Back to Nyvlo
Legal

Data Processing and Sub-processors

Last updated July 2026

This page explains how Nyvlo handles the data you and your users put into the product, and lists the vendors we rely on to run it. It is written for business customers who need to understand our data commitments before they build on Nyvlo.

Our role

When you use Nyvlo to build and run tools, you decide what data goes in and why. That makes you the controller of that data and makes Nyvlo the processor. We process customer data only on your documented instructions and only to provide, secure, and support the service. We do not sell your data and we do not use it to advertise to anyone.

Security and confidentiality

We protect customer data with encryption in transit and at rest, Row-Level Security that isolates each account, access limited to the staff who need it, and vendors chosen for their own security posture. Everyone at Nyvlo who can touch customer data is under a confidentiality obligation. We keep first-party analytics on our own events table with no third-party ad trackers.

Breach notification

If we become aware of a personal-data breach that affects your data, we will notify you without undue delay and share what we know: what happened, which data was involved, the likely impact, and the steps we are taking. We will keep you updated as we learn more so you can meet your own notification duties.

International transfers

Nyvlo and our sub-processors may process data in countries other than where your users are. EU visitors are present, and where data leaves the EU or UK we rely on recognised safeguards such as the Standard Contractual Clauses, together with the technical protections above. Governing law and venue for any dispute are set in our Terms and remain the State of California, United States, with disputes handled in the courts located in California.

Your rights and ours

You can export and delete all of your data from Settings at any time. Deletion also cancels any live subscription and purges your tools, prompts, and published links, keeping only the minimal records we are legally required to hold. We will help you respond to requests from your own users, such as access or deletion requests, to the extent the product allows.

Requesting a signed DPA

If your organisation needs a countersigned Data Processing Agreement, email hello@nyvloai.com and we will send our standard agreement for signature. The contracting entity is Nyvlo Technologies, based in California, and our registered address is available on request.

Sub-processors

We use a small set of vetted vendors to run Nyvlo, each bound by a data-processing agreement and each processing customer data only for one job. By category, they cover: authentication and database, web hosting, build-engine hosting, payment processing, the AI processing that generates your tools, transactional email, error monitoring, optional single-sign-on, and coarse visitor geolocation where the raw IP address is never persisted.

The current named list of sub-processors, what each one handles, and where they operate is available to customers on request: email hello@nyvloai.com. Before we add or replace a sub-processor, we will give customers on a signed DPA notice so you have a chance to review the change.