Legal

General Data Protection Regulation

Last updated: August 7, 2026

This document is for internal compliance purposes. It should be treated as confidential and reviewed by qualified legal counsel before being relied upon in regulatory or litigation contexts.

General Data Protection Regulation – Article 30 Record of Processing Activities, Data Subject Rights Framework, Third-Party Processor Register, and Breach Response Plan

Effective Date: 2025, November 01

Last Reviewed: 2026, May 01

Document Owner: Data Protection Officer (DPO)

Classification: Internal – Compliance

Version: 1.0

Part 1: Introduction and Scope

1.1 Purpose

This document sets out Nuvbook’s formal compliance posture under the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and the UK General Data Protection Regulation (“UK GDPR”), as retained by the Data Protection Act 2018.

It serves as the company’s primary internal reference for:

  • The lawful bases on which Nuvbook processes personal data;
  • The Record of Processing Activities (ROPA) required by GDPR Article 30;
  • The rights of data subjects and the procedures for honouring them;
  • The register of third-party data processors and applicable transfer mechanisms;
  • The data breach detection, response, and notification procedure; and
  • Ongoing accountability and review obligations.

1.2 Scope

This document applies to:

  • All personal data processed by Nuvbook in connection with the operation of its SaaS scheduling and booking platform;
  • All employees, contractors, and partners who handle personal data on behalf of Nuvbook;
  • All third-party processors engaged by Nuvbook to process personal data; and
  • All data subjects whose personal data is processed, including EU/EEA users, UK users, and others protected by applicable data protection law.

1.3 Roles and Responsibilities

<u>Data Controller: Nuvbook | 418 Broadway STE 8805, Albany, NY 12207, USA</u>

<u>Contact: privacy@nuvbook.com | +19143718990</u>

<u>EU Representative: privacy@nuvbook.com (FAO: EU Representative) – GDPR Article 27</u>

<u>DPO Contact: privacy@nuvbook.com (FAO: Data Protection Officer)</u>

As a U.S.-based company processing personal data of EU and UK residents, Nuvbook acts as a Data Controller under GDPR Article 4(7). Where Nuvbook processes data on behalf of business owners (Providers) using the platform, Nuvbook acts as a Data Processor under GDPR Article 28, and Providers act as the relevant Data Controllers.

Nuvbook has designated a Data Protection Officer (DPO) responsible for overseeing GDPR compliance, advising on data protection obligations, monitoring adherence to this document, and acting as the primary point of contact for supervisory authorities and data subjects.

In accordance with GDPR Article 27, Nuvbook has designated an EU representative accessible to data subjects and supervisory authorities within the EU/EEA. EU users may contact this representative at privacy@nuvbook.com marked “FAO: EU Representative.”

Part 2: Lawful Bases for Processing

Nuvbook processes personal data only where a valid lawful basis under GDPR Article 6 applies. For special category data (if any), an additional condition under Article 9 is also required. Nuvbook does not routinely process special category data and instructs Providers to avoid submitting such data through the platform without appropriate safeguards.

The lawful bases relied upon by Nuvbook are:

2.1 Performance of a Contract (Article 6(1)(b))

Processing is necessary to perform the contract with the user (e.g., providing platform access, processing bookings, sending transactional notifications, handling payments). This is the primary lawful basis for core platform operations.

2.2 Consent (Article 6(1)(a))

Where processing is not strictly necessary for the contract, Nuvbook relies on freely given, specific, informed, and unambiguous consent. This applies to:

  • Marketing and promotional communications (email and SMS);
  • Non-essential cookies (analytics, marketing, functional where not required); and
  • Any other optional data collection or processing activity clearly identified at the point of collection.

Consent is collected through affirmative opt-in mechanisms (e.g., unchecked check-boxes). Records of consent are maintained by Nuvbook’s Consent Management Platform (CMP) in accordance with GDPR Article 7. Consent may be withdrawn at any time without penalty.

2.3 Legitimate Interests (Article 6(1)(f))

Nuvbook relies on legitimate interests for processing activities where the interests of the business do not override the rights and freedoms of data subjects, including:

  • Platform security, fraud detection, and abuse prevention;
  • Anonymised analytics and product improvement; and
  • AI assistant improvement using aggregated interaction data.

A Legitimate Interests Assessment (LIA) is conducted and documented for each activity relying on this basis. The LIA confirms that the purpose is necessary, proportionate, and that a balancing test favours Nuvbook’s interests over any foreseeable impact on data subjects.

2.4 Legal Obligation (Article 6(1)(c))

Where processing is required to comply with a legal obligation under U.S. or applicable international law, Nuvbook processes personal data accordingly. Examples include:

  • Retention of financial records for tax and accounting purposes (typically 7 years);
  • Responding to lawful requests from competent authorities; and
  • Data breach notifications to supervisory authorities and affected individuals.

Part 3: Record of Processing Activities (ROPA)

In accordance with GDPR Article 30, Nuvbook maintains this Record of Processing Activities (ROPA) documenting all categories of processing carried out as a Data Controller. This record is reviewed and updated at least annually or whenever a material change to processing activities occurs.

Note: Where Nuvbook acts as a Data Processor on behalf of Providers (business owners), a separate Processor ROPA is maintained per Article 30(2) and is available upon request.

Processing ActivityData CategoriesPurposeLawful BasisRetentionRecipients
Account registration & managementName, email, password, business detailsProvide platform accessContract (Art. 6(1)(b))Duration of account + 90 daysInternal staff
Appointment bookingName, contact, service detailsDeliver booking servicesContract (Art. 6(1)(b))Active relationship + legal obligationsProvider business, Mailgun
Payment processingBilling details (tokenised)Process subscription & service paymentsContract (Art. 6(1)(b))7 years (tax/legal)Stripe, PayPal
Email notificationsName, email addressSend confirmations, reminders, updatesContract (Art. 6(1)(b))Duration of accountMailgun
SMS communicationsPhone number, message contentSend appointment reminders & updatesConsent (Art. 6(1)(a))Duration of consent + 4 years (records)Twilio
Analytics & performanceAnonymised usage data, IP addressImprove platform functionalityLegitimate interest (Art. 6(1)(f))26 monthsGoogle Analytics
AI assistant interactionsChat transcripts, metadataImprove AI accuracy and qualityLegitimate interest (Art. 6(1)(f))24 monthsInternal only
Marketing communicationsName, email addressSend promotional content (opt-in only)Consent (Art. 6(1)(a))Until consent withdrawnInternal, email provider
Legal compliance & fraud preventionAccount data, usage logsDetect abuse, comply with legal obligationsLegal obligation (Art. 6(1)(c)) / Legitimate interest (Art. 6(1)(f))As required by lawAuthorities (if required)

All processing activities listed above are subject to:

  • A documented lawful basis under GDPR Article 6;
  • Data minimization principles – only data strictly necessary for the stated purpose is collected;
  • Purpose limitation – data is not used for purposes incompatible with those stated; and
  • Storage limitation – data is deleted or anonymized once the retention period expires.

Part 4: Data Subject Rights and Request Procedures

GDPR grants data subjects a comprehensive set of rights over their personal data. Nuvbook is committed to honouring all applicable rights promptly, transparently, and free of charge, in accordance with GDPR Articles 12–23.

4.1 Rights Summary and Response Commitments

RightWhat It MeansHow Nuvbook Responds
Right of Access (Art. 15)Request a copy of all personal data heldProvide a structured data export within 30 days
Right to Rectification (Art. 16)Correct inaccurate or incomplete dataUpdate records immediately upon verified request
Right to Erasure (Art. 17)Request deletion (“right to be forgotten”)Delete data within 30 days unless legal retention applies
Right to Restrict Processing (Art. 18)Limit how data is used during a disputeFlag and restrict processing pending resolution
Right to Data Portability (Art. 20)Receive data in a structured, machine-readable formatExport in CSV/JSON format upon request
Right to Object (Art. 21)Object to processing based on legitimate interest or direct marketingCease relevant processing immediately upon receipt
Right to Withdraw Consent (Art. 7(3))Withdraw consent at any time without penaltyHonour immediately; confirm in writing within 5 business days
Right not to be subject to automated decision-making (Art. 22)Not be subject to solely automated decisions with significant effectNo solely automated high-impact decisions are made; human review available on request

4.2 How to Submit a Request

Data subjects may exercise any of the above rights by contacting Nuvbook at:

Email: privacy@nuvbook.com (Subject line: “Data Subject Request – [Right Type]”)

Post: 418 Broadway STE 8805, Albany, NY 12207, USA (FAO: Data Protection Officer)

Nuvbook will:

  1. Acknowledge receipt of the request within 5 business days;
  2. Verify the identity of the requester before processing the request;
  3. Respond substantively within 30 calendar days of receipt (extendable by a further 60 days for complex or numerous requests, with notice given within the initial 30-day period); and
  4. Provide a clear explanation if a request is refused, and inform the data subject of their right to complain to a supervisory authority.

4.3 Verification of Identity

To protect against fraudulent access requests, Nuvbook requires reasonable identity verification before fulfilling any Data Subject Request. Acceptable verification methods include:

  • Confirmation of the registered email address associated with the account;
  • Account login verification; or
  • Government-issued ID (for requests submitted by post or where email verification is insufficient).

Nuvbook will not request more personal data than is necessary for the purpose of identity verification.

4.4 Right to Lodge a Complaint

If a data subject believes their rights have been violated, they have the right to lodge a complaint with their local supervisory authority. Key supervisory authorities include:

Part 5: Third-Party Processor Register and Data Transfer Mechanisms

In accordance with GDPR Article 28, Nuvbook only engages third-party processors that provide sufficient guarantees of GDPR compliance. All processors are bound by Data Processing Agreements (DPAs) that impose obligations at least equivalent to those under GDPR.

Where personal data is transferred outside the UK or EU/EEA to a country not covered by an adequacy decision, Nuvbook relies on Standard Contractual Clauses (SCCs) approved by the European Commission, or the International Data Transfer Agreement (IDTA) for UK transfers, as the primary transfer mechanism.

5.1 Third-Party Processor Register

ProcessorService ProvidedData TransferredTransfer MechanismCertification
StripePayment processingBilling details (tokenized)SCCs / AdequacyPCI DSS, SOC 2
PayPalPayment processingBilling details (tokenized)SCCs / AdequacyPCI DSS, SOC 2
MailgunEmail deliveryName, email addressSCCsISO 27001
TwilioSMS deliveryPhone number, message contentSCCsISO 27001, SOC 2
Google AnalyticsUsage analyticsAnonymized IP, usage dataSCCs / AdequacyISO 27001
CloudflareSecurity & CDNIP address, request metadataSCCs / AdequacyISO 27001, SOC 2

5.2 Data Processing Agreements (DPAs)

Nuvbook maintains executed DPAs with each processor listed above. Each DPA includes, at minimum:

  • The subject matter, duration, nature, and purpose of the processing;
  • The type of personal data and categories of data subjects involved;
  • Obligations on the processor to process data only on Nuvbook’s documented instructions;
  • Requirements for processor sub-contracting, with prior written consent required;
  • Security obligations in line with GDPR Article 32;
  • Breach notification obligations (within 24 hours of discovery to Nuvbook);
  • Assistance obligations for data subject rights and DPIAs; and
  • Return or deletion of data upon termination of the agreement.

5.3 Transfer Impact Assessments (TIAs)

For all international transfers, Nuvbook conducts and documents a Transfer Impact Assessment (TIA) to evaluate whether the level of protection in the destination country is essentially equivalent to GDPR standards. TIAs are reviewed whenever:

  • A new international transfer is established;
  • The legal environment in a destination country changes materially; or
  • A supervisory authority issues guidance affecting the transfer mechanism in use.

Part 6: Data Protection by Design and by Default

In accordance with GDPR Article 25, Nuvbook embeds data protection principles into the design of all new products, features, and processing activities. Privacy is considered from the earliest stages of product development, not as an afterthought.

6.1 Technical Measures

  • End-to-end encryption (HTTPS/TLS) for all data in transit;
  • Encryption at rest for all stored personal data;
  • Role-based access control (RBAC) – staff access data only on a need-to-know basis;
  • Multi-factor authentication (MFA) enforced for all internal systems;
  • Regular penetration testing and vulnerability assessments; and
  • Automated anomaly detection and intrusion monitoring.

6.2 Organizational Measures

  • Mandatory data protection training for all staff with access to personal data (at least annually);
  • A documented data protection policy distributed to all employees;
  • Confidentiality obligations included in all employment contracts and contractor agreements;
  • Internal privacy impact review required for any new processing activity or significant system change; and
  • Regular internal audits of compliance with this document and related policies.

6.3 Data Minimization and Default Settings

Nuvbook’s systems are configured to collect the minimum data necessary by default. Specifically:

  • No optional or non-essential data fields are pre-populated or collected without affirmative user action;
  • Non-essential cookies are set to “off” by default for all users, including non-EU users;
  • Marketing communications require explicit opt-in and are never enabled by default; and
  • Data retention schedules are enforced automatically, with data deleted or anonymized upon expiry.

Part 7: Data Protection Impact Assessments (DPIAs)

In accordance with GDPR Article 35, Nuvbook conducts a Data Protection Impact Assessment (DPIA) before commencing any processing activity that is likely to result in a high risk to the rights and freedoms of individuals. A DPIA is mandatory where processing involves:

  • Systematic and extensive automated processing, including profiling, that produces legal or similarly significant effects;
  • Large-scale processing of special category data or criminal conviction data;
  • Systematic large-scale monitoring of publicly accessible areas; or
  • Any other activity identified on a supervisory authority’s list of processing operations requiring a DPIA.

7.1 DPIA Procedure

  1. The relevant team lead or product owner identifies the need for a DPIA at project initiation.
  2. The DPO is notified and a DPIA template is completed, covering: description of processing, necessity and proportionality assessment, identification of risks, and proposed mitigating measures.
  3. The DPO reviews and approves the DPIA or recommends changes.
  4. Where residual high risk remains after mitigation, the relevant supervisory authority is consulted prior to commencing processing, in accordance with GDPR Article 36.
  5. Completed DPIAs are stored in Nuvbook’s internal compliance register and reviewed whenever the processing activity changes materially.

Nuvbook has conducted DPIAs in connection with the following existing processing activities:

  • The AI assistant and its use of interaction data for model improvement;
  • Large-scale SMS communications via Twilio; and
  • Automated appointment scheduling and client profiling features.

Part 8: Data Breach Detection, Response, and Notification

In accordance with GDPR Articles 33 and 34, Nuvbook maintains a formal data breach response procedure to ensure that all personal data breaches are detected, assessed, contained, and reported within the legally required time-frames.

8.1 Definition of a Personal Data Breach

A personal data breach is any security incident leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored, or otherwise processed (GDPR Article 4(12)).

This includes, but is not limited to:

  • Unauthorized access to Nuvbook’s systems or databases;
  • Accidental disclosure of personal data to an unintended recipient;
  • Loss or theft of a device containing personal data;
  • Ransomware or malware attacks affecting personal data; and
  • Accidental deletion of personal data without backup recovery.

8.2 Breach Response Timeline

Time-frameActionResponsible PartyGDPR Reference
0–24 hoursDetect, contain, and assess the breach. Log incident details.Security / Engineering teamArt. 33 – preparation
24–48 hoursDetermine if personal data is affected and assess risk to individuals.DPO / Legal teamArt. 33(1)
By 72 hoursNotify relevant supervisory authority (e.g., ICO for UK; lead SA for EU) if risk to individuals is likely.DPOArt. 33(1)
Without undue delayNotify affected data subjects if the breach is likely to result in high risk to their rights and freedoms.DPO / Communications teamArt. 34
OngoingDocument all breach details, actions taken, and outcomes in the internal breach register.DPOArt. 33(5)

8.3 Supervisory Authority Notification (Article 33)

Nuvbook will notify the competent supervisory authority within 72 hours of becoming aware of a breach that is likely to result in a risk to the rights and freedoms of natural persons. The notification will include:

  • The nature of the personal data breach, including categories and approximate number of data subjects and records affected;
  • The name and contact details of the DPO;
  • The likely consequences of the breach; and
  • The measures taken or proposed to address the breach and mitigate its effects.

Where notification cannot be made within 72 hours, a partial notification will be submitted with an explanation of the delay, followed by further information as it becomes available.

8.4 Data Subject Notification (Article 34)

Where a breach is likely to result in a high risk to the rights and freedoms of affected individuals, Nuvbook will notify those individuals without undue delay. The notification will:

  • Describe the nature of the breach in clear, plain language;
  • Provide the DPO’s contact details;
  • Describe the likely consequences;
  • Describe the measures taken or proposed to address and mitigate the breach; and
  • Include practical advice on steps individuals can take to protect themselves.

8.5 Internal Breach Register

All personal data breaches, regardless of whether they meet the threshold for supervisory authority notification, are recorded in Nuvbook’s internal Breach Register. Each entry includes:

  • Date and time of discovery and occurrence (if known);
  • Nature of the breach and data categories affected;
  • Number of data subjects affected (actual or estimated);
  • Risk assessment outcome;
  • Actions taken to contain and remediate the breach; and
  • Whether notification was made to the supervisory authority and/or data subjects, and the rationale if not.

Part 9: Consent Management

Nuvbook’s consent practices are designed to fully comply with GDPR Article 7 and Recital 32. Consent is only relied upon where it is the appropriate lawful basis and is not used as a substitute for other lawful bases.

9.1 Standards for Valid Consent

All consent collected by Nuvbook meets the following standards:

  • Freely given: Consent is not bundled with terms and conditions, nor is it a precondition of service access (unless the processing is strictly necessary for the service).
  • Specific: Consent is obtained separately for each distinct processing purpose. Blanket consent is not used.
  • Informed: The data subject is clearly told who is collecting data, what it will be used for, and how they can withdraw consent before giving it.
  • Unambiguous: Consent is given through a clear, affirmative action (e.g., ticking an unchecked box). Pre-ticked boxes, silence, and inactivity do not constitute consent.

9.2 Consent Records

Nuvbook’s Consent Management Platform (CMP) records the following for each consent event:

  • The identity of the data subject (where determinable);
  • The date, time, and method of consent (e.g., web form, SMS double opt-in);
  • The specific purpose(s) consented to;
  • The version of the privacy notice presented at the time of consent; and
  • Any subsequent withdrawal of consent and the date it was acted upon.

Consent records are retained for the duration of the processing relationship and for 4 years after the last interaction, to enable Nuvbook to demonstrate compliance in the event of a regulatory inquiry or complaint.

9.3 Withdrawal of Consent

Data subjects may withdraw consent at any time through the following mechanisms:

  • Replying STOP to any SMS message;
  • Clicking the “Unsubscribe” link in any marketing email;
  • Updating preferences in account settings; or
  • Contacting privacy@nuvbook.com.

Nuvbook will honour withdrawal requests immediately and confirm in writing within 5 business days. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.

Part 10: Data Retention and Deletion

In accordance with the storage limitation principle (GDPR Article 5(1)(e)), Nuvbook retains personal data only for as long as is necessary for the purposes for which it was collected, or as required by law.

10.1 Retention Schedule

Data CategoryRetention PeriodBasis
Business account dataDuration of subscription + 30 days post-cancellationContract / Legal obligation
Client booking and appointment dataActive relationship + applicable legal obligationsContract / Legal obligation
Payment and billing records7 years from transaction dateLegal obligation (tax/accounting)
AI assistant interaction logs24 months from date of interactionLegitimate interest
SMS consent records4 years from last interactionLegal obligation (TCPA / GDPR Art. 7)
Cookie consent records26 months or duration of consentLegal obligation (GDPR Art. 7)
Analytics and usage data26 months (anonymised thereafter)Legitimate interest
Data breach recordsMinimum 5 years from date of breachLegal obligation (GDPR Art. 33(5))
DPIA recordsRetained while processing activity is live + 3 yearsLegal obligation (GDPR Art. 35)
Employee/contractor personal dataDuration of engagement + 6 yearsLegal obligation

10.2 Deletion and Anonymization

Upon expiry of the relevant retention period, personal data is either:

  • Securely deleted using industry-standard deletion methods that prevent recovery; or
  • Anonymized in a manner that is irreversible and such that the data can no longer be attributed to a specific individual (e.g., for aggregated analytics).

Data deletion and anonymization schedules are automated where technically feasible and audited quarterly by the DPO.

Part 11: Training and Accountability

Nuvbook recognizes that compliance with GDPR is an ongoing organizational commitment, not a one-time exercise. The following measures ensure that accountability is embedded throughout the organization.

11.1 Staff Training

  • All staff with access to personal data complete mandatory GDPR and data protection training upon onboarding and at least annually thereafter;
  • Specialist training is provided for staff in roles with heightened data protection responsibilities (e.g., engineering, customer support, legal);
  • Training completion is recorded by the DPO; and
  • Phishing simulation and security awareness exercises are conducted regularly.

11.2 Internal Audits

  • The DPO conducts an annual review of this document and all associated data protection policies;
  • Processing activities are audited against the ROPA at least annually;
  • Third-party processor compliance is reviewed upon contract renewal and following any material change; and
  • Audit findings are reported to senior management with a remediation plan where required.

11.3 Policy Review Triggers

This document is reviewed immediately (outside of the annual cycle) upon:

  • A material change to Nuvbook’s processing activities or technology stack;
  • A personal data breach or near-miss incident;
  • New or amended guidance from a supervisory authority;
  • A change in applicable law; or
  • A merger, acquisition, or significant corporate restructuring.

Part 12: Contact and Escalation

For any GDPR-related queries, data subject rights requests, breach reports, or compliance concerns, please contact Nuvbook’s Data Protection Officer:

<u>Data Protection Officer</u>

<u>Nuvbook | 418 Broadway STE 8805, Albany, NY 12207, USA</u>

<u>Email: privacy@nuvbook.com</u>

<u>Phone: +19143718990</u>

<u>Response time: Within 5 business days for all enquiries; 30 days for formal DSRs.</u>

<u>EU data subjects may also contact Nuvbook’s EU Representative at the same email address marked “FAO: EU Representative.”</u>

If you are not satisfied with Nuvbook’s response, you have the right to lodge a complaint with your local supervisory authority (see Part 4.4 for a list of key authorities).

Document Sign-Off

Document Title: Nuvbook GDPR Compliance Document v1.0

Prepared by: Data Protection Officer

Reviewed by: Legal / Senior Management

Approved by: [Name / Title]

Approval Date: 2026, May 01

Next Review Due: 2027, May 01

Questions or Concerns?

If you have any questions about this general data protection regulation , please don't hesitate to reach out to our support team.

Contact Support