Privacy policy
Last Updated: August 21, 2026
Introduction and Purpose
This Privacy Policy explains how NANNOS sp. z o.o. (“NANNOS”, “the Company”, “we”, “us”, or “our”) processes Personal Data in connection with the Intsurfing API Platform, API-based services, API endpoints, documentation, account tools, billing functionality, and related service pages that link to this Privacy Policy.
The Intsurfing API Platform is available at https://platform.api.intsurfing.com/ , and the informational API website is available at https://www.api.intsurfing.com/ .
NANNOS sp. z o.o. is the contractual provider and billing entity for the Intsurfing API Services and acts as the Controller of Personal Data processed for account administration, service provision, billing, invoicing, payment administration, security, legal compliance, and related business purposes described in this Privacy Policy.
NANNOS may engage authorized technology, infrastructure, payment, analytics, communication, and support providers to operate parts of the Services. LLC “INTSURFING” provides certain technical, operational, website, platform, and support functions in connection with the Intsurfing API Services and may process Personal Data on behalf of NANNOS for those purposes.
The Services provide structured technical access to publicly available datasets sourced from official or authoritative sources, as well as non-data technical processing functionality. Depending on the Service, Personal Data may therefore be processed as part of publicly available datasets, client-submitted technical processing, or operation of the Website and Platform.
This Privacy Policy also describes the categories of Personal Data we process, why we process it, the applicable legal bases, the parties with whom information may be shared, applicable retention and security practices, and the rights available to Data Subjects.
The Services are intended for businesses and professionals acting for business or professional purposes and are not intended for personal, household, or consumer use.
This Privacy Policy applies unless a separate privacy notice, Data Processing Agreement, or other contractual document expressly governs a particular processing activity.
DEFINITIONS
For the purposes of this Privacy Policy, the following terms have the meanings set out below:
- “Personal Data” means information relating to an identified or identifiable natural person, including identification details, contact information, professional information, technical identifiers, account information, and other information that may identify a person directly or indirectly.
- “Data Subject” means an individual whose Personal Data is processed in connection with the Website, Platform, Services, communications, publicly available datasets, or other activities covered by this Privacy Policy.
- “Processing” encompasses any form of handling or use of Personal Data, whether carried out by automated means or otherwise. This includes, among other actions, the collection, recording, organization, storage, modification, consultation, transmission, restriction, deletion, or destruction of such data.
- “Applicable Data Protection Laws” means laws and binding legal requirements governing Personal Data applicable to the relevant Processing activity, including, where applicable, Regulation (EU) 2016/679 (“GDPR”), applicable United States privacy laws including the CCPA/CPRA, Polish data protection law, and other mandatory privacy laws applicable to the Company or relevant Data Subject.
- “User” refers to any person who accesses, browses, or communicates with the Company through the Website. Users may act in their own capacity or as authorized representatives of legal entities, corporate clients, or other organizations.
- “Website” means the online resource operated by the Company and available at https://www.api.intsurfing.com, together with its subdomains, pages, and technical features provided within this domain.
- “Platform” means the Company’s online environment available at https://www.platform.api.intsurfing.com/ through which registered users create accounts, manage billing information, and access the Company’s API services.
- “Services” means the API-based data-access and technical processing services provided through the Intsurfing API Platform.
- “Cookies” are small data files placed on a User’s device by the Website for purposes such as maintaining functionality, recognizing repeat visits, or collecting aggregated usage information. Cookie behavior and availability may vary depending on the User’s browser or device settings.
- “Third-Party Services” means external services, platforms, or technical solutions that are integrated into the operation of the Website or support its functionality. Such services may include analytics tools, hosting providers, communication systems, or email infrastructure, each operating under its own applicable terms and privacy policies.
- “Controller” means NANNOS sp. z o.o. where it determines the purposes and essential means of Processing Personal Data covered by this Privacy Policy.
- “Processor” or “Service Provider” means an entity that processes Personal Data on behalf of the Controller in connection with the Services, including authorized technology, infrastructure, payment, communication, analytics, or support providers where applicable.
CATEGORIES OF PERSONAL DATA WE PROCESS
-
General Principle of Data Minimization. The Company limits the processing of Personal Data to what is objectively necessary for the operation of the Website and the Platform, the provision of API services, and the handling of inquiries or communications initiated by Users. The scope and nature of the data processed depend on how a User interacts with the Website, the Platform, or the API services.
-
Information Voluntarily Provided by Users. When a User chooses to contact the Company through the Website, including by submitting an inquiry or request for information, the User may voluntarily provide certain Personal Data. This may include identification and contact details (such as name, email address, and telephone number), professional or organizational information (for example, job title or the name of the organization represented), as well as the substantive content of the inquiry itself.
-
Optional Nature of User Submissions. The provision of such information is voluntary. However, without the relevant information, the Company may be unable to properly review the inquiry or provide a meaningful response. Any Personal Data submitted by Users is processed solely for the purpose for which it was provided and is not repurposed for unrelated activities.
-
Technical and Usage-Related Information. When the Website, Platform, or related service pages are accessed, certain technical, usage-related, analytics, and advertising measurement information may be generated automatically through standard web technologies or integrated Third-Party Services. This information may include IP addresses, browser and device characteristics, operating system data, timestamps of access, referral information, page URLs viewed, campaign parameters, Google click identifiers where applicable, cookie or tag identifiers, session-related identifiers, approximate location, and conversion events such as account registration, service activation, or other defined actions. Such information is used for Website and Platform operation, security, analytics, campaign measurement, attribution, service improvement, and related business purposes.
-
Account and Registration Information. When a User creates an account on the Platform, the Company processes Personal Data necessary for account administration and service provision. This may include name, email address, billing address, telephone number, and account credentials.
-
Billing and Payment Information. We process information necessary to administer billing and payments, including billing details, payment status, invoice information, transaction identifiers, payment-method metadata provided by the Payment Processor, and information relating to payment verification or failed payment attempts. Full payment-card details are processed by the applicable Payment Processor and are not stored by the Intsurfing API Platform.
-
Public Records and Dataset Information. Through its API services, the Company processes Personal Data contained in publicly available sources in the United States. Such data may include names, dates of birth, offense-related information, case identifiers, and other information lawfully disclosed under applicable public records laws. The Company does not collect data from private, restricted, or unlawfully obtained sources.
-
Client-Submitted Data for Processing. In connection with its data processing API services, the Company may process Personal Data submitted by clients for the purpose of data parsing, standardization, validation, or related transformation activities. The Company acts as a service provider and processes such data solely on documented instructions from the client and does not use it for independent purposes.
-
Data Categories Not Processed. The Company does not seek to collect or intentionally process special categories of personal data as defined under applicable data protection laws, including data relating to racial or ethnic origin, political or religious beliefs, health or medical conditions, biometric or genetic data, sexual orientation, or trade union membership. If such information is submitted without request or necessity, it is not used and is deleted or anonymized in accordance with internal data handling procedures.
PURPOSE OF PROCESSING PERSONAL DATA
-
The Company processes Personal Data in connection with the operation of the Website and the Platform, the provision of API services, and interactions initiated by Users. All processing activities are aligned with the functional role of the Website as an informational interface and the Platform as a secure service environment.
-
Account Administration and Service Provision. Personal Data provided during account registration and use of the Platform is processed for the purpose of creating and maintaining user accounts, authenticating Users, managing billing, enabling access to API services, and providing customer support.
-
User Communications. Personal Data provided by Users in the course of submitting inquiries or other communications through the Website, Platform, or related contact channels is processed exclusively for the purpose of reviewing, responding to, and handling the specific request. Such data is not used for unrelated purposes and is retained only for the period reasonably necessary to address the relevant communication.
-
Website and Platform Operation, Stability, and Security. Certain technical and usage-related information is processed to ensure the proper operation, security, and stability of the Website and Platform. This includes processing activities related to system administration, performance monitoring, troubleshooting, and the prevention of unauthorized access, misuse, or interference with the Website’s or Platform's technical infrastructure.
-
Analytics, Campaign Measurement, and Performance Assessment. The Company may process technical, usage-related, aggregated, de-identified, and event-based information to assess how the Website, Platform, and related service pages are accessed and used; measure advertising campaign performance; attribute conversions; understand user interaction with service pages; maintain security; improve technical performance; and improve the user experience.
-
Legal Compliance and Legitimate Interests. In limited circumstances, Personal Data may be processed where this is necessary to comply with applicable legal obligations or to respond to lawful requests from competent authorities. Where permitted by law, Personal Data may also be processed to protect the Company’s legitimate interests, including safeguarding its systems, ensuring service integrity, and preventing misuse of the Website or Platform. The Company may process limited technical, usage-related, and conversion-related data for analytics, advertising measurement, attribution, campaign performance assessment, service communication, and, where permitted by applicable law and advertising platform policies, remarketing or similar advertising functions. The Company does not use Personal Data to make automated decisions that produce legal or similarly significant effects for Users.
-
Data Retention and Storage Limitation. Personal Data is retained for periods aligned with the purposes for which it was collected, including responding to communications, maintaining technical security, or meeting applicable legal obligations. Where Personal Data is no longer required for these purposes, it is deleted or anonymized in accordance with the Company’s internal data handling procedures. Retention periods may vary depending on the nature of the data involved and applicable legal requirements.
LEGAL BASIS FOR PROCESSING PERSONAL DATA
-
The processing of Personal Data by the Company is carried out on a lawful ground recognized under applicable data protection and privacy legislation. The legal ground relied upon is determined by the manner in which a User interacts with the Website or Platform, the type of information involved, and the regulatory framework relevant to the User’s jurisdiction.
-
In structuring its data processing activities, the Company takes into account the requirements of Regulation (EU) 2016/679 (General Data Protection Regulation (GDPR) for Users located in the European Economic Area, applicable privacy laws of the United States, including the California Consumer Privacy Act and the California Privacy Rights Act (CCPA/CPRA), as well as the Law of Ukraine “On Personal Data Protection”, where such legal frameworks are relevant to the processing in question.
-
Legal basis. The main legal basis for processing personal data contained in public registers and datasets is the Company's legitimate interest in accordance with Article 6(1)(f) of the GDPR, in particular for the purpose of providing legitimate data access services, supporting compliance and analysing risks for API Clients.
-
User Consent. When a User chooses to submit information through contact forms or other communication channels available on the Website, the processing of such information is based on the User’s deliberate act of providing it. This ground applies in connection with the specific inquiry or communication submitted and does not extend beyond it. A User may revoke consent at any time in accordance with applicable legal requirements.
-
Legitimate Interests. Technical, usage-related, analytics, and advertising measurement information may be processed in connection with the Company’s legitimate interests, including maintaining the functionality and security of the Website and Platform, protecting the technical environment, measuring campaign performance, attributing conversions, improving service pages and user experience, and addressing attempts at misuse or unauthorized access. Where consent is required by applicable law for cookies, similar technologies, or advertising-related processing, the Company relies on such consent. In these cases, the Company evaluates the context of processing, the nature of the information involved, and the interests of Users, and implements measures intended to ensure that individual rights are not adversely affected.
-
Legal Obligations. Certain processing activities may arise from duties imposed by law. This includes situations where information must be retained, disclosed, or otherwise handled in response to binding requests from public authorities or to meet statutory compliance and record-keeping requirements.
-
United States Privacy Considerations. With respect to Users subject to United States privacy regimes, including residents of California, the Company does not sell Personal Data for monetary consideration. The Company may disclose limited technical, usage-related, analytics, and conversion-related information to service providers and advertising technology providers for Website and Platform operation, analytics, attribution, campaign measurement, security, and, where enabled and permitted, advertising or remarketing functions. Where any activity constitutes “sharing” of Personal Data for cross-context behavioral advertising under applicable law, the Company provides applicable notices and choices as required.
-
Sensitive Data and Automated Processing. The Company does not seek to handle sensitive categories of personal data and does not apply automated decision-making or profiling mechanisms that would produce legal or comparable effects for Users. Where information of this nature is submitted unintentionally or without relevance, it is excluded from further use and addressed through the Company’s internal data protection procedures.\
COOKIES AND TRACKING TECHNOLOGIES
-
The Company may use cookies, tags, pixels, local storage, web beacons, analytics tools, advertising measurement tools, and similar technologies on the Website, Platform, and related service pages. These technologies may be used to operate and secure the Website and Platform, remember technical preferences, measure traffic and campaign performance, attribute conversions, understand interactions with service pages, improve the user experience, and support advertising or remarketing functions where permitted.
-
The Company may use Third-Party Services for these purposes, including Google Analytics 4, Google Tag Manager, Google Ads conversion tracking, Google Ads remarketing or similar advertising tools where enabled and permitted, Serpstat, hosting providers, security tools, and other technical service providers. These tools may process technical identifiers, cookie identifiers, device and browser information, referral information, campaign parameters, page interaction data, and conversion events.
-
Users may be able to control cookies and similar technologies through browser settings, device settings, cookie-consent tools, or other choices made available on the Website or Platform. Some features may not function properly if certain cookies or technologies are disabled. Where required by applicable law, the Company requests consent before using non-essential cookies or advertising-related technologies.
DISCLOSURE OF PERSONAL DATA TO THIRD PARTIES
-
General Approach. The Company’s handling of Personal Data does not include its commercialization or distribution for third-party exploitation. Information is shared externally only in connection with the technical operation of the Website, Platform, or where disclosure is required under applicable law.
Any transfer of Personal Data is carried out in a controlled manner and is confined to what is relevant for the specific purpose involved. Measures are taken to preserve confidentiality, integrity, and security throughout the period during which the data remains accessible to a recipient.
Personal Data contained in public datasets is retained in accordance with the availability of the underlying public records, contractual requirements, and applicable legal obligations, and is not retained longer than necessary for the purposes of the API services.
-
Recipients Involved in Website Operations. To maintain, support, measure, and improve the Website, Platform, and Services, the Company works with selected external service providers responsible for hosting, analytics, advertising measurement, remarketing where enabled and permitted, security, payment processing, communication infrastructure, and customer support. This may involve making limited categories of Personal Data available to providers such as Google Analytics 4, Google Tag Manager, Google Ads, Serpstat, hosting environments, payment processors, email infrastructure, security providers, and other technical or operational service providers.
These parties act on the Company’s behalf and operate under contractual terms that address data protection, confidentiality, and information security requirements. Where applicable, such arrangements are documented through data processing agreements consistent with recognized regulatory frameworks.
-
Public Authorities and Legal Requests. Disclosure of Personal Data may occur where the Company is required to do so by law or in response to binding requests issued by courts, regulators, or law enforcement bodies. In such situations, the scope of disclosure is determined by the legal obligation at hand and is limited to the information that must be provided.
-
Corporate Changes and Transactions. In the context of corporate developments such as a reorganization, acquisition, merger, or transfer of assets Personal Data may form part of the information transferred. Where this occurs, the recipient is expected to adhere to data protection standards aligned with those reflected in this Privacy Policy and to implement safeguards offering comparable protection.
-
Safeguards and Ongoing Control. The Company applies data minimization principles to all external disclosures and limits access to Personal Data based on functional necessity. Before sharing information, the Company reviews the recipient’s data handling practices and confirms that appropriate contractual, technical, and organizational measures are in place.
Responsibility for determining the purposes and core parameters of processing remains with the Company, and recipients are not authorized to use Personal Data for activities unrelated to the services they provide.
CROSS-BORDER TRANSFERS OF PERSONAL DATA
-
The Company’s technical setup and operational structure may require Personal Data to be accessed or handled outside the country in which it was originally collected. This may occur, for example, in connection with hosting environments, security services, administrative support, or other functions related to the operation and protection of the Website or Platform.
-
When information is handled across national borders, the Company takes steps to ensure that the level of protection applied to such data remains consistent with applicable data protection requirements. International data flows are not part of the Company’s routine activities and occur only in connection with clearly identified operational or legal needs.
-
For data originating from the European Economic Area, transfers are carried out using mechanisms recognized under Regulation (EU) 2016/679 (GDPR). Depending on the circumstances, this may involve the use of Standard Contractual Clauses adopted by the European Commission or other transfer tools permitted under Articles 44 - 49 of the GDPR.
-
In situations where Personal Data is accessed or processed in jurisdictions governed by United States law, the Company organizes such access in line with relevant state and federal privacy requirements. Measures are taken to address potential risks associated with cross-border access, taking into account the nature of the information involved and the purpose for which access is required.
-
Any cross-border handling of Personal Data is limited to what is relevant for the specific activity involved and is supported by contractual arrangements, technical safeguards, and internal controls. Parties located outside the original jurisdiction are expected to observe data protection standards compatible with applicable law and with the principles reflected in this Privacy Policy.
USER RIGHTS
-
Individuals whose Personal Data is handled by the Company may exercise certain rights granted under applicable data protection and privacy legislation. The availability and scope of these rights depend on the User’s place of residence and the legal framework governing the relevant processing activities.
-
Rights of Users in the European Economic Area. Users located in the European Economic Area are entitled to the rights provided under Regulation (EU) 2016/679 (General Data Protection Regulation). These include the ability to confirm whether Personal Data relating to them is being processed and to obtain access to such information, to request correction of inaccurate or incomplete data, and to seek deletion of Personal Data in situations provided by law.
Depending on the circumstances, Users may also request restrictions on how their information is handled, receive certain categories of data in a portable format, or object to processing based on legitimate interests. Where processing relies on consent, consent may be withdrawn at any time without affecting prior lawful use. Users also retain the right to raise concerns with a competent supervisory authority.
-
Rights under United States Privacy Laws. For Users subject to United States privacy regimes, including residents of California, the Company observes the rights set out in the California Consumer Privacy Act and the California Privacy Rights Act. These rights allow Users to obtain information about the categories of Personal Data collected and the purposes for which it is used, to request access to or deletion of Personal Data held by the Company, and to seek correction of inaccurate information.
Where applicable, Users may also exercise the right to opt out of the sale or sharing of Personal Data. The Company does not sell Personal Data for monetary consideration. If the Company uses advertising or remarketing technologies in a way that constitutes “sharing” of Personal Data for cross-context behavioral advertising under the CCPA/CPRA, the Company will provide applicable notices and opt-out choices as required by law.
-
Exercising User Rights. Requests relating to the exercise of data protection rights may be submitted using the contact details provided in this Privacy Policy. To prevent unauthorized disclosure and protect Personal Data, the Company may request information reasonably necessary to confirm the identity of the requester.
Requests are reviewed and addressed within the time periods established by applicable law. Where a request cannot be fully satisfied due to legal, regulatory, or technical constraints, the Company will provide an explanation consistent with statutory requirements.
EXERCISING DATA SUBJECT RIGHTS AND CONTACT DETAILS
-
Requests relating to the exercise of rights described in this Privacy Policy or under applicable data protection laws may be submitted by contacting the Company through the communication details set out below.
-
Responsibility for handling data protection matters within the Company is assigned to a designated data protection contact. This role is responsible for coordinating responses to data subject requests, ensuring internal consistency in the handling of such matters, and serving as a point of contact with supervisory authorities where required under applicable law.
The Company has not appointed a Data Protection Officer within the meaning of Article 37 of Regulation (EU) 2016/679, as such appointment is not mandatory in light of the nature and scope of the Company’s data processing activities.
-
In order to protect Personal Data from unauthorized disclosure, the Company may ask for information necessary to confirm the identity of the person submitting a request. Any such verification is limited in scope and applied only to the extent required to ensure that information is disclosed to the appropriate individual.
-
Requests are assessed and addressed in accordance with statutory response periods. As a general rule, responses are provided within thirty (30) calendar days from receipt. Where a request involves multiple records or requires additional review, the response period may be extended in line with legal requirements, and the requester will be informed accordingly.
-
Questions, requests, or complaints concerning the processing of Personal Data may be directed to the Company’s data protection contact using the following details:
Data Protection Contact:
Email: contact@intsurfing.com
DATA SECURITY MEASURES
-
The Company applies technical and organizational measures intended to protect Personal Data from unauthorized access, loss, alteration, or disclosure. Information security is treated as part of the Company’s day-to-day operations and is shaped by the characteristics of the Website, Platform, and the limited categories of data processed through it.
-
Personal Data is handled within controlled technical environments where access is restricted based on functional necessity. Only personnel whose responsibilities require such access are permitted to handle Personal Data, and they remain bound by confidentiality and data protection obligations.
-
Information transmitted via the Website and Platform is protected through encryption methods aligned with commonly accepted security practices, including the use of Transport Layer Security (TLS). In addition, the Company relies on a combination of operational safeguards such as access logging, network supervision, firewall controls, and vulnerability management to reduce exposure to unauthorized activity or technical disruption.
-
Security practices and internal procedures are revisited as part of the Company’s ongoing operational oversight. Adjustments may be introduced to reflect changes in technical infrastructure, regulatory expectations, or identified risk factors, with attention given to the nature of the information involved and the potential consequences of a security incident.
-
Where an incident involving Personal Data occurs and presents a material risk to individuals, the Company undertakes an assessment and responds with appropriate remedial measures. Notifications to affected individuals or supervisory authorities are made where required under applicable data protection laws and in line with statutory obligations.
AUTOMATED DECISION-MAKING AND PROFILING
-
The Company’s use of Personal Data does not involve automated decision-making processes that determine outcomes producing legal or comparable effects for Users. Information handled through the Website and related technical interfaces is not applied to automated scoring, predictive analysis, behavioral classification, or similar evaluative models.
-
Communications submitted through the Website and requests received via its contact channels are reviewed and addressed by Company personnel. While automated tools may be used to support technical operations, administrative workflows, or security monitoring, they do not determine responses or outcomes that affect Users without human involvement.
-
The Company does not rely on algorithmic systems to assess individuals, draw conclusions about their behavior, or generate decisions that would materially impact their rights or interests. Automated functionality, where present, serves an auxiliary role and does not substitute human judgment in interactions with Users.
-
Should the Company at any point introduce processing activities that involve automated decision-making or profiling, such activities would be implemented in line with applicable data protection requirements. This would include providing clear notice, maintaining transparency around the processing logic, applying appropriate safeguards, and ensuring human oversight where required by law.
CHILDREN’S DATA POLICY
-
The Company takes into account the enhanced legal protections applicable to Personal Data relating to children and structures its data handling practices accordingly. Relevant requirements include, where applicable, the Children’s Online Privacy Protection Act (COPPA) in the United States, Article 8 of Regulation (EU) 2016/679 (GDPR), and the Law of Ukraine “On Personal Data Protection”.
-
The Website and Platform are intended for general informational and technical use. They are not structured or presented as services aimed at children and are not intended to attract or engage individuals below the minimum age established by applicable law. The Company’s services are designed for use by adults and professional users.
-
The Company does not intentionally seek to collect or process Personal Data relating to children. Its technical architecture is not designed to solicit, encourage, or facilitate the submission of information relating to minors, nor to identify, monitor, or profile individuals below the applicable age threshold.
-
Where the Company becomes aware that Personal Data relating to a child has been provided without appropriate and verifiable consent from a parent or legal guardian, such information is addressed in accordance with internal data handling procedures. This may include deletion or anonymization, taking into account the nature of the data and applicable legal requirements.
-
Users are expected to refrain from submitting Personal Data relating to third parties, including minors, through the Website, API, or related communication channels. Where such information is provided, responsibility for ensuring the existence of all required legal grounds and consents rests with the individual submitting the data.
GOVERNING LAW, JURISDICTION, AND DISPUTE RESOLUTION
-
NANNOS sp. z o.o. is established in Poland and its Processing of Personal Data is subject to the data-protection laws applicable to its activities, including the GDPR and applicable Polish data-protection legislation where relevant.
-
Certain technical or operational Processing may also be subject to the laws applicable to authorized service providers involved in operating the Services.
-
Nothing in this Privacy Policy limits mandatory privacy rights or protections available to a Data Subject under Applicable Data Protection Laws.
-
Where the GDPR applies, Data Subjects have the right to lodge a complaint with a competent data protection supervisory authority, including the competent authority in the Member State of their habitual residence, place of work, or the place of an alleged infringement, as provided by Applicable Law.
-
Questions or concerns should first be directed to the Data Protection Contact where practical, but contacting us does not limit a Data Subject’s right to contact a competent authority or pursue another remedy available under Applicable Law.
FORCE MAJEURE
-
Circumstances may arise that disrupt the Company’s ability to carry out certain operational or procedural aspects of this Privacy Policy. Such situations can result from events outside the Company’s control, including armed conflict, natural disasters, widespread disruptions of telecommunications or internet infrastructure, significant cybersecurity incidents, governmental actions, or other extraordinary conditions affecting the operation of the Website or related technical systems.
-
Where such events occur, the handling of affected processes may be delayed or adjusted for the period during which normal operations are materially impacted. This section does not affect obligations that continue to apply under mandatory data protection laws, nor does it limit the rights of individuals where such rights remain enforceable under applicable legislation.
AMENDMENTS TO THIS PRIVACY POLICY
-
The Company may revise this Privacy Policy to reflect developments in applicable law, regulatory practice, technical arrangements, or internal processes relevant to the handling of Personal Data. An updated version of the Policy will be made available on the Website together with the date from which the revised text applies.
-
The version of the Privacy Policy published on the Website and Platform represents the current description of how Personal Data is handled in connection with the Company’s services. Users may review this information at any time to remain informed about applicable practices.
-
Where changes introduce a material impact on the rights of Users or significantly alter the way Personal Data is processed, the Company will provide additional notice appropriate to the nature of the update. Such notice may take the form of a clearly visible announcement on the Website and Platform or other communication measures intended to ensure transparency, where required under applicable law.
LEGAL DISCLAIMERS
-
This Privacy Policy is provided to explain how the Company approaches the handling of Personal Data in connection with the operation of the Website and related technical services. Its purpose is informational and transparency-oriented. Obligations arising under applicable data protection laws remain unaffected, while this Policy does not establish contractual, fiduciary, advisory, or professional duties between the Company and Users beyond those mandated by law.
-
In operating its services, the Company functions as a technical intermediary facilitating access to information that has been lawfully made available through public or authoritative sources. The Company does not create such information and does not assume responsibility for its accuracy, completeness, or ongoing relevance.
-
Information accessed through the Website or Platform is provided without evaluation of its legal significance or suitability for any particular use. The Company does not offer legal, financial, compliance, investigative, or similar professional services, and does not provide guidance or recommendations based on the information made available through its technical infrastructure.
-
Decisions regarding how information is interpreted or used, including any subsequent processing that may affect third parties, are made independently by Users. Responsibility for ensuring that such use complies with applicable laws, including data protection, privacy, employment, consumer protection, and anti-discrimination requirements, rests with the User.
-
Where the Website or Platform references or integrates third-party platforms, services, or data sources, such references are provided for technical or informational purposes. The Company does not direct or oversee the practices of those third parties and is not responsible for their content, availability, security measures, or data handling practices, except where responsibility arises under mandatory law or is expressly assumed through a binding agreement.
-
Nothing in this Privacy Policy is intended to limit rights that Users may hold under mandatory data protection or privacy legislation. If any provision of this Policy is found to be invalid or unenforceable by a competent authority, the remaining provisions continue to apply to the fullest extent permitted by law.
SCOPE AND APPLICABILITY OF THIS PRIVACY POLICY
-
This Privacy Policy applies to the processing of Personal Data in connection with the operation of the Website, related communication channels, and interactions initiated by Users through the Company’s services. It covers Personal Data provided directly by Users, collected through technical means associated with the functioning of the Website and Platform, or otherwise submitted in the course of communications initiated via the Website or its associated contact mechanisms.
-
This Privacy Policy does not apply to websites, platforms, or services operated by third parties that may be referenced or linked through the Website or Platform. The handling of Personal Data by such third parties is governed by their respective privacy policies and practices.
CONTACT INFORMATION
Users may contact the Company with questions, requests, or concerns relating to this Privacy Policy, the handling of Personal Data, or the exercise of data protection rights using the following details:
Controller
NANNOS sp. z o.o.
Ostrobramska 101A/301
04-041 Warszawa
Poland
KRS: 0001246729
NIP: 1133204311
REGON: 544967531
Company website: https://www.nannostech.com/
Product / Platform: https://platform.api.intsurfing.com/
Product website: https://www.api.intsurfing.com/
Privacy contact: contact@intsurfing.com
Certain technical, Platform, Website, and support functions are provided on behalf of NANNOS sp. z o.o. by LLC “INTSURFING”.