Nomis (“Nomis”, the “Service”) is an AI-assisted legal research platform operated by BYGEN AI Kft., with its registered seat at 5600 Békéscsaba, Lázár utca 3. 1/8., Hungary (“we”, “us”, “our”). This Privacy Policy describes how we collect, use, and share personal data, and explains the rights available to you under the GDPR.
Section 01
Applicability of this policy — controller and processor roles
BYGEN AI Kft. acts as controller of personal data — that is, we determine the purpose and means of processing — for:
- individuals who register for and use Nomis directly, on our Starter, Growth, or Scale plans;
- visitors to our website; and
- our own contract administration, invoicing, and statutory record-keeping.
Where an organization has entered into a separate agreement with us — including our standard Data Processing Addendum — to use Nomis with its own personnel or clients, that organization is the controller of the personal data its users submit through the Service, and we act as its processor, on its instructions. In that case, the organization's own privacy notice and its agreement with us — not this policy — governs how that data is used, and requests concerning that data should be directed to the organization. This policy does not limit or override the terms of any such agreement. If you are using Nomis as an employee or representative of an organization with such an agreement in place, please consult your organization for details of how your data is handled.
Where the distinction is not clear-cut, we describe throughout this policy which capacity we are acting in.
Section 02
Personal data we collect
| Category | Description |
|---|---|
| Account information | Email address, name, display name, avatar |
| Billing information | Processed through Stripe; we retain your Stripe customer and subscription identifiers and plan details, not your payment card number |
| Onboarding information | Business type, industry, company size, VAT status, and stated answer preferences |
| Inferred user context | See Section 2.1 below |
| Uploaded files | The uploaded file, extracted text, and, for images, the image content |
| Project content | Documents, instructions, and settings you add to a Project workspace |
| Conversation content | The questions you submit and the answers we generate, including any memoranda or presentations produced from a conversation |
| Internal quality review records | Where an answer is reviewed internally, we retain a copy of the query, the answer, and reviewer notes; these records are retained independently of the source conversation |
| Support and issue reports | The content of reports and requests you submit, and any attachments |
| Saved references | URLs and notes you bookmark |
| Communications | If you contact us directly (support, sales, or otherwise), the content of that communication and your contact details |
2.1 Inferred user context
Nomis retains contextual information about you across conversations — such as your business type, tax status, industry, and jurisdiction — so that this context does not need to be restated in each new conversation. This information is generated by the system's language model based on prior conversations; it is not information you have entered directly, and its accuracy is not guaranteed. You may view and delete individual entries at any time in your account settings.
Section 03
How we use personal data
The majority of our processing is necessary to provide the Service you have contracted for (GDPR Article 6(1)(b)). Certain activities — including the use of inferred user context and internal quality review — are based on our legitimate interest in operating a reliable service (Article 6(1)(f)). Billing records are additionally retained to meet statutory accounting obligations (Article 6(1)(c)).
| Purpose | Data involved | Legal basis |
|---|---|---|
| Account administration | Account and authentication data | Contract |
| Onboarding and answer personalization | Onboarding information | Contract |
| Answering user questions | Query text, retrieved legal sources, generated answer | Contract |
| Processing uploaded files and images | File content and extracted text | Contract |
| Semantic search | Query text, converted to a vector representation | Contract |
| Maintaining context across conversations | Inferred user context | Legitimate interest |
| Web search (when enabled by the user) | Search query, transmitted to our search provider | Provision of a requested feature |
| Project and bookmark management | Project and bookmark content | Contract |
| Billing and invoicing | Email address and payment events, processed via Stripe | Contract; legal obligation (accounting) |
| Transactional email | Recipient address and message content | Contract |
| Support handling | Report content and attachments | Contract; legitimate interest |
| Internal quality review | Query, answer, and source data | Legitimate interest |
| Service improvement | De-identified query text | Legitimate interest |
| Debugging and system monitoring | Prompts and completions logged in our internal tracing system | Legitimate interest |
| Preventing misuse and protecting the Service | Account and usage data | Legitimate interest |
| Complying with legal obligations | Data relevant to the specific request | Legal obligation |
Section 05
Use of artificial intelligence
As this is core to how the Service works, we describe it here in addition to Section 3 above:
- Your query, the retrieved legal sources, and the generated answer are transmitted to our AI inference provider to produce a response.
- Content requiring semantic search is transmitted to a separate embedding provider.
- The system infers and retains contextual information about you across conversations, as described in Section 2.1; this information may be viewed and deleted by the user.
- No automated content-filtering or guardrail layer is currently applied to AI-generated output.
- We do not make legal or other significant decisions concerning users solely through automated processing; matters escalated for expert review are reviewed by a qualified professional.
- Whether content transmitted to our providers is used for model training purposes is governed by our contractual terms with each provider; confirmation of these terms is pending for certain providers.
Zero data retention by our model provider, by default
Our AI inference provider (AWS Bedrock) does not, by default, retain your prompts or the generated output on its own systems after the response is returned, and does not use that content to train its models. In practice, this means the model provider itself does not keep a copy of your query or the answer once it has been generated and sent back to Nomis. This is separate from, and does not affect, Nomis's own operational logging described elsewhere in this policy — including AI-invocation logs we retain for 365 days and debugging traces in our internal tracing system — which we generate and retain under our own configuration, independent of the model provider's retention practice.
Section 06
International data transfers
Nomis is built EU-first. The large majority of processing — including AI answer generation and all core infrastructure (database, file storage, hosting) — takes place within the EU, and we do not route this processing through providers outside the European Economic Area (“EEA”) by default.
A small number of ancillary services rely on providers that operate global infrastructure — this currently includes our embedding provider and our web search provider, and, further down the chain, sub-processors that some of our providers rely on for their own infrastructure or support functions. In every case, we require our providers to have a data processing agreement in place that includes an appropriate safeguard for any transfer outside the EEA — either an adequacy decision by the European Commission, or standard contractual clauses where no adequacy decision applies, consistent with Chapter V GDPR.
The specific safeguard confirmed for each recipient is listed in the Sub-processors document.
Section 07
Data retention and account deletion
We retain personal data for as long as necessary for the purposes described in this policy, including to meet legal, accounting, and dispute-resolution obligations. Defined retention periods do apply to certain technical logs: application logs are retained for 30 days, AI model-invocation logs (which may include prompt and embedding text) for 365 days, and infrastructure audit logs for 365–400 days.
Account deletion
When you close your account, we delete or anonymize the personal data associated with it, except where we are required or permitted to retain certain data — for example, for legal, accounting, security, or dispute-resolution purposes, or where data has already been aggregated or de-identified. Some data may take a limited period to be fully removed from backups, logs, and archives. You can delete certain content yourself at any time, without closing your account, from your account settings.
Section 08
Security
Detailed technical information is published in our Security and Trust Center documentation, which we recommend to any organization with specific security or compliance requirements. In summary:
- Data in transit between your browser and our servers is encrypted using TLS.
- Our database and file storage are encrypted at rest.
- Access requires an authenticated session; there is no public access to application data.
Not currently in place
Third-party security certification, a completed independent penetration test, multi-factor authentication for end users, and field-level encryption of conversation content (conversation text is stored in a standard database column, protected by infrastructure-level controls rather than per-field encryption). Organizations with specific compliance or regulatory requirements should review the Security and Trust Center documentation in full before relying on the Service for regulated use cases.
Section 09
Minors
The Service is not directed to, and is not intended for use by, anyone under the age of 18. We do not knowingly collect personal data from minors. If you believe a minor has provided personal data to us, please contact us at privacy@asknomis.com and we will take steps to delete that information.
Section 10
Your data protection rights
Under the GDPR, you have the right to:
| Right | Description |
|---|---|
| Access | Obtain a copy of the data we hold about you |
| Rectification | Correct inaccurate data |
| Erasure | Request deletion of your data |
| Restriction | Request that processing be limited |
| Portability | Receive your data in a structured, portable format |
| Objection | Object to processing based on legitimate interest |
| Automated decision-making | Rights concerning decisions made solely by automated means; we do not currently make decisions about users solely through automated processing without human review |
To exercise any of these rights, contact us at privacy@asknomis.com. We will respond within one month of receipt; this period may be extended by up to two further months where necessary, taking into account the complexity or number of requests, in which case we will inform you of the extension within the initial one-month period. We may ask you to verify your identity before fulfilling a request. Requests are currently reviewed and fulfilled manually rather than through an automated self-service system.
If you are using the Service under an organization's agreement with us, as described in Section 1, please direct your request to that organization in the first instance.
Section 12
Updates to this policy
We may update this policy from time to time in response to changes in our practices, or for legal or regulatory reasons. We will notify registered users by email at least 15 days before any material change takes effect. Non-material changes, such as corrections and clarifications, take effect upon publication. The “Last updated” date at the top of this policy reflects the most recent revision.
Section 13
How to contact us
If you have questions or concerns about this policy or our handling of your personal data, email us at privacy@asknomis.com. Our full identity and registration details are set out at the top of this policy; Section 1 explains when we act as controller versus processor.
| Effective from | 1 August 2026 |
| Last updated | 1 August 2026 |
| Related documents | Sub-processors · Security · Trust Center · Data Processing Addendum · Terms of Service |