Nevai
Home
Products
WWebsiteA fast public website with forms, appointments and a focused webshop connected to the work behind it.CClassesClasses, appointments and participants for dance, fitness and teaching businesses.HHospitalityReservations, staff, menus, tables and orders in one hospitality workflow.+CustomExtra modules, Activepieces automation and defined AI work where your process needs more.
See it in practiceQuinn.ArtArtist portfolio and appointmentsSalsaPleasureDance school website and ClassesView all projects →
Pricing DemoAboutWorkContact us
Contact us

Privacy and cookies

This statement explains which personal data Nevai processes through this Website, the Nevai App and our services, why we process it and which choices and rights apply. When an organisation uses Nevai for its own students, guests, employees or customers, that organisation usually determines the purpose of the processing.

Draft for local review · 5 September 2026 · company details, the processor list and legal review are still required. Do not publish.
  • About this statement
  • Who is responsible?
  • What does this statement cover?
  • Which data do we process?
  • Why do we use data?
  • Data about our customers' customers
  • Service providers and transfers
  • How long do we retain data?
  • How do we secure data?
  • Your privacy rights
  • Children and families
  • AI, automation and media
  • Cookies and local storage
  • Changes and contact

Who is responsible?

[LEGAL NAME], trading as Nevai, is the controller for personal data we use for our own business operations, such as Website contact, enquiries, customer accounts, invoicing, support and security. Our contact details are [REGISTERED ADDRESS] and privacy@nevai.app.

When a customer organisation uses Nevai to manage data about its students, guests, employees or other contacts, that organisation generally determines why and how the data is used. Nevai then processes it as a processor under the agreement and processing arrangements. The organisation remains the first point of contact for its own services.

What does this statement cover?

This statement applies to nevai.app, the Nevai App, contact and appointment forms, customer accounts, support and the services Nevai manages for customer organisations. A public Website belonging to a customer organisation also needs its own privacy statement for processing controlled by that organisation.

External websites and services have their own privacy rules. When a customer activates an external calendar, payment provider, accounting package or other integration, it will be made clear before use which party receives the data and for what purpose.

Which data do we process?

Depending on the service, this may include:

  • name, email address, telephone number and organisation details;
  • account identity, profile preferences, roles and access rights;
  • contact enquiries, appointments, schedules, registrations, attendance, availability and reservations;
  • family or guardian relationships when an organisation works with minors;
  • orders, products, credits, subscriptions and payment status without storing card or bank details in Nevai;
  • content, documents, images and class videos added by authorised users;
  • support messages, limited technical diagnostics, security events and device or network information where necessary.

We do not request data that is unnecessary for the selected process. Forms show which fields are required.

Why do we use data?

We use personal data to handle enquiries and appointments, perform agreements, secure accounts and access, deliver selected services, provide support, investigate errors and abuse, and meet legal obligations.

The legal basis depends on the purpose: performance of a contract, steps taken at a person's request before entering into a contract, a legal obligation, or a legitimate interest such as security and normal customer communication. We request separate consent for optional marketing or other processing that requires consent. Confirming that privacy information has been read does not automatically make consent the legal basis.

Data about our customers' customers

A dance school, restaurant or other organisation may use Nevai for people, classes, appointments, reservations, messages, content or sales. That organisation determines which data it needs, who may access it, which retention period applies and what information it provides to the people concerned.

Nevai does not use this data for its own advertising and does not sell it. We process it only for the agreed service, security, support and legal obligations. A request about a class registration, restaurant reservation or other relationship with such an organisation should first be addressed to that organisation. We assist it where required under the processing arrangements.

Service providers and transfers

Nevai uses Supabase for authentication, relational data and storage within the selected environment. Hosting may be shared, dedicated or on customer infrastructure. Other providers are used only where required for services such as email, calendars, payments, accounting or technical management and where the relevant function has been activated.

The final version will include an up-to-date processor list stating each provider's name, purpose, location and appropriate safeguards for transfers outside the European Economic Area. Provider secrets do not belong in the Website or app, and payment card and bank details remain with the selected payment provider.

How long do we retain data?

We do not retain data longer than necessary for the purpose, the agreement and legal obligations. For Website forms and public bookings, the applicable retention period is shown with the form or process and recorded when the submission is received. A later change does not silently extend an earlier retention period.

Limited Website diagnostics are retained for no more than 30 days. A requested account closure currently has a 7-day recovery period; the Auth identity is then deleted if no legal or operational block applies. Certain evidence records concerning access, deletion or privacy requests may be retained for up to 365 days without retaining the deleted content itself. Financial data follows the applicable statutory retention period once live sales and invoicing are used.

Deletion from active systems does not mean that a record immediately disappears from every historical backup. A recovery copy remains restricted and must be processed again under current deletion and retention rules after restoration.

How do we secure data?

Nevai uses personal accounts, organisation boundaries, roles and permissions, encrypted connections and database policies to restrict access. The server checks authorisation again; merely hiding a button in the interface is never the security measure. Secret database, payment and provider details are not included in public Websites or browser code.

Access is limited to people and providers who need it for their task. No measure eliminates every risk. If you suspect abuse or a data breach, report it via security@nevai.app without unnecessarily including sensitive data in the first message.

Your privacy rights

Depending on the circumstances, you may request access, correction, deletion, restriction or portability, or object to processing. You may withdraw consent for future processing where consent is the legal basis. We may request additional information to verify your identity securely.

For data managed by a customer organisation through Nevai, submit the request to that organisation. For data controlled by Nevai, email privacy@nevai.app. We respond within the legal time limit and explain when a request cannot be completed in full, for example because of a statutory retention duty or the rights of others. You may also lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) via https://autoriteitpersoonsgegevens.nl.

Children and families

Nevai is not a service through which children independently enter into payment agreements with Nevai. Customer organisations may use family relationships so that a parent or guardian can help a minor with registrations, credits or payments. The organisation determines which age rules, consent and information apply.

A guardian relationship is not inferred from a name alone. Access to a minor's data requires an explicit organisation-specific relationship and appropriate permissions. Minors do not automatically receive payment authority.

AI, automation and media

AI or automation is used only for an agreed task with information that may lawfully be used for that task. A generated summary, proposal or answer may require human review. Nevai does not make decisions based solely on AI that have legal or similarly significant effects on people, unless a separately assessed process is introduced later and clearly explained.

Photos, videos and other media may contain personal data. The customer organisation determines who may upload and view them and which retention period is appropriate. Publication or reuse outside the agreed class, Website or organisation requires its own valid basis and clear information.

Cookies and local storage

This public Website currently uses no analytics, advertising or marketing cookies. It does use necessary local browser storage for choices you make:

  • nevai-language remembers the selected language until you change it or clear browser storage;
  • nevai-theme remembers light or dark mode until you change it or clear browser storage;
  • nevai-home-theme is an older theme key that is read only for compatibility;
  • nevai-cookie-consent-v1 stores your choice only if optional cookies are enabled in the future.

Necessary preferences are not used to track you across other websites. Before optional analytics or marketing storage is enabled, you will first be given a clear choice. You can clear local storage through your browser; preferences will then be requested again or reset to their defaults.

Changes and contact

We update this statement when our services, providers or legal obligations change. The date of the current version appears at the top. We inform affected customers appropriately when a significant change is made.

Privacy questions and requests can be sent to privacy@nevai.app.

[LEGAL NAME] · [LEGAL FORM] · [REGISTERED ADDRESS] · Chamber of Commerce [REGISTRATION NUMBER] · VAT ID [VAT ID] · supervisory authority: Dutch Data Protection Authority (Autoriteit Persoonsgegevens), https://autoriteitpersoonsgegevens.nl.

Nevai
HomeProductsPricingAboutWork
Demo →Contact us ↗
PrivacyTerms© 2026 Nevai · All rights reserved.