This policy explains what personal data Nvoria collects, why we collect it, and what rights you have. It covers the website at nvoria.com and the Nvoria platform, which is currently in private beta.
Nvoria provides a corporate events and gifting platform to organisations. We handle personal data in two distinct roles.
As a controller (a “data fiduciary” under India's Digital Personal Data Protection Act, 2023) for data about our website visitors, prospective customers, and the administrators and contacts at organisations we work with. We decide why and how that data is used, and this policy describes it.
As a processor (a “data processor”) for data that a customer organisation puts into the platform about its own employees, guests, recipients, and vendors. In that case the customer decides why and how the data is used, and we act on its instructions. If you are an employee or guest of a Nvoria customer and want to know how your data is being used, please contact that organisation first; we will help them respond.
We do not buy marketing lists, and we do not sell personal data.
Where the DPDP Act applies, we rely on your consent or on legitimate uses recognised by that Act. Where the EU or UK GDPR applies, our legal bases are performance of a contract, legitimate interests (securing and improving the Services, and business communications with corporate contacts), consent (for marketing and non-essential cookies), and compliance with legal obligations. We do not use personal data for automated decision-making that produces legal or similarly significant effects.
Transactional emails are part of the Services and are sent to people who have accounts or who have been invited to an event or gifting programme by a customer organisation. Some notification types can be adjusted in your settings; core service and security messages cannot be switched off while your account is active.
Marketing emails are sent only with consent or where otherwise permitted, and always include a one-click unsubscribe link. You can also email privacy@nvoria.com to opt out. Opting out of marketing does not affect your access to the Services.
If a customer organisation sends messages to you through Nvoria, that organisation is the sender and controls the list. We will pass opt-out and deletion requests to them and will honour suppression requests at the platform level so that the address is not contacted again through our infrastructure.
We use strictly necessary cookies to keep you signed in, maintain your session, remember preferences, and protect against cross-site request forgery. These are required for the platform to work. Where we use analytics or other non-essential cookies, we ask for consent first and you can withdraw it at any time. Most browsers let you block or delete cookies, though blocking necessary cookies will prevent sign-in from working. This site's public landing pages set no cookies.
We share personal data only as described here:
We do not sell personal data and we do not share it with advertisers for their own purposes.
Our primary infrastructure is hosted in India (AWS Asia Pacific (Mumbai)). Some service providers may process limited data outside India. Where we transfer personal data across borders, we do so in accordance with applicable law and put appropriate safeguards in place, such as standard contractual clauses or equivalent contractual protections.
When a customer's contract ends, we delete or return customer data in line with the agreed terms. Backups are purged on a rolling schedule.
We encrypt data in transit using TLS and at rest using managed keys. Access to production systems is restricted to authorised personnel, protected by single sign-on and least-privilege roles, and logged. Customer workspaces are isolated at the database level. We run a web application firewall and rate limiting in front of our services, keep audit trails of significant actions, and review access periodically. No system can be guaranteed completely secure, but we work to protect data and will notify affected people and regulators of a reportable breach as required by law.
Depending on where you live, you may have the right to:
To exercise any of these, email privacy@nvoria.com. We will respond within 30 days. We may need to verify your identity first. If we act as a processor for a customer organisation, we will forward your request to them and support their response.
The Services are for business use and are not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child's data has been provided to us, contact us and we will delete it.
We may update this policy as the platform develops. If a change is material we will give notice by email or through the Services before it takes effect. The “last updated” date above always reflects the current version.
Privacy and data protection: privacy@nvoria.com
General enquiries: hello@nvoria.com
Security reports: security@nvoria.com