Legal

Encryption at Rest Policy

Last updated: August 7, 2026

Effective Date: November 01, 2025

Last Reviewed: May 01, 2026

1. Purpose

This Encryption at Rest Policy explains how Nuvbook ("Nuvbook," "we," "our," or "us") protects stored data through encryption. It applies to all personal, business, and operational data held on the Platform by both business owners ("Providers") and the clients they serve ("End Users").

This policy supports our commitments under applicable data protection and security frameworks, including the General Data Protection Regulation (GDPR), the California Consumer Privacy Act and California Privacy Rights Act (CCPA/CPRA), the Gramm-Leach-Bliley Act (GLBA), and U.S. federal and state-level privacy and security requirements.

2. Scope

This policy applies to all data stored within the Nuvbook Platform, including account and registration data, booking and appointment records, client contact information, AI assistant interaction logs, billing and invoicing records, website builder content, SMS and messaging records, and analytics data. It covers data held on Nuvbook-managed infrastructure as well as data processed by authorised third-party service providers acting on our behalf.

3. Encryption Standards

All data stored on Nuvbook systems is encrypted at rest using industry-standard encryption methods. Nuvbook applies strong encryption algorithms consistent with current best practices to ensure that stored data cannot be read or accessed by unauthorised parties, even in the event of physical or logical access to the underlying storage infrastructure.

Encryption keys are managed through secure key management practices. Access to encryption keys is restricted to authorised personnel and systems only, and keys are rotated on a regular basis to reduce the risk of compromise.

4. What Is Encrypted

Account and profile data, including names, email addresses, business information, and login credentials, is encrypted at rest. Booking and appointment records, including client contact details and scheduling information, are encrypted at rest. AI assistant interaction logs are encrypted at rest for the duration of their retention period, which is no longer than 24 months from the date of the interaction unless otherwise required by law. Analytics data that may be associated with individual users is encrypted at rest prior to any anonymisation or aggregation.

Payment data is not stored on Nuvbook servers. All payment processing is handled exclusively by third-party providers such as Stripe and PayPal, who maintain their own encryption and security standards in accordance with Payment Card Industry Data Security Standards (PCI DSS).

5. Third-Party Processors

Nuvbook works with a number of third-party service providers to deliver its Platform, including Stripe and PayPal for payment processing, Mailgun for email communications, Twilio for SMS messaging, and Google Calendar for scheduling integrations. Where data is shared with these providers, Nuvbook requires that they maintain appropriate encryption and security controls under the terms of their data processing agreements. Providers are bound by their own privacy policies and security practices, which users are encouraged to review.

6. International Data Transfers

Where encrypted data is transferred outside of the user's country of residence or the European Economic Area, Nuvbook applies additional safeguards including Standard Contractual Clauses and secure transfer protocols to ensure that data remains protected throughout the transfer process.

7. Breach Response

In the event of a confirmed data breach, Nuvbook will conduct an immediate assessment to determine the scope and nature of the incident. Nuvbook will notify the relevant supervisory authority within 72 hours and will notify affected users without undue delay where the breach is likely to result in a high risk to their rights and freedoms, in accordance with GDPR Articles 33 and 34 and applicable U.S. state-level breach notification laws.Encryption at rest is a key control that limits the potential impact of a breach by ensuring that accessed data cannot be read without the corresponding decryption keys.

8. Provider Responsibilities

While Nuvbook encrypts all data stored on its own systems, Providers are responsible for the security of any data they export, download, or store outside of the Platform. Providers should apply equivalent encryption standards to any client or business data held in their own systems, in accordance with the regulations applicable to their industry and jurisdiction.

9. Updates to This Policy

Nuvbook may update this policy from time to time to reflect changes in our technology, legal obligations, or business practices. Updates will be communicated via email or in-platform notice. Continued use of the Platform after such updates constitutes acceptance of the revised policy. The effective date will always be displayed at the top of this document.

10. Contact

For questions about this policy or our security practices, please reach out to us at privacy@nuvbook.com,

by mail at

418 Broadway STE 8805, Albany, NY 12207, USA,

or by phone at +1 (914) 371-8990.

Our response time is 5 to 10 business days.

Questions or Concerns?

If you have any questions about this encryption at rest policy, please don't hesitate to reach out to our support team.

Contact Support