Skip to main content

Privacy Policy

Last updated: August 8, 2026

This Privacy Policy explains how Navero processes personal data in accordance with applicable privacy laws, including the EU General Data Protection Regulation (GDPR/AVG).

1. Data Controller

Navero App, a eenmanszaak registered in the Netherlands, acts as the data controller for personal data processed through our platform unless explicitly stated otherwise.

Registered address: Pompenburg 384, Rotterdam, the Netherlands. KvK number: 99925451. VAT number: NL005418730B96.

2. Data We Process

  • Account and profile data (such as email address and authentication data).
  • Portfolio-related data you provide or authorize us to import.
  • Technical and usage data (such as device, browser, logs, and diagnostics).
  • Support communications and issue reports.
  • Email choices and consent records, suppression status, and delivery events such as sent, delivered, opened, clicked, bounced, complaint, and unsubscribe events.

3. Legal Bases

We process personal data on one or more legal bases: performance of a contract for requested account and service communications, legitimate interests where those interests are not overridden by your rights, legal obligations, and consent where required.

Where applicable law requires consent for direct marketing by email, we send account-opening, sales/conversion, or product-marketing emails only after obtaining valid consent. Any legally available existing-customer exception is used only when its conditions are satisfied.

4. Purposes of Processing

  • To provide and secure the service.
  • To import, organize, and display portfolio information.
  • To communicate service updates and support responses.
  • To help you complete an account-opening process you started and explain available plans, where permitted by law.
  • To send optional product updates and marketing communications according to your separate choices.
  • To record email delivery, engagement, suppression, and preference events so we can operate communications, measure effectiveness, prevent unwanted sends, and demonstrate compliance.
  • To improve reliability, usability, and fraud prevention.
  • To comply with legal and regulatory obligations.

5. Email Communications and Your Choices

Essential account, authentication, security, billing, and support messages are service communications and are not controlled by optional marketing preferences.

Account-opening reminders and plan offers are an optional non-transactional category. If you choose this category during registration, Navero may send helpful account-opening reminders and information or offers about available plans while the account-opening process remains incomplete, but only where this is permitted by law and any required consent has been obtained.

Separately, Navero may send a limited number of account-opening service messages to help you complete a process you initiated. These messages are support-focused and do not contain plan offers or product promotion.

Product-marketing emails and weekly or monthly digest emails are separate categories. A choice about one category does not automatically opt you into another.

You can change these choices through the preferences link in an email. Each non-transactional message provides a simple way to stop that category, and you can also unsubscribe from all optional email. Withdrawing consent or objecting does not affect essential service messages or processing that occurred before your choice changed.

6. Sharing of Data

We may share data with processors and service providers that support hosting, communications, customer support, analytics, and billing operations under appropriate contractual safeguards. This includes Resend for transactional and permitted marketing email delivery and delivery-event processing, and Paddle for subscription and payment processing.

We do not sell personal data.

We may disclose data when legally required or to protect rights, security, and platform integrity.

7. International Transfers

If personal data is transferred outside the European Economic Area, we apply appropriate safeguards, such as adequacy decisions or Standard Contractual Clauses.

8. Retention

We retain personal data only as long as necessary for the purposes described in this policy, including legal, accounting, and security obligations.

Account and portfolio data are generally retained while your account is active and for up to 12 months after account closure, unless a shorter or longer period is required by law.

Billing and tax records are retained for statutory periods that apply to us (for Dutch tax administration purposes, this is commonly up to 7 years).

Security and operational logs are retained for up to 12 months unless extended retention is required for incident investigation or legal obligations.

Email delivery and engagement events are retained only as long as needed for communications operations, measurement, security, and compliance. We may retain suppression and objection records longer so that we continue to honor your choice not to receive optional email.

Encrypted backups are retained on a rolling basis for up to 35 days before automatic deletion or overwrite.

9. Your Rights

  • Access, rectification, erasure, and data portability.
  • Restriction of processing and objection to processing based on legitimate interests.
  • Withdrawal of consent where processing is based on consent.
  • Objection at any time to processing for direct marketing; after an objection, we stop using your personal data for that purpose.
  • Where available, data portability exports can be requested through in-product self-service downloads (CSV and JSON formats).
  • Deletion requests are handled without undue delay and, in normal cases, within 30 days, subject to legal retention obligations.
  • Lodging a complaint with a supervisory authority, including the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).

10. Security

We use technical and organizational security measures designed to protect personal data against unauthorized access, alteration, disclosure, or destruction.

These measures include encryption in transit, access controls based on least privilege, monitoring, and security hardening for production systems.

No method of transmission or storage is completely secure, but we continuously work to reduce risk and respond quickly to incidents.

11. Cookies and Similar Technologies

We use cookies or similar technologies necessary for service functionality and security. Where legally required, non-essential cookies are used only with valid consent.

12. Contact

For privacy requests or questions, contact Navero App at support@navero.app.