measure performance, personalize experiences, and provide secure authentication.
Cookies vary by:
1) Origin: first-party vs. third-party.
2) Storage duration: permanent vs. session cookies.
3) Purpose: preferences, technical, analytics, marketing.
4) Necessity: required vs. preference cookies.
We may use third-party cookies such as:
• Google Analytics – understanding usage patterns.
• Google Remarketing – showing relevant ads (optional).
• reCAPTCHA – blocking bots.
Clients may block cookies, but some Website functions may not operate correctly.
15. Conclusion
We strive to protect personal data and ensure transparency in processing activities.
If you have questions, please contact us (see section 4).
If personal data reaches us lawfully from third parties, your rights remain the same as if you provided the data directly.
If you believe your privacy rights have been violated, you may file a complaint with the appropriate supervisory authority.