Terms and Privacy
Version 1.0 · Last updated: June 18, 2026. Requires legal review before publishing; «...» fields to be filled.
Terms of Use — NyoCorp
About this document
These Terms of Use ("Terms") govern access to and use of the NyoCorp platform, including its modules, websites, applications, APIs, features, spaces, accounts and related functionality ("Service"), offered by «LEGAL ENTITY», registered under company number 41.408.464/0001-19, headquartered at «ADDRESS» ("NyoCorp", "we").
These Terms are structured to serve, in a single document, individual users, sole proprietors, teams, companies and organizations. Where a rule applies differently to individuals or organizations, this is stated expressly.
By creating an account, accessing or using the Service, you declare that you have read, understood and agree to these Terms and the Privacy Policy.
This document must be validated by legal counsel before final publication. Fields between «...» must be filled before publishing.
1. Definitions
To make reading easier:
NyoCorp: the platform and set of services we offer.
Service: NyoCorp's websites, systems, applications, APIs, modules, accounts, spaces and features.
User: a natural person who accesses or uses the Service.
Organization: a company, sole proprietor, team, association, entity or other group that uses the Service via a space, plan, business account or authorized users.
Administrator: a user with administrative permissions over a space, organization or account.
Space: a logical environment within NyoCorp grouping users, data, permissions, modules and settings.
User Content: data, files, records, secrets, contacts, transactions, cards, tickets, messages or any information entered into the Service by users or organizations.
Zero-knowledge: an architecture in which certain content is encrypted on the user's device and cannot be read by NyoCorp, within applicable technical limits and settings.
2. Acceptance of Terms
By accessing or using the Service, you agree to these Terms. If you do not agree, do not use the Service.
If you use the Service on behalf of an organization, you declare you have authority to bind that organization to these Terms. In that case, "you" may refer to both the individual user and the represented organization, as the context requires.
The Privacy Policy is part of these Terms and explains how personal data is processed.
3. Who may use the Service
You must be at least 18 years old or the legal age of majority in your jurisdiction to use the Service, except where there is valid authorization from a legal guardian or contracting by an authorized organization.
The Service is not directed at children or adolescents. Do not collect, publish or enter data of minors on the platform without an adequate legal basis and without observing applicable legal requirements.
4. Individuals, sole proprietors, teams and organizations
NyoCorp can be used by different customer profiles, on the same technology and security foundation.
4.1 Individual use — If you use the Service for personal purposes, you are responsible for the data you enter, your credentials, safeguarding your master password and complying with these Terms.
4.2 Use by a sole proprietor, team or organization — If the Service is used by an organization, the organization is responsible for: administering its spaces, users, permissions and roles; ensuring authorized users comply with these Terms; granting, reviewing and revoking access, including upon offboarding of employees or contractors; having a legal basis to enter or process third-party personal data on the platform; defining who may view, export, share, delete or administer data in the space; maintaining its own notices, policies, contracts or legal bases when acting as data controller.
NyoCorp may process organization data as processor or as controller, as explained in the Privacy Policy.
4.3 Space administrators — Administrators may have powers to manage members, permissions, billing, modules, settings, retention, export and deletion of space data. The organization is responsible for choosing trustworthy administrators and maintaining internal access governance.
5. Description of the Service
NyoCorp offers a modular platform that may include, among others:
NyoVault: vault for passwords, notes, cards, TOTP, keys and secrets, with zero-knowledge features at compatible levels;
NyoFinance: personal or organizational financial management, with accounts, transactions, categories, goals and reports;
NyoCard / NyoPeople: digital business cards, public or shared profiles, contacts and directories;
CRM and Client Registry: management of clients, leads, contacts, history and relationships;
Helpdesk / Support: tickets, messages, queues, SLA, assignees and support history;
Account, IAM and Spaces: authentication, members, roles, permissions and privacy settings.
The Service may evolve. Features may be added, modified, limited, removed, replaced or discontinued, with notice where reasonably necessary.
6. Account, master password and security
6.1 Account creation and maintenance — You must provide true, complete and up-to-date information. We may require email verification, additional authentication, device confirmation or other security measures. You are responsible for keeping your credentials confidential and for all activity in your account, except for a failure attributable to NyoCorp.
6.2 Master password and loss of access — In zero-knowledge features, your master password, recovery phrase, local key or equivalent mechanism may be needed to decrypt protected content. NyoCorp does not receive your master password in clear text. If you lose your master password and have no valid recovery method, zero-knowledge data may become permanently unrecoverable. NyoCorp cannot recover, reset or decrypt that content without the proper key.
6.3 Organization security — Organizations are responsible for internal security processes, such as onboarding and offboarding of users, periodic access reviews, appointment of administrators, permission governance and proper use of available security features.
7. Zero-knowledge architecture and limits
NyoCorp offers zero-knowledge features in compatible modules and levels. This means that certain content is encrypted on the user's device before being sent to the server, and NyoCorp does not hold the key needed to decrypt it.
Not all data is zero-knowledge. Account, billing, security, logs, support, public cards, CRM, Helpdesk, metadata and data from modules configured as Open may be server-readable so the Service can function.
The Privacy Policy explains in more detail what may be encrypted on the device and what may be server-readable in each module and privacy level.
8. Privacy levels and space settings
The Service offers two privacy levels: Open (default) and Total, defined per module or space, subject to technical availability. At the Open level, certain data is server-readable (only inherently sensitive fields, such as vault secrets, stay encrypted); at the Total level, content is end-to-end encrypted on the device (zero-knowledge).
You understand that: more private levels may limit search, reports, automations, recovery, collaboration and server-side processing; more open levels may enable more functionality but require certain data to be server-readable; public data, such as shared cards and profiles, is treated differently from secrets stored in a vault; settings made by organization administrators may affect space members.
9. User Content
You retain rights over the User Content you enter into the Service.
You grant NyoCorp a technical, limited, worldwide, non-exclusive license necessary to operate the Service, including storing, transmitting, processing, displaying, syncing, backing up, protecting, making available, recovering and deleting User Content according to your instructions, space settings, contracted features and applicable law.
In zero-knowledge content, this operation occurs over encrypted data that NyoCorp cannot read without the proper key.
You are responsible for ensuring you have the rights, authorizations and legal bases to enter, publish, share or process User Content on the platform, especially when it involves third-party data.
10. Third-party data
You must not enter, publish or share third-party personal data without authorization, contract, legal basis or valid justification.
In modules such as CRM, Helpdesk, Client Registry, NyoPeople, NyoCard and directories, you or your organization may act as responsible for third-party data entered on the platform. NyoCorp may act as processor of that data, as explained in the Privacy Policy.
If a third party requests removal, access or correction of data entered by you or your organization, we may forward the request to the space administrator or controlling customer, where applicable.
11. Cards, profiles and public content
By publishing cards, profiles, pages, public links or shareable data, you understand that this information may be accessed by people who receive the link or, depending on configuration, by external mechanisms.
You are responsible for the accuracy and legality of the published data. NyoCorp may remove, suspend or restrict public content that violates these Terms, third-party rights, security, applicable law or platform policies.
Removal of public content from NyoCorp does not guarantee removal of copies, caches, screenshots, indexing or shares made by third parties outside the platform.
12. Acceptable use
You agree not to use the Service to:
perform unlawful, fraudulent, abusive or deceptive acts;
violate privacy, data protection, intellectual property or third-party rights;
store, distribute or facilitate malware, phishing, spam, scams or malicious content;
attempt to access accounts, spaces, systems or data without authorization;
bypass, test or exploit vulnerabilities without express authorization;
carry out attacks, abusive scraping, denial of service or infrastructure overload;
sell, rent, sublicense or resell the Service without authorization;
enter sensitive or regulated data into modules not prepared for that purpose;
use the Service in a way that may harm NyoCorp, other users or third parties.
We may apply technical limits, rate limits, blocks, reviews or suspensions to protect the platform.
13. Plans, payments, subscriptions and taxes
Some features may be free, paid, limited, promotional or subject to subscription.
Prices, limits, features, billing cycle, renewal, taxes, payment methods and commercial terms will be presented at the time of purchase or commercial proposal.
Payments may be processed by third parties, such as Stripe. NyoCorp does not store the full payment card number when processing is done by an external provider.
Unless otherwise stated, subscriptions may renew automatically at the end of each cycle. You may cancel renewal according to the options available in the account, commercial proposal or support channel.
13.1 Refund and withdrawal — Refunds, cancellations, credits and the right of withdrawal will follow applicable law, the commercial policy in force and the terms presented at purchase. For consumers in Brazil, where applicable, the right of withdrawal for purchases made outside the commercial establishment will be observed, under consumer law. Specific refund policy: «DEFINE REFUND POLICY».
13.2 Default — In case of payment failure or default, we may limit, suspend or terminate access to paid features, with notice where appropriate, preserving legal obligations and applicable export or deletion rules.
14. APIs, integrations and third-party services
The Service may allow integrations with external providers, APIs, webhooks, federated authentication, payment, email, automation, storage or other tools.
Use of third-party services may be subject to those parties' terms and policies. NyoCorp does not control external services and is not liable for failures, unavailability, acts or policies of third parties, except where the law provides otherwise.
You are responsible for configuring integrations securely, reviewing permissions and protecting tokens, keys, webhooks and credentials.
15. Availability, maintenance and support
NyoCorp will make reasonable efforts to keep the Service available, secure and functional. However, we do not guarantee uninterrupted, error-free or outage-free operation.
There may be maintenance, updates, failures, outages, loss of connectivity, incidents, third-party limitations or interruptions necessary for security and product evolution.
Support channel: «SUPPORT CHANNEL».
Customers with a specific plan, proposal or contract may have additional support, availability or SLA conditions, if expressly contracted.
16. Suspension and termination
You may close your account using the available features or through the support/privacy channel.
We may suspend, limit or terminate accounts, spaces, features or content when there is: a breach of these Terms; a risk to the security of the platform, users or third parties; fraud, abuse, spam, malicious use or unlawful activity; default; a legal order or request from a competent authority; a relevant technical or operational need.
Where reasonable and permitted, we will send notice before or after the measure.
16.1 Effects of termination — Account and data deletion will follow the Privacy Policy. In zero-knowledge content, loss of the key, master password or recovery phrase may prevent data recovery. In organizational accounts, terminating an individual user may not delete data belonging to the organization's space. The administrator or organization may retain, transfer or delete data according to permissions, settings, legal obligations and applicable contract.
17. Intellectual property
NyoCorp, its software, brands, names, interfaces, designs, documentation, code, texts, logos, visual elements and other Service components belong to NyoCorp or its licensors.
These Terms transfer no intellectual property right to you, except the limited license to use the Service as contracted.
You must not copy, modify, distribute, sell, sublicense, reverse engineer, exploit vulnerabilities or create derivative works of the Service, except where permitted by law or expressly authorized.
18. Feedback
If you submit suggestions, ideas, comments or feedback about NyoCorp, we may use them without obligation to compensate, provided this does not involve improper disclosure of personal or confidential data.
19. Confidentiality
You must keep confidential non-public information obtained through use of the Service, including technical and commercial information, credentials, third-party data, organization data, secrets, keys, tokens and security information.
NyoCorp will also adopt reasonable measures to protect confidential information of users and organizations, in accordance with the Privacy Policy, Service settings and applicable law.
20. Disclaimers and limitation of liability
The Service is provided "as is" and "as available", without warranties beyond those required by applicable law.
To the maximum extent permitted by law, NyoCorp will not be liable for: loss of zero-knowledge data caused by loss of the master password, key, device or recovery phrase; misuse of the account due to the user's failure to safeguard credentials; content entered, published or shared by users or organizations; decisions made based on data entered by the user; failures of third parties, external integrations, payment providers, email, internet or infrastructure beyond NyoCorp's reasonable control; indirect damages, lost profits, lost revenue, lost opportunity or consequential damages, where such limitation is permitted by law.
NyoCorp's total liability, where applicable and permitted by law, will be limited to the amount paid by the user or organization in the 12 months prior to the event giving rise to the claim, or to another limit set out in a proposal, contract or applicable law.
Nothing in these Terms limits liability that cannot be limited by law, such as willful misconduct, fraud, intentional violation, non-waivable consumer rights or other legally protected situations.
21. Indemnification
You agree to indemnify and hold NyoCorp harmless from losses, liabilities, damages, fines, costs and expenses arising from: misuse of the Service; breach of these Terms; violation of third-party rights; illegal or unauthorized content entered by you or your organization; lack of a legal basis to process third-party data; misuse of APIs, integrations, tokens or credentials.
This clause will apply within the limits permitted by applicable law, especially in consumer relations.
22. Changes to the Service and to the Terms
We may update these Terms to reflect changes in the Service, the law, operations, security or the commercial model.
Material changes will be communicated by reasonable means, such as publication on the platform, notice in the account or email. Continued use after the changes take effect will indicate acceptance of the new Terms, except where the law requires specific consent.
23. Governing law, venue and dispute resolution
These Terms are governed by the laws of the Federative Republic of Brazil, except where mandatory local rules apply to the user or organization.
The courts of «VENUE» are elected to resolve disputes related to these Terms, without prejudice to mandatory consumer rights, including the right to sue in their own domicile where applicable.
Before starting a formal dispute, we recommend contacting the support channel to attempt an amicable resolution.
24. General provisions
If any clause of these Terms is found invalid, illegal or unenforceable, the rest will remain in force.
Tolerance of a breach of any obligation does not mean waiver of a right.
You may not assign your account or rights over the Service without authorization. NyoCorp may assign these Terms in case of corporate reorganization, merger, acquisition, asset sale or business succession, subject to applicable law.
These Terms, together with the Privacy Policy, commercial proposal, contracted plan and any applicable specific documents, constitute the agreement between you and NyoCorp regarding use of the Service.
25. Contact
General support: «SUPPORT CHANNEL».
Privacy and personal data: [email protected].
Service provider: «LEGAL ENTITY», company number 41.408.464/0001-19, «ADDRESS».
Privacy Policy — NyoCorp
About this document
This Privacy Policy explains how «LEGAL ENTITY», registered under company number 41.408.464/0001-19, responsible for the NyoCorp platform and its modules ("NyoCorp", "we"), processes personal data of users, visitors, customers, space administrators, organization members and other data subjects related to use of our services.
This Policy is structured to serve individual users, sole proprietors, teams and organizations in a single document. Where necessary, we explain separately the situations in which NyoCorp acts as controller or as processor of personal data.
NyoCorp observes applicable data protection law, including Brazil's General Data Protection Law — LGPD (Law No. 13.709/2018), the Brazilian Internet Civil Framework (Law No. 12.965/2014) and, where applicable to data subjects located in the European Economic Area, the General Data Protection Regulation — GDPR.
This document must be validated by legal counsel before final publication. Fields between «...» must be filled before publishing.
1. Summary
NyoCorp has zero-knowledge features: in compatible modules and privacy levels, such as NyoVault at the Total level, content is encrypted on the user's device before reaching our servers.
NyoCorp does not receive or store your master password when the zero-knowledge flow is active.
Not all modules are zero-knowledge. Some features need to process server-readable data to function, such as financial reports, CRM, Helpdesk, public cards, billing data, security, authentication and support.
Server-readable data is not public. It remains protected by technical and organizational controls, such as TLS, access control, per-space isolation, security logs and permissions.
We do not sell personal data and do not perform behavioral advertising profiling.
You can exercise rights such as access, correction, deletion, portability, withdrawal of consent and objection, subject to applicable technical, legal and contractual limits.
In organizational accounts, the company or organization administering the space may be the controller of data entered by its users, and NyoCorp may act as processor.
2. Who we are and how to contact us
Controller, where applicable: «LEGAL ENTITY», company number 41.408.464/0001-19, headquartered at «ADDRESS».
Platform: NyoCorp, including its current and future modules, such as NyoVault, NyoFinance, NyoCard, NyoPeople, CRM, Helpdesk, account, identity, spaces and permissions.
Data Protection Officer (DPO): NyoCorp's Data Protection Officer.
DPO contact: [email protected].
General support channel: «SUPPORT CHANNEL».
3. When we act as controller and when we act as processor
NyoCorp may process personal data in different roles, depending on the situation.
3.1 When we act as controller — We act as controller when we decide the purposes and essential means of data processing. This happens, for example, when we process data to: create and administer user accounts; authenticate access and protect the platform; process payments and subscriptions; send transactional, security and support communications; manage plans, billing, invoicing and commercial relationships; operate waitlists, pre-registration, landing pages and pre-launch communications; prevent fraud, abuse, unauthorized access and security incidents; comply with legal, tax, regulatory and judicial obligations; maintain audit records and access logs; improve the product with optional telemetry, when consented.
3.2 When we act as processor — We act as processor when a customer, company, organization, team or space administrator uses NyoCorp to process third-party data under their own purposes. This may occur, for example, when an organization uses the platform to store or process: data of clients, leads, contacts and suppliers; data of employees, contractors, agents or team members; tickets, conversations, support requests and service records; CRM, Helpdesk, registries, tasks, operational history and internal information; data published in cards, profiles or directories created by the organization's users.
In these situations, the organization or space administrator usually acts as data controller, and NyoCorp processes that data according to the organization's instructions, contracted features, space settings, this Policy, the Terms of Use and applicable law.
3.3 Mixed situations — Some operations may involve different roles at the same time. For example, in a business account, the organization may be controller of data entered into a CRM, while NyoCorp remains controller of the data needed for platform security, billing, technical logs, support, fraud prevention and legal compliance.
4. Zero-knowledge architecture and its limits
NyoCorp was designed to offer strong privacy features, including zero-knowledge architecture in compatible modules and levels.
When data is protected at the zero-knowledge level: content is encrypted on the user's device before being sent to the servers; the keys needed to decrypt content remain under the control of the user or authorized device; NyoCorp stores the encrypted content but does not hold the key needed to read it; loss of the master password, recovery phrase or equivalent mechanism may render the encrypted content unrecoverable.
4.1 What zero-knowledge does not mean — Zero-knowledge does not mean no data is processed by NyoCorp. Even in spaces or modules with encrypted content, we may process metadata and technical data needed to operate the service, such as: account, user, space and organization identifiers; email, name and plan data; subscription and billing status; creation, update, sync or deletion dates; access logs, IP, user-agent, session and device data; approximate size, item type, technical identifiers and sync events; data needed for support, security, audit and legal compliance.
In case of a legal order, we may be required to provide the data we hold, including encrypted data, technical records, metadata, logs, account and billing data. For zero-knowledge content, NyoCorp does not hold the key needed to decrypt the content.
5. Data we process
5.1 Data YOU provide (Category — Examples — Main purpose — Server-readable?):
Account data — name, email, language, preferences — account creation, identification, communication — Yes.
Credentials and authentication — OPAQUE verifier, tokens, authorized devices — authentication and security — Partially; master password is not received.
Master password — password used to derive keys on the device — local unlock of encrypted data — We do not receive the master password.
NyoVault content — passwords, notes, cards, TOTP, keys and secrets — secret storage — Depends on the level; secrets are encrypted.
Financial data — accounts, transactions, amounts, dates, categories and goals — financial management and reports — Depends on the privacy level.
Cards and profiles — name, title, company, phone, email, social, avatar, links — digital cards and public or shared profiles — Yes, when published or shared.
CRM/Helpdesk data — clients, contacts, tickets, messages, history and SLA — support and relationship operation — Yes, depending on the feature.
Payment data — name, email, plan, billing identifier — billing and subscription — Yes; the full card stays with the payment processor.
Communications — messages sent to support, requests and replies — support and service — Yes.
5.2 Data collected automatically (Category — Examples — Purpose — Typical legal basis):
Access logs — IP, date/time, user-agent, login result — security, audit, legal obligation — legal obligation / legitimate interest.
Session and device data — session identifier, device, browser, approximate location by IP — account protection and fraud prevention — contract execution / legitimate interest.
Technical events — errors, performance, authentication attempts, sync events — stability and security — legitimate interest.
Optional telemetry — pseudonymized or aggregated usage events — product improvement — consent.
Landing page data — name, email, WhatsApp, interest, source, consent — waitlist, pre-launch communication and affiliates — consent / legitimate interest.
5.3 Data we do not sell or use for behavioral advertising — We do not sell personal data, do not commercialize user bases and do not perform behavioral advertising profiling.
6. Privacy levels per module
NyoCorp lets the user or space administrator choose between two privacy levels: Open (default) or Total. The exact behavior may vary by module, since some features need server-readable data to function.
NyoVault — Open (default): secrets (passwords, TOTP, keys) always stay encrypted on the device; names and titles are server-readable for search and organization. Total: all vault content is encrypted on the device, including names and sensitive fields.
NyoFinance — Open (default): financial data is server-readable for full reports, searches and calculations. Total: amounts, descriptions and balances are encrypted on the device, with local calculations.
NyoCard / NyoPeople — card and profile data is server-readable when published or shared (same across Open and Total).
CRM, Client Registry and Helpdesk — operational data is normally server-readable for search, SLA, aggregation and service (same across Open and Total).
6.1 Who sees vs. encrypt — The encryption level is different from visibility control. Data may be server-readable but visible only to authorized people within a space, according to roles, permissions and access rules. Likewise, encrypted data may require the master password, an authorized device or the proper key to be viewed.
6.2 Public data — Data published in cards, profiles, public pages or shareable links may be accessed by people who have the link or by external mechanisms, depending on configuration. You may remove or unpublish this data within the platform, but third parties may have made copies, screenshots, cache, indexing or external shares beyond our control.
7. Purposes and legal bases
We process personal data for the following purposes (Purpose — Examples — Typical legal basis in Brazil):
Create an account and provide the service — registration, login, spaces, sync — contract execution.
Authentication and security — OPAQUE, device verification, blocks, logs — contract execution / legitimate interest / legal obligation.
Billing and subscriptions — plan, invoices, payment, receipts and history — contract execution / legal obligation.
Support and essential communications — email verification, security alerts, service — contract execution / legitimate interest.
Module operation — Vault, Finance, Card, People, CRM, Helpdesk — contract execution.
Optional telemetry — product improvement, usage metrics — consent.
Waitlist and pre-launch — capturing interested people, communications about launch — consent.
Aggregate analytics and affiliates — traffic source, nyo_ref cookie, referral attribution — legitimate interest, with minimization and objection.
Fraud and abuse prevention — rate-limit, incident investigation, logs — legitimate interest / legal obligation.
Legal compliance — access logs, tax obligations, legal orders — legal obligation / regular exercise of rights.
Defense of rights — audit, evidence preservation, disputes — regular exercise of rights / legitimate interest.
Where the legal basis is consent, you may withdraw it at any time, without affecting processing already carried out on a valid basis before withdrawal.
8. Cookies, local storage and similar technologies
We use cookies, local storage and similar technologies to operate the platform securely (Type — Examples — Purpose — Typical term — Can refuse?):
Necessary — session, CSRF, authentication — keep login, security and functioning — session or short term — no, they are essential.
Security — trusted device, login attempts — protect the account and prevent abuse — as needed for security — partially.
Preferences — language, theme, settings — remember preferences — as configured — yes.
Affiliates — nyo_ref — attribute a referral to a referrer — up to 90 days — yes.
Telemetry — opt-in usage events — product improvement — up to 90 days in raw form — yes.
We may also use localStorage, sessionStorage and IndexedDB for preferences, session, offline operation and local storage of cryptographic material on the device. Private keys or local secrets must not be sent to the server in clear text.
The nyo_ref affiliate cookie is a first-party cookie, used only for referral attribution. It is not used for behavioral advertising, builds no advertising profile and is not sold to third parties.
9. Data sharing and sub-processors
We do not sell personal data. We share data only when necessary to operate the platform, comply with legal obligations, protect rights or provide contracted features (Processor/sub-processor — Purpose — Data involved — Expected location):
Stripe — payments and subscriptions — name, email, billing data and payment identifiers — USA or other regions operated by the provider.
Resend — transactional emails — email, name and message content — USA or other regions operated by the provider.
Google, when enabled — federated login/OIDC — Google identifier, name and email — USA or other regions operated by the provider.
«HOSTING PROVIDER» — infrastructure, servers and database — data stored and processed by the platform — Brazil by default / other regions per plan.
Support, security or monitoring providers, if applicable — support, logs, stability and protection — necessary technical data and communications — as contracted.
In zero-knowledge features, infrastructure operators store or process encrypted content but do not receive the key needed to decrypt that content.
We may also share data when there is a legal obligation, court order, request from a competent authority, defense of rights, fraud investigation or protection of the security of the platform and third parties.
10. International transfer and data residency
By default, NyoCorp seeks to store the main data in infrastructure located in Brazil. Some sub-processors, such as payment, email, authentication, support, security or monitoring providers, may process data outside Brazil.
Where there is an international transfer of personal data, we will adopt mechanisms permitted by applicable law, such as contractual clauses, adequacy decisions, binding corporate rules, specific consent where applicable or other mechanisms provided by the LGPD, GDPR or equivalent law.
Business plans may provide for specific data residency in Brazil, the European Union, the United States or another region, subject to technical availability and contracting.
11. Retention, deletion, backups and legal hold
We keep personal data for as long as necessary to fulfill the purposes described in this Policy, subject to legal obligations, security, audit, defense of rights and account or organization settings (Category — Typical term):
Account data and user content — while the account or space exists, except for deletion or legal retention.
Zero-knowledge content — while the item, account or space exists; after purge, not recoverable by NyoCorp.
Application access logs — for the applicable legal term, including at least 6 months when required by the Internet Civil Framework.
Security and audit logs — for the period needed for security, audit, defense of rights and compliance, possibly pseudonymized, anonymized or subject to crypto-shredding.
Tax and billing data — for the applicable tax, accounting and regulatory term.
Raw opt-in telemetry — up to 90 days; afterward, preferably aggregated or anonymized.
Waitlist and pre-launch — until launch and for a reasonable additional period, except for unsubscribe or legal obligation.
Data subject requests — for the period needed to demonstrate handling and comply with legal obligations.
Backups — kept for a limited backup cycle, according to the technical policy in force: «BACKUP PERIOD».
11.1 Account deletion — You may request deletion of your account. Before deleting, we recommend exporting your data, especially zero-knowledge content, as NyoCorp may be unable to recover it after the purge. Deletion may involve: a deletion request by the user, authorized administrator or privacy channel; verification of the requester's identity and authority; suspension or grace period, if applicable; deletion or anonymization of active data; minimum retention of data required by law, security, audit, billing, defense of rights or legal order; later elimination according to retention terms.
11.2 Organizational accounts — In business or organizational spaces, deleting an individual account may not automatically erase data belonging to the organization, such as tickets, CRM records, operational history, logs, documents, corporate cards or data entered in the space. In these cases, the administering organization may define rules for retention, export, ownership transfer and space closure, subject to applicable law.
11.3 Backups — Backups may contain deleted data for a limited period, until their automatic replacement in the backup cycle. During that period, the data remains protected and isolated, not restored for active use, except for continuity, disaster recovery, security, legal obligation or competent order needs.
11.4 Legal hold — If there is a court order, request from a competent authority, investigation, dispute or legal obligation requiring data preservation, we may suspend deletion or purge of the covered data until the obligation ends.
12. Data subject rights
You may request, as applicable by law: confirmation of the existence of processing; access to personal data; correction of incomplete, inaccurate or outdated data; anonymization, blocking or elimination of unnecessary, excessive or non-compliant data; data portability, where applicable; information about sharing; withdrawal of consent; objection to processing based on legitimate interest; review of automated decisions, where applicable; elimination of data processed on the basis of consent, subject to legal retention; complaint to a competent authority.
How to exercise: send a request to [email protected] or use the privacy portal when available.
We may request additional information to confirm your identity, protect your account and prevent improper access to personal data.
12.1 Technical limits on zero-knowledge data — For zero-knowledge data, NyoCorp may provide the encrypted data it holds. Export in a readable format may depend on the user's device, where the data is decrypted locally.
12.2 Requests involving organizational accounts — Where NyoCorp acts as processor, we may forward the request to the controlling customer or act on their instructions, except where the request involves data processed by NyoCorp itself as controller, such as account, security, billing or support data.
13. Security
We adopt technical and organizational measures appropriate to the risks of processing, including, as the case may be: encryption in transit (TLS); local and zero-knowledge encryption in compatible modules; strong authentication and the OPAQUE protocol where applicable; logical isolation between spaces and tenants; roles and permissions (RBAC); auto-lock on inactivity; device verification; rate-limit and abuse protection; security and audit logs; administrative access controls; backups and continuity measures; minimization, pseudonymization or anonymization where applicable.
No system is completely immune. In the event of a security incident that may cause relevant risk or harm to data subjects, we will take appropriate measures and notify the competent authority and affected data subjects where required by applicable law.
14. Children and adolescents
NyoCorp is not intended for those under 18, except where there is valid contracting or authorization by a legal guardian or authorized organization, as applicable by law. We do not knowingly collect data of children or adolescents without an adequate legal basis.
15. Sensitive data and health data
NyoCorp's current modules are not intended for processing health data or other sensitive data in a regulated context, except where expressly stated in a feature, contract or specific documentation.
The user or organization must not enter sensitive data into modules not intended for that purpose without an adequate legal basis and without assessing the additional risks and requirements that apply.
A future health module, if launched, will have specific documentation, legal bases, safeguards and terms.
16. Region-specific information
16.1 Brazil — For data subjects in Brazil, the rights set out in the LGPD apply, along with specific rules such as keeping internet application access logs for the applicable legal term. The data subject may also contact the National Data Protection Authority (ANPD).
16.2 European Union and European Economic Area — Where the GDPR applies, data subjects may exercise the rights in Articles 15 to 22 of the GDPR, including access, rectification, erasure, restriction, portability, objection and rights related to automated decisions. Where we process data based on legitimate interest, we may carry out a balancing test. Where the basis is consent, consent may be withdrawn at any time. International transfers subject to the GDPR will use adequate mechanisms, such as adequacy decisions, standard contractual clauses or another permitted mechanism.
16.3 United Kingdom, United States and other regions — Where local laws apply, we may provide additional information, regional addenda or specific mechanisms to meet local rights and requirements. If a local right applies to your case, contact us at [email protected].
17. Changes to this Policy
We may update this Policy to reflect legal, technical, commercial or product changes. Material changes will be communicated by reasonable means, such as a notice on the platform, email or publication of a new version.
Where the law requires specific consent, we will request new consent before the corresponding processing.
18. Contact
Privacy and personal data: [email protected].
General support: «SUPPORT CHANNEL».
Controller, where applicable: «LEGAL ENTITY», company number 41.408.464/0001-19, «ADDRESS».
Brazilian authority: National Data Protection Authority — ANPD.