Privacy Policy
Last updated: 1 September 2026
This Privacy Policy explains how NOMCY LIMITED collects, uses, stores and otherwise processes personal data in connection with the Nomos.cy website, platform and related services (collectively, “Nomos” or the “Service”).
We are committed to protecting your privacy and processing personal data fairly, lawfully and transparently.
This Privacy Policy should be read together with our Terms and Conditions of Use and Subscription and, where applicable, our Cookie Policy.
1. Who we are
Nomos is operated by:
NOMCY LIMITEDRegistration number: HE 490480Registered office: 11 Michail Paridi, 1095 Nicosia, CyprusEmail: mail@nomos.cy
For the purposes of the General Data Protection Regulation (Regulation (EU) 2016/679 – “GDPR”) and applicable Cyprus data protection legislation, NOMCY LIMITED is generally the data controller of the personal data described in this Privacy Policy.
This means that we determine the purposes and means of processing that personal data.
Where another organisation, such as your employer, purchases and administers a corporate Nomos subscription, that organisation may separately act as a controller in relation to personal data which it processes for its own purposes.
2. SCOPE OF THIS PRIVACY POLICY
This Privacy Policy applies to personal data processed when you:
-
visit nomos.cy;
-
create or maintain a Nomos account;
-
purchase or use a subscription;
-
use the Nomos platform;
-
select industries, areas of law, topics or other preferences;
-
create saved searches or bookmarks;
-
receive personalised regulatory newsletters, notifications or alerts;
-
use search, AI-enabled or other interactive functionality;
-
contact us for support or other enquiries;
-
provide feedback or report an error;
-
receive marketing or promotional communications, where you have chosen to receive them; or
-
otherwise interact with Nomos.
This Privacy Policy concerns personal data, meaning information relating to an identified or identifiable natural person.
3. PERSONAL DATA WE COLLECT
The personal data we process depends upon how you interact with Nomos.
3.1 Account and identity information
When you create or use an account, we may collect: name; email address; password or authentication credentials in protected form; organisation or employer; job title or professional role, where provided; account identifier; preferred language; account status; subscription type; and other information you provide when creating or maintaining your account.
3.2 Subscription and transaction information
Where you purchase or use a paid subscription, we may process: subscription plan; commencement and renewal dates; transaction references; payment status; billing name and address; VAT or tax information, where applicable; invoices and credit notes; cancellation and refund information; and correspondence concerning your subscription.
Payments are processed through Revolut Business.
Where payment information is entered directly into Revolut Business or associated payment-processing systems, Nomos does not receive or store complete payment-card details.
Revolut may process personal data as an independent controller and/or service provider in accordance with its own privacy terms and applicable law.
3.3 Personalisation and preference information
A core function of Nomos is to provide personalised regulatory information.
We may therefore process information concerning: industries selected by you; areas of law selected by you; regulatory topics and other interests selected by you; issuing authorities or categories followed by you; preferred language; newsletter and notification preferences; saved searches; bookmarks or saved content; and other settings used to personalise the Service.
We use this information to determine which legal and regulatory developments, documents, newsletters, notifications and other information may be relevant to you.
3.4 Search, usage and interaction information
When you use Nomos, we may process information about how you interact with the Service, including: search queries; filters applied; documents or pages accessed; saved searches; bookmarks; links or source documents accessed; interactions with regulatory updates and newsletters; features used; dates and times of activity; session information; language and display preferences; and other platform interaction data.
This information may be used to provide the functionality requested by you, maintain your account, improve the Service, understand how features are used and improve personalisation.
3.5 User Inputs and AI interactions
Where Nomos allows you to submit prompts, search queries, feedback or other information to AI-enabled functionality, we may process those inputs together with the output generated in response.
Nomos uses Microsoft Azure OpenAI as part of its AI infrastructure.
You should not enter confidential, privileged, commercially sensitive or third-party personal information into AI-enabled functionality unless the relevant functionality is expressly designed for that purpose and you are authorised to provide that information.
You should also avoid including special categories of personal data or other sensitive information in free-text search or AI prompts unless necessary and expressly supported by the Service.
3.6 Technical and device information
When you access Nomos, certain technical information may be collected automatically, including: IP address; device type; browser type and version; operating system; device or browser identifiers; date and time of access; referring and exit pages; diagnostic information; error and crash information; security events; and server and application logs.
3.7 Communications and support information
If you contact us, we may process: your name and contact details; the content of your communication; support requests; complaints; error reports; feedback; records of our response; and related correspondence.
3.8 Marketing information
If you choose to receive marketing or promotional communications from Nomos, we may process: your email address; your marketing preferences; consent records; records of communications sent; unsubscribe or objection requests; and limited information regarding engagement with communications, where lawfully collected.
Marketing and promotional messages will only be sent where permitted by applicable law and, where consent is required, where you have expressly chosen to receive them.
4. HOW WE OBTAIN PERSONAL DATA
We obtain personal data:
-
Directly from you
For example, when you register, subscribe, select preferences, perform searches, save content, contact us or use the Service.
-
Automatically through the Service
Certain technical, security and usage information is generated when you use the website or platform.
-
From your organisation
Where your employer, law firm or another organisation purchases or administers a corporate subscription, it may provide information necessary to establish and manage your access.
From service providers
We may receive limited transaction, authentication, security or technical information from providers assisting us in operating the Service.
5. WHY WE PROCESS PERSONAL DATA AND OUR LEGAL BASES
We process personal data only where we have an appropriate legal basis.
5.1 Providing your account and the Service
We process account information, preferences, searches, saved content, subscription information and related information to: create and administer your account; authenticate you; provide access to the Service; provide search and filtering functionality; maintain saved searches and bookmarks; provide personalised regulatory monitoring; deliver newsletters, notifications and regulatory updates forming part of the Service; administer subscriptions; process cancellations; and provide customer support.
Legal basis: performance of a contract with you or taking steps at your request before entering into a contract (Article 6(1)(b) GDPR).
Where you access Nomos under a contract between Nomos and your employer or organisation, relevant processing may instead be based on our legitimate interests in providing and administering the contracted Service (Article 6(1)(f) GDPR).
5.2 Personalising regulatory information
We process your selected industries, areas of law, topics, preferences and, where applicable, relevant interactions with the Service to identify information which may be relevant to you.
Legal basis: performance of our contract where personalisation forms part of the Service requested by you (Article 6(1)(b) GDPR) and, where appropriate, our legitimate interests in improving the relevance and effectiveness of the Service (Article 6(1)(f) GDPR).
5.3 Operating AI-enabled functionality
We may process search queries, User Inputs and related information through AI and automated technologies to provide AI-assisted search, retrieval, summarisation, classification, translation, recommendation, ranking and other functionality.
Legal basis: performance of our contract where the processing is necessary to provide functionality requested by you (Article 6(1)(b) GDPR), and where appropriate our legitimate interests in operating, improving and safeguarding the Service (Article 6(1)(f) GDPR).
5.4 Operating, maintaining and improving Nomos
We may analyse technical and usage information to: maintain the platform; identify faults; understand how features perform; improve usability; develop new functionality; measure service performance; and improve the relevance and effectiveness of the Service.
Legal basis: our legitimate interests in operating, maintaining, developing and improving Nomos (Article 6(1)(f) GDPR).
Where analytics technology requires consent under applicable cookie or electronic communications rules, the relevant technology will be activated only after the required consent has been obtained.
5.5 Security, fraud prevention and misuse
We may process account, technical, usage and security information to: protect user accounts; prevent unauthorised access; investigate suspected fraud or misuse; enforce subscription and access restrictions; detect malicious activity; maintain platform and network security; and enforce our Terms where appropriate.
Legal basis: our legitimate interests in protecting Nomos, our users and our business (Article 6(1)(f) GDPR) and, where applicable, compliance with a legal obligation (Article 6(1)(c) GDPR).
5.6 Payments, accounting and legal compliance
We process transaction, invoice and subscription information to: administer payments; issue invoices; maintain accounting and tax records; comply with statutory obligations; respond to lawful requests from authorities; and establish, exercise or defend legal claims.
Legal basis: performance of a contract (Article 6(1)(b)), compliance with legal obligations (Article 6(1)(c)), and where appropriate our legitimate interests in establishing, exercising or defending legal rights (Article 6(1)(f) GDPR).
5.7 Service communications
We may send communications concerning: your account; authentication and security; subscription administration; payment; regulatory newsletters or alerts forming part of your selected Service; changes to the Service; changes to our Terms or this Privacy Policy; and other operational matters.
These communications may be delivered using Microsoft email services and related Microsoft infrastructure.
Legal basis: performance of our contract (Article 6(1)(b) GDPR) and, where appropriate, our legitimate interests in administering and securing the Service (Article 6(1)(f) GDPR).
Personalised regulatory newsletters and alerts forming part of the Service are service communications and are distinct from promotional or marketing communications.
5.8 Marketing and promotional communications
Where you expressly choose to receive marketing or promotional communications, we may use your contact information to send information about: Nomos products and subscription plans; new features; offers; events; and other promotional content.
Legal basis: where required, your consent (Article 6(1)(a) GDPR).
You may withdraw consent at any time by using the unsubscribe mechanism provided in the communication or by contacting us.
Withdrawal of consent to marketing does not affect personalised regulatory newsletters or alerts which form part of the Service you have requested.
6. AI, PERSONALISATION AND AUTOMATED PROCESSING
6.1 Use of Azure OpenAI
Nomos uses Microsoft Azure OpenAI to assist with functions including: legal and regulatory search; information retrieval; summarisation; classification and tagging; translation; identifying relationships between documents; matching developments to selected industries, areas of law or interests; ranking or prioritising information; and generating personalised regulatory updates and newsletters.
Our current Azure configuration includes Azure OpenAI services hosted in West Europe.
6.2 Personalisation
The principal personalisation undertaken by Nomos is designed to determine which legal and regulatory information is likely to be relevant to you.
For example, if you select banking and financial regulation as areas of interest, Nomos may prioritise or send regulatory developments classified within those areas.
The information shown to one user may therefore differ from the information shown to another user.
6.3 No solely automated decisions producing legal or similarly significant effects
Nomos does not use personal data to make solely automated decisions about users which produce legal effects concerning them or similarly significantly affect them within the meaning of Article 22 GDPR.
Automated personalisation determines the regulatory information presented or recommended to users; it does not determine users’ legal rights, regulatory obligations, eligibility, creditworthiness, employment, insurance or comparable matters.
7. CORPORATE ACCOUNTS AND ACCOUNT ADMINISTRATORS
Where an organisation purchases Nomos subscriptions for its personnel, the organisation may appoint one or more account administrators.
Corporate administrators may have access to: the user’s name; and the user’s email address.
Corporate administrators do not have access to the user’s searches, saved searches, bookmarks, document viewing history, regulatory preferences or other usage data merely because the organisation pays for the subscription.
Administrators may also be able to add or remove users or administer subscription entitlements.
The organisation is independently responsible for any personal data it processes concerning its personnel for its own employment, compliance or administrative purposes.
8. WHO WE SHARE PERSONAL DATA WITH
We do not sell personal data.
We may disclose personal data to the following categories of recipients where reasonably necessary.
8.1 Microsoft and Azure infrastructure
Nomos uses Microsoft Azure and related Microsoft services to operate significant parts of the Service.
Microsoft may process personal data as a processor or service provider in accordance with our contractual arrangements and Microsoft’s applicable data-protection terms.
8.2 Payment provider
Payments are processed using Revolut Business or other EU authorized financial institutions, payment institutions or e-money institutions (Processors).
Processors may process personal data necessary to process payments, prevent fraud, comply with financial-services obligations and administer transactions.
Depending on the processing activity, Processors may act as independent controllers.
8.3 Professional advisers
We may disclose personal data to lawyers, accountants, auditors, insurers and other professional advisers where reasonably necessary.
8.4 Authorities and courts
We may disclose personal data to regulators, law-enforcement authorities, tax authorities, courts and other public bodies where required by law or reasonably necessary for the establishment, exercise or defence of legal claims.
8.5 Corporate transactions
Personal data may be disclosed to prospective purchasers, investors, lenders, professional advisers and other relevant parties in connection with a proposed or completed merger, financing, investment, restructuring, acquisition or sale of all or part of Nomos or NOMCY LIMITED, subject to appropriate confidentiality and data-protection safeguards.
9. PROCESSORS
Where a service provider processes personal data on our behalf, we require it to process that data only on documented instructions and subject to appropriate contractual, confidentiality and security obligations as required by Article 28 GDPR.
Some third parties, particularly payment providers, may act as independent controllers for some of their processing activities. Their own privacy information will apply to those activities.
10. INTERNATIONAL TRANSFERS
Nomos uses infrastructure located both within and outside the European Economic Area.
The principal Azure services used for database, application and AI processing are currently located in European regions, including West Europe and Italy North.
Certain supporting services are currently configured in the United States, including: Azure Static Web Apps — Central US; and Azure Communication Services — East US.
Microsoft and other service providers may also use subprocessors located outside the EEA.
Where personal data is transferred outside the EEA, we will ensure that an appropriate transfer mechanism is used as required by Chapter V GDPR. This may include: a European Commission adequacy decision; the European Commission’s Standard Contractual Clauses; another mechanism permitted by the GDPR; and supplementary technical, contractual or organisational safeguards where appropriate.
You may contact us at mail@nomos.cy for further information concerning applicable international transfer safeguards.
11. RETENTION
We retain personal data only for as long as reasonably necessary for the purposes for which it was collected and to meet legal, accounting, security and dispute-resolution requirements.
As a general framework: active account information is retained while the account remains active; personalisation preferences are retained while required to provide the Service or until changed or deleted; saved searches and bookmarks are retained while required to provide that functionality; subscription and transaction records are retained for the periods required by applicable accounting and tax law; marketing consent and opt-out records may be retained for as long as necessary to demonstrate compliance and honour users’ preferences; support communications are retained for a reasonable period after resolution; technical and security logs are retained only for as long as reasonably necessary for security, troubleshooting and operational purposes.
Specific technical retention periods may vary depending upon the relevant Azure service, backup arrangements and operational requirements.
When personal data is no longer required, we will delete or anonymise it unless continued retention is required or permitted by law.
12. COOKIES AND SIMILAR TECHNOLOGIES
Nomos may use cookies and similar technologies for purposes including: enabling essential website and account functionality; authentication and security; remembering settings; measuring performance; analytics; and other functionality described in our Cookie Policy.
Cookies or similar technologies which are not strictly necessary will be used only in accordance with applicable consent requirements.
Where consent is required, you will be given an opportunity to accept or reject relevant categories and to change your choices.
Further information is available in our Cookie Policy.
13. YOUR DATA PROTECTION RIGHTS
Subject to the conditions and exceptions in applicable law, you may have the following rights: right of access; right to rectification; right to erasure; right to restriction of processing; right to data portability; right to object to processing based on legitimate interests; right to object to direct marketing at any time; right to withdraw consent where processing is based on consent; and rights concerning qualifying automated decision-making under Article 22 GDPR.
To exercise any of these rights, contact mail@nomos.cy.
14. COMPLAINTS
If you have concerns about our processing of personal data, we encourage you to contact us first at mail@nomos.cy.
You also have the right to lodge a complaint with a competent data-protection supervisory authority.
In Cyprus, the supervisory authority is the: Office of the Commissioner for Personal Data ProtectionRepublic of Cyprus www.dataprotection.gov.cy
15. SECURITY
We implement appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or unauthorised access.
Our technical infrastructure uses Microsoft Azure services and may include, as appropriate: access controls; authentication controls; encryption; secure cloud infrastructure; logging and monitoring; backup and recovery arrangements; vulnerability and security management; and restricted administrative access.
No internet-based service can provide absolute security.
Users are responsible for keeping their account credentials confidential and should notify us promptly at support@nomos.cy if they suspect unauthorised access to their account.
16. CHILDREN
Nomos is principally intended for adults and professional, business, academic and regulatory users.
A person must be at least 18 years old and have legal capacity to purchase a subscription.
Nomos is not directed specifically at children.
17. THIRD-PARTY WEBSITES AND OFFICIAL SOURCES
Nomos contains links to government websites, regulators, public databases and other third-party resources.
When you leave Nomos and visit a third-party website, that organisation may process personal data independently of us.
This Privacy Policy does not govern the privacy practices of third-party websites.
18. CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy from time to time to reflect: changes to Nomos; new functionality; changes in our processing activities; changes to service providers; changes in applicable law or regulatory guidance; or improvements to our privacy practices.
The current version will be published on nomos.cy and will state the date on which it was last updated.
Where a change materially affects how we process your personal data, we will take reasonable steps to bring the change to your attention and, where required by law, obtain consent before carrying out the new processing.
19. RELATIONSHIP WITH THE TERMS OF USE
This Privacy Policy explains how NOMCY LIMITED processes personal data.
It does not form part of the contractual Terms and Conditions of Use and Subscription for the purpose of converting privacy information or consent into contractual obligations.
Your use of the Service is separately governed by the Nomos.cy Terms and Conditions of Use and Subscription.
20. CONTACT US
For questions about this Privacy Policy, our processing of personal data or the exercise of data-protection rights, contact:
NOMCY LIMITED
Registration number: HE 49048011
Michail Paridi1, CY-095
Nicosia, Cyprus
Email: mail@nomos.cy