1. Controller and contact
Controller: Usługi Informatyczne „nex-IT” Jakub Potoczny, NIP 5040061950, REGON 382557666, Przemysłowa 7A/22, 89-400 Sępólno Krajeńskie, Polska.
For privacy matters and rights requests: studio@n3x.pl, telephone +48 531 425 277.
No data protection officer has been appointed because the current processing scope has not been assessed as creating a statutory appointment requirement. The Controller handles privacy contact directly.
2. Scope and self-hosted products
This Policy covers n3x.pl, its public APIs, the N3X Studio form, shared quotes, the administration panel, statistics and communications with N3X.
N3XRemote Server and N3XMarket are self-hosted products. N3X normally does not receive device, operator, session, portfolio, provider-key or analysis data stored in a private instance. The person or organisation operating that instance is the controller and is responsible for its own privacy notice, access controls, retention, backups and security.
N3X desktop applications do not send usage telemetry to N3X. Downloads and update checks connect to GitHub, which receives ordinary connection metadata under its own policy.
3. Purposes, data and legal bases
- Providing a requested tool or function: entered domains, IP addresses, URLs, headers or other technical parameters; Article 6(1)(b) GDPR, or Article 6(1)(f) where the user is not a contracting party (providing the requested service).
- Contact and preparing an offer: name, email, optional company and telephone, budget and enquiry content; Article 6(1)(b) GDPR (steps requested before a contract) and Article 6(1)(f) (correspondence and legal claims).
- Shared quotes: recipient name supplied by the creator, items, prices, notes, terms, identifier and expiry; Article 6(1)(b) or (f) GDPR — providing the requested function and handling a quote.
- Security and abuse prevention: IP address processed briefly in rate-limiter memory, error logs and incident information; Article 6(1)(f) GDPR — protecting the site, users and infrastructure.
- Administrator authentication: email address, account and session identifiers and technical cookies; Article 6(1)(f) GDPR — access control.
- Aggregate statistics: tool-run, download-click and install-action counters, their daily country-code summaries and anonymous Vercel statistics; Article 6(1)(f) GDPR — product improvement, usefulness measurement and assessment of market interest. N3X does not build user profiles.
- Legal obligations: data needed for accounting, authority requests or data-subject rights; Article 6(1)(c) GDPR.
4. Web tools and external sources
Purely local tools, including browser generators, encoding tools, calculators and converters, process content on the device and do not send it to the server unless the interface clearly identifies a server-side or sharing function.
Network tools must perform an external request. Depending on the function, a technical parameter may be sent to RDAP/WHOIS registries and whoisjson.com, Google Public DNS, ip-api.com, ipapi.co, the Polish Ministry of Finance, European Commission VIES, KRS, CEIDG, crt.sh, HackerTarget, macvendors.com, Have I Been Pwned, OpenStreetMap or Cloudflare. When the N3X server makes the request, the provider receives the parameter and N3X server connection metadata. Do not enter confidential or third-party data without a lawful basis.
The speed test makes some connections directly from the device: when the page opens, ipapi.co receives the public IP address and returns approximate location/ISP data; after the test starts, Cloudflare receives measurement traffic and the public IP. Coverage-map tiles are loaded directly from OpenStreetMap, which also sees connection metadata. N3X does not store this data in its database; the test result remains in browser state unless the user copies, downloads or places it in a sharing URL.
The HIBP password check uses k-anonymity: only the initial portion of a SHA-1 hash is sent, never the password or full hash. Email checking opens the HIBP website and then takes place directly between the user and HIBP.
5. AI functions
The N3X Assistant and YAML generator send the message, required conversation context or YAML fragment to GroqCloud (Groq LLC, United States) to generate a response. The interface identifies that the user is interacting with AI. N3X does not store conversation history in its database.
Groq states that ordinary inference data is not retained by default, except temporary logs required for reliability or abuse investigations, retained for up to 30 days; customers can enable Zero Data Retention. Data retained by Groq is located in the United States and transfers may rely on Standard Contractual Clauses. Do not enter personal data, secrets, passwords, keys or special-category data.
AI responses may be incomplete or wrong. They are not automated decisions producing legal effects or legal, medical or investment advice.
6. Analytics and quote statistics
Vercel Web Analytics operates without third-party cookies and provides N3X with aggregate data. N3X removes URL query strings, fragments and quote or short-link identifiers before an event is sent.
When a shared quote is opened, we record the date, general device type, browser, operating system, hosting-provided country code and referrer origin only. We do not store raw IP addresses, full user agents, cities or internet providers and do not send an IP address to a geolocation service.
When a tool is actually run, an application download is clicked or an installation action is selected, the server reads only the two-letter country code derived by Vercel infrastructure and immediately increments a daily aggregate counter. N3X stores no raw or hashed IP address, session identifier, city, precise location, full user agent or individual event for this purpose. The counters are not used to follow one person across tools.
Download-click statistics measure interest on n3x.pl. They do not reveal the country of direct GitHub downloads or the operation, updating or use of a desktop application. They also exclude sessions, devices and agents in private N3XRemote instances and data held by N3XMarket instances.
7. Recipients and transfers outside the EEA
To the extent required to provide the service, data may be processed by:
- Vercel Inc. — hosting, content delivery, protection and analytics;
- Supabase Inc. — database, authentication and site backend;
- Groq LLC — AI response generation;
- Resend Inc. or the configured SMTP operator — delivery of form email;
- GitHub, Inc. — releases, downloads, updates and GHCR images;
- registry and API providers identified for the tools — performing the requested check;
- professional advisers, accounting providers or public authorities — only where there is a lawful need.
Some providers operate in the United States. Transfers rely on an appropriate GDPR Chapter V mechanism, particularly an adequacy decision or Standard Contractual Clauses with supplementary measures, depending on the provider and agreement. Information about safeguards may be requested from the Controller; confidential elements may be redacted.
8. Retention periods
- tool queries: normally only for processing and technical caching; no person-linked search history is created;
- in-memory IP rate limiter: approximately 10 minutes or until the server instance ends;
- global aggregate counters without geographic breakdown: indefinitely because they contain no person identifier; daily country counters: up to 24 months;
- quote-view details: up to 90 days;
- quote content: the period stated in the link followed by an administrative buffer of up to 30 days;
- form correspondence: until the matter is closed and up to 3 years after the last contact, unless a contract, legal obligation or claim requires longer;
- administrator account and sessions: until account removal or session expiry/revocation, subject to security logs;
- hosting and security logs: for the provider's standard technical period and no longer than required for security, diagnostics or a legal obligation.
9. Cookies and device storage
The site uses no advertising cookies or profiling. Supabase cookies are required only for administrator sign-in, while tool settings stored in localStorage remain on the device. The complete inventory, purposes and deletion instructions are in the Cookies and Browser Storage Policy.
10. User rights
Subject to the GDPR, users have rights of access, rectification, erasure, restriction, portability, objection to legitimate-interest processing and withdrawal where a particular operation relies on consent. Withdrawal does not affect prior lawfulness.
Requests may be sent to studio@n3x.pl. The Controller may ask for information needed to verify identity. A response will normally be provided within one month, subject to the statutory extension for complex requests.
A complaint may be lodged with the President of the Personal Data Protection Office, ul. Stawki 2, 00-193 Warsaw, uodo.gov.pl.
11. Voluntary provision, sources and automated decisions
Providing data is voluntary, but omitting a tool parameter, return address in a form or session cookie during sign-in prevents the relevant function. Data comes from the user, their device, public registries/APIs or technical connection headers.
N3X does not make solely automated decisions about users that produce legal or similarly significant effects. Tool popularity sorting uses global counters only.
12. Security, minors and changes
We use proportionate measures including TLS, access control, data minimisation, abuse limits, secret separation and updates. No system guarantees absolute security; incidents are handled according to risk and legal duties.
The services are not directed at children. A minor should not submit contact details, AI content or public quotes without a parent or guardian.
A material policy change will be published with a new date; where it changes the purpose or basis of existing processing, users will be informed as required by law.
