Data Policy
Last Updated: March 9, 2026
1. Introduction
This Data Policy explains how NuForce ("we," "our," or "us") processes, stores, transfers, and protects your data when you use our service business management platform ("Service"). This policy supplements our Privacy Policy and provides detailed information about our data handling practices.
2. Data We Process
2.1 Personal Data
We process the following categories of personal data:
- Identity Data: Name, username, email address, phone number
- Account Data: Account credentials, subscription information, billing details
- Profile Data: Profile picture, job title, company information, preferences
- Usage Data: How you interact with the Service, features used, time spent
- Technical Data: IP address, browser type, device information, operating system
- Location Data: General location information (with your permission)
- Communication Data: Messages, support tickets, feedback, and correspondence
2.2 Business Data
We also process business-related data that you input into the Service:
- Customer and contact information
- Work orders and service records
- Invoices and financial transactions
- Project files and documentation
- Team member information and assignments
- Service schedules and calendars
- Inventory and asset data
3. Legal Basis for Processing
We process your data based on the following legal grounds:
- Contract Performance: To fulfill our contractual obligations and provide the Service
- Legitimate Interests: To improve our Service, ensure security, and prevent fraud
- Consent: When you have given explicit consent for specific processing activities
- Legal Obligations: To comply with applicable laws and regulations
- Vital Interests: To protect the safety and security of our users
4. How We Process Your Data
4.1 Data Collection
We collect data directly from you when you register, use the Service, or communicate with us. We also collect data automatically through your use of the Service, including usage patterns, device information, and system logs.
4.2 Data Storage
Your data is stored in secure data centers with appropriate physical and technical safeguards. We use industry-standard encryption for data at rest and in transit to protect your information.
Storage Locations:
- Primary data centers: [Specify locations]
- Backup storage: Encrypted backups stored in geographically distributed locations
- CDN and caching: Content delivery networks for performance optimization
4.3 Data Processing
We process your data to:
- Provide and maintain the Service
- Process transactions and manage subscriptions
- Analyze usage patterns and improve functionality
- Detect and prevent security threats and fraud
- Generate reports and analytics
- Comply with legal and regulatory requirements
For product analytics and marketing attribution, we aim to use pseudonymous identifiers, including hashed user and organization identifiers, instead of directly identifying fields wherever possible.
5. Data Sharing and Transfers
5.1 Data Sharing
We do not sell your data. We may share your data with trusted service providers who assist us in operating the Service, subject to strict confidentiality and data protection obligations.
5.2 International Transfers
Your data may be transferred to and processed in countries outside your country of residence. We ensure appropriate safeguards are in place, including:
- Standard contractual clauses approved by data protection authorities
- Binding corporate rules for intra-group transfers
- Certification schemes and adequacy decisions where applicable
5.3 Third-Party Services
We integrate with third-party services that may process your data. These services are subject to their own privacy policies and data practices. We carefully select partners who meet our data protection standards.
These services may include Google Analytics 4 for aggregate web analytics, Mixpanel for funnel and product analytics, and Sentry for essential application monitoring, performance diagnostics, and error investigation.
6. Data Security
We implement comprehensive security measures to protect your data:
6.1 Technical Safeguards
- Encryption of data in transit (TLS/SSL) and at rest (AES-256)
- Secure authentication and access controls
- Regular security audits and vulnerability assessments
- Intrusion detection and prevention systems
- Network segmentation and firewall protection
6.2 Organizational Safeguards
- Employee training on data protection and security
- Strict access controls and role-based permissions
- Regular security awareness programs
- Incident response and breach notification procedures
6.3 Physical Safeguards
- Secure data centers with 24/7 monitoring
- Biometric access controls and visitor management
- Environmental controls and backup power systems
7. Data Retention
We retain your data for as long as necessary to fulfill the purposes outlined in this policy, unless a longer retention period is required or permitted by law.
7.1 Retention Periods
- Account Data: Retained while your account is active and for a reasonable period after closure
- Business Data: Retained according to your subscription plan and business needs
- Financial Records: Retained as required by law (typically 7 years)
- Log Data: Retained for security and troubleshooting purposes (typically 90 days to 1 year)
- Analytics Data: Retained according to provider settings and internal reporting needs, then deleted or anonymized where practical
- Marketing Data: Retained until you opt out or withdraw consent
7.2 Data Deletion
When you delete your account or request data deletion, we will delete or anonymize your personal data, except where retention is required for legal, regulatory, or legitimate business purposes. Deleted data may remain in backups for a limited period before being permanently removed.
8. Your Data Rights
You have the following rights regarding your data:
8.1 Access and Portability
You can access your data through your account settings or request a copy in a machine-readable format.
8.2 Correction and Update
You can update or correct your data at any time through your account settings or by contacting us.
8.3 Deletion
You can request deletion of your data, subject to legal and contractual obligations that may require us to retain certain information.
8.4 Restriction and Objection
You can request restriction of processing or object to certain types of data processing, particularly for marketing purposes.
8.5 Withdrawal of Consent
Where processing is based on consent, you can withdraw your consent at any time. This will not affect the lawfulness of processing before withdrawal.
9. Data Breach Procedures
In the event of a data breach that may affect your personal data, we will:
- Immediately investigate and contain the breach
- Assess the risk and impact to affected individuals
- Notify relevant supervisory authorities within 72 hours (where required by law)
- Notify affected users without undue delay if there is a high risk to their rights and freedoms
- Provide clear information about the breach, its consequences, and measures taken
- Take steps to prevent similar breaches in the future
10. Compliance and Certifications
We are committed to compliance with data protection regulations, including:
- GDPR (EU): General Data Protection Regulation compliance
- CCPA (California): California Consumer Privacy Act compliance
- PIPEDA (Canada): Personal Information Protection and Electronic Documents Act
- Other Jurisdictions: Compliance with applicable local data protection laws
We regularly review and update our data protection practices to ensure ongoing compliance with evolving regulations.
11. Data Processing Agreements
If you are a business customer using our Service to process data on behalf of your customers, we act as a data processor. We have data processing agreements in place that define our responsibilities and obligations when processing data on your behalf.
12. Changes to This Data Policy
We may update this Data Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of any material changes by posting the updated policy on this page and updating the "Last Updated" date.
13. Contact Us
If you have questions, concerns, or wish to exercise your data rights, please contact us at:
NuForce Data Protection Team
Email: privacy@nuforce.com
Address: [Your Business Address]
For EU residents, you may also contact our Data Protection Officer at: dpo@nuforce.com
You also have the right to lodge a complaint with your local data protection authority if you believe we have not addressed your concerns adequately.