Nuvyon – Privacy Policy

Last updated: 12 July 2026

1. Controller & contact

IronAPI GmbH, Kochgasse 22/17, 1080 Vienna, Austria, nuvyon@ironapi.com.

2. Data protection officer

No data protection officer has been appointed, as the conditions of Art. 37 GDPR do not apply.

3. Roles

IronAPI is the controller for account/login, app-operation and support data. For inspection data, IronAPI acts as processor: strictly on the instructions of and on behalf of the testing company (Art. 28 GDPR); the controller and the legal basis follow from that company’s privacy policy.

4. Purposes & legal bases (IronAPI as controller)

Account (login, name, email) — authentication/access, Art. 6(1)(b)/(f) GDPR; app operation & support — Art. 6(1)(b)/(f) GDPR, legitimate interest = secure operation.

5. Device permissions

Bluetooth only to read the results of the Metrel/GMC test instrument (not location); camera only for the nameplate/barcode.

6. Recipients/processors

Hosting provider in the EU; no further disclosure; no sale.

7. No tracking

No advertising, no advertising ID, no analytics/advertising/crash SDKs, no cross-app tracking.

8. Transfers to third countries

None (EU/EEA only).

9. Retention period

Inspection data/certificates in accordance with the applicable testing standards and the data-processing agreement; account data for the duration of activation and up to 90 days thereafter, then deletion, unless a statutory retention obligation applies.

10. Your rights (Art. 15–22 GDPR)

Access, rectification, erasure, restriction, data portability, objection; withdrawal of consent (Art. 7(3) GDPR); the right to lodge a complaint with the Austrian Data Protection Authority (Barichgasse 40–42, 1030 Vienna, dsb@dsb.gv.at).

11. Deleting your account/data

Accounts are provided by the testing company; request deletion at nuvyon@ironapi.com; processed within 30 days, subject to retention obligations.

12. Necessity (Art. 13(2)(e) GDPR)

Providing account and inspection data is necessary to use the app and to carry out/document the inspection; without it the app cannot be provided.

13. Third-party data (Art. 14 GDPR)

Where inspection records contain personal data of third parties that was not collected from the data subject, the information obligation under Art. 14 GDPR lies with the responsible testing company.

14. Automated decisions/profiling

None.

15. EU representative (Art. 27 GDPR)

Not required (the controller is established in Austria/the EU).

16. Security

TLS-encrypted transmission, access control.

17. Children

A professional tool, not directed at children.

18. Changes

The date above indicates the current version.