References to "you" apply to customers, merchants, end users, and visitors unless otherwise noted.

Section 1Information We Collect

Account Information

When you create a Nuboc account we collect:

Data You Provide Through Our Services

Depending on which Services you use, we may process:

Usage and Technical Data

We automatically collect certain technical data when you use the Services:

Section 2Lawful Basis for Processing (GDPR)

If you are located in the European Economic Area (EEA) or United Kingdom, we process personal data under the following lawful bases under GDPR Article 6:

Section 3How We Use Your Information

We use collected information to:

Section 4AI Processing

Certain Nuboc services use Anthropic's Claude API to power AI-assisted features. When these features are activated:

Section 5How We Share Your Information

We do not sell your personal information. We share information only in the following circumstances:

Service Providers

We engage the following sub-processors to operate the Services. Each is bound by data processing agreements:

Legal Requirements

We may disclose information if required by law, regulation, court order, or valid legal process. Where permitted, we will notify you before disclosure.

Business Transfers

In connection with a merger, acquisition, or sale of substantially all assets, personal data may be transferred as part of that transaction. We will notify affected users via email and this policy at least 30 days before any such transfer.

Section 6International Data Transfers

Our primary infrastructure runs on Hetzner servers in Germany (EU). Some sub-processors, including Anthropic and Postmark, process data in the United States. Where data is transferred outside the EEA or UK, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission, or other lawful transfer mechanisms, to protect your data.

Section 7Data Retention and Deletion

We retain your data for as long as your account is active or as needed to provide the Services. When you delete your organization:

Section 8Data Security

We implement the following technical and organizational measures to protect your data:

No transmission over the internet or method of electronic storage is 100% secure. We will notify you of any breach affecting your data as required by applicable law.

Section 9Your Rights

All Users

You have the right to:

EEA and UK Residents (GDPR/UK GDPR)

In addition to the above, you have the right to:

California Residents (CCPA/CPRA)

California residents have the right to:

To exercise your California rights, email legal@nuboc.com with the subject line "CCPA Request." We will respond within 45 days.

Section 10Children's Privacy

The Services are not directed to individuals under 16 years of age. We do not knowingly collect personal information from children under 16. If you believe we have inadvertently collected such information, please contact us at legal@nuboc.com and we will delete it promptly.

Section 11Changes to This Policy

We may update this Privacy Policy from time to time. For material changes we will:

Continued use of the Services after the effective date constitutes acceptance of the updated policy.

Section 12Contact Us

If you have questions about this Privacy Policy, wish to exercise your rights, or want to report a data concern:

For EEA/UK data protection inquiries, you may also contact us at the same address. We aim to respond to all privacy requests within 30 days.