This Privacy Policy explains how Teksyte UK Ltd (“Teksyte”, “we”, “us”), as data controller, processes personal data of visitors and customers of nivosync.com and the NivoSync software product (collectively, the “Services”). We comply with the UK Data Protection Act 2018, the UK GDPR, and the EU GDPR where applicable.
1. Data controller
Teksyte UK Ltd is the data controller for the personal data we process under this policy. You can contact us at info@nivosync.com for any privacy-related question. We do not currently appoint a Data Protection Officer because we are not required to under UK GDPR Article 37 (we do not engage in large-scale special-category processing).
2. Personal data we collect
2.1 Contact and account data
When you create an account, contact us, or purchase a Licence:
- Full name
- Email address
- Country (for VAT calculation)
- Optional: VAT number (for B2B reverse-charge billing)
- Account session tokens (passwordless magic link)
2.2 Payment data
We never see, store, or process card details. PayPal, our payment processor, holds payment instruments under their own privacy policy. From PayPal we receive transaction metadata: payer name, payer email, country, transaction ID, amount, currency, status.
2.3 Plugin telemetry
When the Plugin is installed and a Licence is activated, the Plugin contacts our licence-server API with the following data:
- Licence key (necessary to identify your subscription)
- Domain (where the Plugin is being activated; stored as both the full domain string and a salted SHA-256 hash for log purposes)
- Plugin version
- WordPress version (for compatibility verification)
- Activation status (success / failure code)
We do not collect: the contents of your WooCommerce database, your customer lists, your diamond inventory, your sales transactions, or any personal data of your visitors. The Plugin operates entirely within your own WordPress installation and does not transmit any of that data to us.
2.4 Server logs
Our infrastructure automatically logs:
- Truncated IP address (last octet zeroed for IPv4; last 64 bits zeroed for IPv6) for abuse-prevention and rate-limiting
- User-agent string
- HTTP request method, path, response status, timing
- A request correlation ID for cross-log debugging
These logs are retained for 30 days, then permanently deleted.
2.5 Analytics
We currently run no analytics or tracking scripts on this website. We do not record your page views, do not profile your behaviour, and do not share browsing data with any third party. If we adopt an analytics tool in the future, it will be a privacy-focused, cookie-free solution, and this policy will be updated before it goes live.
3. Lawful bases under UK GDPR
- Performance of a contract (Article 6(1)(b)): for account, payment, and Licence-server processing necessary to deliver the Services you have purchased.
- Legitimate interests (Article 6(1)(f)): for security logging, fraud prevention, abuse-rate limiting, and non-personalised analytics. Our interests are balanced against yours by data minimisation (truncated IPs, no cross-site tracking, short retention).
- Compliance with legal obligation (Article 6(1)(c)): for tax record-keeping (HMRC, and EU equivalents under OSS).
- Consent (Article 6(1)(a)): for optional marketing emails. You can withdraw consent at any time via the link in every marketing email or by writing to info@nivosync.com.
4. Retention
| Category | Retention |
|---|---|
| Account data | While Account is active, plus 30 days after closure |
| Active Licence records | For the lifetime of the Licence + 7 years (UK tax law) |
| Cancelled / expired Licence records | 7 years from cancellation (HMRC retention requirement) |
| Tax invoices | 7 years from issue (HMRC) |
| Server access logs | 30 days, then deleted |
| Plugin telemetry per request | 90 days, then aggregated and underlying rows deleted |
| Support tickets | 3 years from last interaction |
| Marketing email opt-ins | Until you withdraw consent |
5. Who we share data with
We share personal data with a small set of carefully chosen processors who help us operate the Services. Each processor is bound by a written data processing agreement (DPA) and by their own GDPR-compliant privacy posture.
| Processor | Purpose | Data shared | Region |
|---|---|---|---|
| PayPal (Europe) S.à r.l. et Cie, S.C.A. | Payment processing, subscription management | Name, email, billing country, payment instrument | EU (Luxembourg) |
| Hetzner Online GmbH | Server hosting, backups | All processing data (encrypted at rest) | Germany / Finland |
| Cloudflare, Inc. | DNS, CDN, DDoS protection | IP address, request metadata (transit only) | Global (UK / EU optimisation enabled) |
| Kualo Limited | Email hosting — inbound (info@, support@, etc.) and outbound transactional email (sign-in links, licence delivery, contact form submissions) | Email address, message content | UK |
| Help Scout PBC | Customer support helpdesk (planned) | Email content, customer name, ticket history | US (under EU SCCs) |
| Sentry (Functional Software, Inc.) | Error tracking and operational alerting (planned) | Stack traces, request context, scrubbed PII | US (under EU SCCs) |
6. International transfers
Where personal data is transferred outside the UK or EEA, we rely on: (a) UK / EU adequacy decisions where they exist; or (b) the European Commission’s Standard Contractual Clauses (SCCs) supplemented by appropriate technical measures (encryption in transit and at rest). For US-based processors not under an adequacy regime, we rely on the EU-US Data Privacy Framework where the processor is self-certified, or on SCCs otherwise.
7. Your rights
Under UK GDPR you have the following rights, exercisable free of charge by writing to info@nivosync.com:
- Right of access — receive a copy of the personal data we hold about you.
- Right to rectification — correct inaccurate or incomplete data.
- Right to erasure (“right to be forgotten”) — have your personal data deleted, subject to legal retention obligations (e.g. tax records).
- Right to restriction — limit processing while a dispute is investigated.
- Right to portability — receive your data in a structured, machine-readable format.
- Right to object — object to processing based on legitimate interests, including direct marketing.
- Right not to be subject to automated decision-making — we do not use automated decision-making with legal effects on you.
We respond to verified requests within 30 days. We may need to verify your identity (e.g. by sending a confirmation email to the registered address) before acting on a request.
If you believe we have not handled your data properly, you have the right to complain to the UK Information Commissioner’s Office (ICO) at ico.org.uk or to your local data-protection authority within the EU.
8. Security
We apply technical and organisational measures appropriate to the risk, including:
- TLS 1.2+ for all data in transit
- AES-256-GCM authenticated encryption for sensitive data at rest
- HKDF-derived per-context encryption keys
- HMAC-signed integrity on all licence-server API responses
- Two-factor authentication on administrative accounts
- Truncated IP addresses in logs (data minimisation)
- Encrypted off-site backups (restic)
- Periodic security audits (most recent: April–May 2026; see Security)
9. Cookies
Cookie usage is described in detail in our Cookies notice. Summary: we use a single strictly-necessary session cookie for authenticated areas of the Site. We do not set marketing or tracking cookies in v1.
10. Children
The Services are not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact us and we will delete it.
11. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be notified to active customers by email at least 30 days before they take effect. The current version is always accessible at /legal/privacy.
12. Contact
For privacy questions or to exercise your rights: info@nivosync.com.
Teksyte UK Ltd, registered in England and Wales.