Legal

Privacy Policy

How Nourvia processes personal data for the All Office marketing site, demos, checkout, billing and support under UAE PDPL.

Effective 13 August 2026 · Version privacy-en-2026-08-13-draft1

1. Who we are

The controller of personal data described in this notice is the legal entity that operates this Site, which trades as Nourvia Innovations / All Office. That entity’s registered legal name, legal form, trade licence number, licensing authority, registered or physical address, and VAT TRN or non-registered status are stated on your invoice and are available on request.

  • Privacy / complaints contact: [email protected]
  • Phone: +971 563988991
  • Data protection officer: none appointed

This notice is issued under Federal Decree-Law No. 45 of 2021 (PDPL) and related UAE data rules, including Decree-Law 14/2023 Art. 10 for digital-trader consumer data.

2. Who this notice covers

This notice covers visitors to the Site, people who request a demo, people who buy or enquire about All Office, and billing/support contacts. The Services are offered to business organisations (Nourvia targets UAE businesses and complies under UAE law; buyers need not be established in the UAE). We do not knowingly collect personal data from children on the Site.

Hosted All Office tenants: employee, payroll, Emirates ID, passport, visa, bank, attendance, customer and supplier records that you put into a paid Subscription workspace are generally processed by Nourvia as processor under the Data Processing Addendum. This notice does not replace that DPA. After handover of a Perpetual Self-Hosted Licence, you are responsible for tenant data on your infrastructure, except data you send us for support and licence-validation telemetry described below.

3. Data we collect (Site, demo, checkout)

CategoryExamplesSource
Identity and contactName, company name, email, phoneYou, on /demo and /buy
Email verificationHashed code, status, timestamps, token id (jti)You and our verification service
PurchasePlan type, AED amount, Stripe session/customer/payment metadata (full card data is handled by Stripe, not stored by us)You and Stripe
Demo provisionCompany slug, login URL, provisioned company/user ids, job status, errorsOur systems and backend provisioner
Security and logsIP address, user agent, rate-limit events, Turnstile pass/fail, access-event type and JSON payloadAutomatic
CommunicationsSales, support and transactional emailsYou and our email provider
Licence check-in (self-host)Licence id, instance id, app version, technical result, check-in IPCustomer instance
Analytics (only if identifiers are configured)GTM/GA4 identifiers and eventsYour browser

Do not enter real employee, payroll, Emirates ID, passport, visa or bank data into a demo tenant unless we have agreed the DPA applies to that demo.

4. Why we process personal data

PDPL does not provide a general “legitimate interests” basis. We process personal data to perform a contract with you or your organisation, to meet legal obligations, or with consent where that is the basis (for example optional marketing).

PurposeDataPDPL basisRecipientsRetention
Provide a demo / create a tenantIdentity, verification, demo provision, IPContract with the requesting person / organisationHosting, email, internal opsDemo tenants expire after 14 days as stated at provisioning and are then deleted from production systems; residual backups expire on the backup cycle. Registration records are kept as needed to operate, support and evidence the demo, then deleted or minimised.
Complete purchase / checkoutIdentity, verification, purchase, IPContractStripe, email, internal opsTax and commercial records for at least five (5) years, or longer if law requires
Email verification and fraud/bot controlVerification, Turnstile, IP, rate limitsContract and security necessary to provide the serviceCloudflare, internal opsVerification codes until they expire, plus a short security window; security logs as needed for abuse prevention
Invoicing, VAT, accountingPurchase, identityLegal obligationAccountant, FTA if required, StripeAt least five (5) years
Service messages (credentials, billing, legal notices)Email, nameContractEmail providerLife of the account or order, then as needed for support and legal claims
Optional marketing (email/SMS/WhatsApp/phone)Contact and consent recordConsent (unchecked, per channel, withdrawable)Email/SMS providers if usedUntil withdrawal, plus a suppression record as long as needed to honour opt-out
AnalyticsGTM/GA4Consent is the intended basis. A Site consent control is not yet available. If analytics identifiers are configured, those scripts may load until that control ships. Use browser settings to block them in the meantime. See the Cookie Notice.GooglePer Google’s cookie durations; see the Cookie Notice
Handle complaints and legal claimsRelevant recordsLegal obligation / claimsAdvisers, authoritiesAs required to handle the complaint or claim
Licence validation (self-host)Telemetry in section 3ContractLicence authority hostValidation events as needed to operate the licence
Hosted tenant HR/finance dataSee DPAProcessor — customer’s instructionsSee DPASee DPA

5. Processors and transfers outside the UAE

There is no published UAE Data Office adequacy whitelist as of this notice. Transfers use PDPL Arts. 22–23 (typically necessity for a contract with you or with a third party in your interest, and/or a contract requiring the recipient to apply PDPL-level protections).

Processor / categoryPurposeTypical location
StripePayments, checkout, and (for subscriptions) billingUnited States / Stripe regions
Cloudflare TurnstileBot protectionGlobal / United States
Email (Resend or SMTP, as configured)Transactional mailResend: United States; SMTP: the host we configure
Hosting and backupsSite, marketing database, application database, backupsProviders and regions used to operate the Services; details available on request
Google (GTM/GA4)Analytics if identifiers are configuredUnited States / Google regions
Professional advisersLegal, tax, support as neededUAE / as engaged

We will not claim certifications we do not hold.

6. Your rights

Subject to PDPL and identity checks, you may request: information/access; correction; erasure; restriction; portability where applicable; to object to or stop direct marketing; to withdraw consent; review of qualifying automated processing; and to complain to the UAE Data Office (and, for digital-trader issues, the Ministry of Economy).

How: email [email protected]. We will respond without undue delay. We may refuse or limit requests as PDPL allows (including tax/legal holds).

Automated processing used today: Turnstile scoring, IP rate limits, and provisioning success/failure. We do not make solely automated decisions that produce legal effects about you without human involvement in sales.

7. Security and breaches

We use access control, encryption in transit (HTTPS), hashed verification codes, and least-privilege admin access as implemented. This is not a guarantee of absolute security and we do not advertise certifications we do not hold.

If a personal-data breach occurs, we will notify the UAE Data Office and affected persons as PDPL requires. When we are processor, we will notify the customer under the DPA without undue delay and no later than 72 hours after becoming aware, unless a shorter period is required by law.

8. Changes

We will post an updated notice with a new effective date and, for a material new purpose, give direct notice and obtain any consent PDPL requires. Continued browsing is not consent to a new purpose.