Skip to main content

Published product document

Nenvik Product Privacy and Data Handling Notice

Version 2026-09-22, effective 23 September 2026 at 1:04 am AEST (Australia/Melbourne). This is the current published version used by product signup.

Content SHA-256: 4b6620a625d313796544d976ec39ad26f89a2d72d21468772c7f1aa456b97630

Nenvik Product Privacy and Data Handling Notice Version: 2026-09-22 1. Scope and contact This Notice explains how Nenvik handles personal information in the hosted Nenvik product. It is separate from any public marketing-site notice and from optional marketing consent. Nenvik is operated by Musa KULTUR, ABN 87 899 287 602, of 22 Aldridge Street, Endeavour Hills VIC 3802, Australia. Contact support@nenvik.com.au or 0413261502 for privacy enquiries, access, correction or complaints. This Notice is designed for Australian privacy obligations, including the Australian Privacy Principles where they apply. It does not reduce rights that apply under the Privacy Act 1988 (Cth), the Notifiable Data Breaches scheme or another applicable law. An immutable published version applies from its recorded effective date. 2. Information we handle and collection sources Depending on the features used, we handle account and identity details (such as names, business names, email, telephone, role, authentication and session records); contact, address, plan, entitlement, subscription, invoice, payment-status and support records; business customers', leads', quotes', jobs', schedule, site, asset, supplier, expense, timesheet and communication records; files and media; and audit, legal-acceptance, security, delivery and operation receipts. We may also handle technical information needed to operate and protect the Service, including request timing, device/session identifiers, failure codes and limited logs. We collect this information from people who use signup, verification, checkout, support or the Service; authorised customer administrators; people who use enabled customer portals and forms; and service providers when reconciling payment, delivery, storage or operational status. We do not use purchased or scraped marketing lists as an ordinary source of product-account information. Legal-acceptance receipts do not retain raw IP addresses or raw browser user-agent strings. Customers should not place health information, government identifiers, criminal records or other sensitive information in a feature unless the feature expressly supports it and the Customer has the required authority. 3. Purposes and roles We handle information to create and secure accounts and workspaces; provide product features and portals; administer trials, plans, billing and support; store and deliver files and communications; prevent abuse; investigate faults; maintain audit evidence; comply with law; enforce agreements; resolve disputes; and operate, secure, support and maintain the reliability of the Service using appropriately limited or aggregated operational information. The Customer decides what operational information its authorised users place in its workspace and why. Customer is responsible for its collection notices, permissions and lawful use. Nenvik operates the Service and handles information for the purposes above. These practical descriptions do not replace a role assigned by applicable law. We do not sell personal information. Optional direct marketing is separate from product access and requires a separate valid permission. 4. Service providers and overseas handling We use or make available the following provider boundaries. A provider's own subprocessor list, service terms and processing locations can change; the current inventory and source evidence are maintained with this Notice. We take reasonable steps appropriate to the circumstances, including contractual terms and provider controls, when personal information is handled overseas. Processing may occur outside Australia as stated below. Active or launch-required boundaries: • Vercel hosts and delivers the web application, static assets, request processing and scheduled routes. It may receive request, account, session, application and log data needed to serve the Service. The production application's server functions are configured in Vercel's Sydney region (syd1); content delivery, provider support and Vercel subprocessors may still involve overseas handling. • Supabase provides the managed PostgreSQL boundary used by the application. The source binds the current managed connection target to an Australia/Sydney (ap-southeast-2) pooler. Supabase Auth is not used by this product code. Provider support, backups and subprocessors may still involve overseas handling. • Stripe processes subscription, billing, payment and tax-related data when paid payment functionality is enabled. Stripe may handle customer, representative, billing, payment-method, transaction and fraud/security data and may transfer it globally, including to the United States. • Resend delivers transactional email when production email delivery is enabled. It may receive recipient and sender email addresses, names, message content and delivery metadata. Resend states that its primary processing operations take place in the United States. • Cloudflare R2 provides the configured S3-compatible private-file, public-media and job-evidence storage used by the Service. It may receive private files, public images, job evidence, documents and associated object metadata. The configured R2 service does not by itself establish Australian-only residency; Cloudflare support, infrastructure and subprocessors may involve overseas handling. • ClickSend delivers SMS for Customers with an active purchased SMS entitlement and applicable recipient authority. It may receive sender and recipient phone numbers, message content and delivery metadata. Its published subprocessor information identifies Australian, EU, United States and Philippines support or processing locations and other location-specific services. Optional or not currently enabled boundaries: • Xero, QuickBooks and MYOB accounting connectors exist only behind missing-configuration gates in this source. They are not listed as active Nenvik processors. Enabling one requires a new inventory review and notice/version decision before customer data is transmitted. Customer-directed public-website destinations: A Customer may choose, at its tenant level, to configure Google Analytics 4, Google gtag.js delivery for Analytics or Google Ads, Microsoft Clarity, Meta Pixel, TikTok Pixel, LinkedIn Insight Tag or Pinterest Tag for that Customer's public website. These are optional destinations selected by the Customer, not Nenvik processors enabled for every Customer. The website code loads the configured analytics tags only after a visitor chooses Analytics and the configured marketing tags only after a visitor chooses Marketing; it does not load them merely because Nenvik offers the configuration. When enabled and consented, those destinations can receive visitor/device/event identifiers and related web information, including page URL, referrer, IP-derived or network information, browser/device characteristics, cookies or similar identifiers, timestamps, page views and interactions. Microsoft Clarity can additionally receive session-replay interaction and page-rendering data. The Customer must decide whether to enable a destination, configure it, give visitors a clear public-site notice, obtain any consent or other lawful basis required for its website, avoid sending sensitive or prohibited data, and handle visitor requests. Nenvik does not claim to control these recipients' regions, subprocessors, retention or deletion once data is sent to them. The provider documentation and the Customer's direct agreement with that provider govern those matters. The Customer can also configure verification-only metadata for Google Search Console, Bing Webmaster Tools, Pinterest, Meta or one bounded custom verification provider. That metadata does not load a tracking script. If the chosen verification provider later scans the public page, it may receive the page/domain, the public verification token and ordinary request data; the Customer remains responsible for that destination and its public-site disclosure. We do not promise Australian-only processing, a particular provider retention period or that a provider's current subprocessor list will never change. We review a material provider/data-use change before it is activated and, where required, publish a new immutable notice and apply the relevant reacceptance process. 5. Security and disclosure We use measures designed to protect information against misuse, interference, loss and unauthorised access, modification or disclosure. These include server-side tenant and role checks, private-object authorisation, access controls, audit evidence, credential separation and controlled release practices. No internet service can guarantee absolute security. We may disclose information to service providers described above, to a Customer or its authorised users, where required or permitted by law, to protect rights and safety, or in connection with a corporate transaction where lawful. Customers remain responsible for communications sent to their own recipients and for recipient authority and consent. 6. Retention, access, correction and complaints We retain information while needed to provide and secure an active account, meet legal or financial obligations, resolve disputes and maintain necessary audit evidence. Following Owner-initiated closure, the Service offers a 30-day export opportunity and primary data becomes eligible for the controlled deletion workflow after 90 days, subject to legal holds and the preserved-evidence categories described in the Product Terms. Backups and provider-held information follow their applicable operational retention and verified rotation controls; this Notice does not promise a fixed backup-erasure date. You may ask to access or correct personal information, or make a privacy complaint, by contacting support@nenvik.com.au. We may need to verify identity and the relevant Customer relationship. A request concerning information controlled by a Customer may be referred to or handled with that Customer. We will acknowledge a privacy complaint and explain the next steps. If it is not resolved, an individual may be able to contact the Office of the Australian Information Commissioner at https://www.oaic.gov.au/. 7. Incidents, marketing and changes We assess suspected eligible data breaches promptly and, where the Notifiable Data Breaches scheme applies, notify the OAIC and affected individuals as required. We will inform affected Customers without unreasonable delay where notification is required or reasonably necessary for protective action. Service, security, billing and account messages are separate from optional marketing. Commercial email or SMS requires the applicable consent, sender identification and unsubscribe process. Acknowledging this Notice is not consent to marketing and does not waive privacy rights. An effective published Notice is immutable. We may publish a new version when practices or law change. Where practicable, we will give 30 days' notice of a material ordinary change; a shorter period may be necessary for law or urgent security. A material change to data categories, purposes, sharing, overseas handling, retention or individual rights requires a new immutable version and the applicable acknowledgement or reacceptance process.

Website and signup privacy notice

This separate notice covers the public website, email enquiries and account signup.

Website and signup notice last updated: 2 October 2026