Nuvio Loyalty Privacy Policy
for businesses and Client Account users
- This Privacy Policy sets out the rules for processing personal data in connection with the use of the Nuvio Loyalty system, in particular registration, operation of the Client Account, subscription management, billing, technical support and integrations available in the system.
- The controller of personal data is TRIKPAY SPĂĆKA Z OGRANICZONÄ ODPOWIEDZIALNOĆCIÄ, with its registered office in WrocĆaw (52-326), ul. Eugeniusza Kwiatkowskiego 4/3, entered in the Register of Entrepreneurs of the National Court Register under KRS number 0000878223, NIP: 8943162789, REGON: 387922478 (the âControllerâ).
- This Policy applies to businesses entering into an agreement with the Controller, persons representing those businesses and persons authorised to use the Client Account.
- Personal data is processed in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (GDPR) and applicable national legislation.
§ 1 Scope of personal data processed
- The Controller may process identification and contact data, in particular first and last name, e-mail address, telephone number, company name, business or registered-office address, country, NIP or EU VAT ID and the personâs role within the company.
- In connection with the Client Account, user identifiers, login and authentication data, team-member roles and permissions, account-change history and information about active sessions may be processed.
- In connection with entering into and performing the agreement, the Controller may process details of the selected plan, subscription status, billing history, invoice data, payment identifiers and payment status information. The Controller does not store full payment-card details handled by an external payment provider.
- When technical support is used, data contained in tickets, messages and attachments may be processed, as well as the contact history and actions taken to resolve the ticket.
- When the system is used, technical and security data may be processed, in particular the IP address, access date and time, device type, operating system, browser, session identifiers, login history, error logs and security events.
- If the Client uses the affiliate programme, integrations or payment services, the Controller may process referral-attribution data, integration settings, connection status and identifiers assigned by an external provider.
§ 2 Purposes and legal bases of processing
- Creation and operation of the Client Account, entering into and performing the agreement, providing system functionality and managing subscriptions and integrations â Article 6(1)(b) GDPR.
- Verification of persons representing the Client and management of team-member access â Article 6(1)(f) GDPR, namely the legitimate interests of the Controller and the Client in properly conducting the cooperation and controlling access.
- Billing, issuing and retaining accounting documents and compliance with tax obligations â Article 6(1)(c) GDPR in conjunction with applicable tax and accounting legislation.
- Handling enquiries, technical tickets and complaints â Article 6(1)(b) or Article 6(1)(f) GDPR, depending on the nature of the matter.
- Ensuring system security, preventing abuse, diagnosing errors, maintaining service continuity and establishing, pursuing or defending claims â Article 6(1)(f) GDPR.
- Analysing how the system is used and developing its functionality â Article 6(1)(f) GDPR and, for technologies requiring consent, Article 6(1)(a) GDPR.
- Sending commercial information or carrying out marketing activities â on the basis of consent where required by applicable law. Consent may be withdrawn at any time without affecting the lawfulness of processing carried out before its withdrawal.
§ 3 Recipients of personal data and external services
- Data may be disclosed to entities supporting the Controller in providing the services, in particular providers of hosting, cloud infrastructure, databases, authentication, e-mail, security monitoring and technical support.
- Payment and billing data may be disclosed to payment providers, in particular Stripe and, where the relevant services are enabled, Worldline, as well as to accounting and legal service providers.
- Where functions connected with Apple Wallet or Google Wallet are used, necessary technical and configuration information may be disclosed to Apple or Google to the extent required for the selected service to operate.
- Data may be disclosed to public authorities or other authorised entities where required by law.
- Some providers may process data outside the European Economic Area. In such cases, the Controller uses mechanisms required by Chapter V GDPR, in particular adequacy decisions or standard contractual clauses, depending on the basis for the relevant transfer.
§ 4 Cookies, analytics and marketing technologies
- The system uses cookies and similar technologies necessary for login, session maintenance, remembering settings, ensuring security and the correct operation of the Client Account.
- Cookies may also be used to remember information about the referral and affiliate campaign from which the user accessed the system.
- Google Ads and Meta Pixel may be used in the system to measure marketing effectiveness, analyse conversions and create statistics. Their providers may receive technical information, including IP address, device or browser identifiers and information about events in the system.
- The user may restrict cookies in the browser settings. Disabling necessary cookies may prevent login or use of some system functions.
§ 5 Retention period
- Data connected with the Client Account and performance of the agreement is retained for the term of the agreement and subsequently for the period necessary to settle the cooperation and defend against claims.
- Accounting, tax and billing documents are retained for the period required by applicable law.
- Ticket and correspondence data is retained until the matter is closed and subsequently for a period justified by the possibility of pursuing or defending claims.
- Technical and security logs are retained for the period necessary to ensure security, diagnose incidents and prevent abuse.
- Data processed on the basis of consent is retained until the consent is withdrawn or the purpose of processing ceases earlier, subject to retaining limited information needed to demonstrate the granting or withdrawal of consent.
- Data may remain in backups for a limited period in accordance with their secure overwrite cycle.
§ 6 Rights of data subjects
- To the extent provided for by the GDPR, the data subject has the right of access, rectification, erasure, restriction of processing, data portability and the right to object to processing based on Article 6(1)(f) GDPR.
- Where processing is based on consent, it may be withdrawn at any time without affecting the lawfulness of processing carried out before its withdrawal.
- A request to exercise these rights may be sent to iod@nuvio.group. The Controller may verify the requesterâs identity before fulfilling the request.
- The data subject has the right to lodge a complaint with the President of the Polish Personal Data Protection Office or another competent supervisory authority in a Member State of the European Union.
§ 7 Voluntary provision of data and automated decisions
- Providing data is voluntary, but data marked as required is necessary to create the Client Account, enter into or perform the agreement, complete billing or handle a ticket.
- The Controller does not make decisions concerning Client Account users based solely on automated processing that produce legal effects or similarly significantly affect them.
§ 8 Changes to the Privacy Policy and contact
- This Policy may be updated due to changes in law, the operation of the system or external services used. The current version is published on the Nuvio website.
- Privacy questions should be sent to iod@nuvio.group, while other questions about the service should be sent to sales@nuvio.group.
Last updated: 24.02.2026
TRIKPAY SPĂĆKA Z OGRANICZONÄ ODPOWIEDZIALNOĆCIÄ
Owner of the Nuvio brand
ul. Eugeniusza Kwiatkowskiego 4/3, 52-326 WrocĆaw
NIP: 8943162789 | REGON: 387922478 | KRS: 0000878223
