Legal

SSL/TLS Encryption Policy

Last updated: August 7, 2026

Effective Date: November 01, 2025

Last Reviewed: May 01, 2026

1. Purpose

This SSL/TLS Encryption Policy describes how Nuvbook ("Nuvbook," "we," "our," or "us") uses Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols to protect data transmitted between users and the Platform. It outlines our commitment to secure communication, the standards we apply, and the responsibilities of all parties involved in using the Platform.

This policy supports our obligations under applicable data protection and security frameworks, including the General Data Protection Regulation (GDPR), the California Consumer Privacy Act and California Privacy Rights Act (CCPA/CPRA), and applicable U.S. federal and state-level privacy and security requirements.

2. Scope

This policy applies to all data transmitted between users and the Nuvbook Platform, including data exchanged during account registration and login, booking and appointment management, AI assistant interactions, payment initiation and processing, SMS and email communications, website builder activity, and all other Platform features. It covers data in transit across Nuvbook-managed infrastructure as well as communications routed through authorized third-party service providers.

3. How SSL/TLS Encryption Works

SSL and TLS are cryptographic protocols that establish an encrypted connection between a user's device and our servers. When a user accesses the Nuvbook Platform, this connection is secured before any data is exchanged, ensuring that information transmitted cannot be intercepted, read, or tampered with by unauthorized third parties.

This is the same technology used by banks, healthcare providers, and major e-commerce platforms to protect sensitive information in transit. Users can identify a secure connection by the padlock icon displayed in their browser's address bar and the use of "https" at the start of the Platform's web address.

4. Encryption Standards

Nuvbook applies current industry-standard TLS protocols across all Platform communications. We support only versions of TLS that meet modern security requirements and have deprecated older, less secure versions of the protocol, including SSL 3.0 and early TLS versions, in line with guidance from the Payment Card Industry Security Standards Council and other recognised security authorities.

Our TLS implementation uses strong cipher suites that provide both encryption and authentication, ensuring that data cannot be read in transit and that users are communicating with genuine Nuvbook systems rather than an impersonating party. TLS certificates are issued by trusted certificate authorities and are renewed and monitored on an ongoing basis to prevent lapses in coverage.

5. What Is Protected in Transit

All data exchanged between users and the Platform is protected by TLS encryption while in transit. This includes account credentials and login sessions, personal and business profile information, booking and appointment details, client contact information, AI assistant interactions and automated communications, payment initiation requests routed to our third-party payment processors, and SMS and email communications facilitated through our messaging infrastructure.

Payment card data is never transmitted through Nuvbook's own systems. All payment transactions are routed directly through our PCI-DSS Level 1 certified payment processors, Stripe and PayPal, which apply their own TLS encryption standards throughout the payment flow.

6. Third-Party Service Providers

Nuvbook works with a number of third-party providers to deliver Platform functionality, including Stripe and PayPal for payment processing, Mailgun for email delivery, Twilio for SMS messaging, and Google Calendar for scheduling integrations. Where data is transmitted to or from these providers, Nuvbook requires that the communication be secured using TLS encryption consistent with current industry standards. Each provider maintains its own security certifications and policies, which users are encouraged to review directly.

7. Certificate Management

Nuvbook uses SSL/TLS certificates issued by recognized and trusted certificate authorities. These certificates are monitored for validity and renewed ahead of expiry to ensure uninterrupted encryption across the Platform. In the event that a certificate issue is identified, our team will act promptly to resolve it and maintain the security of all user communications.

8. Limitations and User Responsibilities

While Nuvbook applies TLS encryption to all data transmitted through the Platform, the security of data once it reaches a user's own device depends in part on the security of that device. Users are responsible for maintaining the security of their own systems, including keeping software and browsers up to date, using strong and confidential login credentials, and ensuring that any devices used to access the Platform are adequately protected.

Nuvbook cannot guarantee the security of communications that take place outside of the Platform, such as data shared via personal email accounts, third-party applications not integrated with Nuvbook, or other channels beyond our control.

9. Incident Response

In the event that Nuvbook identifies a vulnerability or failure in our TLS implementation, we will act immediately to investigate, remediate, and restore secure communications. If a confirmed breach of data in transit occurs, Nuvbook will notify the relevant supervisory authority within 72 hours and will notify affected users without undue delay where the breach is likely to result in a high risk to their rights and freedoms, in accordance with GDPR Articles 33 and 34 and applicable U.S. state-level breach notification laws.

10. Compliance Reviews

Nuvbook reviews its TLS configuration and certificate management practices on a regular basis to ensure continued alignment with current security standards. As the TLS landscape evolves and new guidance is issued by recognised standards bodies, we will update our implementation accordingly and reflect any material changes in revisions to this policy.

11. Updates to This Policy

Nuvbook may update this policy from time to time to reflect changes in our technology, legal obligations, or business practices. Updates will be communicated via email or in-platform notice. Continued use of the Platform after such updates constitutes acceptance of the revised policy. The effective date will always be displayed at the top of this document.

12. Contact

For questions about this policy or our encryption practices, please reach out to us at privacy@nuvbook.com,

by mail at

418 Broadway STE 8805, Albany, NY 12207, USA

or by phone at +1 (914) 371-8990.

Our response time is 5 to 10 business days.

Questions or Concerns?

If you have any questions about this ssl/tls encryption policy, please don't hesitate to reach out to our support team.

Contact Support