Privacy Policy
Effective date: 12 July 2026 Last updated: 12 July 2026
This Privacy Policy explains how NuVend AI Ltd, trading as Nuvend ("Nuvend", "we", "us", or "our"), collects, uses, stores, and protects personal data when you use our platform at nuvend-ai.com and related services (the "Service").
Nuvend is a business-to-business (B2B) software-as-a-service platform that connects to your third-party business platforms, such as Google Ads, Google Analytics, Google Merchant Centre, Google Search Console, and Shopify, to provide unified data analytics, reporting, and management through an AI assistant that is a core part of the platform.
This policy applies to our business customers ("you" or "your") and your authorised users. It does not apply to the end consumers of your business. Your relationship with your own customers is governed by your own privacy practices. We are not responsible for the privacy practices of any third-party platform you connect to Nuvend; your use of those platforms is governed by their respective privacy policies and terms of service.
Contents
- Who is responsible for your data?
- What data do we collect?
- How do we use your data?
- What is our legal basis for processing?
- Data from connected third-party platforms
- Google API Services — Limited Use Disclosure
- Shopify data handling
- Artificial intelligence features
- Who do we share data with?
- International data transfers
- How do we protect your data?
- How long do we retain data?
- Cookies and local storage
- Your rights under GDPR (EU/EEA and UK)
- Your rights under US privacy laws
- Children's privacy
- Changes to this policy
- Governing law
- Contact us
1. Who is responsible for your data?
Nuvend acts in two capacities depending on the type of data:
- Data controller: for personal data we collect directly from you, such as your account information, session data, and communications with us. As controller, we determine the purposes and means of processing this data.
- Data processor: for data we access from your connected third-party platforms (such as Google Ads, Shopify, and others) on your behalf and at your instruction. As processor, we process this data to provide the Service and as otherwise set out in this policy and our Data Processing Agreement.
While we act as processor for the substantive data from your connected platforms, we act as controller for audit logs and operational metadata that we generate for our own security and compliance purposes. These logs record actions taken (such as connection events, sync operations, and data deletions) and associated metadata (user ID, IP address, timestamps) but do not contain the substantive business data from your platforms.
Controller details:
| Entity | NuVend AI Ltd |
| Trading as | Nuvend |
| Registered address | Birr Technology Centre, Birr, Co. Offaly, R42 HX39 |
| Registration number | 817972 |
| Privacy contact | privacy@nuvend-ai.com |
| Data Protection Officer | Not appointed (not required under GDPR Art. 37). For privacy enquiries, contact privacy@nuvend-ai.com. |
| EU Representative | Not applicable — Nuvend is established in the EU/EEA, so an Article 27 EU representative is not required. |
2. What data do we collect?
2.1 Account and authentication data
When you create a Nuvend account, we collect:
| Data | Source | Purpose |
|---|---|---|
| Full name | You provide at registration | Identifying you within the platform |
| Email address | You provide at registration | Account identification, communications, authentication |
| Password | You create at registration (stored as a cryptographic hash and not stored in readable form) | Authentication |
| Two-factor authentication secrets | Generated when you enable 2FA | Securing your account |
Providing your name and email address is a contractual requirement necessary to create your account and deliver the Service. If you do not provide this data, we cannot provide the Service to you. Connecting third-party platforms is optional.
2.2 Session and security data
When you use Nuvend, we automatically collect:
| Data | Purpose |
|---|---|
| IP address | Security, fraud prevention, audit logging |
| User agent (browser and device information) | Security, fraud prevention |
| Session tokens | Maintaining your authenticated session |
2.3 Organisation data
When you create or join an organisation in Nuvend:
| Data | Purpose |
|---|---|
| Organisation name | Identifying your organisation within the platform |
| Membership and role assignments | Access control and permissions |
| Invitation emails (for users you invite) | Delivering invitations on your behalf |
2.4 Data from connected platforms
When you connect a third-party platform to Nuvend, we access and store data from that platform on your behalf. This data varies by platform and is detailed in Section 5. We access this data at your instruction when you authorise the connection, and we use it to provide the Service. We access this data solely as a data processor acting on your instructions. We do not determine independent purposes for processing your customers' personal data.
2.5 Audit and operational data
We maintain audit logs of significant actions taken within the platform (such as connections, disconnections, data deletions, and administrative actions). These logs contain your user ID, IP address, and action metadata. We maintain these logs as data controller for our own security, accountability, and compliance purposes.
3. How do we use your data?
We use the data we collect for the following purposes:
| Purpose | Data used |
|---|---|
| Providing the Service: authenticating you, displaying your dashboards, syncing your connected platform data, generating reports and analytics | Account data, session data, connected platform data |
| Account communications: sending you account verification emails, password reset links, organisation invitations, and service notifications | Email address, name |
| Security and fraud prevention: detecting unauthorised access, investigating suspicious activity, maintaining audit trails | IP address, user agent, session data, audit logs |
| Service improvement: diagnosing technical issues and improving platform reliability | Pseudonymised operational data (see lawful basis in Section 4) |
| Legal compliance: meeting our obligations under applicable tax and accounting laws, anti-money laundering regulations, and responding to lawful requests from competent authorities | As required by the specific legal obligation |
We do not use your data for:
- Advertising, retargeting, or interest-based marketing
- Selling to or sharing with data brokers, advertising platforms, or information resellers
- Profiling for credit-worthiness or lending decisions
- Surveillance for non-security purposes
- Training artificial intelligence or machine learning models on your business data
4. What is our legal basis for processing?
Under the General Data Protection Regulation (GDPR), we rely on the following lawful bases:
| Processing activity | Lawful basis | GDPR Article |
|---|---|---|
| Account creation and authentication | Performance of contract. Necessary to deliver the Service you signed up for. | Art. 6(1)(b) |
| Storing OAuth tokens for platform connections | Performance of contract. Integral to delivering the core Service. We determine the technical means of their storage, encryption, and lifecycle management as part of our platform infrastructure. | Art. 6(1)(b) |
| Transactional emails (verification, password reset, invitations) | Performance of contract. Necessary for service delivery. | Art. 6(1)(b) |
| Security logging, IP address collection, fraud prevention | Legitimate interest. Protecting our platform and your data from unauthorised access. Our interest in preventing unauthorised access and protecting customer data outweighs the minimal privacy impact of recording IP addresses and user agents, which are routinely processed by any web service. | Art. 6(1)(f) |
| Audit logging | Legitimate interest. Maintaining accountability and security. Our interest in detecting and investigating unauthorised actions and maintaining a verifiable record for compliance outweighs the minimal impact of recording action metadata. | Art. 6(1)(f) |
| Service improvement and diagnostics | Legitimate interest. Improving platform reliability and diagnosing issues. We use pseudonymised operational data (with direct identifiers removed) for this purpose. Our interest in maintaining a reliable service outweighs the minimal impact on your privacy. | Art. 6(1)(f) |
| Processing connected platform data (as processor) | Your instructions. We process on your behalf under our Data Processing Agreement. | Art. 28 |
| Retaining records for tax or legal obligations | Legal obligation. Required by applicable tax and accounting laws. | Art. 6(1)(c) |
Where we rely on legitimate interest, we have conducted a balancing assessment to ensure our interests do not override your rights and freedoms. You may request details of our legitimate interest assessments by contacting privacy@nuvend-ai.com. You have the right to object to processing based on legitimate interest (see Section 14).
5. Data from connected third-party platforms
When you connect a third-party platform to Nuvend, you authorise us to access specific data from that platform via its API using OAuth authentication or API credentials. We request only the minimum permissions necessary to provide the features of the Service.
Google services: When you connect your Google account, you authorise access to the following Google services through a single OAuth authentication. The data accessed from each service is detailed below.
5.1 Google Ads
| OAuth scope | https://www.googleapis.com/auth/adwords |
| Access level | Sensitive (full management) |
| Data accessed | Campaign data, ad group data, keyword data, ad performance metrics, conversion data, account structure |
| Purpose | Displaying advertising analytics and performance reporting within the Nuvend dashboard; uploading offline conversions (such as call tracking data); managing campaign settings, budgets, and targeting, enabling you to manage your Google Ads without switching between platforms |
| Why full access is needed | Google Ads provides only a single OAuth scope with no read-only variant. Full management access is required to enable conversion uploads and campaign management features. |
| Sync frequency | Approximately every hour |
| Initial sync | Up to 90 days of recent data, with ongoing backfill of up to 5 years of historical data |
5.2 Google Analytics
| OAuth scope | https://www.googleapis.com/auth/analytics.edit |
| Access level | Sensitive (full management) |
| Data accessed | Website and application analytics data, traffic metrics, user behaviour data (aggregated), conversion data, GA4 property configuration (key events, custom dimensions, custom metrics, data streams) |
| Purpose | Displaying website analytics and performance reporting within the Nuvend dashboard; managing GA4 property configuration (including key events, custom dimensions, custom metrics, and data streams), enabling you to manage your Analytics setup without switching between platforms |
| Why full access is needed | The GA4 Admin API requires the analytics.edit scope for property discovery, key event management, data stream listing, and custom dimension/metric configuration. A read-only scope would limit Nuvend to displaying report data without the ability to manage your Analytics configuration. |
| Sync frequency | Approximately every 6 hours |
| Initial sync | Up to 90 days of recent data, with ongoing backfill of up to 5 years of historical data |
5.3 Google Merchant Centre
| OAuth scope | https://www.googleapis.com/auth/content |
| Access level | Sensitive (full management) |
| Data accessed | Product listings, product status, shopping performance data, feed diagnostics |
| Purpose | Displaying product and shopping analytics within the Nuvend dashboard; managing product feed data, viewing product disapprovals, and updating feed settings, enabling you to manage your Merchant Centre without switching between platforms |
| Why full access is needed | Full management access is required to enable product feed management features. A read-only scope would limit Nuvend to displaying data without the ability to take action on your behalf. |
| Sync frequency | Varies by resource type (approximately every 30 minutes for products; up to 24 hours for reference data) |
| Initial sync | Up to 90 days of recent data, with ongoing backfill of up to 5 years of historical data |
5.4 Google Search Console
| OAuth scope | https://www.googleapis.com/auth/webmasters.readonly |
| Access level | Sensitive (read-only) |
| Data accessed | Search performance data (queries, impressions, clicks, position), URL inspection data, site maps |
| Purpose | Displaying search engine optimisation analytics within the Nuvend dashboard |
| Sync frequency | Approximately every 6 hours |
| Initial sync | Up to 90 days of recent data, with ongoing backfill of up to 5 years of historical data |
5.5 Shopify
| Access scopes | read_orders, write_orders, read_products, write_products, read_inventory, write_inventory, read_fulfillments, write_fulfillments, read_locations, read_draft_orders, write_draft_orders, read_returns, write_returns, read_discounts, write_discounts, read_gift_cards, write_gift_cards, read_content. Conditional scopes (require Shopify Partner approval): read_customers, write_customers, read_companies, write_companies |
| Data accessed | Product data, order data (including customer email, shipping/billing addresses), customer data (name, email, phone number, address, marketing consent), inventory levels, fulfilment data. We also store the complete data record as provided by the Shopify API, which may include additional fields beyond those listed (such as customer tags, order notes, and geographic data). |
| Purpose | Displaying e-commerce analytics, order reporting, customer insights, and inventory management within the Nuvend dashboard. The write_orders scope enables order management automation (such as updating order tags, adding notes, and managing fulfilment workflows) as directed by you through the Nuvend platform. |
| Sync frequency | Approximately every 15 minutes |
| Initial sync | Up to 60 days of recent data, with ongoing backfill of up to 5 years of historical data |
| Webhooks | We receive real-time updates for order, product, and customer changes via Shopify webhooks, verified using HMAC-SHA256 signatures |
Shopify customer data: When you connect your Shopify store, we access personal data belonging to your customers (names, email addresses, phone numbers, addresses). This data is classified as Level 2 Protected Customer Data under Shopify's framework. We apply enhanced security measures for this data, including encryption at rest and in transit, role-based access controls, per-organisation data isolation, and audit logging. We process this data solely on your behalf as a data processor. You are responsible for ensuring you have the appropriate legal basis to share this data with us and for informing your customers as required by applicable privacy laws.
5.6 Other platforms
Nuvend supports additional platform connections, including Brightpearl, Freshdesk, Freshsales, and Klaviyo (limited availability). These integrations may access personal data including contact names, email addresses, phone numbers, and postal addresses, depending on the platform and the data you choose to connect. For each platform, the specific data accessed, permissions requested, and sync frequency are displayed to you during the connection setup process. We will update this policy before launching any new platform integrations.
Disconnection
When you disconnect a platform from Nuvend, we immediately:
- Wipe all stored credentials (OAuth tokens and API keys) by nullifying all encrypted fields
- Soft-delete all synced data from that connection
- Log the disconnection for audit purposes
Soft-deleted data is permanently purged from our primary database — within 30 days for Shopify data, and on account closure for data from other connectors. See Section 12 for full retention details.
Account termination
Upon termination of your Nuvend subscription, we will retain your data for 60 days to allow you to export it. You may request early deletion at any time by contacting privacy@nuvend-ai.com, in which case we will begin the deletion process promptly. After the retention period (or upon early deletion request), we will delete your data in accordance with the retention periods described in Section 12.
6. Google API Services — Limited Use Disclosure
Nuvend's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically:
-
We only use Google API data to provide user-facing features that are prominent in the Nuvend user interface: analytics dashboards, performance reports, conversion tracking, and campaign and product management tools that you interact with directly.
-
We do not transfer Google API data to third parties except:
- To our infrastructure providers (listed in Section 9) solely for providing user-facing features, with appropriate data protection agreements in place
- To our AI inference provider (listed in Section 9) to power user-facing AI features within the Nuvend platform, such as the AI assistant. Data is processed transiently for inference only. Our AI provider does not retain your data after processing and does not use it for model training.
- When necessary for security purposes (e.g., investigating abuse)
- To comply with applicable laws or regulations
- As part of a merger, acquisition, or asset sale, and only with your explicit prior consent
-
We do not allow humans to read your Google API data unless:
- You have given specific, affirmative consent (e.g., when requesting technical support that requires data access)
- It is necessary for security purposes
- It is required to comply with applicable law
- The data is aggregated and anonymised (with all identifiers including organisation IDs removed) for internal operational purposes such as monitoring system performance and maintaining service reliability
-
We never use Google API data for:
- Advertising, retargeting, personalised marketing, or interest-based advertising
- Selling to or sharing with advertising platforms, data brokers, or information resellers
- Determining credit-worthiness or for lending purposes
- Surveillance or tracking of individuals
- Training artificial intelligence or machine learning models
All Google API data is stored in encrypted databases with access controlled by role-based permissions and per-organisation data isolation. Credentials (OAuth tokens) used to access Google APIs are encrypted at rest using AES-256-GCM with envelope encryption.
7. Shopify data handling
GDPR compliance
Nuvend implements all three of Shopify's mandatory GDPR compliance webhooks:
| Webhook | What we do |
|---|---|
Customer data request (customers/data_request) | We log the request and work with you to provide the relevant stored data for the specified customer within 30 days |
Customer data erasure (customers/redact) | We remove the specified customer's personal data from active use immediately — across both customer and order records, and in our analytics store — and permanently purge it within 30 days |
Shop data erasure (shop/redact) | We initiate deletion of all data associated with your shop — across every connected store for that shop, in both our primary database and our analytics store — completed within 30 days of receiving the webhook |
All Shopify webhooks are verified using HMAC-SHA256 signatures to prevent tampering.
Data handling on disconnection or uninstall
Disconnection (removing the connection in Nuvend) and uninstall (removing access from your Shopify admin) are distinct events. In both cases:
- All synced data (orders, products, customers) is soft-deleted immediately
- All credentials are wiped immediately
- Soft-deleted data is permanently purged from our primary database within 30 days
For uninstalls, Shopify sends us a shop/redact webhook 48 hours after uninstall, confirming that all shop data should be deleted. We complete this deletion within 30 days of receiving the webhook.
If applicable tax or accounting laws require retention of certain records, we will retain only the minimum data required and inform you by email of what is retained and the legal basis for retention.
AI and machine learning
We do not use Shopify Merchant Data or Customer Data (including derived or aggregated data) for training artificial intelligence or machine learning models unless we have explicit written consent from Shopify and/or the merchant, as required by the Shopify Partner Program Agreement.
When you use Nuvend's AI assistant features, Shopify data retrieved to answer your queries is processed by our AI inference provider (Anthropic) for real-time inference only, not for training. Anthropic does not retain this data after processing. See Section 8 for full details on how AI features handle your data.
8. Artificial intelligence features
Nuvend provides an AI assistant as a core feature of the platform, which helps you analyse your business data, build dashboards, and manage your connected platforms through natural language. When you use the AI assistant, your queries and relevant business data are processed by our AI inference provider.
How it works
When you ask the AI assistant a question (for example, "show me revenue trends" or "find orders from this customer"), the assistant may retrieve data from your connected platforms to answer your query. This data, which may include information from your Google, Shopify, or other connected services, is sent to our AI inference provider (Anthropic) as part of the query context.
What data is processed
| Data | When it is sent |
|---|---|
| Your message to the AI assistant | Every AI interaction |
| Business data from connected platforms (metrics, order details, customer information) | When the assistant retrieves data to answer your query |
| Conversation history within the current session | To maintain context during multi-turn conversations |
How your data is protected
- No training: Our AI inference provider (Anthropic) does not use your data to train or improve its models. This is contractually prohibited under our agreement with Anthropic.
- No retention: Data is processed transiently for inference only. Anthropic does not retain your data after generating a response.
- You stay in control: management actions the AI assistant can take on your connected platforms are subject to your configuration and your confirmation before they are applied.
- Conversation storage: AI conversation messages are stored on our servers to maintain conversation continuity across sessions. Your browser stores only a reference to the active chat session (see Section 13). Conversation data is subject to the same security protections as other platform data (encryption at rest, per-organisation data isolation, access controls).
- Observability: We use Langfuse (an LLM observability platform) to monitor AI assistant quality and reliability. AI conversation traces, which may include data from your connected platforms, are stored in Langfuse for this purpose. See Section 9 for details.
AI and your connected platform data
When you use the AI assistant to interact with data from your connected platforms, that data is subject to the same protections described in Section 6 (for Google data) and Section 7 (for Shopify data), in addition to the protections described in this section.
We do not use data from any connected platform to train artificial intelligence or machine learning models.
9. Who do we share data with?
We do not sell, rent, or trade your personal data. We share data with our sub-processors (listed below) and will disclose data where required by law or to protect rights and safety.
Sub-processors
| Sub-processor | Service | Data processed | Location | Transfer mechanism |
|---|---|---|---|---|
| Railway (Railway Corporation) | Application hosting, database hosting (PostgreSQL, ClickHouse, Redis), Electric sync | All platform data | EU West (Amsterdam, Netherlands) | EU-US Data Privacy Framework (certified); Standard Contractual Clauses (2021 EU SCCs + UK SCCs) in Railway DPA |
| Resend (Plus Five Five, Inc.) | Transactional email delivery | Recipient email addresses, email content (names, organisation names, invitation links) | United States (AWS) | Standard Contractual Clauses (2021 EU SCCs + UK SCCs, Module 2, governed by Irish law) in Resend DPA |
| Anthropic (Anthropic PBC) | AI inference for the AI assistant | User queries, conversation context, business data retrieved during AI interactions (may include data from connected platforms) | United States | Standard Contractual Clauses (2021 EU SCCs); Anthropic DPA with zero data retention for inference |
| Autumn (useautumn.com) | Billing and subscription management | Organisation ID, organisation name, email address, feature usage data | United States | Limited account metadata only; sensitive payment and subscription data remains in your own Stripe account (see Stripe). A Data Processing Agreement with Standard Contractual Clauses is being requested from Autumn. |
| Langfuse (Langfuse GmbH) | AI quality monitoring and observability | AI conversation traces, prompts, completions (may include business data from connected platforms), user feedback scores | European Union (Germany) | Data remains within the EEA; no cross-border transfer required |
| Stripe (Stripe, Inc.) | Payment processing | Payment method details, billing address, organisation ID, transaction amounts | United States | EU-US Data Privacy Framework (certified); Standard Contractual Clauses in Stripe DPA |
Railway, Anthropic, and Langfuse process data from your connected platforms (for which we act as processor); Resend, Autumn, and Stripe process only your account and billing data (for which we act as controller).
We will update this list before engaging any new sub-processor. We will notify you at least 30 days before engaging a new sub-processor. If you object, you may terminate the affected services within that notice period. Details of the notification process, objection mechanism, and your remedies are set out in our Data Processing Agreement.
Other disclosures
We will disclose data only where:
- Required to comply with applicable laws, regulations, or legal processes
- Necessary to protect the rights, property, or safety of Nuvend, our customers, or the public
- In connection with a merger, acquisition, or sale of assets, with your explicit prior consent (and, for Google API data, in accordance with the Google API Services User Data Policy)
End-consumer requests
If we receive a data subject access request directly from one of your end customers (for example, a consumer whose data we process via your Shopify store), we will promptly notify you and will not respond directly unless you instruct us to do so or unless required by law.
10. International data transfers
Nuvend serves customers in the European Union, European Economic Area, the United Kingdom, the United States, and Australia. Our infrastructure providers may process data in locations outside your country of residence.
Safeguards for EU/EEA data
When personal data is transferred from the EU/EEA to countries without an adequacy decision from the European Commission, we rely on:
- EU-US Data Privacy Framework (DPF): where our US-based sub-processors are certified under the DPF
- Standard Contractual Clauses (SCCs): the European Commission's 2021 standard contractual clauses, incorporated into our agreements with sub-processors
- Supplementary measures: including encryption in transit and at rest, access controls, and Transfer Impact Assessments
Safeguards for UK data
For transfers from the United Kingdom, we rely on:
- UK-US Data Bridge (the UK extension of the EU-US DPF)
- UK International Data Transfer Agreement (IDTA) or the UK Addendum to EU SCCs
The European Commission renewed the UK's adequacy decision in December 2025, valid until December 2031, meaning data flows freely between the EU/EEA and the UK.
Safeguards for Australian data
Nuvend is established in the European Union (Ireland) and hosts data within the EEA. We do not transfer personal data to Australia; personal data of our Australian customers is processed within the EEA under the safeguards described above.
11. How do we protect your data?
We implement technical and organisational measures to protect your data against unauthorised access, disclosure, alteration, or destruction:
Encryption
- In transit: All data transmitted between your browser and our servers, and between our servers and third-party APIs, is encrypted using TLS (Transport Layer Security)
- At rest: All databases are encrypted at rest using their provider's encryption capabilities
- Credentials: All OAuth tokens and API keys stored for your connected platforms are encrypted using AES-256-GCM with envelope encryption. Each connection's credentials are encrypted with a unique data encryption key (DEK), which is itself encrypted with a master encryption key (MEK)
Access controls and data isolation
- Per-organisation data isolation: Your data is logically isolated from other customers' data. Every request to our systems is scoped to your organisation, so each organisation can only access its own data.
- Role-based access: Platform access is controlled by role assignments (owner, admin, member, viewer) within each organisation
- Principle of least privilege: Internal access to production systems is restricted to authorised personnel only. Nuvend employees may only access your data for the purposes of providing technical support (with your consent), investigating security incidents, or complying with legal obligations. All such access is logged.
Infrastructure security
- Application runs in isolated containers on hardened infrastructure
- Non-root process execution
- Environment secrets managed through secure environment variable injection (never committed to code)
Incident response
In the event of a personal data breach:
- We will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, where feasible, and in any event without undue delay, where the breach is likely to result in a risk to your rights and freedoms (where we are the controller). If notification is delayed, we will provide reasons for the delay.
- We will notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms, as required by GDPR Art. 34
- We will notify Shopify within 24 hours where data obtained through Shopify APIs is involved, including during the data retention/purge window
- We will notify you (as our customer) without undue delay where we are acting as processor, so you can meet your own notification obligations. The specific timeframe for processor breach notification is set out in our Data Processing Agreement.
- If a sub-processor experiences a data breach affecting your data, we will notify you without undue delay upon becoming aware. Our liability in such circumstances is governed by our Data Processing Agreement.
12. How long do we retain data?
We retain data only for as long as necessary to fulfil the purposes described in this policy or as required by law.
| Data category | Retention period |
|---|---|
| Account data (name, email, profile) | For the duration of your account. Deleted when you delete your account (hard-delete with cascading removal of sessions, memberships, and associated records) |
| Session data (IP, user agent, session token) | 7 days from last activity (sessions expire automatically) |
| Connected platform data (synced orders, products, customers) | For the duration of the connection. Soft-deleted immediately on disconnection. Shopify data is permanently purged from our primary database within 30 days of disconnection; data from other connectors is removed when your account is closed |
| Analytics data (aggregated snapshots in our analytics store) | Retained for the life of your account to provide historical analytics. Contains aggregated and behavioural data only — no direct identifiers (names, emails, phone numbers, or raw records), which are held only in our primary database. Deleted on account closure or on a verified erasure request |
| Connector credentials (OAuth tokens, API keys) | For the duration of the connection. Wiped immediately (all encrypted fields nullified) on disconnection |
| Audit logs | 3 years from creation (13 months in active storage, remainder in secure archive). Audit logs contain only action metadata, not the personal data involved in the action. |
| GDPR request logs | 6 years from date of request completion, to demonstrate accountability under GDPR Article 5(2) and cover civil limitation periods. Logs contain only request metadata (dates, type, response, verification steps), not the personal data that was the subject of the request. |
| Deletion logs | 7 years from date of deletion, to cover tax record retention obligations across operating jurisdictions. Logs record what was deleted (category, not content), when, why, and confirmation of completion. |
Note: The retention periods for audit logs (3 years), GDPR request logs (6 years), and deletion logs (7 years) are policy commitments. Automated enforcement of these retention limits is planned for implementation.
| Transactional email records | Retained by Resend (our email provider) for the duration of our account; deleted within 90 days of account termination. Backups retained for 7 days. We do not store email content on our own systems beyond the point of transmission. | | OAuth state cookies | 10 minutes (automatically cleared after authentication callback) |
Permanent purge process
Soft-deleted data in our primary database (PostgreSQL) is permanently removed by an automated daily purge process that runs at 3:00 AM UTC, in batches, 30 days after soft-deletion. This process is logged for auditability. Analytics data (see the retention table above) is retained for the life of your account and is deleted on account closure or on a verified erasure request, rather than by the daily purge.
13. Cookies and local storage
Nuvend uses minimal cookies and browser storage. We do not use any third-party tracking cookies, analytics tools, or advertising pixels on the Nuvend platform.
Cookies
| Cookie | Purpose | Type | Duration |
|---|---|---|---|
| Session cookie | Maintains your authenticated session | Strictly necessary (httpOnly, Secure) | 7 days |
OAuth state cookies (oauth_state_*) | CSRF protection during OAuth authentication flows | Strictly necessary (httpOnly, Secure, SameSite=Lax) | 10 minutes |
Local storage
| Key | Purpose | Duration |
|---|---|---|
nuvend.activeChat.{workspaceSlug} | Tracks the active AI chat session for your current workspace | Persistent (until you clear browser data) |
nuvend.local-pending.{resourceId} | Queues optimistic write operations for data changes | 24 hours (automatically expires and self-cleans) |
nuvend.modelTier.{workspaceId} | Stores your preferred AI model tier per workspace | Persistent (until you clear browser data) |
nuvend.workspace.{slug}.lastSubpath | Remembers the last visited page within each workspace | Persistent (until you clear browser data) |
theme | Stores your light/dark mode display preference (managed by the next-themes library) | Persistent (until you clear browser data) |
We do not use tracking cookies, advertising pixels, or any technology that tracks you across third-party websites. Because we use only strictly necessary cookies, we do not require cookie consent under the ePrivacy Directive.
14. Your rights under GDPR (EU/EEA and UK)
If you are located in the European Economic Area or the United Kingdom, you have the following rights regarding your personal data:
| Right | Description |
|---|---|
| Access (Art. 15) | Request a copy of the personal data we hold about you |
| Rectification (Art. 16) | Request correction of inaccurate personal data |
| Erasure (Art. 17) | Request deletion of your personal data (subject to legal retention requirements) |
| Restriction (Art. 18) | Request that we limit how we process your data |
| Notification to recipients (Art. 19) | We will notify each recipient to whom your data has been disclosed of any rectification, erasure, or restriction, unless this proves impossible or involves disproportionate effort. We will inform you of those recipients on request. |
| Data portability (Art. 20) | Receive your personal data in a structured, commonly used, machine-readable format (such as JSON or CSV) |
| Object (Art. 21) | Object to processing based on legitimate interest, or to processing for direct marketing purposes (where applicable) |
| Withdraw consent | Where processing is based on consent, withdraw that consent at any time |
| Automated decisions (Art. 22) | Not be subject to decisions based solely on automated processing that produce legal or similarly significant effects |
Nuvend does not engage in automated decision-making or profiling that produces legal or similarly significant effects on you.
How to exercise your rights
Contact us at privacy@nuvend-ai.com with your request. We may ask you to verify your identity before processing your request, to protect your data from unauthorised access. We will respond within one month as required by applicable law. If your request is complex, we may extend this by a further two months, and we will inform you of any extension within the first month.
There is no charge for exercising your rights. If requests are manifestly unfounded or excessive, we may charge a reasonable fee or refuse to act, and we will inform you of our reasons.
Right to lodge a complaint
You have the right to lodge a complaint with your local data protection supervisory authority:
- EU/EEA: Our lead supervisory authority is the Irish Data Protection Commission (DPC) — https://www.dataprotection.ie. You may also lodge a complaint with your local authority: https://edpb.europa.eu/about-edpb/about-edpb/members_en
- United Kingdom: Contact the Information Commissioner's Office (ICO) at https://ico.org.uk
15. Your rights under US privacy laws
California (CCPA/CPRA)
As of 12 July 2026, Nuvend does not meet the revenue or data volume thresholds for CCPA/CPRA applicability. We include this section as a transparency measure and will update it if our status changes.
If you are a California resident and the California Consumer Privacy Act / California Privacy Rights Act applies to our processing of your data, you have the following rights:
| Right | Description |
|---|---|
| Right to know | Request disclosure of the categories and specific pieces of personal information we have collected |
| Right to delete | Request deletion of personal information we have collected |
| Right to correct | Request correction of inaccurate personal information |
| Right to opt-out | Opt out of the sale or sharing of personal information |
| Right to limit | Limit the use of sensitive personal information |
| Non-discrimination | We will not discriminate against you for exercising any of these rights |
Nuvend does not sell your personal information. Nuvend does not share your personal information for cross-context behavioural advertising. Because we do not sell or share personal information, we are not required to provide a "Do Not Sell or Share" link. Should this change, we will provide this mechanism.
Where we process personal information on your behalf, our use is governed by our Data Processing Agreement, which restricts our use of that information to the purposes set out in our agreement with you.
For retention periods applicable to each category of personal information, see Section 12.
To exercise your rights, contact us at privacy@nuvend-ai.com.
Other US states
If you reside in a US state with applicable consumer privacy legislation (including Virginia, Colorado, Connecticut, and others), you may have similar rights to access, correct, delete, and opt out of certain processing of your personal data. Contact us at privacy@nuvend-ai.com to exercise any applicable rights.
16. Children's privacy
Nuvend is a B2B platform designed for use by businesses and their authorised representatives. Our Service is not directed at, and we do not knowingly collect personal data from, individuals under the age of 16 (or the applicable age of digital consent in your jurisdiction).
If we become aware that we have collected personal data from a child without appropriate consent, we will delete that data promptly. If you believe a child has provided us with personal data, please contact us at privacy@nuvend-ai.com.
17. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices, the Service, or applicable laws.
- Material changes: We will notify you by email at least 30 days before the changes take effect, unless the change is required by law or necessary to address an immediate security risk, in which case we will notify you as soon as reasonably practicable
- Minor changes: We will update the "Last updated" date at the top of this policy
If a change affects how we use data obtained from Google APIs, we will notify you and obtain your consent before implementing the change, in accordance with the Google API Services User Data Policy.
We encourage you to review this policy periodically for the latest information on our privacy practices.
18. Governing law
This policy is governed by and construed in accordance with the laws of Ireland. Any disputes arising from this policy shall be subject to the exclusive jurisdiction of the courts of Ireland, without prejudice to your right to lodge a complaint with your local data protection supervisory authority or to bring proceedings in the courts of your place of habitual residence.
Our liability in connection with this policy is governed by and subject to the limitations set out in our Terms of Service.
19. Contact us
If you have any questions about this Privacy Policy, wish to exercise your privacy rights, or have concerns about how your data is handled, please contact us:
| Privacy contact | privacy@nuvend-ai.com |
| Postal address | Birr Technology Centre, Birr, Co. Offaly, R42 HX39 |
| Website | nuvend-ai.com |
For matters related to data we process on your behalf (connected platform data), please refer to our Data Processing Agreement which governs that relationship.
Where your instructions conflict with our legal obligations, we will inform you of the conflict (to the extent legally permitted) and will comply with our legal obligations. We will not process your data in a manner that we believe violates applicable law, even if instructed to do so.
This Privacy Policy was last updated on 12 July 2026.