Privacy Policy
Last updated: 8 September 2026
This policy explains how Naarva handles personal data when you visit our website, contact us or use our service. Naarva is a service for businesses. The account, billing and integration sections apply when you use those features.
1. Who is responsible
The controller for the processing described in this policy is:
Paul Lukas Roder, trading as NaarvaMontessoristraße 21
40670 Meerbusch
Germany
[email protected]
You can send privacy questions and requests to this email or postal address. No data protection officer has been appointed.
2. Website and security
Our website and application database are hosted by netcup GmbH, Emmy-Noether-Str. 10, 76131 Karlsruhe, Germany. netcup provides server infrastructure under a data processing agreement.
We use Cloudflare, Inc., United States, for DNS, reverse proxying, content delivery (CDN) and protection against malicious traffic. Website requests pass through Cloudflare's network before reaching our server, or receive cached public resources from that network. Cloudflare processes connection and request information, including IP addresses, requested URLs, timestamps and HTTP headers, and handles the content transmitted through its proxy. Processing can take place outside the European Economic Area. See the international transfer information below and Cloudflare's Privacy Policy.
Delivering pages requires processing your IP address, requested resource, request time and technical HTTP information such as browser headers. Security and operational records may contain connection information, timestamps and error or authentication outcomes. We use these to deliver the service, prevent abuse and investigate faults. Our netcup web server does not keep a routine page-by-page access log; this does not exclude Cloudflare's traffic and security records. Fonts and brand assets are served from our website.
We use Cloudflare R2 in its EU jurisdiction to store private backups of the application database for disaster recovery. Backups can contain the account, workspace, billing and connected business records described below. They are transferred over an encrypted connection and encrypted at rest by the provider. They are not publicly accessible. Cloudflare describes the storage restriction in its R2 data location information.
The legal basis is our legitimate interest in operating a secure, reliable website (Article 6(1)(f) GDPR). Processing necessary to provide a service you have requested is also based on Article 6(1)(b) GDPR where you are our contracting party.
3. Contact and service emails
When you email us, we process your email address, name if provided, message, attachments and delivery metadata to answer your enquiry and provide support. Incoming mail to [email protected] passes through Cloudflare Email Routing to our mailbox hosted by Hostinger. These providers handle the message and routing information needed for delivery and mailbox operation. Please send only information needed for your request.
We use Resend (Plus Five Five, Inc., United States) to send account verification, password reset and workspace invitation emails. Resend receives the recipient address, subject, message content and delivery information; messages can include the secure links needed for these actions. Our sending region is Ireland. Resend stores message content and delivery records in the United States, including when sending from Ireland. Its standard retention for email and log data is 30 days, with a seven-day backup retention period, as described in its data protection information.
We process contract enquiries and necessary service correspondence under Article 6(1)(b) GDPR. For other enquiries and communications with people acting for a business, the basis is our legitimate interest in responding and supporting that business (Article 6(1)(f) GDPR). Legal record-keeping obligations may also apply (Article 6(1)(c) GDPR).
4. Accounts and workspaces
Creating an account requires your name, email address and password. We store a password hash, verification status and account timestamps. Authentication also uses session records, which can include an IP address, browser information and expiry time, and rate-limit records to prevent abuse. Passwords are not stored in readable form.
Workspace data includes memberships, roles, invitations, companies, projects, costs and settings you or other authorised workspace users provide. Other workspace members can see information according to their permissions. If someone invites you, we receive your email address and intended workspace role from that person. Invitation links expire after seven days. An invitation alone does not create a user account.
These operations provide and administer the requested service under Article 6(1)(b) GDPR. For users representing a business, and for access security, we rely on the legitimate interests of providing that business with the service and protecting its data (Article 6(1)(f) GDPR). Required account information is necessary to create and secure an account; without it we cannot provide account access.
5. Billing and connected services
Stripe processes payments for your Naarva subscription. On Stripe's hosted checkout and customer portal, Stripe processes the billing, contact, tax and payment information you provide. We receive customer and subscription identifiers, plan and payment status, billing periods and related transaction information. Full payment card numbers and security codes are not stored by Naarva. The bases are contract performance (Article 6(1)(b) GDPR) and applicable accounting and tax obligations (Article 6(1)(c) GDPR). Stripe also acts as a controller for its own payment, fraud prevention and regulatory purposes. See Stripe's Privacy Policy.
Connecting a business data source is separate from paying for Naarva. When an authorised workspace user connects Stripe, RevenueCat or Paddle, Naarva reads the selected account's relevant product, customer, subscription, payment, refund and revenue records. These can contain personal data, including stable customer and transaction identifiers. RevenueCat imports can also read transaction exports from an Amazon S3 bucket configured by the customer. The sources are the connected providers and the workspace's authorised users.
We use imported records to calculate and display the workspace's business metrics. Where these records contain personal data about the customer's own customers or subscribers, the customer determines the purposes and legal basis and Naarva acts as its processor. That processing requires a separate data processing agreement with the customer; this policy does not replace it. Please direct requests about that business's customer records to the business concerned. We assist it with requests relating to the data we process for it.
Integration credentials are kept server-side and stored per connection in encrypted form where required. Disconnecting stops future imports and removes stored per-connection credentials. Previously imported business history remains in the workspace. A Stripe App's external permissions can be revoked by uninstalling it in Stripe.
6. Cookies and browser storage
Our application uses the following functional storage:
- Authentication cookies: secure session cookies keep you signed in. A session is valid for up to seven days and can be renewed while you use the service. Signing out ends that session.
- Workspace selection: the naarva-workspace cookie remembers the workspace you selected for up to one year. It does not grant access to a workspace.
- Appearance: local storage under the key theme remembers your light or dark appearance choice until you change it or clear the website's stored data. It has no automatic expiry.
Cloudflare's security features may also use cookies when a bot check or security challenge is required. These support abuse prevention and can remember a completed challenge. Their use and duration depend on the security feature involved; Cloudflare describes them in its security cookie documentation.
Storage necessary for the service or preference you explicitly request is based on Section 25(2)(2) of the German Telecommunications Digital Services Data Protection Act (TDDDG). Related personal data is processed to provide the service and protect access, as described above. You can delete or block storage in your browser; doing so may sign you out or prevent account features and saved preferences from working. Usage statistics are described separately below.
7. Error reports and usage statistics
Error reports. We use Sentry (Functional Software, Inc., United States) to detect and fix software failures. Our error reports are limited to an event identifier, time, severity, error type, predefined operation and code location. We remove message details, page URLs, request contents, cookies, user details and business data before sending reports. Session Replay, tracing and session tracking are disabled. Sentry can still receive the network IP address used to send a browser report. Our project uses Sentry's EU ingestion region; this does not exclude international support or other processing. The basis is our legitimate interest in diagnosing faults and keeping Naarva reliable (Article 6(1)(f) GDPR). See Sentry's Privacy Policy.
Usage statistics. We use TelemetryDeck GmbH, Germany, to understand which parts of Naarva are used and improve the product. We send predefined page categories and events such as using the demo, clicking a signup button or successfully creating or signing into an account, together with the SDK version and random visit identifiers. The identifiers exist only in browser memory and change on a full page reload. They are not account identifiers and are not stored in cookies or local storage. We do not send names, email addresses, form contents, financial data, workspace identifiers or full page URLs in these events.
Ordinary connection information, including the source IP address and website origin, reaches the receiving service. TelemetryDeck describes its service as producing anonymous statistics using EU infrastructure. We do not use it to identify returning individuals or build advertising profiles. For the limited processing involved in generating these statistics, we rely on our legitimate interest in understanding product use with minimised data (Article 6(1)(f) GDPR). This is separate from the financial metrics within your workspace. See TelemetryDeck's privacy information.
You can object to usage analytics. Naarva honours Global Privacy Control and Do Not Track: when either is enabled in a browser that supports it, our analytics integration does not send events. You can also contact us at [email protected] to exercise your right to object. We cannot reliably link the random visit identifiers to a particular account or person.
8. Recipients and international transfers
The providers described above receive data needed for their respective services. Within a workspace, access follows the assigned roles. We may also disclose relevant information to authorities when legally required, or to professional advisers where necessary to meet legal obligations or establish, exercise or defend legal claims. We do not sell personal data or share workspace data for advertising.
Website infrastructure, email, payment and monitoring providers may process information outside the European Economic Area, including in the United States. This can include service infrastructure, subprocessors and support access. A European sending or ingestion region alone does not rule out these transfers. Applicable transfer arrangements are described in the providers' data protection terms, including the European Commission's Standard Contractual Clauses for transfers without an applicable adequacy decision:
- Resend data processing and transfer terms
- Cloudflare data processing and transfer terms
- Hostinger data processing and transfer terms
- Stripe data processing and transfer terms
- Sentry data processing and transfer terms
You can ask us for further information or a copy of the relevant safeguards, subject to necessary protection of confidential information.
9. How long we keep data
We retain personal data for the purpose for which it is needed. The criteria depend on the record:
- Account and workspace records are needed while the account or workspace is in use and for handling its closure. Ending a paid subscription, archiving a project or disconnecting a provider does not by itself delete the workspace or its history. Contact us to request account closure, export or erasure; requests are handled after checking identity and the rights of other workspace users.
- Enquiries are retained while we handle the matter and any follow-up. Correspondence relevant to a contract, tax obligation or legal claim can be retained for the applicable statutory period or for as long as the claim needs to be established, exercised or defended.
- Billing and tax records are retained for the periods required by German tax and commercial law, depending on the type of document. Such records are restricted to those purposes when no longer needed to provide the service.
- Server system journals have a 14-day retention limit and size limits; container logs rotate by size. Information needed to investigate a particular incident may be preserved for that investigation or a related legal claim. Error reports are used to investigate faults and recurring problems, with provider retention and deletion controls also applying.
- Cookie and invitation validity periods are listed above. Expiry of a login or invitation does not mean every related database record is automatically erased at that moment.
- Database backups in Cloudflare R2 are scheduled for deletion after seven days for daily copies, 35 days for weekly copies and 100 days for monthly copies. Cloudflare normally completes lifecycle deletion within 24 hours after expiry. The three most recent successful local recovery copies are also retained on our server. Backups can contain earlier versions of deleted records until rotation removes them. They are used for recovery; applicable erasure requests must be reapplied before restored data returns to ordinary use.
Statistical information that no longer relates to an identifiable person can be retained for comparisons over time. We do not keep an account-to-visit mapping for TelemetryDeck statistics. TelemetryDeck does not specify a fixed deletion date for statistical events in its cold storage.
10. Your rights
Subject to the GDPR's conditions, you have rights of access, rectification, erasure, restriction of processing and data portability (Articles 15–20 GDPR). Where processing is based on consent, you may withdraw that consent at any time without affecting the lawfulness of earlier processing. Reading this policy or creating an account is not consent to unrelated marketing.
Right to object: under Article 21 GDPR, you may object on grounds relating to your particular situation to processing based on legitimate interests, including related profiling. We will stop that processing unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or need it for legal claims. You may object to processing for direct marketing at any time.
Send requests to [email protected]. We may need proportionate information to verify your identity. We respond within the GDPR's time limits, normally within one month. We do not use solely automated decisions, including profiling, that produce legal or similarly significant effects on you within Article 22 GDPR.
You may lodge a complaint with a supervisory authority, particularly where you live or work or where you believe an infringement occurred. The authority responsible for our location is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW), Postfach 20 04 44, 40102 Düsseldorf, Germany. Its contact and complaint information is available online. You do not have to contact us before complaining.
We update this policy when our processing changes. The date at the top identifies the current version.