Privacy Policy

Last updated: July 9, 2026

This policy explains, in plain language, what data Haladir Inc. ("Haladir," "we") handles, where it lives, how long we keep it, and who else touches it. It covers visitors to haladir.com and the people who use the Nomos operator console we run for our customers.

1. Two situations, two roles

There are two ways you might interact with us, and our role is different in each.

You visit haladir.com or contact us. Here we decide what is collected and why. Under data protection law, including the GDPR, we act as the controller. Section 3 describes what this involves.

You use the Nomos console at work. The console is provided to your employer or the warehouse operator you work with (our customer). The customer owns that data and decides how it is used. We process it only on their instructions, as a processor. If you want data in the console corrected or deleted, the fastest route is through the customer; we will help them respond.

2. What the console handles

The Nomos operator console is a planning tool for warehouse work. The data in it is mostly about operations, not about people:

  • warehouse operational data: orders, waves, picks, dispatch and staffing schedules, cut-off times, and similar records from the customer’s warehouse systems;
  • operator accounts: name, work email address, and sign-in records for the people the customer invites;
  • an action log recording which operator took which action in the console, kept so that operational decisions can be traced;
  • assistant conversations: if an operator uses the built-in assistant, the messages and the operational context needed to answer them.

The personal information involved is limited to operator names, work email addresses, sign-in records, and the actions and messages tied to an operator account. The console does not handle consumer personal data beyond what appears in the customer’s order records.

3. Website visitors

On haladir.com we keep collection minimal. If you email us or book a call, we receive what you send: typically your name, email address, company, and message. We use it to reply and to follow up.

We measure site traffic with Vercel Analytics, which works without cookies and does not track you across other sites. We do not run advertising trackers and we do not sell personal information.

4. Subprocessors: who else touches the data

We use a small number of providers to run the service. For customer data in the console, they are:

  • Google Cloud (europe-west3 region, Frankfurt, Germany) hosts the console and all warehouse operational data.
  • WorkOS (United States) handles sign-in. It processes operator names, work email addresses, and sign-in events, and nothing else.
  • OpenRouter (United States) runs the AI models behind the console assistant. When an operator uses the assistant, the messages and the operational context needed to answer them are sent for inference. If the assistant is not used, nothing is sent.
  • Discord (United States) carries operational notifications and commands for customers who choose to turn on the optional Discord integration. Customers who do not enable it send nothing to Discord.

The website itself is hosted on Vercel, which does not receive any customer warehouse data. We will update this page before adding a subprocessor that handles customer data.

5. Where data lives

Warehouse operational data is hosted in the European Union, in Google Cloud’s Frankfurt region (europe-west3), and stays there.

Two narrow categories are processed in the United States: sign-in details (names, work emails, sign-in events) by WorkOS, and assistant messages by OpenRouter when the assistant is used. Where EU law requires safeguards for these transfers, we rely on the European Commission’s Standard Contractual Clauses.

6. How long we keep data

We keep data only while there is a business need for it, in line with our internal data management policy. Personal information is deleted or de-identified as soon as it no longer has a business use.

When a pilot or contract ends, the customer’s accounts and data are deleted within 60 days. Customers can ask for an export of their data before deletion.

7. Security

Data is encrypted in transit and at rest. Console access is by invitation only, with multi-factor authentication supported, and operator actions are recorded in an action log. Our security practices, including how we test the software, are described on the Security page at haladir.com/security.

8. Your rights

Depending on where you live, you can ask us for access to the personal information we hold about you, ask for it to be corrected or deleted, ask for a copy, or object to how it is used. Write to access@haladir.com and we will respond within the timeframe the law sets, generally one month.

If your personal information sits in a customer’s console data, that customer decides how it is used, so please raise the request with them first. We support our customers in answering these requests. If you are in the EU or UK and are not satisfied with our answer, you can complain to your local data protection authority.

9. Changes to this policy

When we change this policy, we will post the new version here and update the date at the top. For material changes affecting console customers, we will tell them directly.

10. Contact

Questions and requests about this policy or your personal information:

Haladir Inc.
Privacy team