GDPR
How we protect your privacy
on nizu.io and when you use our services
NIZU OÜ and its affiliates offer many services to help you run
your
business, including a platform to
host your
own NIZU database. As part of running those services we collect data about you and your
business.
This data is
not only essential to run our services, but also critical for the safety of our services and
all
our
users.
This policy explains what information is collected, why it is collected, and how we
use
it.
Information we collect
Most of the personal data we collect is directly provided by our users when they register and use our services. Other data is collected by recording interactions with our services.
Account & Contact Data: When you register on our
website
to
use or download one of our
products, or to
subscribe to one of our services (NIZU Online, Free Trial, NIZU Apps, nizu.io, etc.), or
fill in
one
of our
contact forms, you voluntarily give us certain information. This typically includes your
name,
company name,
email address, and sometimes your phone number, postal address (when an
invoice
or
delivery is
required),your business sector and interest in NIZU, as well as a personal
password.
We never record or store credit card information from our customers, and always
rely on
trusted
third-party PCI-DSS-compliant payment processors for credit
card
processing,
including for recurring payment processing.
Job Application Data: When you apply for a job on our website
or
via an employment agency, we
usually
collect your contact information (name, email, phone) and any information you choose to
share
with us in
your introduction letter and Curriculum Vitae.
For certain positions with a higher risk of application fraud, we may also collect your passport
or
ID number,
for the purpose of uniquely identifying candidates.
If we decide to send you a job proposition, we will also ask you to provide extra personal
details
as required
to fulfill our legal obligations and personnel management requirements.
We will not ask you to provide information that is not necessary for the
recruitment
process. In
particular, we will never collect any information about your racial or ethnic origin,
political opinions,
religious beliefs, trade union membership or sexual life.
Browser Data:
When you visit our website and access our online services, we detect and store your browser
language and
geolocation
in order to customize your experience according to your country and preferred language.
Our servers also passively record a summary of the information sent by your browser for
statistical,
security
and legal purposes:
your IP address, the time and date of your visit and the page or resource
you
are
accessing, your browser version and platform, and the web page
that referred you to our website.
Your browser may also be used to store and retrieved your current session data, with the help of
a
session
cookie
(see also the Cookie section for more details).
Form protection: some forms on our website may be protected by Google reCAPTCHA. This technology relies on heuristics that are based on technical characteristics of your browser and device, and may also use specific Google cookies. See also Google Privacy Policy and Terms of Use in the Third Party Service Providers section below.
Customer Databases: When you subscribe to an NIZU Cloud service and
create your own
NIZU database (for example by starting a Free Trial), any information or content you submit or
upload into your
database is your own, and you control it fully.
Similarly, when you upload an on-premises database to the NIZU Upgrade website, you own
the
data in it.
This data will often include personal information, for example: your list of employees,
your contacts
and customers, your messages, pictures, videos, etc. We only ever collect this
information
on your
behalf, and you always retain ownership and full control on this data.
Free Trial Session Recording: When you start a free trial on
our
NIZU Cloud service, you may
be offered
the possibility to consent to the recording of the beginning for your free trial session in
order to
help us
improve the user experience of our products.
If you consent, the information that is collected includes what is visible on the
screen during
the first 2 hours of your free trial, as well as your interactions with our apps
(where you
click, which menu you open, etc.). This data is consolidated in the form of a video that our
User
Experience
experts can watch for a limited time.
This will likely include some personal data such as names, emails, phone numbers,
pictures,
depending on what real-world information you input into your database during the recording
period.
Password
fields and other sensitive fields are automatically excluded from the recording, but we
cannot entirely
exclude the possibility that some sensitive information may be recorded, depending on where you
type
it.
The other sections of this Policy explain:
- how we process this data,
- how long we keep it,
- and how you can access or request deletion of this data
- and which third-party service providers are involved.
If you do not consent or if we do not offer you the option to opt-in, your trial session will not be recorded and no data will be collected for this purpose.
Github.com Account Data: When you subscribe to the nizu.io platform and create your project, the platform requires authorization to access your Github.com account, which includes an OAuth token granting access to your account, and later, the contents of your project repository.
In-App Purchase (IAP) Transaction Data: When you use NIZU on
the
NIZU Cloud or on your own
self-hosted
deployments, some optional "In-App Purchase" services may be active by default. This typically
includes
auto-completion features to help you quickly input client and supplier info, as well as
integration
with
third-party service providers for sending and receiving SMS, WhatsApp Messages, Telegram
Messages,
paper letters, etc.
When you use these services, with or without payment, some necessary transaction data is
transmitted to
NIZU Cloud services and have to be communicated to third-party services for the purpose of
executing
the
service. You can find the detailed privacy policy for each service on the IAP Privacy Policy page.
The IAP services are always optional, even when enabled by default, and the IAP Privacy Policy also explains how you can opt-out of those services.
How we use this information
Account & Contact Data: We use your contact
information
in
order to provide our services,
to answer
your requests, and for billing and account management reasons. We may also use this
information
for
marketing
and communication purposes (our marketing messages always come with a way for you to opt-out
at
any
time). We
also use this data in aggregated/anonymised form in order to analyze service trends.
If you have registered to participate in an event published on our website, we may
transfer
your name,
email address, phone number and company name to our local organizer and to
the
sponsors of the
event for both direct marketing purposes and in order to facilitate the preparations and
booking
for
the event.
If you have expressed interest in using NIZU or otherwise asked to be contacted by an
NIZU
service
provider, we may also transfer your name, email address, phone number and company
name
to one of
our official Partners in your
country
or
region, for
the purpose of contacting you to offer their local assistance and services.
Job Application Data: We will only process this information for our recruitment process, in order to evaluate and follow-up with your application, and in the course of preparing your contract, if we decide to send you a job proposition. You may contact us at any time to request the deletion of your information.
Browser Data: This automatically recorded data is
anonymously
analyzed in order to maintain
and improve
our services. Google reCAPTCHA may also be used for security purposes, in order to prevent
abuse
of
our
services. In that case we only process the anonymous score that reCAPTCHA determines based
on
your
browser and
device.
We will only correlate this data with your personal data when required by law or for
security
purposes, if
you have violated our Acceptable Use Policy.
Customer Database: We only collect and process this data
on
your
behalf, in order to perform
the services
you have subscribed to, and based on the instructions you explicitly gave when you
registered or
configured your
service and your NIZU database.
Our Helpdesk staff and engineers may access this information in a limited and
reasonable
manner in order
to solve any issue with our services, or at your explicit request for support reasons, or as
required by law, or
to ensure the security of our services in case of violation of our Acceptable Use Policy in order to keep our services secure.
Free Trial Session Recording: The purpose of these
recordings
is to
improve our products: they will be seen and analysed solely by our R&D Usability team,
who
will
treat your
data as strictly confidential information. By watching the recordings they will be able to
see a
tangible
representation of a user’s first steps into NIZU and improve the User Experience
accordingly.
The recordings are processed and stored with tools provided by FullStory (cf.
our
list
of service providers), under strict confidentiality terms.
The other sections of this Policy explain :
Github.com Account Data: During the configuration phase of your nizu.io project, the platform uses your OAuth token to setup the Github.com project you will use for nizu.io, including the necessary web hooks and deployment key to allow nizu.io to detect every commit you push to your project repository. The OAuth token is not stored and is deleted as soon as you close your nizu.io session, or after 2 days.
The contents of your project repository is stored as long as your nizu.io subscription is active in order to provide the service itself.
Our Helpdesk staff and engineers may access this information in a limited and reasonable manner in order to solve any issue with our services, or at your explicit request for support reasons, or as required by law, or to ensure the security of our services in case of violation of our Acceptable Use Policy in order to keep our services secure.
In-App Purchase (IAP) Transaction Data: You can find the detailed privacy policy for each service on the IAP Privacy Policy page.
Accessing Your Data
Accessing, Updating or Deleting Your Personal Information
Account & Contact Data: You have the right to access and update personal data you have previously provided to us. You can do so at any time by connecting to your personal account on nizu.io. If you wish to permanently delete your account or personal information for a legitimate purpose, please contact our Helpdesk to request so. We will take all reasonable steps to permanently delete your personal information, except when we are required to keep it for legal reasons (typically, for administration, billing and tax reporting reasons).
Job Application Data: You may contact us at any time to request access, updates or deletion of your application information. The easiest way to do it is to reply to the last message you exchanged with our Human Resource personnel.
Customer Database:You can manage any data collected in
your
databases hosted on nizu.io at
any time,
using your administration credentials, including modifying or deleting any personal data
stored
therein.
At any time you can export a complete backup of your database via our control panel,
in
order
to transfer
it, or to manage your own backups/archive. You are responsible for processing this data in
compliance with all
privacy regulations.
You may also request the deletion of your entire database via your control panel, at
any
time.
When you use the NIZU Database Upgrade service, your data is automatically deleted
after
your
upgrade was successfully completed, and may also be deleted upon request from you.
Free Trial Session Recording:
You
may
contact us at any time to
request access
to or deletion of the recording of your trial session (see contact info below). Please
remember
to
include the
name or the URL of your database (e.g. mydatabase.nizu.io) to allow us to retrieve
your
specific
recording. Recordings are automatically destroyed after 2 months, so if your trial is older
than that the data does not exist anymore.
The other sections of this Policy explain :
- what is recorded,
- how we process this data,
- how long we keep it
- and which third-party service providers are involved.
Github.com Account Data: You can view and manage the
project
repository data collected from
your
Github.com account directly on nizu.io.
You may request the deletion of this information via your control panel on nizu.io, at
any
time.
You can also request the deletion of your Github.com OAuth token by simply logging out
from
nizu.io.
In-App Purchase (IAP) Transaction Data: You can find the detailed privacy policy for each service on the IAP Privacy Policy page.
Safety Retention Period: we retain a copy of your data in our backups for safety reasons, even after they are destroyed from our live systems. See Data Retention for more details.
Security
We realize how important and sensitive your personal data is, and we take a great number of measures to ensure that this information is securely processed, stored and preserved from data loss and unauthorized access. Our technical, administrative and organizational security measures are described in details in our Security Policy.
Third Party Service Providers / Subprocessors
In order to support our operations we rely on several Service Providers. They help us with various services such as payment processing, web audience analysis, cloud hosting, marketing and communication, etc.
Whenever we share data with these Service Providers, we make sure that they use it in compliance with Data Protection legislation, and that the processing they carry out for us is limited to our specific purpose and covered by a specific data processing contract.
Below is a list of the Service Providers we are currently using, why we use them, and what kind of data we share with them.
In-App Purchase (IAP): The list of third-party service providers for each IAP service is available on the IAP Privacy Policy page.
A. Subprocessors
These third-party service providers are processing data for which NIZU is Controller or
Processor,
on behalf of NIZU.
Important: due to the great variability in resources and services provided by these subprocessors, NIZU Customers cannot select the subprocessor that will be used to process their data. They can however choose their main hosting region (see the Data Location section).
Purpose and Shared Data
Subprocessors
-
Hetzner Online GmbH
Privacy & Security
Purpose
-
Infrastructure and hosting of nizu.io (production + backups), NIZU OÜaS (production + backups), nizu.io (backups), DDOS Protection.
Shared Data
-
Currently hosted by Hetzner: Production data from nizu.io and its affiliate services, including Customer Databases; Backup data.
Data Center Certifications: ISO 27001:2022, SOCOTEC.
-
Paypal
Privacy & Security
-
Payment processing on nizu.io.
-
Order details (amount, description, reference), Customer name and email.
Only stored by Paypal: credit card info.
-
Stripe
Privacy & Security
-
Payment processing on nizu.io.
-
Order details (amount, description, reference), Customer name and email.
Only stored by Stripe: credit card info.
Data Retention
Account & Contact Data: we will only retain such data as long as necessary for the purpose for which it was collected, as laid out in this policy, including any legal retention period, or as long as necessary to carry out a legitimate and reasonable promotion of our products and services.
Job Application Data: If we do not hire you, we may keep the information you provide for up to 3 years in order to contact you again for any new job proposition that may come up, unless you ask us not to do so. You may ask us to erase your personal information earlier, however we will retain a minimal subset of information, specifically your name, email address, and passport/ID number, for a limited period of 18 months. This retention is strictly necessary to protect the integrity of our recruitment process (prevention of repeated applications for the same position, test fraud, and defense of our legal interests). If we hire you, your personal information will be stored for the duration of your employment contract with us, and afterwards, during the applicable legal retention period that applies in the country where we employed you.
Browser Data: we may retain this data for a maximum of 12 months, unless we need to keep it in relation with a legitimate concern related to the security or performance of our services, or as required by law. Any server-side session information is discarded maximum 7 days after it stops being actively used.
Server Logs & Security Logs: we retain those logs for a maximum of 12 months, unless we need to keep them in relation with a legitimate concern related to the security or performance of our services, or as required by law.
Customer Database: we will only retain this data as long as necessary for providing the services you subscribed to. For databases hosted on the NIZU Cloud, if you cancel the service your database is kept deactivated for 3 weeks (the grace period during which you can change your mind), and then destroyed. For databases uploaded to the NIZU Database Upgrade website, your database is kept for up to 4 months after the last successful upgrade, and may be deleted earlier upon request.
Free Trial Session Recording: The recordings are automatically deleted after 2 months, and may be deleted earlier once they have been processed, or considered irrelevant, or upon request.
Github.com Account Data: we keep this data as long as your nizu.io subscription is active, except the OAuth token which is deleted after 2 days, or as soon as you logout from nizu.io.
In-App Purchase (IAP) Transaction Data:You can find the detailed privacy policy for each service on the IAP Privacy Policy page.
Safety Retention Period: As part of our Security Policy, we always try to preserve your
data
from
accidental or malicious deletion. As a result, after we delete any of your personal
information
(Account &
Contact Data) from our database upon request from you, or after you delete any personal
information
from your
database (Customer Database), or if you delete your entire database, it is not immediately
deleted
from our
backup systems, which are secured and inalterable. The personal data could remain stored for
up
to
12 months in
those backups, until they are automatically destroyed.
We commit not to use those backup copies of your deleted data for any purpose except
for
maintaining the
integrity
of our backups, unless you or the law require us to do so.
Physical Data Location / Data Transfers
Hosting Locations
Production & Backups
Customer databases are hosted in the NIZU Cloud Hosting Region closest to where they are situated, and can request a change of region (subject to availability).
In addition to the production copy, NIZU commits to maintaining at least three redundant backup copies of each customer database, stored in separate data centers that are geographically distant enough to ensure resilience against region-wide and country-wide incidents.
The table below lists the current countries hosting production environments and backups for each NIZU hosting region. These locations may evolve within the same region as needed to maintain service continuity, performance, and compliance with contractual and legal obligations.
It is not possible to choose or restrict the backup locations. The same locations are used for all customers within the same hosting region to ensure consistency and data integrity.
| Hosting Region | Production Location | Backup Locations |
|---|---|---|
| Europe (DE, BE, FI, CH) | Europe (DE, BE, FI, CH) | Europe (DE, BE, FI, CH) |
: countries with this sign are in the
EU or currently subject to an adequacy decision from EU authorities.
Database Upgrades
Customer databases are upgraded within their current production hosting location (see
above)
or
on a global upgrade server located in Europe
In-App Purchase (IAP) Transaction Data
You can find the detailed privacy policy for each service on the IAP Privacy Policy page.
Free Trial Session Recording
Free trial sesssions recording data is processed by FullStory (see our Service
Providers) in Google Cloud data centers located in the United States. As a reminder,
this
data is only
recorded if you opt-in and is only
kept for a
very limited time.
International Staff
In some cases, the personal data mentioned in this Privacy Policy may be accessed by staff
members
of NIZU OÜ
subsidiaries in other countries. Such access will always be done for the same purposes and
with
the
same privacy
and security precautions as if it was done by our own local staff, so all the guarantees we
provide
still apply.
NIZU uses EU Standard Contractual Clauses to bind subsidiaries
in a
way
that offers
sufficient safeguards on data protection for the limited and temporary data transfers that
occur
for
such
access.
Third Party Disclosure
Except as explicitly mentioned above, we do not sell, trade, or otherwise transfer your personal data to third parties. SMS/text messaging opt-in is excluded from any data transfer covered above. We may share or disclose aggregated or de-identified information, for research purposes, or to discuss trends or statistics with third-parties.
Policy Updates
We may update this Privacy Policy from time to time, in order to clarify it, to reflect any changes to our website, or to comply with legal obligations. The "Last Updated" mention at the top of the policy indicates the last revision, which is also the effective date of those changes. We give you access to archived versions of this policy, so you can review the changes.
Contacting Us
If you have are any question regarding this Privacy Policy, or any
enquiry about your personal
data,please reach
out to the NIZU Helpdesk or contact us via email at privacy@nizu.io or by post:
NIZU OÜ. - Data Protection
Lasnamäe linnaosa, Lõõtsa tn 5-11
11415 Tallinn
Estonia
VAT: EE102264113