Privacy Policy
Effective Date: January 1, 2026 Last Updated: September 29, 2026
At Nevalto ("Nevalto", "we", "our", or "us"), operated under Swiss law, we respect your privacy and are committed to protecting the personal data of facility operators, coaches, stringers, players, and visitors who use our platform and website.
This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit nevalto.com or interact with the Nevalto venue management, court booking, racquet stringing, and smart facility digital twin software.
---
1. Regulatory Framework & Data Sovereignty
Nevalto operates strictly under the principles of privacy-by-design and privacy-by-default: - Swiss Federal Act on Data Protection (nDSG / FADP). - European General Data Protection Regulation (EU GDPR 2016/679). - All customer database records, telemetry, and automated audit logs are hosted in certified EU/EEA and Swiss enterprise data centers with end-to-end encryption at rest (AES-256) and in transit (TLS 1.3).
---
2. Information We Collect
A. Information You Provide Directly - Account & Profile Data: Name, email address, phone number, organisation or club name, billing address, and role (e.g. Club Manager, Stringer, Coach, Member). - Workshop & Customer Records: Player racquet specifications, string inventory details, tension logs, and order intake notes entered into the Stringing Workshop application. - Billing & Payment Details: VAT numbers, billing contacts, and payment status. Credit card and banking transactions are processed securely via PCI-DSS Level 1 certified gateways (e.g. Stripe, Swiss QR-bill generators); Nevalto never stores raw payment card numbers.
B. Facility Telemetry & Operational Data - Court Bookings & IoT Automation: Court reservation timestamps, automated lighting relay states (Loxone Miniserver), and turnstile access events (Unifi Access) associated with valid booking passes. - Analytics & Diagnostic Metrics: Browser user agent, operating system, anonymised IP addresses, and session interaction metrics aggregated via privacy-friendly edge analytics without cross-site tracking.
---
3. How We Use Your Information
We process personal and venue data exclusively for legitimate operational purposes: 1. Delivering Platform Services: Powering conflict-free court scheduling, automated lighting activation, member passes, and racquet intake tracking. 2. AI & Machine Learning Features: Generating 72-hour court demand forecasts, tension recommendations via the Gemma Tension Advisor, and executive operational briefings. Customer data is never used to train generalized external public models. 3. Communications & Support: Providing real-time service notifications, maintenance alerts, stringing readiness SMS/email notifications, and responsive customer support. 4. Legal & Financial Compliance: Complying with Swiss accounting standards, tax obligations, and statutory retention rules.
---
4. Data Sharing & Third-Party Processors
We do not sell, rent, or trade your personal data. Data is shared strictly with vetted sub-processors necessary for platform execution: - Cloud Infrastructure & Hosting: Vercel (Edge network & compute), certified EU cloud providers. - Payment & Invoicing: Stripe Payments Europe, Bexio ERP integration endpoints. - Communication Channels: Transactional email and SMS delivery gateways with strict DPA clauses.
---
5. Data Retention & Deletion
We retain personal information only for as long as necessary to fulfill the purposes outlined in this policy or to comply with statutory legal and accounting retention periods (typically 10 years for financial records under the Swiss Code of Obligations). Upon termination of an organisation account, operational data is securely erased or anonymised in accordance with our data exit schedule.
---
6. Your Rights Under GDPR and Swiss nDSG
As a data subject, you hold the following statutory rights: - Right to Access: Request a comprehensive export of your personal data held by Nevalto. - Right to Rectification: Correct any inaccurate or incomplete records. - Right to Erasure ("Right to be Forgotten"): Request deletion of your data when retention is no longer legally mandated. - Right to Data Portability: Receive your structured data in standard machine-readable formats (JSON/CSV). - Right to Object / Restrict Processing: Restrict certain processing activities or withdraw consent at any time.
To exercise any of these rights, contact our Data Protection Officer at [email protected].
---
7. Security Measures
We enforce rigorous technical and organizational security controls: - Role-Based Access Control (RBAC) and Zero-Access passcode gating for administrative hubs. - AES-GCM-256 encrypted client vault key management. - Continuous vulnerability scanning and automated CI/CD security quality gates.
---
8. Contact & Data Protection Officer
If you have questions, feedback, or concerns regarding this Privacy Policy or our data handling practices, please contact:
Nevalto Data Protection Office Darkventure Studio Sàrl Email: [email protected] Website: https://nevalto.com/contact