Last updated: 26.03.2026. This Privacy Policy explains how Nevascholar.com collects, uses, discloses, stores, and protects personal data when you access our websites, applications, and related services. We comply with the EU General Data Protection Regulation (GDPR).
Introduction
This Privacy Policy explains how Nevascholar.com ("Nevascholar", "we", "us") collects, uses, discloses, stores, and protects personal data when you access our websites, applications, and related services (the "Services").
We comply with the EU General Data Protection Regulation (GDPR). We practice privacy by design and by default throughout our product and engineering lifecycle and continually assess risk to maintain appropriate technical and organizational measures.
Controller and Contact
For the purposes of GDPR, Nevascholar.com is the Controller of personal data processed through the Services.
Primary contact for privacy questions and rights requests: info@nevascholar.com. If required under Article 27 GDPR, Nevascholar will appoint an EU/UK representative and publish their contact details in this Policy.
Scope and Relationship to Other Agreements
This Policy applies to personal data about website visitors, registered users, trial users, business contacts, and prospective customers processed in connection with the Services.
For enterprise customers, where Nevascholar processes personal data strictly on their instructions, the parties' Data Processing Agreement (DPA) governs; in such cases Nevascholar acts as a Processor and the enterprise customer remains the Controller.
Definitions
Categories of Personal Data We Collect
- Account Data:Name, email address, authentication credentials, profile settings, language and time-zone preferences.
- User Content:Prompts, uploaded files, drafts, feedback and other content you submit to the Services in the course of academic writing assistance.
- Usage and Log Data:Feature usage, clickstream, timestamps, diagnostic and performance logs, error and crash reports, and telemetry related to quality and reliability.
- Device and Technical Data:IP address, device identifiers, operating system, browser type and version, locale, referrer, and approximate location inferred from IP.
- Communications:Support requests, survey responses, email preferences and marketing subscriptions.
- Billing Data:Payment tokens and limited billing details handled by our PCI-compliant payment processor; Nevascholar does not store full card PANs on its systems.
- Special Categories:Nevascholar does not intend to collect special category data. If you include such data in your User Content, we will process it only where a lawful basis under GDPR applies.
Sources of Personal Data
- Directly from you when you create an account, submit content, communicate with us, or configure settings.
- Automatically from your use of the Services through cookies, pixels, SDKs, logs and similar technologies.
- From limited third parties such as payment processors or optional social login providers, subject to their own privacy disclosures.
Purposes of Processing and Lawful Bases
Service Operation
Provide and operate the Services; authenticate users; personalize features; maintain and improve core functionality. Legal basis: Contract (Art. 6(1)(b)).
Customer Support
Communications about service changes, security alerts, and transactional messages. Legal basis: Contract (Art. 6(1)(b)) and Legitimate Interests (Art. 6(1)(f)).
Security & Abuse Prevention
Threat detection, fraud monitoring, and incident response. Legal basis: Legitimate Interests (Art. 6(1)(f)) and Legal Obligation (Art. 6(1)(c)).
Analytics & R&D
Product improvement, research and development, quality assurance. Legal basis: Legitimate Interests (Art. 6(1)(f)); Consent (Art. 6(1)(a)) where required.
AI Training
Machine learning model improvement. You may opt out via Service settings. Legal basis: Legitimate Interests (Art. 6(1)(f)).
Marketing
Subject to your preferences. Legal basis: Consent (Art. 6(1)(a)); you may withdraw at any time.
Payments & Invoicing
Legal basis: Contract (Art. 6(1)(b)) and Legal Obligation (Art. 6(1)(c)).
Legal Compliance
Requests from competent authorities, exercise/defense of legal claims. Legal basis: Legal Obligation (Art. 6(1)(c)) and Legitimate Interests (Art. 6(1)(f)).
Model Training and Evaluation: By default, we do not use customer content to train our models. If you opt in through settings or a separate agreement, we process such content for model training/evaluation under Consent (Art. 6(1)(a)); you may withdraw at any time.
Bot and Abuse Protection (reCAPTCHA)
On selected pages (such as contact and newsletter forms), we use Google reCAPTCHA v3 to estimate whether activity is likely to come from a human user and to protect the Services from spam, automated abuse, credential stuffing, and similar threats.
reCAPTCHA analyzes browser and device signals and related technical data and transmits them to Google for this security and fraud-prevention purpose. Google provides reCAPTCHA to us as a processor for those limited purposes; we remain the controller for explaining this processing to you in this Policy. The lawful basis aligns with the "Security & Abuse Prevention" purpose described above (including legitimate interests and, where applicable, legal obligations).
reCAPTCHA may set a strictly necessary cookie (for example _GRECAPTCHA) so the check can run. See this section together with "Cookies and Similar Technologies" for context.
International Data Transfers
Where personal data is transferred outside the EEA/UK, we use appropriate safeguards such as the European Commission's Standard Contractual Clauses (SCCs) and, where applicable, the UK International Data Transfer Addendum (IDTA) and/or EU–US Data Privacy Framework. We also perform transfer impact assessments and apply supplementary measures where needed.
Data Retention
We retain personal data only as long as necessary for the purposes set out in this Policy and then delete or anonymize it according to our retention schedule. Typical periods include:
- Account data: account lifetime plus 24 months
- Usage logs: up to 12 months
- Backups: up to 35 days
- Billing records: as required by applicable law
- Support tickets: up to 24 months
See Annex A for the full retention schedule.
Security Measures
We implement technical and organizational measures appropriate to the risk, including:
- Encryption in transit and at rest
- Least-privilege access control and MFA
- Network segmentation and continuous monitoring
- Vulnerability management and regular testing
- Employee security training
- An incident response program with post-incident reviews
Automated Decision-Making
We do not make decisions producing legal or similarly significant effects solely by automated processing. If we introduce such processing in the future, we will implement safeguards and provide the right to obtain human review, express your point of view, and contest decisions.
Your Rights under GDPR
You have the following rights regarding your personal data:
- Access: request a copy of personal data we hold about you
- Rectification: request correction of inaccurate data
- Erasure: request deletion of your data ("right to be forgotten")
- Restriction: request that we limit how we use your data
- Data Portability: receive your data in a structured, machine-readable format
- Object: object to processing based on legitimate interests
- Withdraw Consent: where processing is based on consent, you may withdraw at any time
- Supervisory Authority: lodge a complaint with your local data protection authority
How to Exercise Your Rights
Submit your request to info@nevascholar.com. We will verify your identity and respond without undue delay, and in any event within one month, extendable as permitted by law.
Children's Privacy
Our Services are not directed to children under 16 and we do not knowingly collect personal data from them. If you believe a child has provided personal data, contact us so we can delete it.
Disclosures
We may disclose personal data:
- To service providers acting as Processors under written data protection terms
- To comply with laws or lawful requests from competent authorities
- To protect the rights, property, or safety of Nevascholar, users, or the public
- In connection with business transactions such as a merger, acquisition, financing, or sale of assets
Do-Not-Track and Preference Signals
There is currently no uniform industry standard for recognizing browser "Do-Not-Track" or similar preference signals. If standards are adopted that we must follow, we will update this Policy accordingly.
For Users From Turkey
If you are accessing Nevascholar from Türkiye, please refer to our privacy notice written within the scope of Turkish Personal Data Protection Code no. 6698 (Data Protection Law). That notice (Website Privacy Disclosure) provides additional information about how your data is processed in accordance with Turkish law.
Changes to This Policy
We may update this Policy from time to time to reflect changes in our practices, technologies, or legal requirements. We will post the updated version with a new effective date and, where material, provide additional notice.
Annex A: Retention Schedule
| Data Category | Retention Period | Notes |
|---|---|---|
| Account Profile | Account lifetime + 24 months | Deletion or anonymization after inactivity window |
| Authentication Logs | Up to 12 months | Security and abuse monitoring |
| Application Logs | Up to 12 months | Diagnostics and performance analysis |
| Backups | Up to 35 days (rolling) | Encrypted backups, disaster recovery only |
| Billing Records | As required by law | Financial and tax compliance |
| Support Tickets | Up to 24 months | Quality assurance and auditing |
| Marketing Preferences | Until opt-out or account deletion | Controlled by user settings |
Annex B: Categories of Processors
| Processor Category | Purpose |
|---|---|
| Cloud Hosting and Storage | Infrastructure, compute, and secure data storage (preferably EU/EEA regions) |
| Customer Support and Ticketing | Manage user requests, communications, and issue tracking |
| Email Delivery | Transactional and notification emails |
| Analytics and Telemetry | Usage metrics to improve reliability and performance (consent where required) |
| Payment Processing | Tokenized payments; no card or payment device stored on Nevascholar systems |
| Security and Anti-Abuse | Monitoring, threat detection, fraud and abuse prevention |
| Google (reCAPTCHA) | Bot and abuse risk analysis on selected website forms (processor) |
| AI and LLM Providers | To provide the service, to train AI models |