Legal

Privacy Policy

This policy explains what personal data NUVENAR LTD collects, why we collect it, who we share it with, how long we keep it, and the rights you have over it. It applies to nuvenar.com, NuvenarHub, and every service we operate.

Effective: 2026-08-22

Last reviewed: 22 August 2026. We review this policy at least every twelve months and after any material change to the services, sub-processors, or applicable law.

1. Who we are

NUVENAR LTD ("NUVENAR", "we", "us", "our") is a private limited company registered in England and Wales, company number 17240693. Registered office: 128 City Road, London, EC1V 2NX, United Kingdom. We are registered with the UK Information Commissioner's Office under Data Protection registration reference ZC228344 (valid to 20 August 2027). We act as a data controller for personal data submitted through nuvenar.com and as a data processor for personal data customers process inside NuvenarHub. Our Data Protection contact is reachable at support@nuvenar.com. General enquiries: info@nuvenar.com.

2. The personal data we collect

2.1 Information you give us directly

  • Contact form data: name, email address, company, telephone (optional), the message you write.
  • Account registration data: name, email, password (hashed with bcrypt), business name, business address, telephone, billing details.
  • Payment data: handled by Stripe. We never store full card numbers. We retain the last four digits, card brand, expiry, and Stripe customer/payment-method tokens.
  • Customer service correspondence: emails, WhatsApp messages, and in-app assistant transcripts you exchange with our support team.
  • Content you upload to NuvenarHub: contact records, call recordings, transcripts, conversation history, attachments, custom properties, ad creatives, and any other content you choose to store.

2.2 Information we collect automatically

  • Technical data: IP address, user agent, device type, operating system, screen resolution, timezone, referring URL.
  • Usage data: pages visited, features used, click events, error events, session duration, timestamps.
  • Cookies and similar technologies: only essential cookies required to keep you logged in. We use Plausible Analytics for traffic measurement, which is cookieless and does not track across sites.
  • Server logs: HTTP request logs, retained for 30 days for security and debugging.

2.3 Information from third parties

  • Stripe: payment status, charge IDs, customer IDs, subscription IDs.
  • Meta Platforms (WhatsApp Business Platform, Facebook Pages and Messenger, Instagram, Facebook Lead Ads, Meta Ads): when you connect your Meta business assets to NuvenarHub we receive Page identifiers, Page names, Instagram Business Account identifiers, sender identifiers (PSID / IGSID), message content and attachments, conversation and thread metadata, webhook subscription state, lead form submissions, ad performance metrics, and long-lived access tokens issued to us on your behalf. Full detail in section 17 below.
  • Google Ads / TikTok Ads (where connected): campaign performance, ad spend, conversion events.
  • Google (Sign-In and, where you connect it, Gmail): OAuth identity claims (Google account identifier "sub", email address, name, profile picture) when you sign in with Google. When you additionally connect your Gmail account for outbound email, message metadata (headers such as From, To, Subject, Message-ID, thread ID, delivery status) and the ability to send messages on your behalf. We never receive or store the body content of your incoming email. Full detail in section 16 below.
  • Treatwell / Fresha (where connected): booking events, customer contact details.

3. Lawful bases for processing (UK GDPR Article 6)

  • Contract (Art. 6(1)(b)): to deliver and bill for the services you have signed up for, including NuvenarHub subscriptions and bespoke engagements.
  • Legitimate interest (Art. 6(1)(f)): to reply to enquiries, to keep the service secure, to detect abuse, to improve the product, to send transactional emails about your account, and to perform direct marketing to existing customers within reasonable expectations. You can object at any time by emailing us.
  • Legal obligation (Art. 6(1)(c)): to retain tax and accounting records for the period required by HMRC (currently six years from the end of the relevant accounting period), and to respond to lawful requests from courts and regulators.
  • Consent (Art. 6(1)(a)): for non-essential cookies (if any are added in future), for marketing emails to new prospects who are not existing customers, and for any other processing where consent is the only available basis. You can withdraw consent at any time without affecting prior lawful processing.

4. Special category data

We do not require, request, or seek special category data (health, biometric, racial or ethnic origin, political opinions, religious beliefs, trade union membership, sex life, sexual orientation, genetic data) for the operation of NuvenarHub or for the marketing site. Customers who upload such data into their own NuvenarHub workspace do so as data controllers and are responsible for establishing a valid lawful basis under UK GDPR Article 9.

5. Sub-processors and recipients

We share personal data only with the sub-processors that operate the service, only for the purpose set out below, and only under written contracts that mandate appropriate technical and organisational safeguards. The full and current list:

  • Hetzner Online GmbH (Germany / Finland) - cloud hosting infrastructure.
  • Cloudflare, Inc. (USA, UK office) - DNS, CDN, DDoS protection, edge security.
  • Stripe Payments UK, Ltd. (UK) - payment processing, billing, customer portal.
  • Resend, Inc. (USA) - transactional email delivery.
  • Anthropic, PBC (USA) - AI features (Claude). Training on customer data is disabled.
  • OpenAI, LLC (USA) - AI features (GPT and Whisper). Training on customer data is disabled.
  • Twilio Inc. (USA, UK office) - voice calling and SMS (Calling module).
  • Meta Platforms Ireland Ltd. (Ireland) - WhatsApp Business Cloud API, Facebook Lead Ads, Instagram messaging (where customers connect their assets).
  • Google Ireland Ltd. (Ireland) - Google Sign-In (OAuth identity), Gmail API for send + metadata (where you connect a Gmail account), Google Ads sync, optional reCAPTCHA.
  • TikTok Information Technologies UK Ltd. (UK) - TikTok Ads sync (where customers connect their assets).
  • Plausible Analytics OU (Estonia) - cookieless web analytics for nuvenar.com.

We do not sell, rent, or trade personal data. We do not share personal data with advertising networks for re-targeting. Where a sub-processor is added or removed, we will update this list and email account administrators at least thirty (30) days before the change takes effect.

6. International data transfers

Primary storage is in the European Economic Area (Hetzner Helsinki, Finland). Some sub-processors above are based outside the UK and EEA. Where personal data is transferred to a country not subject to a UK adequacy regulation, we rely on the UK International Data Transfer Agreement (IDTA) or the EU Standard Contractual Clauses with the UK Addendum, together with supplementary technical measures including encryption in transit and at rest.

7. Retention

  • Contact form messages: 24 months from receipt, then deleted.
  • Account data (active customers): for the lifetime of the account.
  • Account data (closed accounts): 90 days post-closure to permit reactivation, then anonymised. Billing records retained six (6) years for HMRC.
  • Customer content inside NuvenarHub: until the customer deletes it or the account is closed.
  • Server logs: 30 days.
  • Security event logs: 12 months.
  • Backups: rolling 35-day window, encrypted at rest.

8. Your rights under UK GDPR

You have the right to:

  • Be informed about how we process your data (this notice).
  • Access a copy of your personal data.
  • Correct inaccurate or incomplete data.
  • Erase your personal data (right to be forgotten), subject to overriding lawful obligations.
  • Restrict processing in defined circumstances.
  • Receive your data in a portable, machine-readable format.
  • Object to processing based on legitimate interest or direct marketing.
  • Withdraw consent where consent is the lawful basis.
  • Not be subject to a solely automated decision that produces a legal or similarly significant effect.

To exercise any of these rights email support@nuvenar.com. We respond within one calendar month. We may extend that by a further two months for complex requests, and we will tell you within the first month if we do.

9. Right to complain

You have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk, by phone on 0303 123 1113, or by post at Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF. We would appreciate the chance to address your concern first.

10. Security

We apply organisational and technical safeguards proportionate to the risk. These include: TLS 1.2+ in transit, AES-256 at rest for application databases and backups, bcrypt password hashing, principle of least privilege, scoped API keys, mandatory webhook signature verification, immutable audit logs on security events, multi-factor authentication available on every account, regular dependency scanning, time-bound vendor access, segregated staging and production environments, and incident response procedures. No system is 100 percent secure. We will notify the ICO within 72 hours of becoming aware of a personal data breach where it presents a risk to individuals, and we will notify affected data subjects without undue delay where the breach presents a high risk.

11. Children

Our services are not intended for individuals under 18. We do not knowingly collect personal data from anyone under 18. If you believe we have collected data from a minor, email us and we will delete it.

12. Cookies

We use strictly necessary cookies to keep you logged in. We do not use advertising cookies, tracking cookies, or third-party analytics cookies. Plausible Analytics is cookie-free. See the cookie policy at /legal/cookies for details.

13. Marketing

Existing customers will receive transactional emails about their account and occasional product updates as a legitimate interest. You can opt out at any time by clicking the unsubscribe link in the email or by emailing us. We do not perform email marketing to prospects who have not opted in or to purchased lists.

14. Automated decisions and profiling

We do not make solely automated decisions that have a legal or similarly significant effect on individuals. NuvenarHub uses AI to suggest replies, summarise calls, and route conversations, but the end-user customer (the operator of the NuvenarHub account) makes the final decision in every case.

15. Updates to this policy

If we change this policy in a material way, we will email registered customers at least 30 days before the change takes effect and update the "Last reviewed" date above. Continued use of the services after the change indicates acceptance of the updated policy.

16. Google user data

This section describes how NuvenarHub accesses, uses, stores, shares, and deletes user data received from Google APIs. It applies whenever you sign in to NuvenarHub with Google or connect your Gmail account.

16.1 Scopes we request

  • openid, email, profile (Google Sign-In): required to authenticate you and create or match your NuvenarHub account. We receive your Google account identifier (sub), verified email address, name, and profile picture URL.
  • https://www.googleapis.com/auth/gmail.send (only when you connect Gmail): required to send outbound email from your Gmail address on your behalf, for example follow-up sequences, campaign sends, and one-off messages composed inside NuvenarHub.
  • https://www.googleapis.com/auth/gmail.metadata (only when you connect Gmail): required to detect replies and delivery outcomes on threads you have sent through NuvenarHub, so we can update the conversation status, trigger workflows, and pause sequences when a recipient replies.

We do not request, and we cannot access, any scope that would allow us to read the body content, attachments, or private metadata of your incoming email. Reply detection is limited to knowing that a new message exists on a thread we sent, together with routing headers (From, To, Subject, Message-ID, Date, thread ID, label IDs, size estimate).

16.2 How we use Google user data

  • Authenticate you and create or match a NuvenarHub account.
  • Send outbound email you compose or schedule inside NuvenarHub, from your Gmail address.
  • Detect that a reply has arrived on a thread so the conversation view updates, sequences pause, and workflows fire.
  • Show delivery / bounce / reply state on the conversation timeline.

16.3 What we do NOT do with Google user data

  • We do not use Google user data for advertising, ad targeting, or ad measurement.
  • We do not sell, rent, or trade Google user data.
  • We do not transfer Google user data to any AI provider (including Anthropic, OpenAI, or Voyage AI) for training, inference, or any other purpose. Google user data is never included in prompts to any large language model.
  • We do not read the body content, attachments, or private metadata of your incoming email.
  • We do not share Google user data with any third party other than the infrastructure sub-processors listed in section 5 (Hetzner for hosting, Cloudflare for edge, Resend for transactional NuvenarHub emails), and only to the minimum extent necessary to operate the service.
  • Human employees of NUVENAR LTD do not read your Google user data except (a) with your explicit consent (for example a support ticket where you ask us to look), (b) for security investigations, or (c) to comply with law.

16.4 Storage and security of Google user data

Google OAuth access tokens and refresh tokens are encrypted at rest using AES-256 in the NuvenarHub database and are never exposed to the NuvenarHub frontend or to any third party. Access is restricted to the backend API workers that make outbound Google API calls. Message metadata retrieved via gmail.metadata is stored only as long as the associated NuvenarHub conversation exists, and is deleted immediately when the conversation, contact, or account is deleted.

16.5 Disconnecting and deleting Google user data

You can disconnect your Google account from NuvenarHub at any time from Settings → Integrations → Google. Disconnection (a) calls Google's token revocation endpoint so the OAuth grant is removed on Google's side, (b) permanently deletes the encrypted tokens from our database within seconds, and (c) purges any cached Gmail metadata within 30 days. You can also revoke NuvenarHub's access directly at myaccount.google.com/permissions. Deleting your NuvenarHub account triggers the same purge automatically. To request deletion of any residual Google user data outside these flows, email support@nuvenar.com.

16.6 Google API Services User Data Policy: Limited Use

NuvenarHub's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

17. Meta platform data

This section describes how NuvenarHub accesses, uses, stores, shares, and deletes data received from Meta Platforms (Facebook, Messenger, Instagram, and the WhatsApp Business Platform). It applies whenever a NuvenarHub customer connects a Facebook Page, an Instagram Business or Creator Account, a Meta Ads account, or a WhatsApp Business Account to NuvenarHub. NuvenarHub is a Meta Verified Tech Provider (WhatsApp Business Solution Provider).

17.1 Roles

The NuvenarHub customer (the operator of the connected Meta assets) is the data controller in respect of end-user communications and audience data flowing through those assets. NUVENAR LTD is the processor operating NuvenarHub on the customer's behalf. Meta acts as a separate controller for platform-level data under Meta's own terms.

17.2 Meta permissions we request and the data they return

We request only the permissions required to operate the features the customer has enabled. Depending on the connected asset, the following permissions may be granted to NuvenarHub, and the following data may be received:

  • pages_show_list, pages_manage_metadata - list of Facebook Pages the connecting user administers, Page ID, Page name, Page category, and the ability to subscribe or unsubscribe NuvenarHub's webhook to the Page. Purpose: allow the customer to pick which Page(s) to connect, and receive real-time events for those Pages.
  • pages_messaging - Messenger conversation content sent to or from the connected Page, sender Page-Scoped ID (PSID), attachments, message timestamps, read and delivery receipts, and Page inbox thread metadata. Purpose: unified team inbox, workflow triggers on inbound messages, automated and human replies from within NuvenarHub.
  • pages_read_engagement - basic Page insights and engagement metrics on posts and messaging, where the customer enables reporting features. Purpose: dashboards showing volume, response time, and CSAT for the connected Page.
  • instagram_basic - Instagram Business Account ID, username, profile picture URL, media count. Purpose: identify the Instagram account being connected and display it in NuvenarHub.
  • instagram_business_manage_messages - Instagram Direct Message content sent to or from the connected IG Business Account, sender Instagram-Scoped ID (IGSID), sender username, attachments, timestamps, and thread metadata. Purpose: unified inbox and reply automation for Instagram DMs.
  • instagram_business_manage_comments - comments on the connected IG account's media, commenter username and ID, comment text and timestamps. Purpose: automated comment replies, keyword-triggered DM handoffs, and moderation.
  • instagram_business_content_publish (only where the customer enables scheduled publishing) - the ability to publish or schedule posts on the connected IG Business Account. Purpose: publish content composed inside NuvenarHub.
  • leads_retrieval - lead form submissions from Facebook Lead Ads campaigns owned by the connected Page or Business, including the lead's answers to form questions (typically name, email, phone, custom fields). Purpose: sync new leads into NuvenarHub for CRM, automation, and follow-up.
  • ads_read - ad account ID, campaign, ad-set and ad metadata, spend and performance metrics for the connected Meta Ads account. Purpose: consolidated ad performance dashboards.
  • ads_management (only where the customer enables ad management features) - the ability to create, edit and pause campaigns, ad sets and ads within the connected Meta Ads account. Purpose: campaign management from inside NuvenarHub.
  • business_management - Business Manager ID, name, and the list of assets (Pages, IG accounts, Ad accounts, WABAs) the connecting user administers within that Business. Purpose: correctly scope connected assets and honour Business Manager permissions.
  • whatsapp_business_management - WhatsApp Business Account (WABA) ID, phone number IDs, display name, quality rating, message template inventory, business profile, and webhook subscription state. Purpose: onboard and administer the WhatsApp channel.
  • whatsapp_business_messaging - WhatsApp message content (inbound and outbound), media attachments, sender phone numbers, message and conversation identifiers, delivery, read and failure receipts, per-message pricing category. Purpose: send and receive WhatsApp messages from within NuvenarHub, log conversations, and trigger workflows.

We request only the subset of the above that the customer's enabled features require. Permissions the customer does not need are not requested and, if previously granted, can be revoked by the customer at any time in Meta Business Settings without affecting the rest of the integration.

17.3 Long-lived access tokens

On successful connection, Meta issues NuvenarHub a long-lived Page access token, User access token, or System User access token depending on the flow. These tokens are encrypted at rest using AES-256 in the NuvenarHub database, are never exposed to the NuvenarHub frontend or to any third party, and are accessible only to the backend workers that call Meta's APIs on the customer's behalf. Tokens are rotated when Meta requires it and are deleted immediately on disconnection or account deletion.

17.4 Webhook subscription state

For each connected Page, IG Business Account, or WABA, NuvenarHub subscribes to the specific Meta webhook fields required for the enabled features (for example messages, messaging_postbacks, messaging_reactions, message_reads, feed, mention, messages, message template status updates). We record the subscription state so we can reconcile it after Meta-initiated changes.

17.5 How we use Meta data

  • Deliver and log the customer's connected messaging channels (Messenger, Instagram DMs, WhatsApp) in the NuvenarHub inbox.
  • Trigger workflows, sequences, chatbot flows, and human-agent notifications on inbound events.
  • Retrieve Facebook Lead Ads submissions and sync them to the customer's CRM inside NuvenarHub.
  • Show consolidated Meta Ads spend, delivery and conversion metrics in the customer's dashboards.
  • Provide audit logs of who sent what from the customer's connected assets.
  • Provide customer support to the connecting customer, and troubleshoot integration issues, only where the customer has requested support.

17.6 What we do NOT do with Meta data

  • We do not use Meta Platform Data to advertise, retarget, build cross-service marketing profiles, or measure conversions on unrelated services.
  • We do not sell, rent, lease, licence, or trade Meta Platform Data.
  • We do not use Meta Platform Data to build, augment, train, or fine-tune any machine-learning or artificial-intelligence model, and we do not send Meta Platform Data to any third-party AI provider (including Anthropic, OpenAI, or Voyage AI) for training. Where the customer explicitly enables AI reply suggestions, summarisation, or classification inside NuvenarHub, the specific message content is sent to the customer's chosen AI provider for inference only, is subject to that provider's zero-retention or no-training terms as configured by us, and is never used to train shared models.
  • We do not merge or combine Meta Platform Data with data from any other data source outside the customer's own NuvenarHub workspace.
  • We do not share Meta Platform Data with any third party other than the infrastructure sub-processors listed in section 5, and only to the minimum extent necessary to operate the service the customer has enabled.
  • Human employees of NUVENAR LTD do not read Meta Platform Data except (a) with the customer's explicit consent (for example a support ticket where the customer asks us to look), (b) for security or abuse investigations, (c) to comply with a lawful request, or (d) to enforce our Acceptable Use Policy.

17.7 Retention of Meta data

  • Message content, conversation metadata, contact identifiers (PSID, IGSID, WhatsApp phone number), and Page / IG / WABA identifiers: retained for the life of the customer's NuvenarHub subscription. Deleted within 30 days of the customer disconnecting the asset, deleting the conversation, or closing the account, save for backups (rolling 35-day encrypted window) and legally required retention.
  • Access tokens and refresh tokens: deleted within seconds of disconnection or account closure.
  • Lead Ads submissions: retained inside the customer's CRM until the customer deletes the record.
  • Ad performance metrics: aggregated metrics are retained for reporting continuity; identifiable ad-account associations are deleted on disconnection.
  • Webhook and API logs: 30 days for operational logs, 12 months for security event logs.

17.8 Disconnecting and deleting Meta data

A customer can disconnect any Meta asset from NuvenarHub at any time from Settings → Integrations. Disconnection: (a) revokes the associated access token via Meta'sDELETE /{asset-id}/permissionsendpoint and unsubscribes NuvenarHub's webhook where applicable; (b) deletes the encrypted token from our database within seconds; and (c) purges the associated Meta data from active systems within 30 days.

An end user of a connected Page, IG account, or WhatsApp number can request deletion of their data held by NuvenarHub by contacting the NuvenarHub customer they messaged (the data controller for that conversation). Where a request is directed to us, we will pass it to the relevant customer and, where lawful, action deletion on that customer's instructions.

Meta's programmatic Data Deletion Request: NuvenarHub honours Meta's data-deletion callback protocol. When a Facebook user removes NuvenarHub from their apps at facebook.com/settings?tab=applications, Meta sends a signed deletion callback to NuvenarHub, and we delete the associated data and return a confirmation URL and code that the user can use to check status. The callback endpoint is registered in the Meta App Dashboard and its URL is available from Meta on request.

For any other Meta-data deletion request, email support@nuvenar.com from the address on file for the connected NuvenarHub account or, if you are an affected end user, with enough detail to identify the conversation and Page / IG account concerned.

17.9 Meta Platform Terms compliance

NuvenarHub's use, storage, and sharing of data received from Meta adheres to the Meta Platform Terms, the Developer Data Use Policies, the Messenger Platform Policy, the Instagram Community Guidelines, the WhatsApp Business Solution Terms, and the WhatsApp Business Messaging Policy, each as amended from time to time.

18. Contact and Data Protection Officer

We have not formally appointed a Data Protection Officer because we are not required to under UK GDPR Article 37. For any privacy question, request, or complaint, email support@nuvenar.com. Our postal address is available on request to verified data subjects.

This policy is provided in good faith and reflects our actual data practices as of the effective date above. It does not constitute legal advice. If you need legal advice about how UK GDPR applies to your own organisation, consult a qualified solicitor.

Get in touch

Leave your details. We reply the same working day.

A tailored walkthrough of NuvenarHub for your business, real pricing for your team size, and a migration plan from whatever stack you run today. No BDR chase.

We use your details to reply and to send occasional product updates. Full detail in our Privacy Policy.