Legal
Privacy Policy
How Nourvia processes personal data for the All Office marketing site, demos, checkout, billing and support under UAE PDPL.
Effective 13 August 2026 · Version privacy-en-2026-08-13-draft1
1. Who we are
The controller of personal data described in this notice is the legal entity that operates this Site, which trades as Nourvia Innovations / All Office. That entity’s registered legal name, legal form, trade licence number, licensing authority, registered or physical address, and VAT TRN or non-registered status are stated on your invoice and are available on request.
- Privacy / complaints contact: [email protected]
- Phone: +971 563988991
- Data protection officer: none appointed
This notice is issued under Federal Decree-Law No. 45 of 2021 (PDPL) and related UAE data rules, including Decree-Law 14/2023 Art. 10 for digital-trader consumer data.
2. Who this notice covers
This notice covers visitors to the Site, people who request a demo, people who buy or enquire about All Office, and billing/support contacts. The Services are offered to business organisations (Nourvia targets UAE businesses and complies under UAE law; buyers need not be established in the UAE). We do not knowingly collect personal data from children on the Site.
Hosted All Office tenants: employee, payroll, Emirates ID, passport, visa, bank, attendance, customer and supplier records that you put into a paid Subscription workspace are generally processed by Nourvia as processor under the Data Processing Addendum. This notice does not replace that DPA. After handover of a Perpetual Self-Hosted Licence, you are responsible for tenant data on your infrastructure, except data you send us for support and licence-validation telemetry described below.
3. Data we collect (Site, demo, checkout)
| Category | Examples | Source |
|---|---|---|
| Identity and contact | Name, company name, email, phone | You, on /demo and /buy |
| Email verification | Hashed code, status, timestamps, token id (jti) | You and our verification service |
| Purchase | Plan type, AED amount, Stripe session/customer/payment metadata (full card data is handled by Stripe, not stored by us) | You and Stripe |
| Demo provision | Company slug, login URL, provisioned company/user ids, job status, errors | Our systems and backend provisioner |
| Security and logs | IP address, user agent, rate-limit events, Turnstile pass/fail, access-event type and JSON payload | Automatic |
| Communications | Sales, support and transactional emails | You and our email provider |
| Licence check-in (self-host) | Licence id, instance id, app version, technical result, check-in IP | Customer instance |
| Analytics (only if identifiers are configured) | GTM/GA4 identifiers and events | Your browser |
Do not enter real employee, payroll, Emirates ID, passport, visa or bank data into a demo tenant unless we have agreed the DPA applies to that demo.
4. Why we process personal data
PDPL does not provide a general “legitimate interests” basis. We process personal data to perform a contract with you or your organisation, to meet legal obligations, or with consent where that is the basis (for example optional marketing).
| Purpose | Data | PDPL basis | Recipients | Retention |
|---|---|---|---|---|
| Provide a demo / create a tenant | Identity, verification, demo provision, IP | Contract with the requesting person / organisation | Hosting, email, internal ops | Demo tenants expire after 14 days as stated at provisioning and are then deleted from production systems; residual backups expire on the backup cycle. Registration records are kept as needed to operate, support and evidence the demo, then deleted or minimised. |
| Complete purchase / checkout | Identity, verification, purchase, IP | Contract | Stripe, email, internal ops | Tax and commercial records for at least five (5) years, or longer if law requires |
| Email verification and fraud/bot control | Verification, Turnstile, IP, rate limits | Contract and security necessary to provide the service | Cloudflare, internal ops | Verification codes until they expire, plus a short security window; security logs as needed for abuse prevention |
| Invoicing, VAT, accounting | Purchase, identity | Legal obligation | Accountant, FTA if required, Stripe | At least five (5) years |
| Service messages (credentials, billing, legal notices) | Email, name | Contract | Email provider | Life of the account or order, then as needed for support and legal claims |
| Optional marketing (email/SMS/WhatsApp/phone) | Contact and consent record | Consent (unchecked, per channel, withdrawable) | Email/SMS providers if used | Until withdrawal, plus a suppression record as long as needed to honour opt-out |
| Analytics | GTM/GA4 | Consent is the intended basis. A Site consent control is not yet available. If analytics identifiers are configured, those scripts may load until that control ships. Use browser settings to block them in the meantime. See the Cookie Notice. | Per Google’s cookie durations; see the Cookie Notice | |
| Handle complaints and legal claims | Relevant records | Legal obligation / claims | Advisers, authorities | As required to handle the complaint or claim |
| Licence validation (self-host) | Telemetry in section 3 | Contract | Licence authority host | Validation events as needed to operate the licence |
| Hosted tenant HR/finance data | See DPA | Processor — customer’s instructions | See DPA | See DPA |
5. Processors and transfers outside the UAE
There is no published UAE Data Office adequacy whitelist as of this notice. Transfers use PDPL Arts. 22–23 (typically necessity for a contract with you or with a third party in your interest, and/or a contract requiring the recipient to apply PDPL-level protections).
| Processor / category | Purpose | Typical location |
|---|---|---|
| Stripe | Payments, checkout, and (for subscriptions) billing | United States / Stripe regions |
| Cloudflare Turnstile | Bot protection | Global / United States |
| Email (Resend or SMTP, as configured) | Transactional mail | Resend: United States; SMTP: the host we configure |
| Hosting and backups | Site, marketing database, application database, backups | Providers and regions used to operate the Services; details available on request |
| Google (GTM/GA4) | Analytics if identifiers are configured | United States / Google regions |
| Professional advisers | Legal, tax, support as needed | UAE / as engaged |
We will not claim certifications we do not hold.
6. Your rights
Subject to PDPL and identity checks, you may request: information/access; correction; erasure; restriction; portability where applicable; to object to or stop direct marketing; to withdraw consent; review of qualifying automated processing; and to complain to the UAE Data Office (and, for digital-trader issues, the Ministry of Economy).
How: email [email protected]. We will respond without undue delay. We may refuse or limit requests as PDPL allows (including tax/legal holds).
Automated processing used today: Turnstile scoring, IP rate limits, and provisioning success/failure. We do not make solely automated decisions that produce legal effects about you without human involvement in sales.
7. Security and breaches
We use access control, encryption in transit (HTTPS), hashed verification codes, and least-privilege admin access as implemented. This is not a guarantee of absolute security and we do not advertise certifications we do not hold.
If a personal-data breach occurs, we will notify the UAE Data Office and affected persons as PDPL requires. When we are processor, we will notify the customer under the DPA without undue delay and no later than 72 hours after becoming aware, unless a shorter period is required by law.
8. Changes
We will post an updated notice with a new effective date and, for a material new purpose, give direct notice and obtain any consent PDPL requires. Continued browsing is not consent to a new purpose.