How Nandzz collects and uses personal data, and the rights you have. This covers account holders, visitors and people who book through a Nandzz page.
This document is also available in Italian. For consumers resident in Italy, the Italian version prevails.
The short version
The data controller is [LEGAL NAME] S.r.l., [STREET, POSTCODE CITY (PROVINCE)], Italia, VAT [P.IVA — pending registration]. You can reach us at [email protected] or by PEC at [PEC ADDRESS].
We have not appointed a Data Protection Officer, because the law does not require it for our activities. Your requests are handled directly by the team responsible for privacy.
Bookings and AI chats on a business's page.Each business using Nandzz controls the personal data of its own customers. We act as that business's processor under Art. 28 GDPR (see our DPA). This applies to:
For requests about that data, contact the business directly. We will help them answer you. Section 4 explains this in more detail.
The table below lists each processing activity under the GDPR (Regulation (EU) 2016/679), with the data used, the legal basis under Art. 6 GDPR, and how long we keep it.
| Activity | Data | Legal basis | Retention |
|---|---|---|---|
| Account and sign-in | Email, password (hashed), username, display name, Google account name, email and avatar if you use Google sign-in, phone number if you verify it | Contract (Art. 6(1)(b)) | While your account exists. Deleted within 30 days of account deletion. |
| Your public page and content | Profile details, bio, avatar, branding, business address, published content, links, gallery, comments, likes and follows | Contract (Art. 6(1)(b)) | Until you delete it or your account |
| Payments and invoicing | Name, email, billing address, plan, transactions, credit history. Card data stays with Stripe. | Contract; legal obligation (tax and accounting, Art. 6(1)(c)) | 10 years, as required by Italian accounting law (Art. 2220 Civil Code) |
| Service emails and messages | Email or phone number, message content | Contract; legitimate interest in security notices | Delivery logs for 24 months |
| Cookieless visitor statistics | A one-way hash of IP address, browser user-agent and date, which rotates every day. Raw IP addresses are never stored. If you are signed in, your user ID is used instead. | Legitimate interest (Art. 6(1)(f)): showing page owners how many people visit | 13 months |
| Security and abuse prevention | IP address, request and authentication logs, rate-limit counters | Legitimate interest: keeping the service secure | Up to 90 days, unless needed for an investigation |
| AI features you use | Instructions and content you submit to the AI editor | Contract | Not stored by us beyond the job result. The provider keeps it for up to 30 days for abuse monitoring. |
| Support and contact form | Name, email, your message | Legitimate interest in answering you; contract where it relates to your account | Up to 24 months after the conversation ends |
| Content reports (DSA) | URL reported, reason, your name and email if given | Legal obligation (DSA Art. 16) | 24 months |
| Terms acceptance records | Version accepted and timestamp | Legal obligation and legitimate interest in proving consent and acceptance | While your account exists |
We do not use your data for advertising, profiling or automated decisions with legal or similarly significant effects (Art. 22 GDPR). We do not use your content or your customers' data to train AI models.
Providing account and payment data is necessary to use those features. Everything else is optional.
Where we rely on legitimate interests, we have balanced them against your rights. We keep the data minimal, for example by hashing visitor data daily. You can object at any time by writing to [email protected]. We will stop unless we have compelling legitimate grounds, or need the data for legal claims.
When you book an appointment or chat with an AI agent on a business's Nandzz page, the business collects the following data, and its own staff can see it:
The business is the controller, and Nandzz processes the data on its behalf. Its own privacy notice applies. Ask the business directly if you want to exercise your rights.
On the business's behalf, we:
Booking customer details are anonymised automatically 24 months after the appointment, or earlier if the business deletes them or closes its account.
If you are signed in to your own Nandzz account when you book, we also link the booking to your account so you can manage it. For that link we are the controller, and the legal basis is contract.
Our main database is hosted in the EU. Some providers in the table above are based in the United States or may access data from there. When data leaves the EU/EEA, we rely on safeguards:
You can ask us for a copy of these safeguards.
We protect data with:
No system is perfectly secure. If a breach is likely to put you at risk, we will notify you and the competent authority as the law requires.
Under the GDPR you have the right to:
Write to [email protected]. We answer within one month. In complex cases this can be extended by two more months, and we will tell you if so. We may ask you to confirm your identity.
You also have the right to complain to a supervisory authority. In Italy that is the Garante per la protezione dei dati personali. You can also complain to the authority where you live or work.
Nandzz is not intended for children under 14, and they may not create an account. If you believe a child under 14 has given us personal data, contact us and we will delete it.
United Kingdom.The UK GDPR gives you the same rights. You can complain to the Information Commissioner's Office (ico.org.uk). Transfers from the UK use the UK Addendum to the Standard Contractual Clauses, or the UK–US data bridge.
California and other US states. In the last 12 months we collected the categories described in section 2:
We used them for the business purposes described above. We do not sell personal information. We do not share it for cross-context behavioural advertising. We do not use sensitive personal information to infer characteristics.
You may request to know, correct or delete your personal information through the contacts above. We will not discriminate against you for exercising these rights. An authorised agent can make a request on your behalf, with proof of authorisation.
We update this policy when our processing changes. For significant changes, we will notify you in the app or by email before they apply. The date at the top shows the current version.