Legal

Privacy Policy

Last updated: 13 September 2026

This policy explains in plain language what personal data Netluno uses, why it is used and the choices available to you. It covers the public website, accounts, completed-job imports, billing and the optional newsletter.

Who is responsible for the data

Michael Agnona, at Not configured before launch, operates Netluno. It is the controller for account administration, billing, service security, support and its optional newsletter.

For a privacy request, contact support@netluno.com.

When a customer uploads personal data about its clients, technicians, staff or contractors so Netluno can provide job analysis on its instructions, that customer is normally the controller and Netluno acts as its processor. Those responsibilities must also be covered by an Article 28 data-processing agreement before customer personal data is accepted.

Information we process

  • Account identity and contact information received through Clerk, including name, email address, authentication identifiers and session information.
  • Business name, selected target margin, account settings and subscription status.
  • Completed-job data supplied by the customer: customer and technician names, job dates, revenue, planned and actual labour, hourly direct labour cost, planned and actual material costs, optional notes, import history and calculated profitability indicators. Includes expected and actual revenue, direct labour totals, other direct costs and job currency.
  • Stripe customer, checkout, subscription, invoice and tax references needed to administer billing. Stripe processes payment-card and billing details on its hosted pages.
  • Limited request-quota, security, error and operational records needed to protect and operate the service. Quota identifiers are hashed.
  • Email address, consent version, request and confirmation timestamps, and temporary confirmation evidence for the optional newsletter.

Netluno does not receive or store full payment-card details. Job CSV files do not require card, health, government-identifier or other special-category data.

Purposes and legal bases

PurposeGDPR legal basis
Create accounts and provide job-profit analysis, imports, exports and supportPerformance of the customer contract
Authenticate users, prevent abuse, investigate errors and protect tenantsLegitimate interests in operating a secure service
Create and administer trials, subscriptions, taxes and invoicesPerformance of the contract and compliance with accounting or tax obligations
Send essential account, service and support messagesPerformance of the contract or legitimate interests, depending on the message
Send requested profitability tips, product news and promotional offersConsent, which may be withdrawn at any time
Keep evidence and respond to legal claims or authoritiesLegal obligation or legitimate interests in establishing, exercising or defending legal claims

Account and job fields required by the service are necessary to perform the contract; without them, Netluno cannot create the account or calculate the requested job analysis. Newsletter consent is optional and does not affect access to assessment results or the service.

Providers and international transfers

Access is limited to providers needed for the purposes above. The active architecture currently includes:

ProviderPurpose
VercelWebsite and application hosting and delivery
Neon / configured PostgreSQL providerApplication database and backups, according to the production contract and region
ClerkAuthentication, user identity and sessions
StripeHosted checkout, subscription billing, tax collection configuration and billing portal
ResendTransactional account email
BrevoNewsletter confirmation email, consented mailing list and unsubscribe handling

PostHog analytics and Sentry monitoring are disabled in the current launch configuration. They must not be enabled until their data, retention and consent requirements have been reviewed. New CSV imports are processed directly and are not uploaded to UploadThing.

Some providers or their support teams may process data outside the European Economic Area. The exact contracting entities, locations, subprocessors, data-processing agreements and transfer mechanisms still require provider-level verification before live customer data is accepted.

Optional newsletter

The newsletter is separate from account creation. The form uses an unchecked consent box. Brevo sends a confirmation email, and the address is added to the list only after the link is confirmed. Every marketing email must provide an unsubscribe link, and a prior unsubscribe or blocklist choice is not overwritten on retry.

The service keeps the consent version and confirmation timestamps as evidence. Assessment answers are not sent to Brevo with the subscription request.

Cookies and local browser storage

No optional audience-measurement tool is enabled in the current launch configuration, so Netluno does not currently display a non-essential-cookie consent banner. The following storage supports requested or necessary functions:

  • Clerk authentication cookies maintain login and protect account access.
  • The NEXT_LOCALE cookie remembers the language selected by the visitor.
  • A local browser flag remembers that the welcome/newsletter popup has been shown; clearing browser storage can cause it to appear again.

Stripe- or Clerk-hosted pages may use their own cookies for payment or authentication. If PostHog, Sentry or another non-essential tracker is enabled later, Netluno must update this policy and implement any consent mechanism required before that activation.

How long information is kept

Netluno aims to keep data only for as long as necessary for the stated purpose. Current implemented and unresolved periods are:

Account and completed-job data
Kept while the account is active. A closure request immediately restricts local access and starts a seven-day operator review; it does not itself complete erasure.
Billing and tax evidence
Kept for the period required by applicable accounting, tax, dispute and Stripe rules; the exact operational schedule is not yet approved.
Unconfirmed newsletter requests
Confirmation links expire after 24 hours and unconfirmed records are scheduled for cleanup after two days.
Confirmed newsletter consent
Kept while the subscription is active and afterward only as needed to prove consent or preserve an unsubscribe; the exact evidence period is not yet approved.
Security and operational records
Kept for a proportionate period that is still awaiting formal approval.
Backups
Expire under a production backup-retention schedule that has not yet been approved or restore-tested.

Because the deletion workflow, provider cleanup and final retention schedule are not fully implemented and approved, Netluno must not promise immediate or fully automated deletion. This is a live-mode blocker.

Your data-protection rights

Depending on the processing and applicable law, you may request access, correction, erasure, restriction, objection and portability. You may withdraw newsletter consent at any time without affecting processing that occurred before withdrawal.

A request may be sent to the privacy contact above. Netluno may ask for proportionate information to verify identity and will coordinate with a customer controller where the request concerns data uploaded by that customer.

You may also lodge a complaint with the French data-protection authority, the CNIL, at cnil.fr.

Export and account closure

Authenticated owners can download a JSON export from the Account page. A closure request restricts access, but support must still coordinate subscription handling, provider deletion, legal holds and backup expiry. The request screen is not confirmation that all copies have been erased.

Open account data and privacy controls

Security

Netluno uses tenant-scoped access controls, authenticated server operations, transport encryption, bounded uploads and rate controls designed to reduce risk. No internet service can guarantee absolute security. Suspected incidents should be reported to the privacy contact without including customer records in the initial message.

Customer responsibility for uploaded data

Customers must have a lawful basis and provide appropriate notices for personal data they upload. They should minimise names and notes, avoid sensitive data that Netluno does not require, control who can access the account and respond to data-subject requests for their own records.