Nenvik Product Privacy and Data Handling Notice
Version: 2026-09-22
1. Scope and contact
This Notice explains how Nenvik handles personal information in the hosted Nenvik product. It is separate from any public marketing-site notice and from optional marketing consent. Nenvik is operated by Musa KULTUR, ABN 87 899 287 602, of 22 Aldridge Street, Endeavour Hills VIC 3802, Australia. Contact support@nenvik.com.au or 0413261502 for privacy enquiries, access, correction or complaints.
This Notice is designed for Australian privacy obligations, including the Australian Privacy Principles where they apply. It does not reduce rights that apply under the Privacy Act 1988 (Cth), the Notifiable Data Breaches scheme or another applicable law. An immutable published version applies from its recorded effective date.
2. Information we handle and collection sources
Depending on the features used, we handle account and identity details (such as names, business names, email, telephone, role, authentication and session records); contact, address, plan, entitlement, subscription, invoice, payment-status and support records; business customers', leads', quotes', jobs', schedule, site, asset, supplier, expense, timesheet and communication records; files and media; and audit, legal-acceptance, security, delivery and operation receipts. We may also handle technical information needed to operate and protect the Service, including request timing, device/session identifiers, failure codes and limited logs.
We collect this information from people who use signup, verification, checkout, support or the Service; authorised customer administrators; people who use enabled customer portals and forms; and service providers when reconciling payment, delivery, storage or operational status. We do not use purchased or scraped marketing lists as an ordinary source of product-account information. Legal-acceptance receipts do not retain raw IP addresses or raw browser user-agent strings.
Customers should not place health information, government identifiers, criminal records or other sensitive information in a feature unless the feature expressly supports it and the Customer has the required authority.
3. Purposes and roles
We handle information to create and secure accounts and workspaces; provide product features and portals; administer trials, plans, billing and support; store and deliver files and communications; prevent abuse; investigate faults; maintain audit evidence; comply with law; enforce agreements; resolve disputes; and operate, secure, support and maintain the reliability of the Service using appropriately limited or aggregated operational information.
The Customer decides what operational information its authorised users place in its workspace and why. Customer is responsible for its collection notices, permissions and lawful use. Nenvik operates the Service and handles information for the purposes above. These practical descriptions do not replace a role assigned by applicable law. We do not sell personal information. Optional direct marketing is separate from product access and requires a separate valid permission.
4. Service providers and overseas handling
We use or make available the following provider boundaries. A provider's own subprocessor list, service terms and processing locations can change; the current inventory and source evidence are maintained with this Notice. We take reasonable steps appropriate to the circumstances, including contractual terms and provider controls, when personal information is handled overseas. Processing may occur outside Australia as stated below.
Active or launch-required boundaries:
• Vercel hosts and delivers the web application, static assets, request processing and scheduled routes. It may receive request, account, session, application and log data needed to serve the Service. The production application's server functions are configured in Vercel's Sydney region (syd1); content delivery, provider support and Vercel subprocessors may still involve overseas handling.
• Supabase provides the managed PostgreSQL boundary used by the application. The source binds the current managed connection target to an Australia/Sydney (ap-southeast-2) pooler. Supabase Auth is not used by this product code. Provider support, backups and subprocessors may still involve overseas handling.
• Stripe processes subscription, billing, payment and tax-related data when paid payment functionality is enabled. Stripe may handle customer, representative, billing, payment-method, transaction and fraud/security data and may transfer it globally, including to the United States.
• Resend delivers transactional email when production email delivery is enabled. It may receive recipient and sender email addresses, names, message content and delivery metadata. Resend states that its primary processing operations take place in the United States.
• Cloudflare R2 provides the configured S3-compatible private-file, public-media and job-evidence storage used by the Service. It may receive private files, public images, job evidence, documents and associated object metadata. The configured R2 service does not by itself establish Australian-only residency; Cloudflare support, infrastructure and subprocessors may involve overseas handling.
• ClickSend delivers SMS for Customers with an active purchased SMS entitlement and applicable recipient authority. It may receive sender and recipient phone numbers, message content and delivery metadata. Its published subprocessor information identifies Australian, EU, United States and Philippines support or processing locations and other location-specific services.
Optional or not currently enabled boundaries:
• Xero, QuickBooks and MYOB accounting connectors exist only behind missing-configuration gates in this source. They are not listed as active Nenvik processors. Enabling one requires a new inventory review and notice/version decision before customer data is transmitted.
Customer-directed public-website destinations:
A Customer may choose, at its tenant level, to configure Google Analytics 4, Google gtag.js delivery for Analytics or Google Ads, Microsoft Clarity, Meta Pixel, TikTok Pixel, LinkedIn Insight Tag or Pinterest Tag for that Customer's public website. These are optional destinations selected by the Customer, not Nenvik processors enabled for every Customer. The website code loads the configured analytics tags only after a visitor chooses Analytics and the configured marketing tags only after a visitor chooses Marketing; it does not load them merely because Nenvik offers the configuration.
When enabled and consented, those destinations can receive visitor/device/event identifiers and related web information, including page URL, referrer, IP-derived or network information, browser/device characteristics, cookies or similar identifiers, timestamps, page views and interactions. Microsoft Clarity can additionally receive session-replay interaction and page-rendering data. The Customer must decide whether to enable a destination, configure it, give visitors a clear public-site notice, obtain any consent or other lawful basis required for its website, avoid sending sensitive or prohibited data, and handle visitor requests. Nenvik does not claim to control these recipients' regions, subprocessors, retention or deletion once data is sent to them. The provider documentation and the Customer's direct agreement with that provider govern those matters.
The Customer can also configure verification-only metadata for Google Search Console, Bing Webmaster Tools, Pinterest, Meta or one bounded custom verification provider. That metadata does not load a tracking script. If the chosen verification provider later scans the public page, it may receive the page/domain, the public verification token and ordinary request data; the Customer remains responsible for that destination and its public-site disclosure.
We do not promise Australian-only processing, a particular provider retention period or that a provider's current subprocessor list will never change. We review a material provider/data-use change before it is activated and, where required, publish a new immutable notice and apply the relevant reacceptance process.
5. Security and disclosure
We use measures designed to protect information against misuse, interference, loss and unauthorised access, modification or disclosure. These include server-side tenant and role checks, private-object authorisation, access controls, audit evidence, credential separation and controlled release practices. No internet service can guarantee absolute security.
We may disclose information to service providers described above, to a Customer or its authorised users, where required or permitted by law, to protect rights and safety, or in connection with a corporate transaction where lawful. Customers remain responsible for communications sent to their own recipients and for recipient authority and consent.
6. Retention, access, correction and complaints
We retain information while needed to provide and secure an active account, meet legal or financial obligations, resolve disputes and maintain necessary audit evidence. Following Owner-initiated closure, the Service offers a 30-day export opportunity and primary data becomes eligible for the controlled deletion workflow after 90 days, subject to legal holds and the preserved-evidence categories described in the Product Terms. Backups and provider-held information follow their applicable operational retention and verified rotation controls; this Notice does not promise a fixed backup-erasure date.
You may ask to access or correct personal information, or make a privacy complaint, by contacting support@nenvik.com.au. We may need to verify identity and the relevant Customer relationship. A request concerning information controlled by a Customer may be referred to or handled with that Customer. We will acknowledge a privacy complaint and explain the next steps. If it is not resolved, an individual may be able to contact the Office of the Australian Information Commissioner at https://www.oaic.gov.au/.
7. Incidents, marketing and changes
We assess suspected eligible data breaches promptly and, where the Notifiable Data Breaches scheme applies, notify the OAIC and affected individuals as required. We will inform affected Customers without unreasonable delay where notification is required or reasonably necessary for protective action.
Service, security, billing and account messages are separate from optional marketing. Commercial email or SMS requires the applicable consent, sender identification and unsubscribe process. Acknowledging this Notice is not consent to marketing and does not waive privacy rights.
An effective published Notice is immutable. We may publish a new version when practices or law change. Where practicable, we will give 30 days' notice of a material ordinary change; a shorter period may be necessary for law or urgent security. A material change to data categories, purposes, sharing, overseas handling, retention or individual rights requires a new immutable version and the applicable acknowledgement or reacceptance process.
Website and signup privacy notice
This separate notice covers the public website, email enquiries and account signup.
Website and signup notice last updated: 2 October 2026
Who operates Nenvik
Nenvik is operated by Musa KULTUR, ABN 87 899 287 602, of 22 Aldridge Street, Endeavour Hills VIC 3802, Australia. Contact support@nenvik.com.au for privacy enquiries.
Information you provide
The public contact page provides email links for product questions and account support. If you choose to send an email, your email provider and Nenvik receive the information you include in that message.
Account signup asks for your name, business name, email address and plan preference, with an optional promotion code. If you submit the form, Nenvik records a signup request and sends a single-use email verification link. The request and link expire after 48 hours. No business account is created at this first step. If you verify your email and continue, you review the current Product Terms and Product Privacy Notice before the account is created.
How we use signup information
We use signup details to process your request, send and verify the email link, check the selected offer or promotion, protect the signup process, and complete account setup if you continue. We do not use signup acknowledgement as permission for marketing messages.
Browsing and browser storage
The public marketing website stores your cookie banner choice in your browser’s local storage so it can remember that choice. The marketing website uses cookieless Vercel Web Analytics to understand visits and page performance. It does not use cookies or browser storage to identify visitors, and the marketing website does not load advertising tags. The hosting and application providers may process ordinary request and security information needed to deliver and protect the website; provider handling is described in the published Product Privacy Notice.
Customer websites built with Nenvik are separate. A Customer may configure optional analytics or marketing tags for its own website, which are controlled by that Customer’s settings and visitor consent choices.
Providers and product information
Website hosting, email delivery and product data providers can process information needed for their services, including outside Australia. Their current purposes, boundaries and known overseas handling are described in the published Product Privacy and Data Handling Notice. Provider locations and subprocessors can change.
If you have a Nenvik account, you can delete it yourself from inside the app or the website. How to delete your account explains the in-app steps and how to ask us to delete an account by email if you cannot sign in. Records a business must keep, such as jobs, invoices, payments and audit logs, can be retained, as that page explains.
Questions and requests
For a privacy question, a request about access, correction or deletion, or a privacy complaint, contact support@nenvik.com.au. We may need to confirm your identity and the relevant account or enquiry. Requests about an active product account are handled with reference to the published Product Privacy and Data Handling Notice.