Data protection by architecture, not by disclaimer

Nodra is engineered around GDPR principles: collect the minimum, pseudonymize early, aggregate always, delete on schedule. And we are honest about what remains your responsibility.

What Nodra does by design

  • Data minimization. The agent strips content, names and identifiers on the device. Email text, documents, passwords, keystrokes and screenshots are excluded in every configuration.
  • Purpose limitation. Data serves process analysis, not individual evaluation. Reports are aggregated at process and team level.
  • Pseudonymization. Users and devices become opaque codes before transmission. Any mapping, where needed, is stored separately, encrypted and access-restricted.
  • Storage limitation. Each audit has a retention lifecycle: after the verification window, raw data is deleted and only aggregated insights remain.
  • Security of processing. Encryption in transit and at rest, per-tenant keys, tenant isolation, least-privilege access, audit logs. GDPR Article 32 names pseudonymization and encryption among appropriate measures, and both are core to the design.
  • Accountability support. Architecture, data-flow and retention documentation exists so your records of processing and DPIA work start from facts, not from a sales deck.

What remains a shared responsibility

Infrastructure alone never makes a deployment lawful. The legal basis for the project, employee transparency, works-council or union processes where applicable, and the roles of controller and processor are defined with your legal and privacy advisors. Nodra gives them accurate technical inputs and a design that makes the right answer achievable.

AI processing, treated as its own question

Building an Italian backend and then sending raw logs to an uncontrolled AI provider would be theater. Nodra keeps raw data inside its own infrastructure: identifiers are removed and data is aggregated before any AI-assisted analysis, providers are bound by data processing agreements, and Enterprise customers can set custom AI policies including EU-region inference.

For the security controls behind these principles, see the security overview.

Your DPO will have questions. Good.

Bring them to the call, or send the questionnaire first. We answer in writing.

Frequently asked questions

Is Nodra GDPR compliant out of the box?

No tool makes an organization compliant by itself, and claims like that should worry you. Nodra is designed to support compliant deployments: minimization, pseudonymization, encryption, configurable retention and documentation. Compliance itself depends on purpose, legal basis, transparency and your configuration, assessed with your advisors.

Is pseudonymized data still personal data?

Often yes. Pseudonymized data can remain personal data under GDPR when it can be linked back to a person. Nodra treats it accordingly: encrypted storage, restricted mapping access, and deletion per retention policy. We never market pseudonymization as anonymization.

Does Nodra support a DPIA?

Yes. The Nodra Privacy and Security Pack provides architecture, data flow, data categories, retention, security measures, subprocessor list and deletion procedures, which is the technical input a DPIA needs. Your DPO or legal advisor leads the assessment.

What about employee workplace regulations?

Workflow analysis touches labor law in several jurisdictions, including Italy. Nodra projects are configured with the customer to respect applicable requirements, and we recommend involving a labor and data protection specialist before deployment. We say this openly because it is true.

Where is data processed?

The Nodra backend runs on cloud infrastructure in EU data centers. Any AI-assisted analysis runs on sanitized, aggregated datasets under a defined policy, with EU-region processing options on Enterprise.