Scope
This policy explains what data the https://nesly.net website and the https://console.nesly.net console collect from visitors and users, how it is used and how it is protected. The statutory notice on personal data is in the Personal Data Notice.
Data collected
- Marketing site: no analytics, advertising or tracking tools; only server access logs (IP address, browser information) are kept for security.
- Console: account details (name, e-mail), billing details (legal name, address, tax or national ID), your projects' configuration and usage metrics (requests, data transfer, build time).
- Your applications' code and data are processed solely to provide the Service; their content is not inspected for marketing or analytics.
Payment security
- Card number, expiry date and security code are never stored or processed by us; the payment step takes place on the bank's virtual POS page.
- 3D Secure authentication is mandatory for all card payments.
- Renewal charges use a secure token provided by the bank that contains no card data.
- The site and console are served over HTTPS only; certificates renew automatically.
Data security
- Applications run in kernel-isolated containers (gVisor), each customer in its own namespace.
- Environment variables are readable only by the account that owns the project and by the application itself; platform credentials are held in a separate secret store.
- Every project gets its own database and database user and cannot reach another customer's database. Deleting a project does not destroy the database immediately; it is retained for a period so it can be brought back.
- Staff access to production systems is role-based and logged.
Third parties
Your data is not shared with third parties for marketing. Providers essential to the Service (the bank's virtual POS for payments, the authorised e-invoice integrator, e-mail delivery) receive only the data needed for their function. Data may be disclosed to competent authorities where legally required.
Changes and contact
Changes to this policy can be tracked from the date at the top of the page. Questions: nesly@nesly.net.