Legal

Security overview

A summary of the technical and organisational measures we currently apply to protect customer data. This page is descriptive, is provided for information only, and does not form part of any contract. Our binding data protection commitments are set out in the Data Processing Agreement, the Privacy Policy, and the main services agreement. Measures evolve; we may update this page from time to time without notice, provided the overall level of protection is not materially reduced.

Effective: 2026-08-21

1. Governance

NUVENAR LTD (company number 17240693, registered office 128 City Road, London, EC1V 2NX) is registered in England and Wales and is registered with the UK Information Commissioner's Office (ICO) under Data Protection registration reference ZC228344 (valid to 20 August 2027). We operate an information-security programme informed by the control families of ISO/IEC 27001:2022 and the principles of the UK GDPR and the ICO's Accountability Framework.

2. Infrastructure

Production services run on dedicated infrastructure in EU data centres, fronted by an edge network that provides web-application firewall and DDoS mitigation. Third-party services used to deliver features are listed as sub-processors in our privacy policy. Each sub-processor is bound by written terms that impose data protection and confidentiality obligations substantially equivalent to those in our Data Processing Agreement.

3. Encryption

  • Data in transit is protected using TLS 1.2 or higher between end-user devices, our services, and third-party APIs. HSTS is enabled on all customer-facing domains.
  • Data at rest in the primary datastore is encrypted with AES-256 using keys managed by the underlying infrastructure provider.
  • Secrets and API credentials are held in a centralised encrypted store and are not committed to source-control repositories.

4. Access control

  • Staff and contractor access to production systems is role-based, granted on the principle of least privilege, and reviewed periodically.
  • Multi-factor authentication is mandatory for all staff accounts that can access production systems, customer data, or code repositories.
  • Access is revoked promptly on role change or departure.
  • Customers control their own workspace access, including team membership, roles, permissions, and where offered, IP restrictions and single sign-on.

5. Application security

  • Code changes are peer-reviewed and pass automated tests before being deployed to production.
  • Dependencies are scanned for known vulnerabilities and patched on a risk-prioritised basis.
  • The web application is designed with defences against the OWASP Top 10, including input validation, output encoding, prepared statements, CSRF protection, and secure session management.
  • We conduct periodic penetration testing by qualified third parties. Executive summaries are available under NDA on written request from paying customers with a legitimate need.

6. Monitoring and logging

  • Application and infrastructure logs are centralised and retained for a period appropriate to the log type and applicable legal requirements.
  • Authentication events, administrative actions, and security-relevant events are recorded.
  • Automated alerting flags anomalies for review by our on-call team.

7. Backups and business continuity

  • The primary datastore is backed up on an automated schedule. Backups are encrypted and held in a separate geographical region within the EU.
  • Restore procedures are tested periodically.
  • We maintain documented incident response and business continuity procedures.
  • No backup or continuity plan can guarantee zero data loss or zero downtime, and none is warranted here or elsewhere.

8. Vendor and sub-processor management

Before appointing a sub-processor that will process personal data, we assess its security posture, contractual data protection commitments, and location of processing. Our current sub-processor list is maintained in the privacy policy. Notice and objection rights are set out in the Data Processing Agreement.

9. International transfers

Where personal data is transferred to, or accessed from, a country outside the UK, we rely on a lawful transfer mechanism recognised under UK Data Protection Law (a UK adequacy regulation, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or another lawful safeguard). Full detail is in the Data Processing Agreement.

10. Personal data breach response

We maintain a written incident response plan covering detection, containment, eradication, recovery, and communication. In the event of a confirmed personal data breach affecting customer data, we will notify the affected customer without undue delay in accordance with the Data Processing Agreement and applicable law. Our notification is not an admission of fault or liability.

11. Compliance and platform alignment

  • UK GDPR and Data Protection Act 2018. We process personal data in line with the six data protection principles, honour data-subject rights within statutory timeframes, and cooperate with the ICO where required.
  • PECR. Marketing communications and cookie-like technologies are handled in accordance with the Privacy and Electronic Communications Regulations.
  • Meta platforms. Where customers connect WhatsApp Business Platform, Instagram, or Messenger, we operate as a solution provider under the applicable Meta terms (including the WhatsApp Business Solution Terms, WhatsApp Business Messaging Policy, Instagram Platform Policy, and Messenger Platform Policy). Customers remain responsible for their own compliance with those terms.
  • Google APIs. Where customers connect Google Sign-In or other Google services, we handle data received from Google APIs in accordance with the Google API Services User Data Policy, including the Limited Use requirements. We only request the minimum OAuth scopes needed for the connected feature.
  • Payment card data. Card payments are processed by Stripe, a PCI-DSS Level 1 service provider. We do not store, process, or transmit full card numbers, and our environment is not required to be PCI-DSS certified as a result.

12. Customer responsibilities

Security is a shared responsibility. Customers are responsible for establishing the lawful basis for their processing, obtaining and managing end-user consents where required, configuring workspace access controls, safeguarding user credentials, keeping their contact details current, complying with the terms of any third-party platforms they connect, and using the security features made available in the services. We are not liable for the consequences of a customer's failure to do so.

13. Responsible disclosure

If you believe you have identified a security vulnerability in our services, please report it privately to security@nuvenar.com. We ask that you allow us reasonable time to investigate and remediate before any public disclosure, that you do not access, modify, or delete customer data, that you do not degrade the service, and that you do not use social-engineering, phishing, or physical attacks. We do not currently operate a paid bug-bounty programme, but we will acknowledge good-faith reports and, at our discretion, credit reporters publicly with their consent.

14. No warranty

No information-security programme can eliminate all risk. This page describes our current approach in good faith. It is not a warranty, guarantee, or condition of the services, express or implied, and nothing on this page creates any contractual right in favour of any person. Our contractual data protection commitments are set out exclusively in the Data Processing Agreement and the main services agreement.

15. Contact

Security enquiries and vulnerability reports: security@nuvenar.com. General data protection enquiries: support@nuvenar.com.

Get in touch

Leave your details. We reply the same working day.

A tailored walkthrough of NuvenarHub for your business, real pricing for your team size, and a migration plan from whatever stack you run today. No BDR chase.

We use your details to reply and to send occasional product updates. Full detail in our Privacy Policy.