Help centre

Privacy and personal data

Controller and contact

The controller for the NFA.run service is Sole proprietor Daniil Kokorin, Georgia, Batumi, 15 Tabidze St, registration number В26424221, tax ID 345860151. Questions about personal data and rights requests can be sent to noreply@nfa.run or https://nfa.run/support. Identify the email used for your account, but do not send sign-in codes, authenticator secrets or payment-card details.

Data used to provide your account and orders

We store account email, role and status; sign-in sessions and security events; order references, items, amounts, payment status and payment-provider transaction references; balance movements; accepted document versions; delivery records and encrypted activation files. These records let us provide sign-in, process the contract, deliver purchases and resolve payment or access problems. We do not collect your PayPal password or full payment-card details on NFA.run.

Support and public reviews

Support conversations, their order links and uploaded images are stored privately. Access is limited to you and authorised staff according to roles and assignments. Internal staff notes are not public. Submit only information needed for your issue. After moderation, a product review displays its chosen name, rating and text publicly; the author’s email is not displayed. Editing a review sends it back to moderation.

Purposes and legal grounds

Account, payment, delivery and support data are processed to take steps at your request and perform the purchase contract. Transaction records may also be retained to meet applicable accounting and legal obligations. Security logs, access controls, abuse prevention and backup procedures serve our legitimate interest in protecting customers, funds and the service. A review is published when you submit it for that purpose. We do not require marketing consent to let you buy and do not currently use the site to send advertising newsletters.

Service providers and locations

The application and database run on Hetzner in Helsinki, Finland. Cloudflare handles network delivery and protection. Timeweb sends sign-in emails and receives the recipient address and message. PayPal processes payments and receives order references, items and amounts; its own privacy notice applies to its service. Acode supplies account activation: the integration uses product types and activation references, not your NFA.run login email or card details. Encrypted recovery copies may be stored separately from the VPS. The controller is based in Georgia; some providers operate internationally, so processing is not confined to the EEA. Contact us for information about the applicable transfer arrangements and data locations.

Retention and protection

Email codes expire after 10 minutes and are stored as keyed hashes. Expired authentication records are removed by scheduled cleanup. Authenticated sessions expire after 30 days without activity. Authenticator secrets and activation files are encrypted; staff access requires additional authentication. Account records are needed while the account is in use. Order, payment, warranty and dispute records are retained for contract handling and applicable legal obligations or claims; the relevant purpose and required legal period determine retention, rather than browser-cookie expiry. A deletion request is assessed against those obligations; records that must be retained are restricted to the necessary purpose.

Your rights

Where applicable law provides them, you can request access, correction, deletion, restriction or portability of your data, and object to processing based on legitimate interests. Contact noreply@nfa.run or use a private support request. We may ask for proportionate verification to avoid disclosing someone else’s data. You can also complain to the competent data-protection authority, including the authority in your EU country of residence. Clearing browser storage alone does not delete server records. This notice may be updated as the service changes; accepted order terms remain saved separately.

Incoming messages to noreply@nfa.run are copied to the project owner and technical administrator using Mail.ru and Yandex Mail so they can respond to your request.

Cryptocurrency payments

When you select Heleket, we send the invoice reference, amount, currency and callback/return addresses. We do not send your NFA.run login email or the item list to Heleket. Heleket processes the chosen coin, network and transaction data on its payment page under its own privacy notice: https://heleket.com/privacy. We retain the provider reference, payment status and credit or delivery record to process your order and resolve issues.

Need help?

Contact support

Sole proprietor Daniil Kokorin is the controller for NFA.run. This notice explains data used for sign-in, orders, support and security, with contact details for privacy requests.

Send a focused privacy request

Contact noreply@nfa.run or open a private support request. Identify the account email and explain which records or right your request concerns. Do not include payment-card details, email codes or authenticator secrets.

Questions about this page

Does clearing my browser delete my account?

No. Clearing cookies and local storage removes data from that browser. Orders, support records and other server records require a separate request, subject to applicable retention obligations.