Privacy Policy
Last updated: April 15, 2025
At Novyse ("we", "us", or "our"), we take your privacy and data sovereignty seriously. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website, download our applications, or use our secure communication platform.
1. Data Controller & Contact Information
The Data Controller responsible for the processing of personal data collected through this website and the Novyse platform under the EU General Data Protection Regulation (GDPR - Regulation EU 2016/679) and the Italian Privacy Code (D.Lgs. 196/2003 as amended) is:
Entity Name: Novyse Development Team / Novyse Platform
Operational Origin: Italy / European Union
Primary Contact: contact@novyse.com
Data Protection Contact: privacy@novyse.com
2. Information We Collect & Data Minimization
In compliance with the GDPR principle of data minimization (Article 5(1)(c)), we only collect information that is strictly necessary for providing and securing our services.
2.1 Information You Voluntarily Provide
- Account Registration: When you register for an account, we collect your username, email address, and authentication credentials (hashed and salted via modern cryptographic algorithms like Argon2id or OPAQUE protocol).
- Newsletter Subscription: If you voluntarily subscribe to product announcements, we collect your email address with your explicit opt-in consent.
- Support Communications: When you email our support or billing team, we retain correspondence history to resolve your inquiries.
2.2 Technical & Usage Data
- Server Log Data: Temporary connection logs containing IP address, user-agent, and connection timestamps strictly for security, DDoS mitigation, and firewall operation. These logs are automatically rotated and purged.
- Client Performance & Telemetry: By default, our self-hostable binaries have telemetry disabled (
telemetry: false). Any crash reports are strictly opt-in and sanitized.
2.3 End-to-End Encrypted Content (E2EE)
Private 1-on-1 messages and direct voice/video streams are end-to-end encrypted using state-of-the-art cryptographic protocols. Novyse does not hold decryption keys and cannot read, decrypt, or share the plaintext contents of your private communications.
3. Lawful Bases for Processing (GDPR Art. 6)
We process your personal data only when an explicit legal ground applies:
| Purpose | Data Category | GDPR Lawful Basis |
|---|---|---|
| Providing communications & platform services | Account credentials, username, email | Performance of a contract (Art. 6(1)(b)) |
| Newsletter & product updates | Email address | Consent (Art. 6(1)(a)) |
| Network security, DDoS prevention & bug fixes | IP address, server logs, error data | Legitimate interests (Art. 6(1)(f)) & Legal obligation (Art. 6(1)(c)) |
| Handling legal or billing inquiries | Communication logs, billing history | Legal obligation (Art. 6(1)(c)) & Performance of a contract (Art. 6(1)(b)) |
4. Data Retention Schedule
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected:
- Active Accounts: Retained while your account remains active. If you request account deletion, all personal data is permanently purged within 30 calendar days.
- Temporary Server Logs: Technical connection logs (IP addresses) are retained for a maximum of 30 to 90 days for network security and defense against cyberattacks, then automatically overwritten.
- Newsletter Records: Retained until you unsubscribe via the link in any newsletter email or contact us.
- Statutory Invoices & Billing Records: Retained for statutory periods mandated by commercial and tax legislation (typically 5 to 10 years).
5. Third-Party Sharing & Sub-processors
We do not sell, rent, or monetize your personal information. We only share data with trusted infrastructure sub-processors strictly necessary to deliver our services:
- Hosting & Ingress: Cloudflare & Kubernetes infrastructure for DDoS mitigation, CDN edge caching, and reverse proxy routing.
- Real-Time Media: Self-hosted or managed LiveKit SFU nodes for low-latency voice and video routing.
- Storage: S3-compatible object storage for user attachments and backups.
- Email Delivery: Stalwart mail servers or authenticated SMTP relays for transactional alerts and password resets.
- Legal Compliance: We will only disclose personal data to law enforcement authorities if compelled by a lawful, valid court order or binding legal subpoena issued by a court of competent jurisdiction.
6. International Data Transfers
Novyse infrastructure is primarily hosted within the European Union. If any data transfer outside the European Economic Area (EEA) is necessary (for instance, when utilizing global CDN edge caching), we ensure adequate protection through:
- EU Commission Adequacy Decisions (Art. 45 GDPR);
- Standard Contractual Clauses (SCCs) approved by the European Commission (Art. 46 GDPR); and
- Robust technical safeguards, including strict end-to-end encryption and encryption at rest.
7. Cookies & Tracking Technologies
Our landing page uses only strictly necessary functional cookies and local storage items (such as your chosen light/dark theme preference). We do not load tracking pixels or third-party marketing trackers without your prior explicit consent.
For detailed disclosures on cookie categories, expiration periods, and how to manage your consent preferences, please review our dedicated Cookie Policy.
8. Data Security
We implement comprehensive technical and organizational measures (TOMs) to safeguard your data, including TLS 1.3 encryption in transit, AES-256 encryption at rest, secure credential hashing, automated vulnerability patching, and role-based access control.
While we employ industry-standard defenses, no transmission over the internet is completely infallible; we continuously monitor, test, and reinforce our security posture.
9. Your Privacy Rights
9.1 Rights Under the GDPR (EU/EEA & UK)
Under GDPR Articles 15–22, you have the following rights:
- Right of Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Request correction of inaccurate or incomplete data.
- Right to Erasure ("Right to be Forgotten"): Request the permanent deletion of your personal data.
- Right to Restrict Processing: Request temporary restriction of data processing under certain statutory grounds.
- Right to Data Portability: Receive your data in a structured, commonly used, and machine-readable format.
- Right to Object: Object at any time to processing based on legitimate interests or direct marketing.
- Right to Withdraw Consent: Withdraw previously given consent at any time without affecting prior lawful processing.
- Right to Lodge a Complaint: You have the right to lodge a complaint with a competent supervisory data protection authority, such as the Italian Data Protection Authority (Garante per la protezione dei dati personali at www.garanteprivacy.it) or your local EEA supervisory authority.
9.2 Rights Under US State Laws (CCPA / CPRA)
If you are a resident of California or other US states with comprehensive privacy statutes:
- Right to Know & Access: Learn categories and specific pieces of personal information collected.
- Right to Delete & Correct: Request deletion or correction of personal information.
- No Sale or Sharing: We do not sell or share personal information for cross-context behavioral advertising.
- Non-Discrimination: We will never discriminate against you for exercising your legal privacy rights.
To exercise any of these rights, please email our privacy team at privacy@novyse.com. We will respond within 30 days without undue delay.
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect evolving technical, legal, or operational practices. We will notify you of material changes by updating the "Last updated" date at the top of this page or by displaying a prominent notice on our website or within our applications.
11. Contact Us
If you have questions, comments, or data rights requests regarding this Privacy Policy, please contact us at: