Version v1.0

Privacy Policy

Effective date: 12 July 2026 Last updated: 12 July 2026


This Privacy Policy explains how NuVend AI Ltd, trading as Nuvend ("Nuvend", "we", "us", or "our"), collects, uses, stores, and protects personal data when you use our platform at nuvend-ai.com and related services (the "Service").

Nuvend is a business-to-business (B2B) software-as-a-service platform that connects to your third-party business platforms, such as Google Ads, Google Analytics, Google Merchant Centre, Google Search Console, and Shopify, to provide unified data analytics, reporting, and management through an AI assistant that is a core part of the platform.

This policy applies to our business customers ("you" or "your") and your authorised users. It does not apply to the end consumers of your business. Your relationship with your own customers is governed by your own privacy practices. We are not responsible for the privacy practices of any third-party platform you connect to Nuvend; your use of those platforms is governed by their respective privacy policies and terms of service.


Contents

  1. Who is responsible for your data?
  2. What data do we collect?
  3. How do we use your data?
  4. What is our legal basis for processing?
  5. Data from connected third-party platforms
  6. Google API Services — Limited Use Disclosure
  7. Shopify data handling
  8. Artificial intelligence features
  9. Who do we share data with?
  10. International data transfers
  11. How do we protect your data?
  12. How long do we retain data?
  13. Cookies and local storage
  14. Your rights under GDPR (EU/EEA and UK)
  15. Your rights under US privacy laws
  16. Children's privacy
  17. Changes to this policy
  18. Governing law
  19. Contact us

1. Who is responsible for your data?

Nuvend acts in two capacities depending on the type of data:

While we act as processor for the substantive data from your connected platforms, we act as controller for audit logs and operational metadata that we generate for our own security and compliance purposes. These logs record actions taken (such as connection events, sync operations, and data deletions) and associated metadata (user ID, IP address, timestamps) but do not contain the substantive business data from your platforms.

Controller details:

EntityNuVend AI Ltd
Trading asNuvend
Registered addressBirr Technology Centre, Birr, Co. Offaly, R42 HX39
Registration number817972
Privacy contactprivacy@nuvend-ai.com
Data Protection OfficerNot appointed (not required under GDPR Art. 37). For privacy enquiries, contact privacy@nuvend-ai.com.
EU RepresentativeNot applicable — Nuvend is established in the EU/EEA, so an Article 27 EU representative is not required.

2. What data do we collect?

2.1 Account and authentication data

When you create a Nuvend account, we collect:

DataSourcePurpose
Full nameYou provide at registrationIdentifying you within the platform
Email addressYou provide at registrationAccount identification, communications, authentication
PasswordYou create at registration (stored as a cryptographic hash and not stored in readable form)Authentication
Two-factor authentication secretsGenerated when you enable 2FASecuring your account

Providing your name and email address is a contractual requirement necessary to create your account and deliver the Service. If you do not provide this data, we cannot provide the Service to you. Connecting third-party platforms is optional.

2.2 Session and security data

When you use Nuvend, we automatically collect:

DataPurpose
IP addressSecurity, fraud prevention, audit logging
User agent (browser and device information)Security, fraud prevention
Session tokensMaintaining your authenticated session

2.3 Organisation data

When you create or join an organisation in Nuvend:

DataPurpose
Organisation nameIdentifying your organisation within the platform
Membership and role assignmentsAccess control and permissions
Invitation emails (for users you invite)Delivering invitations on your behalf

2.4 Data from connected platforms

When you connect a third-party platform to Nuvend, we access and store data from that platform on your behalf. This data varies by platform and is detailed in Section 5. We access this data at your instruction when you authorise the connection, and we use it to provide the Service. We access this data solely as a data processor acting on your instructions. We do not determine independent purposes for processing your customers' personal data.

2.5 Audit and operational data

We maintain audit logs of significant actions taken within the platform (such as connections, disconnections, data deletions, and administrative actions). These logs contain your user ID, IP address, and action metadata. We maintain these logs as data controller for our own security, accountability, and compliance purposes.


3. How do we use your data?

We use the data we collect for the following purposes:

PurposeData used
Providing the Service: authenticating you, displaying your dashboards, syncing your connected platform data, generating reports and analyticsAccount data, session data, connected platform data
Account communications: sending you account verification emails, password reset links, organisation invitations, and service notificationsEmail address, name
Security and fraud prevention: detecting unauthorised access, investigating suspicious activity, maintaining audit trailsIP address, user agent, session data, audit logs
Service improvement: diagnosing technical issues and improving platform reliabilityPseudonymised operational data (see lawful basis in Section 4)
Legal compliance: meeting our obligations under applicable tax and accounting laws, anti-money laundering regulations, and responding to lawful requests from competent authoritiesAs required by the specific legal obligation

We do not use your data for:


Under the General Data Protection Regulation (GDPR), we rely on the following lawful bases:

Processing activityLawful basisGDPR Article
Account creation and authenticationPerformance of contract. Necessary to deliver the Service you signed up for.Art. 6(1)(b)
Storing OAuth tokens for platform connectionsPerformance of contract. Integral to delivering the core Service. We determine the technical means of their storage, encryption, and lifecycle management as part of our platform infrastructure.Art. 6(1)(b)
Transactional emails (verification, password reset, invitations)Performance of contract. Necessary for service delivery.Art. 6(1)(b)
Security logging, IP address collection, fraud preventionLegitimate interest. Protecting our platform and your data from unauthorised access. Our interest in preventing unauthorised access and protecting customer data outweighs the minimal privacy impact of recording IP addresses and user agents, which are routinely processed by any web service.Art. 6(1)(f)
Audit loggingLegitimate interest. Maintaining accountability and security. Our interest in detecting and investigating unauthorised actions and maintaining a verifiable record for compliance outweighs the minimal impact of recording action metadata.Art. 6(1)(f)
Service improvement and diagnosticsLegitimate interest. Improving platform reliability and diagnosing issues. We use pseudonymised operational data (with direct identifiers removed) for this purpose. Our interest in maintaining a reliable service outweighs the minimal impact on your privacy.Art. 6(1)(f)
Processing connected platform data (as processor)Your instructions. We process on your behalf under our Data Processing Agreement.Art. 28
Retaining records for tax or legal obligationsLegal obligation. Required by applicable tax and accounting laws.Art. 6(1)(c)

Where we rely on legitimate interest, we have conducted a balancing assessment to ensure our interests do not override your rights and freedoms. You may request details of our legitimate interest assessments by contacting privacy@nuvend-ai.com. You have the right to object to processing based on legitimate interest (see Section 14).


5. Data from connected third-party platforms

When you connect a third-party platform to Nuvend, you authorise us to access specific data from that platform via its API using OAuth authentication or API credentials. We request only the minimum permissions necessary to provide the features of the Service.

Google services: When you connect your Google account, you authorise access to the following Google services through a single OAuth authentication. The data accessed from each service is detailed below.

5.1 Google Ads

OAuth scopehttps://www.googleapis.com/auth/adwords
Access levelSensitive (full management)
Data accessedCampaign data, ad group data, keyword data, ad performance metrics, conversion data, account structure
PurposeDisplaying advertising analytics and performance reporting within the Nuvend dashboard; uploading offline conversions (such as call tracking data); managing campaign settings, budgets, and targeting, enabling you to manage your Google Ads without switching between platforms
Why full access is neededGoogle Ads provides only a single OAuth scope with no read-only variant. Full management access is required to enable conversion uploads and campaign management features.
Sync frequencyApproximately every hour
Initial syncUp to 90 days of recent data, with ongoing backfill of up to 5 years of historical data

5.2 Google Analytics

OAuth scopehttps://www.googleapis.com/auth/analytics.edit
Access levelSensitive (full management)
Data accessedWebsite and application analytics data, traffic metrics, user behaviour data (aggregated), conversion data, GA4 property configuration (key events, custom dimensions, custom metrics, data streams)
PurposeDisplaying website analytics and performance reporting within the Nuvend dashboard; managing GA4 property configuration (including key events, custom dimensions, custom metrics, and data streams), enabling you to manage your Analytics setup without switching between platforms
Why full access is neededThe GA4 Admin API requires the analytics.edit scope for property discovery, key event management, data stream listing, and custom dimension/metric configuration. A read-only scope would limit Nuvend to displaying report data without the ability to manage your Analytics configuration.
Sync frequencyApproximately every 6 hours
Initial syncUp to 90 days of recent data, with ongoing backfill of up to 5 years of historical data

5.3 Google Merchant Centre

OAuth scopehttps://www.googleapis.com/auth/content
Access levelSensitive (full management)
Data accessedProduct listings, product status, shopping performance data, feed diagnostics
PurposeDisplaying product and shopping analytics within the Nuvend dashboard; managing product feed data, viewing product disapprovals, and updating feed settings, enabling you to manage your Merchant Centre without switching between platforms
Why full access is neededFull management access is required to enable product feed management features. A read-only scope would limit Nuvend to displaying data without the ability to take action on your behalf.
Sync frequencyVaries by resource type (approximately every 30 minutes for products; up to 24 hours for reference data)
Initial syncUp to 90 days of recent data, with ongoing backfill of up to 5 years of historical data

5.4 Google Search Console

OAuth scopehttps://www.googleapis.com/auth/webmasters.readonly
Access levelSensitive (read-only)
Data accessedSearch performance data (queries, impressions, clicks, position), URL inspection data, site maps
PurposeDisplaying search engine optimisation analytics within the Nuvend dashboard
Sync frequencyApproximately every 6 hours
Initial syncUp to 90 days of recent data, with ongoing backfill of up to 5 years of historical data

5.5 Shopify

Access scopesread_orders, write_orders, read_products, write_products, read_inventory, write_inventory, read_fulfillments, write_fulfillments, read_locations, read_draft_orders, write_draft_orders, read_returns, write_returns, read_discounts, write_discounts, read_gift_cards, write_gift_cards, read_content. Conditional scopes (require Shopify Partner approval): read_customers, write_customers, read_companies, write_companies
Data accessedProduct data, order data (including customer email, shipping/billing addresses), customer data (name, email, phone number, address, marketing consent), inventory levels, fulfilment data. We also store the complete data record as provided by the Shopify API, which may include additional fields beyond those listed (such as customer tags, order notes, and geographic data).
PurposeDisplaying e-commerce analytics, order reporting, customer insights, and inventory management within the Nuvend dashboard. The write_orders scope enables order management automation (such as updating order tags, adding notes, and managing fulfilment workflows) as directed by you through the Nuvend platform.
Sync frequencyApproximately every 15 minutes
Initial syncUp to 60 days of recent data, with ongoing backfill of up to 5 years of historical data
WebhooksWe receive real-time updates for order, product, and customer changes via Shopify webhooks, verified using HMAC-SHA256 signatures

Shopify customer data: When you connect your Shopify store, we access personal data belonging to your customers (names, email addresses, phone numbers, addresses). This data is classified as Level 2 Protected Customer Data under Shopify's framework. We apply enhanced security measures for this data, including encryption at rest and in transit, role-based access controls, per-organisation data isolation, and audit logging. We process this data solely on your behalf as a data processor. You are responsible for ensuring you have the appropriate legal basis to share this data with us and for informing your customers as required by applicable privacy laws.

5.6 Other platforms

Nuvend supports additional platform connections, including Brightpearl, Freshdesk, Freshsales, and Klaviyo (limited availability). These integrations may access personal data including contact names, email addresses, phone numbers, and postal addresses, depending on the platform and the data you choose to connect. For each platform, the specific data accessed, permissions requested, and sync frequency are displayed to you during the connection setup process. We will update this policy before launching any new platform integrations.

Disconnection

When you disconnect a platform from Nuvend, we immediately:

Soft-deleted data is permanently purged from our primary database — within 30 days for Shopify data, and on account closure for data from other connectors. See Section 12 for full retention details.

Account termination

Upon termination of your Nuvend subscription, we will retain your data for 60 days to allow you to export it. You may request early deletion at any time by contacting privacy@nuvend-ai.com, in which case we will begin the deletion process promptly. After the retention period (or upon early deletion request), we will delete your data in accordance with the retention periods described in Section 12.


6. Google API Services — Limited Use Disclosure

Nuvend's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically:

  1. We only use Google API data to provide user-facing features that are prominent in the Nuvend user interface: analytics dashboards, performance reports, conversion tracking, and campaign and product management tools that you interact with directly.

  2. We do not transfer Google API data to third parties except:

    • To our infrastructure providers (listed in Section 9) solely for providing user-facing features, with appropriate data protection agreements in place
    • To our AI inference provider (listed in Section 9) to power user-facing AI features within the Nuvend platform, such as the AI assistant. Data is processed transiently for inference only. Our AI provider does not retain your data after processing and does not use it for model training.
    • When necessary for security purposes (e.g., investigating abuse)
    • To comply with applicable laws or regulations
    • As part of a merger, acquisition, or asset sale, and only with your explicit prior consent
  3. We do not allow humans to read your Google API data unless:

    • You have given specific, affirmative consent (e.g., when requesting technical support that requires data access)
    • It is necessary for security purposes
    • It is required to comply with applicable law
    • The data is aggregated and anonymised (with all identifiers including organisation IDs removed) for internal operational purposes such as monitoring system performance and maintaining service reliability
  4. We never use Google API data for:

    • Advertising, retargeting, personalised marketing, or interest-based advertising
    • Selling to or sharing with advertising platforms, data brokers, or information resellers
    • Determining credit-worthiness or for lending purposes
    • Surveillance or tracking of individuals
    • Training artificial intelligence or machine learning models

All Google API data is stored in encrypted databases with access controlled by role-based permissions and per-organisation data isolation. Credentials (OAuth tokens) used to access Google APIs are encrypted at rest using AES-256-GCM with envelope encryption.


7. Shopify data handling

GDPR compliance

Nuvend implements all three of Shopify's mandatory GDPR compliance webhooks:

WebhookWhat we do
Customer data request (customers/data_request)We log the request and work with you to provide the relevant stored data for the specified customer within 30 days
Customer data erasure (customers/redact)We remove the specified customer's personal data from active use immediately — across both customer and order records, and in our analytics store — and permanently purge it within 30 days
Shop data erasure (shop/redact)We initiate deletion of all data associated with your shop — across every connected store for that shop, in both our primary database and our analytics store — completed within 30 days of receiving the webhook

All Shopify webhooks are verified using HMAC-SHA256 signatures to prevent tampering.

Data handling on disconnection or uninstall

Disconnection (removing the connection in Nuvend) and uninstall (removing access from your Shopify admin) are distinct events. In both cases:

For uninstalls, Shopify sends us a shop/redact webhook 48 hours after uninstall, confirming that all shop data should be deleted. We complete this deletion within 30 days of receiving the webhook.

If applicable tax or accounting laws require retention of certain records, we will retain only the minimum data required and inform you by email of what is retained and the legal basis for retention.

AI and machine learning

We do not use Shopify Merchant Data or Customer Data (including derived or aggregated data) for training artificial intelligence or machine learning models unless we have explicit written consent from Shopify and/or the merchant, as required by the Shopify Partner Program Agreement.

When you use Nuvend's AI assistant features, Shopify data retrieved to answer your queries is processed by our AI inference provider (Anthropic) for real-time inference only, not for training. Anthropic does not retain this data after processing. See Section 8 for full details on how AI features handle your data.


8. Artificial intelligence features

Nuvend provides an AI assistant as a core feature of the platform, which helps you analyse your business data, build dashboards, and manage your connected platforms through natural language. When you use the AI assistant, your queries and relevant business data are processed by our AI inference provider.

How it works

When you ask the AI assistant a question (for example, "show me revenue trends" or "find orders from this customer"), the assistant may retrieve data from your connected platforms to answer your query. This data, which may include information from your Google, Shopify, or other connected services, is sent to our AI inference provider (Anthropic) as part of the query context.

What data is processed

DataWhen it is sent
Your message to the AI assistantEvery AI interaction
Business data from connected platforms (metrics, order details, customer information)When the assistant retrieves data to answer your query
Conversation history within the current sessionTo maintain context during multi-turn conversations

How your data is protected

AI and your connected platform data

When you use the AI assistant to interact with data from your connected platforms, that data is subject to the same protections described in Section 6 (for Google data) and Section 7 (for Shopify data), in addition to the protections described in this section.

We do not use data from any connected platform to train artificial intelligence or machine learning models.


9. Who do we share data with?

We do not sell, rent, or trade your personal data. We share data with our sub-processors (listed below) and will disclose data where required by law or to protect rights and safety.

Sub-processors

Sub-processorServiceData processedLocationTransfer mechanism
Railway (Railway Corporation)Application hosting, database hosting (PostgreSQL, ClickHouse, Redis), Electric syncAll platform dataEU West (Amsterdam, Netherlands)EU-US Data Privacy Framework (certified); Standard Contractual Clauses (2021 EU SCCs + UK SCCs) in Railway DPA
Resend (Plus Five Five, Inc.)Transactional email deliveryRecipient email addresses, email content (names, organisation names, invitation links)United States (AWS)Standard Contractual Clauses (2021 EU SCCs + UK SCCs, Module 2, governed by Irish law) in Resend DPA
Anthropic (Anthropic PBC)AI inference for the AI assistantUser queries, conversation context, business data retrieved during AI interactions (may include data from connected platforms)United StatesStandard Contractual Clauses (2021 EU SCCs); Anthropic DPA with zero data retention for inference
Autumn (useautumn.com)Billing and subscription managementOrganisation ID, organisation name, email address, feature usage dataUnited StatesLimited account metadata only; sensitive payment and subscription data remains in your own Stripe account (see Stripe). A Data Processing Agreement with Standard Contractual Clauses is being requested from Autumn.
Langfuse (Langfuse GmbH)AI quality monitoring and observabilityAI conversation traces, prompts, completions (may include business data from connected platforms), user feedback scoresEuropean Union (Germany)Data remains within the EEA; no cross-border transfer required
Stripe (Stripe, Inc.)Payment processingPayment method details, billing address, organisation ID, transaction amountsUnited StatesEU-US Data Privacy Framework (certified); Standard Contractual Clauses in Stripe DPA

Railway, Anthropic, and Langfuse process data from your connected platforms (for which we act as processor); Resend, Autumn, and Stripe process only your account and billing data (for which we act as controller).

We will update this list before engaging any new sub-processor. We will notify you at least 30 days before engaging a new sub-processor. If you object, you may terminate the affected services within that notice period. Details of the notification process, objection mechanism, and your remedies are set out in our Data Processing Agreement.

Other disclosures

We will disclose data only where:

End-consumer requests

If we receive a data subject access request directly from one of your end customers (for example, a consumer whose data we process via your Shopify store), we will promptly notify you and will not respond directly unless you instruct us to do so or unless required by law.


10. International data transfers

Nuvend serves customers in the European Union, European Economic Area, the United Kingdom, the United States, and Australia. Our infrastructure providers may process data in locations outside your country of residence.

Safeguards for EU/EEA data

When personal data is transferred from the EU/EEA to countries without an adequacy decision from the European Commission, we rely on:

Safeguards for UK data

For transfers from the United Kingdom, we rely on:

The European Commission renewed the UK's adequacy decision in December 2025, valid until December 2031, meaning data flows freely between the EU/EEA and the UK.

Safeguards for Australian data

Nuvend is established in the European Union (Ireland) and hosts data within the EEA. We do not transfer personal data to Australia; personal data of our Australian customers is processed within the EEA under the safeguards described above.


11. How do we protect your data?

We implement technical and organisational measures to protect your data against unauthorised access, disclosure, alteration, or destruction:

Encryption

Access controls and data isolation

Infrastructure security

Incident response

In the event of a personal data breach:


12. How long do we retain data?

We retain data only for as long as necessary to fulfil the purposes described in this policy or as required by law.

Data categoryRetention period
Account data (name, email, profile)For the duration of your account. Deleted when you delete your account (hard-delete with cascading removal of sessions, memberships, and associated records)
Session data (IP, user agent, session token)7 days from last activity (sessions expire automatically)
Connected platform data (synced orders, products, customers)For the duration of the connection. Soft-deleted immediately on disconnection. Shopify data is permanently purged from our primary database within 30 days of disconnection; data from other connectors is removed when your account is closed
Analytics data (aggregated snapshots in our analytics store)Retained for the life of your account to provide historical analytics. Contains aggregated and behavioural data only — no direct identifiers (names, emails, phone numbers, or raw records), which are held only in our primary database. Deleted on account closure or on a verified erasure request
Connector credentials (OAuth tokens, API keys)For the duration of the connection. Wiped immediately (all encrypted fields nullified) on disconnection
Audit logs3 years from creation (13 months in active storage, remainder in secure archive). Audit logs contain only action metadata, not the personal data involved in the action.
GDPR request logs6 years from date of request completion, to demonstrate accountability under GDPR Article 5(2) and cover civil limitation periods. Logs contain only request metadata (dates, type, response, verification steps), not the personal data that was the subject of the request.
Deletion logs7 years from date of deletion, to cover tax record retention obligations across operating jurisdictions. Logs record what was deleted (category, not content), when, why, and confirmation of completion.

Note: The retention periods for audit logs (3 years), GDPR request logs (6 years), and deletion logs (7 years) are policy commitments. Automated enforcement of these retention limits is planned for implementation.

| Transactional email records | Retained by Resend (our email provider) for the duration of our account; deleted within 90 days of account termination. Backups retained for 7 days. We do not store email content on our own systems beyond the point of transmission. | | OAuth state cookies | 10 minutes (automatically cleared after authentication callback) |

Permanent purge process

Soft-deleted data in our primary database (PostgreSQL) is permanently removed by an automated daily purge process that runs at 3:00 AM UTC, in batches, 30 days after soft-deletion. This process is logged for auditability. Analytics data (see the retention table above) is retained for the life of your account and is deleted on account closure or on a verified erasure request, rather than by the daily purge.


13. Cookies and local storage

Nuvend uses minimal cookies and browser storage. We do not use any third-party tracking cookies, analytics tools, or advertising pixels on the Nuvend platform.

Cookies

CookiePurposeTypeDuration
Session cookieMaintains your authenticated sessionStrictly necessary (httpOnly, Secure)7 days
OAuth state cookies (oauth_state_*)CSRF protection during OAuth authentication flowsStrictly necessary (httpOnly, Secure, SameSite=Lax)10 minutes

Local storage

KeyPurposeDuration
nuvend.activeChat.{workspaceSlug}Tracks the active AI chat session for your current workspacePersistent (until you clear browser data)
nuvend.local-pending.{resourceId}Queues optimistic write operations for data changes24 hours (automatically expires and self-cleans)
nuvend.modelTier.{workspaceId}Stores your preferred AI model tier per workspacePersistent (until you clear browser data)
nuvend.workspace.{slug}.lastSubpathRemembers the last visited page within each workspacePersistent (until you clear browser data)
themeStores your light/dark mode display preference (managed by the next-themes library)Persistent (until you clear browser data)

We do not use tracking cookies, advertising pixels, or any technology that tracks you across third-party websites. Because we use only strictly necessary cookies, we do not require cookie consent under the ePrivacy Directive.


14. Your rights under GDPR (EU/EEA and UK)

If you are located in the European Economic Area or the United Kingdom, you have the following rights regarding your personal data:

RightDescription
Access (Art. 15)Request a copy of the personal data we hold about you
Rectification (Art. 16)Request correction of inaccurate personal data
Erasure (Art. 17)Request deletion of your personal data (subject to legal retention requirements)
Restriction (Art. 18)Request that we limit how we process your data
Notification to recipients (Art. 19)We will notify each recipient to whom your data has been disclosed of any rectification, erasure, or restriction, unless this proves impossible or involves disproportionate effort. We will inform you of those recipients on request.
Data portability (Art. 20)Receive your personal data in a structured, commonly used, machine-readable format (such as JSON or CSV)
Object (Art. 21)Object to processing based on legitimate interest, or to processing for direct marketing purposes (where applicable)
Withdraw consentWhere processing is based on consent, withdraw that consent at any time
Automated decisions (Art. 22)Not be subject to decisions based solely on automated processing that produce legal or similarly significant effects

Nuvend does not engage in automated decision-making or profiling that produces legal or similarly significant effects on you.

How to exercise your rights

Contact us at privacy@nuvend-ai.com with your request. We may ask you to verify your identity before processing your request, to protect your data from unauthorised access. We will respond within one month as required by applicable law. If your request is complex, we may extend this by a further two months, and we will inform you of any extension within the first month.

There is no charge for exercising your rights. If requests are manifestly unfounded or excessive, we may charge a reasonable fee or refuse to act, and we will inform you of our reasons.

Right to lodge a complaint

You have the right to lodge a complaint with your local data protection supervisory authority:


15. Your rights under US privacy laws

California (CCPA/CPRA)

As of 12 July 2026, Nuvend does not meet the revenue or data volume thresholds for CCPA/CPRA applicability. We include this section as a transparency measure and will update it if our status changes.

If you are a California resident and the California Consumer Privacy Act / California Privacy Rights Act applies to our processing of your data, you have the following rights:

RightDescription
Right to knowRequest disclosure of the categories and specific pieces of personal information we have collected
Right to deleteRequest deletion of personal information we have collected
Right to correctRequest correction of inaccurate personal information
Right to opt-outOpt out of the sale or sharing of personal information
Right to limitLimit the use of sensitive personal information
Non-discriminationWe will not discriminate against you for exercising any of these rights

Nuvend does not sell your personal information. Nuvend does not share your personal information for cross-context behavioural advertising. Because we do not sell or share personal information, we are not required to provide a "Do Not Sell or Share" link. Should this change, we will provide this mechanism.

Where we process personal information on your behalf, our use is governed by our Data Processing Agreement, which restricts our use of that information to the purposes set out in our agreement with you.

For retention periods applicable to each category of personal information, see Section 12.

To exercise your rights, contact us at privacy@nuvend-ai.com.

Other US states

If you reside in a US state with applicable consumer privacy legislation (including Virginia, Colorado, Connecticut, and others), you may have similar rights to access, correct, delete, and opt out of certain processing of your personal data. Contact us at privacy@nuvend-ai.com to exercise any applicable rights.


16. Children's privacy

Nuvend is a B2B platform designed for use by businesses and their authorised representatives. Our Service is not directed at, and we do not knowingly collect personal data from, individuals under the age of 16 (or the applicable age of digital consent in your jurisdiction).

If we become aware that we have collected personal data from a child without appropriate consent, we will delete that data promptly. If you believe a child has provided us with personal data, please contact us at privacy@nuvend-ai.com.


17. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our practices, the Service, or applicable laws.

If a change affects how we use data obtained from Google APIs, we will notify you and obtain your consent before implementing the change, in accordance with the Google API Services User Data Policy.

We encourage you to review this policy periodically for the latest information on our privacy practices.


18. Governing law

This policy is governed by and construed in accordance with the laws of Ireland. Any disputes arising from this policy shall be subject to the exclusive jurisdiction of the courts of Ireland, without prejudice to your right to lodge a complaint with your local data protection supervisory authority or to bring proceedings in the courts of your place of habitual residence.

Our liability in connection with this policy is governed by and subject to the limitations set out in our Terms of Service.


19. Contact us

If you have any questions about this Privacy Policy, wish to exercise your privacy rights, or have concerns about how your data is handled, please contact us:

Privacy contactprivacy@nuvend-ai.com
Postal addressBirr Technology Centre, Birr, Co. Offaly, R42 HX39
Websitenuvend-ai.com

For matters related to data we process on your behalf (connected platform data), please refer to our Data Processing Agreement which governs that relationship.

Where your instructions conflict with our legal obligations, we will inform you of the conflict (to the extent legally permitted) and will comply with our legal obligations. We will not process your data in a manner that we believe violates applicable law, even if instructed to do so.


This Privacy Policy was last updated on 12 July 2026.