Privacy Policy
This Privacy Policy is incorporated by reference in the Terms and Conditions of Nevlin™ ("Nevlin", or "us") and is part of the agreement between you, user of the Website nevlin.com (“Website” or “Service”), and Nevlin.
Important Privacy Information
To use Nevlin, we ask for basic information such as your name, email address, date of birth, and a few onboarding answers about your trading/investing experience and goals, so we can personalise your learning path. We also automatically collect technical information from your device (IP address, device type, operating system, language and time-zone settings) to run the Service securely.
Because Nevlin is a paid subscription product, we also take steps to confirm that payments made on the Service are genuine. For every payment we run automated checks (such as card verification and fraud/sanctions screening). In specific situations — for example, a payment dispute, a refund request outside our normal window, or a mismatch between the cardholder's name and your account — we may ask you to confirm your identity, using methods chosen at our discretion, in order for you to continue using paid features. This protects you from unauthorized use of your card and helps us meet the requirements of our payment partners. Sections 2 and 3 below explain exactly what we may ask for and why.
For more on what we do with your data, your rights, and who controls it, please read on — or contact us at privacy@nevlin.com.
This Privacy Policy explains what personal data is collected when you use the Nevlin website located at nevlin.com and the mobile application and services provided through it (together, the "Service"), and how that personal data is processed. This Privacy Policy is incorporated by reference into, and forms part of, Nevlin's Terms and Conditions.
BY USING THE SERVICE, YOU CONFIRM THAT (I) YOU HAVE READ, UNDERSTOOD AND AGREE TO THIS PRIVACY POLICY, AND (II) YOU ARE AT LEAST 18 YEARS OF AGE. If you do not agree, or cannot make this confirmation, you must not use the Service. In that case you should: (a) contact us to request deletion of your data; (b) cancel any active subscription using the functionality provided on the Service; and (c) stop accessing the Service.
Key definitions
- "GDPR" means the General Data Protection Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data.
- "EEA" includes all current member states of the European Union and the European Economic Area; for the purposes of this Policy, the EEA also includes the United Kingdom.
- "Process", in respect of personal data, includes to collect, store, use, and disclose personal data to others.
- "Personal data" means any information relating to an identified or identifiable natural person, as defined in Article 4(1) GDPR.
TABLE OF CONTENTS
2. Categories of Personal Data we Collect
3. Purposes of Processing and Legal Bases
4. With Whom We Share Your Personal Data
5. How You Can Exercise Your Privacy Rights
7. International Data Transfers
8. Changes to This Privacy Policy
11. How "Do Not Track" Requests Are Handled
Personal Data Controller
NEVLIN LTD, a company registered under the laws of Cyprus with the registration number HE 497956, having its registered office at Spyrou Kyprianou, 38, Germasogeia, Limassol, 4042, Cyprus, is the controller of your personal data for the purposes of the GDPR
Categories of Personal Data we Collect
We process data (i) that you give us directly — for example, when you complete onboarding or contact support — and (ii) that we collect automatically when you use the Service.
2.1 Data you give us
- Identifiers and onboarding data. Name, email address, date of birth, country, and your self-reported trading/investing experience level and learning goals, provided when you register and complete the onboarding questions.
- Commercial information. When you subscribe, our payment processor collects your card or payment-account details on our behalf. We do not collect or store full card numbers; we may receive a secure payment token, the last digits of your card, and details of the plan, date, and amount of each transaction.
- Support communications. Any information you provide through our "Contact us" form, in-app chat, or support emails, including the content of your message.
- Identity verification data. If your account or a payment you make is selected for enhanced verification under the risk-based checks described in Section 3, we may ask you to provide: documents that identify you; and, in limited cases, proof of address or confirmation of the last four digits of the payment card used. We only request this where a specific risk indicator applies (for example, a payment dispute, an out-of-window refund request, or a mismatch between the cardholder's name and your account name) — it is not required from every user by default.
2.2 Data we collect automatically
- Acquisition data. The referring URL or advertising campaign that brought you to the Service.
- Device and location data. Language settings, IP address, time zone, device type and model, device settings, operating system and version.
- Usage data. How you interact with lessons and courses, your progress and streaks, and your activity within the practice simulator, which uses virtual, non-withdrawable funds only — the simulator does not connect to any real brokerage or bank account.
- Transaction data. Date, time, and amount of each transaction, and the type of payment method used.
- Automated fraud and verification signals. For every payment we automatically generate certain technical signals, including address-verification (AVS) results, card-network fraud scores, a device fingerprint, and the outcome of automated sanctions and Politically Exposed Persons ("PEP") screening. These signals let us confirm that most payments are genuine without asking you for any documents.
- Cookies and similar technologies. We use cookies, SDKs and similar technologies to operate the Service, remember your preferences, measure how the Service is used, and support advertising. A session cookie expires when you close your browser; a persistent cookie remains on your device for a set period. You can disable most cookies through your browser or device settings; some features may not work as intended if you do.
Purposes of Processing and Legal Bases
The sections below set out why we process your personal data, which categories of data are involved, and the legal basis we rely on under the GDPR.
To provide the Service
We use your data to create and run your account, deliver lessons and courses, and operate the practice simulator (virtual funds only, no withdrawals). Data categories: Identifiers, onboarding data, usage data. Legal basis: Performance of contract; legitimate interest in protecting our legal rights after the relationship ends.
To communicate with you
We email you about your account, product updates, and important changes. You can unsubscribe from non-essential messages at any time. Data categories: Identifiers, contact data. Legal basis: Legitimate interest (customer engagement) or consent.
To personalise and measure advertising
We and advertising partners such as [e.g. Meta, Google, TikTok] use your data to show relevant ads and measure campaign performance. Data categories: Onboarding data, device/location data, advertising identifiers, cookies. Legal basis: Consent, or legitimate interest where consent is not required under applicable law.
To provide customer support
We use your data to respond to support requests, using tools such as [helpdesk / live-chat provider]. Data categories: Identifiers, contact data, usage data. Legal basis: Performance of contract; legitimate interest in resolving requests.
To research and improve the Service
We analyse how learners use lessons, courses and the simulator (for example, which topics are most engaging) using tools such as [e.g. Amplitude, Google Analytics], to improve our curriculum and product. Data categories: Device data, usage data. Legal basis: Legitimate interest (product improvement).
To send marketing communications
With your consent (or another applicable legal basis), we may tell you about new courses, features, or offers, using tools such as [e.g. ActiveCampaign]. Data categories: Identifiers, contact data. Legal basis: Consent, or legitimate interest where permitted.
To process your subscription payment
We use payment processors such as [e.g. Solidgate, PayPal] to charge your chosen payment method. We never see or store your full card number. Data categories: Commercial/transaction data. Legal basis: Performance of contract.
To enforce our Terms and prevent fraud generally
We use your data to enforce our agreements, investigate suspected misuse, and protect Nevlin and other users from fraud or abuse. Data categories: All categories. Legal basis: Performance of contract; legitimate interest.
To comply with legal obligations
We process, and where legally required disclose, your data to comply with applicable law, including tax, accounting, and lawful law-enforcement requests. Data categories: All categories. Legal basis: Legal obligation.
With Whom We Share Your Personal Data
We share personal data with third parties that help us operate, provide, improve, and market the Service, and for the purposes set out in Section 3. The categories of recipients include:
- Cloud hosting providers [Amazon Web Services].
- Analytics providers [Meta, Google, Amplitude].
- Marketing and advertising partners [Meta, Google, ActiveCampaign].
- Payment processing providers [Solidgate, PayPal, ApplePay, GooglePay].
- Communication providers [FreshDesk,OpenAI].
- Law enforcement and other public authorities, to enforce our Terms, protect our rights or those of our users, or respond to lawful requests from courts, regulators, or government authorities.
- Parties to a corporate transaction, such as a merger, acquisition, reorganisation, or asset sale, in which personal data may be a transferred business asset.
How You Can Exercise Your Privacy Rights
Subject to applicable law, you have the following rights over your personal data:
- Access, correction, and update. Request a copy of your personal data, or ask us to correct or update it.
- Deletion. Request erasure of your personal data. We will honour this request except to the extent we are legally required, or reasonably need, to retain certain data — for example, identity verification records or transaction records, as described in Section 10.
- Objection and restriction. Ask us to stop or limit certain processing, such as marketing.
- Marketing opt-out. Unsubscribe from marketing emails at any time using the link in the email footer, or by contacting us.
- E-privacy / cookie settings. Manage non-essential cookies and tracking through the privacy settings available in the Service's footer, menu, or profile section.
- Ad personalisation settings. You can also limit personalised advertising directly through your device: on iOS and Android, in the device's advertising/privacy settings; on macOS and Windows, in the system privacy settings. Industry opt-out tools are also available through the Network Advertising Initiative, the Digital Advertising Alliance, and their EU/Canada equivalents.
- Complaint to a supervisory authority. If you are based in the EEA, you may lodge a complaint with the data protection authority in the EU member state where you live, work, or where the alleged infringement occurred.
- Data portability. Request your personal data in a commonly used, machine-readable format.
- To exercise any of these rights, please contact us at privacy@nevlin.com.
Age Limitation
Nevlin's Service relates to financial education and requires a valid payment method held in the user's own name. Accordingly, we do not knowingly provide the Service to, or process personal data of, anyone under 18 years of age (or the age of legal majority in their jurisdiction, if higher). If you become aware that anyone under this age has provided us with personal data, please contact us at privacy@nevlin.com.
International Data Transfers
We may transfer personal data to countries other than the one in which it was originally collected, to provide the Service and for the purposes described in this Policy. Where we transfer personal data originating in the EEA to a country without an adequate level of data protection, we rely on an appropriate legal safeguard, such as the European Commission's Standard Contractual Clauses or an applicable adequacy decision.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you through the Service or by other reasonable means, and you will have an opportunity to review the revised Policy before it takes effect. Continuing to use the Service after the changes take effect means you agree to the revised Policy.
California Privacy Rights
This section applies only to residents of California, United States, and provides additional detail required under the California Consumer Privacy Act ("CCPA") and California's Shine the Light law.
- Shine the Light. California residents may ask us once a year what personal information, if any, we share with third parties for those third parties' own direct marketing purposes. We do not share your personal information with third parties for their own direct marketing purposes within the meaning of that law.
- Sensitive personal information. Identity verification data described in Section 2 may constitute "sensitive personal information" under the California Privacy Rights Act. We collect and use it only for the identity-verification and fraud-prevention purpose described in Section 3, and we do not sell or share it.
- Right to opt out of sale/sharing. We may share certain information with advertising and analytics partners in a way that could be characterised as "selling", "sharing", or "targeted advertising" under California law. Where available, a "Your Privacy Choices" link in the Service's footer, menu, or profile section lets you opt out; we also aim to honour recognised opt-out preference signals.
Data Retention
We retain personal data for as long as reasonably necessary to achieve the purposes set out in this Policy, including for as long as you hold an account with us, and as needed to comply with our legal obligations, resolve disputes, and enforce our agreements. Two specific periods apply:
- Identity verification data (Section 2.1) is retained for five (5) years from the date of verification, in line with international good practice for payment fraud-prevention records, after which it is securely deleted unless a longer period is required by law or to resolve an ongoing dispute.
- Commercial and transaction data is retained for as long as required under applicable accounting and tax law.
Even after you submit a deletion request, a limited subset of data needed to meet these retention obligations may be kept until that obligation is satisfied.
How "Do Not Track" Requests Are Handled
Except as otherwise described in this Policy, the Service does not currently respond to browser "Do Not Track" signals. Please refer to the privacy policies of the third-party services we use (Section 4) to see whether they honour such signals.
Date of last revision: September 17, 2026
Contact Us
NEVLIN LTD, a company registered under the laws of Cyprus with the registration number HE 497956, having its registered office at Spyrou Kyprianou, 38, Germasogeia, Limassol, 4042, Cyprus
Email: privacy@nevlin.com
© NEVLIN LIMITED 2026 All rights reserved.