Nuvyon – Privacy Policy
Last updated: 12 July 2026
1. Controller & contact
IronAPI GmbH, Kochgasse 22/17, 1080 Vienna, Austria, nuvyon@ironapi.com.
2. Data protection officer
No data protection officer has been appointed, as the conditions of Art. 37 GDPR do not apply.
3. Roles
IronAPI is the controller for account/login, app-operation and support data. For inspection data, IronAPI acts as processor: strictly on the instructions of and on behalf of the testing company (Art. 28 GDPR); the controller and the legal basis follow from that company’s privacy policy.
4. Purposes & legal bases (IronAPI as controller)
Account (login, name, email) — authentication/access, Art. 6(1)(b)/(f) GDPR; app operation & support — Art. 6(1)(b)/(f) GDPR, legitimate interest = secure operation.
5. Device permissions
Bluetooth only to read the results of the Metrel/GMC test instrument (not location); camera only for the nameplate/barcode.
6. Recipients/processors
Hosting provider in the EU; no further disclosure; no sale.
7. No tracking
No advertising, no advertising ID, no analytics/advertising/crash SDKs, no cross-app tracking.
8. Transfers to third countries
None (EU/EEA only).
9. Retention period
Inspection data/certificates in accordance with the applicable testing standards and the data-processing agreement; account data for the duration of activation and up to 90 days thereafter, then deletion, unless a statutory retention obligation applies.
10. Your rights (Art. 15–22 GDPR)
Access, rectification, erasure, restriction, data portability, objection; withdrawal of consent (Art. 7(3) GDPR); the right to lodge a complaint with the Austrian Data Protection Authority (Barichgasse 40–42, 1030 Vienna, dsb@dsb.gv.at).
11. Deleting your account/data
Accounts are provided by the testing company; request deletion at nuvyon@ironapi.com; processed within 30 days, subject to retention obligations.
12. Necessity (Art. 13(2)(e) GDPR)
Providing account and inspection data is necessary to use the app and to carry out/document the inspection; without it the app cannot be provided.
13. Third-party data (Art. 14 GDPR)
Where inspection records contain personal data of third parties that was not collected from the data subject, the information obligation under Art. 14 GDPR lies with the responsible testing company.
14. Automated decisions/profiling
None.
15. EU representative (Art. 27 GDPR)
Not required (the controller is established in Austria/the EU).
16. Security
TLS-encrypted transmission, access control.
17. Children
A professional tool, not directed at children.
18. Changes
The date above indicates the current version.