1. Who we are
NivaDesk is operated by:
EGGCRAFT LIMITED
Registered in England and Wales, company number 16566512
VAT number GB 514512621
141 Randolph Avenue
London
W9 1DN
United Kingdom
EGGCRAFT LIMITED is registered with the UK Information Commissioner's Office (ICO), registration reference ZC019612.
Email: contact@nivadesk.co.uk
For privacy-related questions, data requests, or account deletion requests, please contact us by email.
2. What this Privacy Policy covers
This Privacy Policy applies to:
- our website;
- the NivaDesk web app;
- the NivaDesk mobile and desktop apps;
- account registration and login;
- customer support and email communication;
- payment and subscription management;
- uploaded files, client files, order records, notes, tasks, workflow data, and workspace content;
- integrations or third-party services connected to NivaDesk.
This Privacy Policy does not apply to websites, apps, or services that we do not own or control.
3. Our role: controller and processor
In some situations, we act as a data controller. This means we decide how and why certain personal data is processed. For example, we are the controller when you create a NivaDesk account, contact us, subscribe to updates, pay for a plan, or use our website.
In other situations, we act as a data processor. This means we process data on behalf of our customers. For example, if a business uses NivaDesk to store its own client names, order details, files, notes, addresses, tasks, or workflow information, that business is usually the controller of that data, and we process it according to their instructions.
If your personal data was added to NivaDesk by one of our customers, please contact that customer first if you want to exercise your rights regarding that data.
4. Personal data we collect
We may collect the following types of personal data.
4.1 Account and profile data
When you create or use a NivaDesk account, we may collect:
- name;
- email address;
- password or authentication information;
- profile photo or avatar;
- company or workspace name;
- role within a workspace;
- language, timezone, and app preferences;
- login method, such as email/password, Google sign-in, or Apple sign-in.
4.2 Workspace and business content
When you use NivaDesk, you or your team may add content such as:
- customer or client details;
- order details;
- workflow status;
- order notes;
- customer notes;
- task lists and reminders;
- delivery dates and timelines;
- addresses;
- uploaded files;
- images, PDFs, design files, documents, and attachments;
- team member roles and access permissions;
- history logs and activity records.
You are responsible for ensuring that any personal data you upload to NivaDesk has been collected and added lawfully.
4.3 Payment and subscription data
If you purchase a paid plan, we or our payment providers may process:
- billing name;
- billing address;
- email address;
- payment method information;
- subscription plan;
- invoices and transaction history;
- tax or accounting information where required.
We do not store full card numbers ourselves. Payment details are processed by third-party payment providers such as Stripe, Apple, Google, or other payment platforms depending on how you subscribe.
4.4 Device, usage, and technical data
When you use our website or apps, we may collect:
- IP address;
- device type;
- operating system;
- browser type;
- app version;
- crash reports;
- log-in times;
- pages or features used;
- performance and diagnostic data;
- approximate location based on IP address;
- cookies and similar technologies.
This helps us keep NivaDesk secure, improve performance, fix bugs, and understand how users interact with our services.
4.5 Communication data
If you contact us, we may collect:
- your name;
- email address;
- message content;
- support requests;
- feedback;
- attachments or screenshots you send us;
- records of our communication with you.
4.6 Data from third-party login or integrations
If you choose to sign in with or connect a third-party service, such as Google or Apple, we may receive limited information from that service, such as:
- name;
- email address;
- profile image;
- authentication identifier.
If future NivaDesk integrations allow access to services such as calendar, files, email, storage, or other business tools, we will only access the data needed to provide the feature you choose to use.
5. How we use personal data
We use personal data to:
- create and manage your account;
- provide access to NivaDesk;
- create and manage workspaces;
- store and sync orders, clients, tasks, files, notes, timelines, and workflow information;
- manage team roles and permissions;
- provide customer support;
- process payments and subscriptions;
- send service-related emails;
- improve app performance and reliability;
- detect bugs, abuse, fraud, or security issues;
- comply with legal, tax, accounting, and regulatory obligations;
- understand how users use our website and services;
- send product updates or marketing communications where permitted.
We will not use your workspace content to advertise to your customers.
6. Legal bases for processing
Where UK GDPR or EU GDPR applies, we rely on the following legal bases:
Contract
We process data when necessary to provide NivaDesk to you, manage your account, process payments, and deliver features you request.
Legitimate interests
We may process data for our legitimate business interests, including improving NivaDesk, preventing misuse, securing our services, responding to support requests, and understanding product usage.
Consent
We may rely on consent for optional features, marketing emails, cookies that are not strictly necessary, or certain third-party integrations.
Legal obligation
We may process data when required to comply with law, tax, accounting, security, fraud prevention, or regulatory obligations.
7. Workspace content and uploaded files
NivaDesk allows users to upload and store business files, client files, documents, images, PDFs, design files, and other materials.
We process uploaded files only to provide the service, including:
- storing files;
- displaying files in your workspace;
- syncing files across your devices;
- allowing downloads;
- applying workspace permissions;
- creating metadata such as file name, upload date, file size, and uploader;
- maintaining security and audit logs;
- supporting offline access or upload queues where enabled.
We do not claim ownership of your uploaded content. You retain all rights to the content you upload, subject to the rights you grant us to operate and provide the service.
Client Files and cloud-stored message attachments require an active eligible paid plan to open, preview, download, upload, rename, or delete them through the app. If eligible paid access ends, those files may be retained for up to 90 days so access can be restored if the workspace resubscribes during that period; after the retention period they may be deleted.
8. Team workspaces and permissions
If you are invited to a NivaDesk workspace, the workspace owner or administrators may be able to:
- see your name and email address;
- assign you a role;
- control your access;
- view your activity within the workspace;
- remove your access;
- manage shared workspace content.
If you add another user to a workspace, you confirm that you have permission to provide their email address or other relevant information.
9. Google, Apple, and third-party sign-in
If you sign in using Google, Apple, or another supported authentication provider, we use the information provided by that service only to authenticate you and provide access to your account.
We do not receive or store your Google or Apple password.
If we later offer additional Google, Apple, calendar, email, file, or cloud integrations, we will only request access to the information needed for the feature and will use that information only to provide or improve the user-facing feature you choose to enable.
We will not use data from connected third-party services for advertising or sell that data to third parties.
10. ChatGPT App and connected AI features
NivaDesk may offer a ChatGPT App or connected AI feature that allows you to connect your NivaDesk workspace to ChatGPT or a similar assistant through a secure OAuth connection and MCP server.
If you choose to connect NivaDesk to ChatGPT, the assistant may request workspace data only for the workspace you select and only for the tools and permissions you authorise. Access remains subject to your NivaDesk plan, workspace role, feature permissions, and security rules.
Depending on the tools enabled for your account, ChatGPT may be able to search, summarise, create, or update NivaDesk records such as orders, order details, dashboard summaries, financial fields, tasks, order notes, personal notes, messages, quick replies, workflow status, due dates, customer information, internal IDs, timestamps, and history or audit information.
Financial data, messages, notes, and other sensitive workspace content should only be returned where your NivaDesk role and plan allow access. Write actions, such as creating an order, adding a note, or updating an order status, should only happen after your request or confirmation.
We use the ChatGPT connection to provide the integration you choose to enable. We do not sell your workspace content or use it to advertise to your customers. You can disconnect or stop using the connected feature where the product provides that option.
11. Payments and subscriptions
Payments may be processed by third-party providers such as Stripe, Apple App Store, Google Play, or other payment platforms.
These providers may collect and process payment information according to their own privacy policies and terms. We receive limited payment and subscription information needed to manage your NivaDesk plan, invoices, renewals, cancellations, refunds, and account status.
12. Cookies and analytics
Our website and services may use cookies or similar technologies to:
- keep you signed in;
- remember preferences;
- improve security;
- understand website usage;
- measure performance;
- improve the product.
Some cookies are necessary for the service to work. Others, such as analytics or marketing cookies, may depend on your consent where required by law.
You can manage cookies through your browser settings. Disabling some cookies may affect the functionality of our website or app.
Bot protection (reCAPTCHA and App Check)
To protect sign-up, sign-in and our APIs from automated abuse, our website and apps use Google reCAPTCHA and Firebase App Check. These services may set cookies and collect device, browser and usage information, which is sent to Google to tell genuine users apart from bots and other automated traffic.
Your use of reCAPTCHA is subject to the Google Privacy Policy (https://policies.google.com/privacy) and Terms of Service (https://policies.google.com/terms). We rely on our legitimate interest in keeping the service secure and preventing fraud and abuse.
13. Marketing communications
We may send you emails about product updates, feature announcements, offers, or news about NivaDesk.
You can unsubscribe from marketing emails at any time by using the unsubscribe link or contacting us.
Even if you unsubscribe from marketing emails, we may still send important service emails, such as account, billing, security, subscription, or legal notices.
14. Who we share personal data with
We do not sell your personal data.
We may share personal data with trusted third parties only when necessary to operate, support, secure, or improve NivaDesk. These may include:
- hosting and cloud infrastructure providers;
- database and storage providers;
- authentication providers;
- payment processors;
- analytics and performance tools;
- customer support tools;
- email delivery providers;
- error monitoring and crash reporting services;
- accountants, lawyers, or professional advisers;
- authorities where required by law.
We only provide service providers with the information they need to perform their services for us.
15. International transfers
Your data may be stored or processed in the United Kingdom, European Economic Area, United States, or other countries where our service providers operate.
Where personal data is transferred outside the UK or EEA, we use appropriate safeguards where required, such as adequacy decisions, standard contractual clauses, the UK International Data Transfer Agreement, or other lawful transfer mechanisms.
16. Security
We take reasonable technical and organisational measures to protect personal data, including:
- secure authentication;
- restricted access controls;
- encrypted connections where appropriate;
- role-based workspace permissions;
- cloud security controls;
- monitoring for errors and abuse;
- backups and operational safeguards;
- limiting access to personal data to those who need it.
However, no system is completely secure. We cannot guarantee that personal data will always remain completely secure, but we work to protect it and respond appropriately if a security issue occurs.
17. Data retention
We keep personal data only for as long as necessary for the purposes described in this Privacy Policy.
In general:
- account data is kept while your account is active;
- workspace content is kept while the workspace or account remains active;
- billing and invoice data may be kept for legal, tax, and accounting requirements;
- support messages may be kept to help us respond to your request and improve support;
- technical logs may be kept for a limited period for security and troubleshooting;
- deleted data may remain in backups for a limited time before being permanently removed;
- Client Files and cloud-stored message attachments whose paid access has ended may be retained for up to 90 days for restoration upon resubscription, after which they may be deleted.
If you delete your account or request deletion, we will delete or anonymise personal data unless we need to keep it for legal, security, accounting, dispute resolution, or legitimate business reasons.
18. Account deletion and data export
You may request account deletion by contacting us.
Before deleting your account, we may need to verify your identity. If you are part of a workspace owned by someone else, we may need to direct you to the workspace owner for deletion of workspace content.
Where available, you may export your data from within NivaDesk. We believe customers should be able to access and export their own business data, even if their plan changes or expires, subject to reasonable technical and security limits.
19. Your rights
Depending on where you live, you may have rights under data protection law, including the right to:
- access the personal data we hold about you;
- request correction of inaccurate data;
- request deletion of your data;
- object to certain processing;
- restrict processing;
- request data portability;
- withdraw consent where processing is based on consent;
- opt out of marketing communications;
- lodge a complaint with a data protection authority.
If you are in the UK, you can contact the Information Commissioner's Office at ico.org.uk.
To exercise your rights, contact us at: contact@nivadesk.co.uk
We may ask for information to verify your identity before responding to a request.
20. Children
NivaDesk is not intended for children. We do not knowingly collect personal data from children.
If you believe a child has provided personal data to us, please contact us and we will take appropriate steps to delete it.
21. Third-party websites and services
NivaDesk may contain links to third-party websites, services, integrations, or payment providers.
We are not responsible for the privacy practices of third parties. You should review their privacy policies before using their services.
22. Changes to this Privacy Policy
We may update this Privacy Policy from time to time.
If we make material changes, we may notify you by email, in-app notice, or by updating the date at the top of this page.
Your continued use of NivaDesk after the updated Privacy Policy becomes effective means you accept the updated policy.
23. Contact us
If you have questions about this Privacy Policy, your personal data, or your rights, please contact:
EGGCRAFT LIMITED
141 Randolph Avenue
London
W9 1DN
United Kingdom
Email: contact@nivadesk.co.uk