Privacy

1. Controller

The controller for data processing on this website and in the Nuvical platform is novitune Ltd, Ioanni Pasaporti 30, 8543 Koili, Paphos, Cyprus, represented by the Director Sascha Growe. Email: sascha@novitune.com.

2. Hosting and server logs

Our systems run in a data centre in Falkenstein (Saxony, Germany), operated by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. When you visit the website, technically necessary data (IP address, time, page requested, user agent) is processed in server logs. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in secure operation). A data processing agreement under Art. 28 GDPR is in place with the hosting provider.

3. Cookies and local storage

We do not use tracking or marketing cookies. For the login, a technically necessary session token is stored in your browser's local storage. Functional settings (for example language or sidebar state) are stored locally as well. Legal basis: Art. 6(1)(f) GDPR.

4. Registration, customer account and sign-ins

When you create a Nuvical account as a studio, we process your name, email address and password (stored encrypted) in order to provide your account.

Clients of a studio sign in without a password: they enter their email address or phone number and receive a one-time sign-in code by email, SMS or WhatsApp. For this we process the address or number provided and the code, which is only valid for a short time. The messages are delivered by the providers listed in point 10.

The legal basis in each case is Art. 6(1)(b) GDPR (performance of a contract).

Sign-in and security logs. We log sign-ins and sign-in attempts to the admin area with the time, IP address, device and browser information (user agent), the account concerned and whether the attempt succeeded. Changes made by studio managers or our support team (for example to roles, permissions or settings) are logged with the account, time and type of change. The purpose is the security of our systems: detecting and preventing misuse and unauthorised access, and keeping changes traceable. The legal basis is Art. 6(1)(f) GDPR; this also meets our obligations under Art. 32 GDPR. Failed sign-in attempts are deleted after 7 days. For successful sign-ins, the IP address is truncated and the device information removed after 30 days, and the entry is deleted after 90 days. For all other log entries, the IP address is removed after 90 days and the entry is deleted after 3 years. Records of acceptance of our contract terms are kept for as long as the contract exists and claims arising from it can be asserted.

5. Data of studios and their clients (processing on instruction)

Where businesses (studios, practices) use Nuvical to manage their appointments and client data, we process that data as a processor on behalf of the respective business (Art. 28 GDPR). The controller for that data is the business itself. Sensitive fields are stored encrypted (AES-256-GCM). The providers named in point 10 act as sub-processors in this context. The studios' payment service providers are not among them (see point 8).

6. Nuvical apps (iPhone and Android)

With the Nuvical app you book and manage appointments at studios that use Nuvical. We process appointment, client and payment data on behalf of the respective studio (see point 5). In addition:

Notifications (push). Only once you are signed in and allow notifications on your device does your device create a push identifier (token). We store it together with the operating system, app version and app language in order to send you notifications. Creating the push identifier is strictly necessary for the notification service you requested (§ 25(2) no. 2 TDDDG). We send booking confirmations, reminders, cancellations and notices about vouchers you have bought on the basis of Art. 6(1)(b) GDPR. You only receive promotional notifications from a studio, such as an offer after a longer time without a visit, if you have agreed to receive marketing (Art. 6(1)(a) GDPR). When you sign out or delete your account we remove the push identifier. You can turn notifications off at any time in your device settings.

Notifications are delivered through the device manufacturers' services. On Android we use Firebase Cloud Messaging by Google Ireland Ltd. as a processor (see point 10). On iPhone, notifications are delivered by the Apple Push Notification service. Apple (Apple Distribution International Ltd., Hollyhill Industrial Estate, Cork, Ireland) processes the push identifier, the time and the content of the notification as an independent controller. In both cases a transfer to the USA is possible. For Google it is covered by the EU-US Data Privacy Framework and EU standard contractual clauses, for Apple by EU standard contractual clauses. More information: apple.com/legal/privacy.

Permissions. The app only asks for access a feature needs, and only when you use that feature. You can withdraw any permission in your device settings.

  • Camera: to scan the QR code at the studio, for your profile picture and for photos related to your appointment. Photos are only uploaded if you save or send them yourself. The QR code is recognised entirely on your device.
  • Calendar: only to add your appointments to your device calendar. The app does not read your calendar.
  • Face ID or fingerprint: to unlock the app quickly. The check is done by your device. We receive no biometric data, only the result.

Deleting your account. You can delete your account directly in the app: Profile, Personal details, Delete account. This removes your personal data at every studio your account is linked to and deactivates your sign-in account. Bookings and invoices are kept without any link to you where studios are legally required to retain them. Further options are described on the data deletion page.

7. Contacting us through this website (email, WhatsApp)

If you contact us through the options on this website (email or the WhatsApp button), we process the data you send us (for example name, phone number, email address, message content) solely to handle your enquiry. You contact us on your own initiative, so no prior consent is required. The legal basis is Art. 6(1)(b) GDPR (pre-contractual measures) or Art. 6(1)(f) GDPR (legitimate interest in replying). If you write to us via WhatsApp, your phone number and message content are additionally processed by WhatsApp Ireland Ltd. (Meta Platforms Ireland Ltd.); their privacy notice applies in addition, and any transfer to the USA is covered by EU standard contractual clauses or the EU-US Data Privacy Framework. We keep your enquiry only for as long as it is needed to handle it.

8. Payments

Billing of our plans. We collect the fees for Nuvical through Stripe Payments Europe Ltd. (Ireland). Payment-related data is transmitted to Stripe; a transfer to the USA is possible and is covered by EU standard contractual clauses. Legal basis: Art. 6(1)(b) GDPR.

Payments to studios. If you pay a studio through Nuvical, for example a deposit, a voucher or in person by card, the studio is the payee and the controller for this data. The payment is processed by the payment service provider chosen by the studio (currently Stripe or Viva.com), with whom the studio holds its own account. On the studio's behalf we only transmit the details needed for the payment (amount, service and, where applicable, your email address) and receive the payment status. You can find more details in the privacy policy of the studio and of the respective payment service provider.

Apple Pay and Google Pay. If you pay in the app with Apple Pay or Google Pay, the respective provider (Apple Distribution International Ltd. or Google Ireland Ltd., both Ireland) processes your payment data as an independent controller. The studio and its payment service provider do not receive your card number, only an encrypted payment token.

Fraud prevention. Stripe additionally processes payment and device data as an independent controller in order to prevent fraud (Art. 6(1)(f) GDPR). More information: stripe.com/privacy.

In all cases, full card and account details are processed exclusively by the payment service provider, not by us.

9. WhatsApp notifications (optional, with consent)

If a studio activates the WhatsApp channel and you consent to receiving WhatsApp messages when booking, we send appointment confirmations, reminders and cancellations and answer enquiries through the WhatsApp Business Cloud API. Provider: WhatsApp Ireland Ltd. (Meta Platforms Ireland Ltd., 4 Grand Canal Square, Dublin 2, Ireland). Your phone number and the message content are transmitted; a transfer to the USA is possible and is covered by EU standard contractual clauses or the EU-US Data Privacy Framework. Legal basis: Art. 6(1)(a) GDPR (consent) and Art. 6(1)(b) (appointment communication). You can withdraw your consent at any time with effect for the future (reply "STOP" or email sascha@novitune.com). We then send you no further WhatsApp messages. We delete the previous message history on request, and at the latest once it is no longer needed to handle the appointment.

10. Overview of processors

ProviderPurposeLocationThird country
Hetzner Online GmbHServer hosting (Falkenstein data centre)Germanynone
Stripe Payments Europe Ltd.Billing of Nuvical plansIrelandUSA (SCC)
Meta Platforms Ireland Ltd.WhatsApp delivery (Business Cloud API)IrelandUSA (SCC / DPF)
Twilio Inc.SMS deliveryUSA / IrelandUSA (SCC / DPF)
Sendinblue SAS (Brevo)Email deliveryFrancenone (EU)
Google Ireland Ltd.Push notifications on Android (Firebase Cloud Messaging)IrelandUSA (DPF / SCC)

11. Your rights

You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21). You can withdraw consent you have given at any time with effect for the future. You can also exercise your right to erasure yourself in the Nuvical app: Profile, Personal details, Delete account (see point 6). For all such matters, write to sascha@novitune.com.

12. Right to lodge a complaint

You have the right to lodge a complaint with a data protection supervisory authority. The competent authority is the one at the controller's seat (Office of the Commissioner for Personal Data Protection, Cyprus, dataprotection.gov.cy) or the authority where you usually reside.

13. Storage period

We store personal data only for as long as it is needed for the purposes described or for as long as statutory retention obligations apply (for example tax law periods for invoice and point-of-sale data).

14. SSL/TLS encryption

The entire website and platform is delivered over HTTPS (TLS). The connection between your browser and our server is encrypted.

15. Changes to this policy

We may adapt this privacy policy if requirements or our data processing change. The current version is always available on this page with its date.

Last updated: September 2026. This English version is provided for convenience. In case of differences, the German version prevails.