Privacy Policy
Effective date: · Version: 0.1-draft
DRAFT — LEGAL REVIEW REQUIRED. This document is an engineering draft and does not constitute legal advice. Final text must be reviewed by qualified EU counsel before launch.
This policy explains what personal data Nevoiz processes, why, on what legal basis, and the rights you have. Nevoiz is designed around data minimisation and European data sovereignty: the platform is self-hosted on EU infrastructure and does not use advertising or cross-site tracking.
1. Who is responsible (controller)
- Controller: LEGAL REVIEW REQUIRED: registered operating entity name
- Address: LEGAL REVIEW REQUIRED: registered EU address
- Contact for privacy matters: privacy@nevoiz.de
- Data Protection Officer: LEGAL REVIEW REQUIRED: Data Protection Officer contact (if appointed)
2. Categories of personal data
Depending on how you use Nevoiz, we process:
- Account data: your phone number (used for sign-in via one-time SMS code) and your chosen handle and display name.
- Content you create: posts, comments, votes, consultation arguments and endorsements, community notes, and private messages.
- Technical and security data: a truncated IP address and minimal request metadata used for security, abuse prevention, and reliability. We deliberately do not log full IP addresses.
- Device data for notifications: a push notification token, if you enable notifications.
- Support data: information you provide when you contact us.
Nevoiz does not collect biometric identifiers and does not require identity documents. LEGAL REVIEW REQUIRED: confirm this remains accurate for any future verification feature.
3. Purposes and legal bases
We process personal data on the following legal bases under Article 6 GDPR. LEGAL REVIEW REQUIRED: confirm the mapping below with counsel.
| Purpose | Data used | Legal basis |
|---|---|---|
| Provide the service and your account | Account data, content | Art. 6(1)(b) — performance of a contract |
| Sign-in security (SMS one-time codes) | Phone number | Art. 6(1)(b) / Art. 6(1)(f) — legitimate interest in secure access |
| Safety, moderation, and abuse prevention | Content, security data | Art. 6(1)(f) — legitimate interest; Art. 6(1)(c) where legally required |
| Push notifications you enable | Device token | Art. 6(1)(a) — consent (you can withdraw at any time) |
| Responding to your support requests | Support data | Art. 6(1)(b)/(f) |
| Meeting legal obligations | As required | Art. 6(1)(c) — legal obligation |
4. Where the data comes from
We primarily collect data directly from you when you use the app. Some technical data is generated automatically when your device interacts with the service.
5. Processors and recipients
We keep third parties to the minimum needed to run the service. Where processors act on our behalf, they do so under a data processing agreement (Art. 28 GDPR). LEGAL REVIEW REQUIRED: maintain an accurate, complete list of processors.
- Hosting: Hetzner Online GmbH, EU data centres (Germany/Finland).
- SMS delivery for one-time codes: LEGAL REVIEW REQUIRED — named SMS provider (EU-based).
- AI assistance (advisory, human-reviewed): LEGAL REVIEW REQUIRED — named model provider and region.
- We do not sell personal data and do not use it for advertising.
6. International transfers
Nevoiz is designed to keep data within the EU/EEA. LEGAL REVIEW REQUIRED: if any processor involves a transfer outside the EEA, document the safeguard (adequacy decision or Standard Contractual Clauses) here.
7. How long we keep data
We keep personal data only as long as necessary for the purposes above, then delete or anonymise it. LEGAL REVIEW REQUIRED: confirm specific retention periods.
- Account and content: retained while your account is active.
- On deletion: personal identifiers are removed or your contributions anonymised; some records may be retained only where legally required.
- Security logs: retained for a limited period for security and abuse prevention.
8. Your rights
Under the GDPR you have the right to:
- Access your data (Art. 15) — you can request an export from within the app.
- Rectify inaccurate data (Art. 16).
- Erase your data (Art. 17) — you can delete your account from within the app or via the Delete account page.
- Restrict or object to processing (Arts. 18, 21).
- Data portability (Art. 20) — the in-app export is provided in a machine-readable format.
- Withdraw consent at any time, without affecting prior processing (Art. 7(3)).
To exercise these rights, use the in-app tools or contact privacy@nevoiz.de.
9. Complaints to a supervisory authority
You have the right to lodge a complaint with a data protection supervisory authority. LEGAL REVIEW REQUIRED: name the lead supervisory authority — currently recorded as: LEGAL REVIEW REQUIRED: lead EU supervisory authority for the establishment.
10. Automated decision-making and profiling
Nevoiz does not make decisions producing legal or similarly significant effects about you solely by automated means. AI is used only in an advisory, human-reviewed capacity (for example, to assist moderation or summarise content), and it always carries its confidence, sources, and limitations.
11. Account deletion
You can delete your account at any time. When you do, we remove or anonymise your personal data as described in the retention section, subject only to legally required exceptions. See the Delete account page for details.
12. Children and age requirements
Nevoiz is not directed at children. You must be at least 16 years old to use it. LEGAL REVIEW REQUIRED: confirm the minimum age against the applicable Member State's Art. 8 GDPR implementation.
13. Security
We use appropriate technical and organisational measures, including encryption in transit, hardened security headers, rate limiting, minimised logging (truncated IPs, no sensitive data in logs), and access controls. No system can be guaranteed perfectly secure, but security is a first-class design goal.
15. Changes to this policy
We may update this policy. Material changes will be communicated appropriately, and the effective date and version at the top will be updated.