Privacy Policy

Last updated: 12 September 2026

1. Who we are

Negosim is operated by Kern IT, company number BE0845906217, Rue Belliard 2A, 1040 Brussels, Belgium. Kern IT is the data controller for the personal data described in this policy. You can reach us at privacy@kernit.be.

This policy is written to comply with the EU General Data Protection Regulation (GDPR) and Belgian data protection law.

2. What data we collect

Data you give us

  • Account data: e-mail address, username, date of birth (to verify you are at least 16), optional first name, last name, bio and profile picture.
  • Sign in with Google (optional): if you choose it, Google sends us your name, your verified e-mail address and your Google account identifier. We keep the identifier only to recognise you at the next sign-in; you can unlink it from your account at any time.
  • Negotiation content: every message you write during a session, the AI replies, your score and the automated analysis report.
  • Support: the content of tickets and messages you send to our support team.
  • Invitations: the e-mail addresses of people you invite.
  • Directory suggestions: the professional details and logo you submit when suggesting a negotiation coach or firm.

Data generated by your use of the Service

  • Usage data: sessions played, credits consumed and granted (with timestamps), likes, views and leaderboard rankings.
  • Technical data: IP address, browser type, timestamps and error reports collected by our servers and monitoring tools for security and reliability.
  • Billing data: your Stripe customer identifier, plan, subscription status and invoice history. Card numbers are handled by Stripe and never reach our servers.

We do not collect special categories of data and ask you not to include any in your messages.

3. Why and on what legal basis

  • Providing the Service (account, sessions, AI replies, analysis, credits, support): performance of our contract with you (art. 6(1)(b) GDPR).
  • Billing and accounting: contract and legal obligation (art. 6(1)(b) and (c)).
  • Age verification: legal obligation (art. 8 GDPR).
  • Security, abuse prevention, rate limiting, error monitoring: our legitimate interest in running a safe and reliable Service (art. 6(1)(f)).
  • Public sessions and leaderboards: your choice: sessions are shown publicly only if you set them public, which you can revert (art. 6(1)(a)).
  • Transactional e-mails (sign-in links, receipts, ticket updates): contract.
  • Practice reminders and news about Negosim (tips to play your first session, a reminder after a week without playing, new scenarios and features): our legitimate interest in helping our own users use the Service (art. 6(1)(f) GDPR and the exception for existing customers in the ePrivacy rules). Each of these e-mails has a one-click unsubscribe link, and you can switch them off at any time from your account. We never send e-mails about other companies' products.
  • Improving scenarios and the AI experience using aggregated, de-identified statistics: legitimate interest.

4. Artificial intelligence

The AI counterpart, scoring and analysis are produced by Google Gemini(Google Ireland Ltd / Google LLC), acting as our processor. The scenario, your messages and the conversation history are sent to Google's API to generate each reply. We use the paid API tier, under which Google does not use your prompts to train its models. We do not make decisions with legal or similarly significant effects about you based on this processing; scores are informational only.

5. Who we share data with

We only share data with providers we need to run the Service, bound by data processing agreements:

  • Google (Gemini API): AI generation (see section 4).
  • Google (Sign in with Google): only if you choose to sign in with your Google account.
  • Stripe Payments Europe Ltd: payment processing and subscription billing.
  • Our hosting provider in the European Union: servers, database and backups.
  • Our e-mail delivery provider: transactional e-mails, practice reminders and news.
  • Sentry: error monitoring (technical data and pseudonymous identifiers only).

We may disclose data when required by law or to protect our rights. We never sell personal data.

Some providers (Google, Stripe, Sentry) may process data outside the European Economic Area. Transfers rely on the EU-US Data Privacy Framework or the European Commission's Standard Contractual Clauses.

6. Public content

When a session is public, its full transcript, your username, score and analysis can be viewed by anyone, including visitors without an account, and may appear on leaderboards and the home page. Sessions are public by default on the free plan; paid plans can make them private. Do not write anything in a session you would not want to be public.

7. How long we keep data

  • Account and session data: for as long as your account exists.
  • After account deletion: personal identifiers are anonymised immediately; residual anonymised session statistics may be kept for scenario analytics. Backups are rotated within 30 days.
  • Billing records: 7 years, as required by Belgian accounting and tax law.
  • Technical logs and error reports: up to 90 days.
  • Support tickets: 2 years after closure.

8. Your rights

Under the GDPR you can:

  • Access the personal data we hold about you and obtain a copy;
  • Rectify inaccurate data (most fields can be edited from your profile);
  • Erase your data: use "Delete my account" on your profile page, or write to us;
  • Restrict or object to processing based on legitimate interest;
  • Port your data in a machine-readable format;
  • Withdraw consent at any time (for example by making a session private);
  • Lodge a complaint with a supervisory authority.

To exercise a right, e-mail privacy@kernit.be from the address linked to your account. We answer within 30 days.

Belgian supervisory authority: Autorité de protection des données / Gegevensbeschermingsautoriteit, Rue de la Presse 35, 1000 Brussels, contact@apd-gba.be, autoriteprotectiondonnees.be.

9. Cookies and local storage

Negosim uses only what is strictly necessary to run the Service: your sign-in token is stored in your browser's local storage, and a service worker caches static assets so the app loads faster and works offline. We do not use advertising or third-party tracking cookies, so no cookie banner is required. Stripe sets its own cookies on its checkout pages under its own policy.

10. Security

Data is transmitted over HTTPS and stored in the European Union. Sign-in is passwordless with expiring one-time links. Access to production systems is restricted to authorised staff, and administrator actions are logged. No system is perfectly secure; if you believe your account has been compromised, contact us immediately.

11. Children

The Service is not intended for anyone under 16. We verify age at registration and delete accounts found to belong to younger users.

12. Changes

We may update this policy. Material changes are announced by e-mail or in the app before they take effect. The date at the top indicates the latest revision.

13. Contact

Kern IT, Rue Belliard 2A, 1040 Brussels, Belgium
privacy@kernit.be