Privacy Policy
Information on data processing in accordance with the EU General Data Protection Regulation (GDPR).
The responsible party for data processing on this website is:
Kardashev Catalyst UG (haftungsbeschränkt)
Trierer Str. 6, 50676 Köln, Germany
Email: contact@nisd2.eu
When you use our platform, we process the following personal data:
- Account data: name and email address provided via Google OAuth during sign-in
- Form submissions: data you enter in compliance requirement forms
- Uploaded files: evidence documents you upload to the platform
- Technical data: IP address, browser type, and access timestamps in server logs
- Billing data: if you order, the name and address of the organization billed, its VAT number, the email address the invoice goes to and, if you give them, a second address for a copy and your purchase order number. We check the VAT number against the EU's VIES register.
- Referral requests: if you ask for support through the form on /hilfe, we store what you tell us (topic, email address, and optionally name, company, sector, size, what prompted it, your timeframe and your description), the page you opened the form from, and the page you visited before that (referrer). We pass your request to a specialist firm only if you explicitly agreed in the form, and we record when that consent was given. From the moment it is passed on, the firm is its own controller. If an engagement results, the firm pays us a referral fee. You can withdraw your consent at any time.
We process your data for the following purposes:
- Providing the NIS2 compliance platform (Art. 6(1)(b) GDPR - performance of a contract)
- Handling orders, invoices and cancellations (Art. 6(1)(b) GDPR) and keeping invoices for as long as tax law requires (Art. 6(1)(c) GDPR)
- User authentication and account management (Art. 6(1)(b) GDPR)
- Ensuring the security and integrity of our platform (Art. 6(1)(f) GDPR - legitimate interest)
- Looking after customers and prospects in our sales system, so we can advise you about our offer and follow up on requests (Art. 6(1)(f) GDPR, legitimate interest). You can object to this processing at any time.
- Compliance with legal obligations (Art. 6(1)(c) GDPR)
We use the following third-party services to operate the platform and for our sales:
- Google (OAuth): authentication, processes your name and email address for sign-in
- Amazon Web Services (S3): file storage, stores evidence documents you upload
- Resend: transactional email, delivers notification and invitation emails
- Close (Elastic Inc., Jackson, Wyoming, USA): our sales system (CRM). For verified accounts it processes your name and email address, facts about your account and use (such as sign-up, last sign-in, course progress, progress in implementing NIS 2, your plan and whether we may email you) and facts about your company (such as name, sector, number of employees, country). Transfers to the USA are based on the EU Standard Contractual Clauses. When your account is deleted, we also delete your contact in Close.
- Qonto (Paris, France): our business account and invoicing. When you order, it receives the billing data, and it issues and keeps the invoices and credit notes.
We use Umami for website analytics. Umami is self-hosted on our own infrastructure. It does not collect personal data, does not use cookies, and does not track individual users. All data is aggregated and anonymous. No consent is required for this type of analytics.
Separately: if you sign up through a link that carries campaign tags (parameters starting with utm_, for example from an ad), we store those tags with your account, so we can see which ad or link an account came from. Nothing else from the link, such as click IDs, is stored. The legal basis is Art. 6(1)(f) GDPR, our legitimate interest in measuring what our advertising does.
You have the following rights regarding your personal data:
- Right of access (Art. 15): request information about what data we store
- Right to rectification (Art. 16): correct inaccurate data
- Right to erasure (Art. 17): request deletion of your data
- Right to restriction (Art. 18): restrict processing of your data
- Right to data portability (Art. 20): receive your data in a machine-readable format
- Right to object (Art. 21): object to processing based on legitimate interest
To exercise any of these rights, contact us at contact@nisd2.eu.
This website uses SSL/TLS encryption for security reasons and to protect the transmission of personal data and other confidential content. You can recognize an encrypted connection by the "https://" prefix and the lock icon in your browser's address bar.
Your data is stored as long as your account is active and necessary for the purposes described above. Compliance data (form submissions, evidence, audit trail) is retained for the legally required period. When you delete your account, personal data is removed. Anonymized audit trail entries may be retained.
Invoices and credit notes, with the billing data on them, are kept for at least eight years from the end of the calendar year in which they were issued, and longer while a tax assessment they matter for is still open (§ 14b Abs. 1 UStG, § 147 Abs. 3 and 4 AO). Deleting your account does not delete them (Art. 17(3)(b) GDPR). Qonto holds them for the same period.
When your account is deleted, we email you a confirmation of what was deleted, sent through our email provider Resend (Art. 12(3) GDPR). We keep a record of the erasure (name, email address, organization, case reference and what was deleted) to show that we honoured the request (Art. 5(2) GDPR). The email address is removed from it after three years.
We may update this privacy policy from time to time. The current version is always available on this page. Last updated: October 2026.