Nurvia Data Room
Privacy Policy
Last updated: July 11, 2026 · Effective: July 11, 2026
This Privacy Policy explains how Nurvia Inc., referred to as “Nurvia,” “we,” “us,” or “our,” collects, uses, discloses, retains, and protects personal information when you:
- Access or use the Nurvia Data Room
- Open a document, file, presentation, video, spreadsheet, or other confidential material shared through the Data Room
- Sign or accept an electronic agreement, nondisclosure agreement, access agreement, or other record
- Visit a Nurvia Data Room landing page
- Communicate with Nurvia in connection with fundraising, diligence, partnerships, employment, advisory services, acquisitions, or another potential relationship
- Interact with security, access-control, document-viewing, analytics, or support features associated with the Data Room
The Data Room includes websites, document viewers, electronic-signature tools, invitation systems, dashboards, communications, and related services operated by or for Nurvia.
This Privacy Policy applies to the Nurvia Data Room. It does not necessarily govern separate Nurvia products, applications, or services that display a different privacy policy.
The short version
When you access the Nurvia Data Room:
- We collect identifying information such as your name, email address, organization, and title.
- We collect technical information such as your IP address, browser, device, operating system, and approximate location.
- We record how you interact with the Data Room, including which documents and pages you view, how long you view them, clicks, scrolling, navigation, pointer movement, and security-related activity.
- We may use session-replay technology to reconstruct activity occurring within the Data Room.
- Materials may contain visible or invisible watermarks linked to your identity, email address, session, and access time.
- We use this information to provide access, protect confidential information, analyze recipient engagement, investigate misuse, attribute unauthorized disclosures, and enforce our agreements.
- We do not sell your personal information or use Data Room activity for cross-context behavioral advertising.
- Authorized Nurvia personnel and service providers may access this information for the purposes described in this policy.
- You may have rights to access, correct, delete, or obtain a copy of your personal information, subject to legal and security exceptions.
The remainder of this Privacy Policy provides additional detail.
1. Who is responsible for your information
Nurvia Inc. is generally the controller or business responsible for determining how and why personal information collected through the Data Room is processed.
Our contact information is:
Nurvia Inc.
Attention: Privacy
813 Mission Street
San Francisco, California 94103
United States
Email: legal@nurvia.app
Service providers that host, secure, analyze, or support the Data Room generally process personal information on Nurvia’s behalf and according to Nurvia’s instructions.
2. Information we collect
The personal information we collect depends on how you interact with the Data Room and which features are enabled for your access.
2.1 Identity and contact information
We may collect:
- First and last name
- Email address
- Telephone number
- Organization or employer
- Job title or professional role
- Business address
- Investor, advisor, employee, contractor, vendor, customer, partner, or other relationship category
- Name and contact details of the person who invited you
- Information provided by the organization you represent
Some of this information may be provided by the person who invites you before you access the Data Room.
2.2 Authentication and access information
We may collect:
- Account identifiers
- Access-link identifiers
- Invitation records
- Authentication tokens
- Password-related account information
- One-time verification codes
- Login and logout times
- Successful and unsuccessful authentication attempts
- Access approvals, denials, expirations, suspensions, and revocations
- Devices and sessions associated with your access
- Records showing that you accepted the Data Room Terms or another agreement
Passwords, when used, should be stored in a protected form rather than as readable text.
2.3 Electronic-signature and consent information
When you electronically sign or accept an agreement, we may collect:
- Your legal or typed name
- Your electronic signature
- Signature image or drawing
- Signature date and time
- Email address
- IP address
- Device and browser information
- Document version
- Agreement identifier
- Audit trail
- Authentication and verification events
- Records of your consent to electronic transactions
- Records showing when an agreement was delivered, opened, reviewed, accepted, or signed
We use this information to execute agreements, maintain legal records, authenticate signers, and establish the validity and history of an electronic transaction.
We do not use electronic signatures to infer sensitive characteristics about you.
2.4 Device and technical information
We may automatically collect:
- Internet Protocol address
- Browser type and version
- Operating system
- Device type
- Device identifiers
- Screen size and display characteristics
- Language and locale
- Time zone
- Network provider
- Referring page
- Pages visited before or after a Data Room page
- Date and time of access
- Connection and response information
- Error logs
- Performance information
- Cookie and local-storage identifiers
- System configuration information
2.5 Approximate location
We may infer an approximate city, state, region, or country from your IP address.
IP-based location information is approximate and may be inaccurate, particularly when you use a corporate network, mobile network, proxy, or virtual private network.
We do not intend to collect precise GPS location through the Data Room unless you separately and affirmatively choose to provide it.
2.6 Data Room viewing and engagement activity
We may collect detailed information regarding how you interact with the Data Room, including:
- Whether you opened or viewed a file
- Which file, folder, or section you opened
- Which pages, slides, images, cells, sheets, videos, or portions you viewed
- The order in which you viewed Materials
- Date and time of each view
- Number of views
- Time spent in the Data Room
- Time spent on a particular document or page
- Whether the Data Room was visible or active
- Scrolling activity
- Clicks and taps
- Pointer or cursor movement
- Navigation activity
- Search activity
- Zoom or display activity
- Video play, pause, completion, and playback position
- Links or controls selected
- Documents marked as viewed
- Progress through a recommended review sequence
- Errors or interruptions occurring during viewing
- Attempts to access unavailable or restricted Materials
This information may be associated with your name, email address, organization, IP address, device, session, and watermark identifier.
2.7 Session replay and interaction reconstruction
We may use session-replay or similar technologies to reconstruct how a recipient interacted with the Data Room.
Depending on the technology and configuration used, session replay may record or recreate:
- Page navigation
- Document changes
- Pointer movement
- Clicks
- Taps
- Scrolling
- Page visibility
- Interface interactions
- Error events
- Security warnings
- Time spent on particular screens
- Attempts to use restricted controls
Session replay is limited to activity occurring within the Data Room or its associated interfaces.
We do not intend to record:
- Activity in unrelated browser tabs
- Activity in unrelated applications
- The contents of your email account
- The contents of files stored elsewhere on your device
- Password text
- Payment-card information
- Other information outside the Data Room
Fields containing passwords or similarly sensitive authentication information should be excluded or masked from replay tools.
2.8 Security and restriction events
We may collect information about actual or attempted actions involving:
- Printing
- Downloading
- Saving
- Copying
- Pasting
- Text selection
- Screenshots
- Screen recording
- Browser developer tools
- Restricted keyboard shortcuts
- Window switching
- Tab visibility
- Screen-sharing indicators
- Browser extensions
- Automated scripts
- Scraping
- Unusual request patterns
- Repeated authentication failures
- Attempts to modify or avoid a watermark
- Attempts to bypass access restrictions
- Attempts to access unapproved files, endpoints, or accounts
- Other activity that may indicate unauthorized capture or misuse
A security event does not necessarily mean that you successfully performed the associated action.
We may combine these events with other information to investigate potential violations of our Data Room Terms or a nondisclosure agreement.
2.9 Watermark and forensic attribution information
Documents and interfaces may contain visible or invisible markings associated with:
- Your name
- Your email address
- Your organization
- Your IP address
- Date and time
- Session identifier
- Access-link identifier
- Document identifier
- Page identifier
- Unique forensic token
We may retain records linking a watermark or token to the recipient, session, and document view for the purpose of identifying the source of an unauthorized disclosure.
A watermark does not necessarily establish conclusively that a particular person caused a disclosure. It is one source of evidence that may be considered alongside access logs and other information.
2.10 Communications and support information
We collect information when you communicate with us, including:
- Emails
- Support requests
- Questions
- Feedback
- Meeting scheduling information
- Call notes
- Demonstration requests
- Messages submitted through the Data Room
- Reports of suspected security issues
- Privacy requests
- Legal notices
- Communications concerning a potential transaction or relationship
2.11 Potential relationship and diligence information
We may collect information relating to a potential:
- Investment
- Financing
- Partnership
- Customer relationship
- Vendor relationship
- Employment relationship
- Advisory relationship
- Acquisition
- Sale
- Licensing arrangement
- Strategic relationship
- Other business transaction
This may include your professional interests, diligence questions, document requests, meeting history, relationship status, investment focus, and communications with Nurvia.
2.12 Information you submit
We collect information that you voluntarily provide through:
- Forms
- Questionnaires
- Signature fields
- Access requests
- Document requests
- Feedback fields
- Messages
- Uploaded materials
- Email communications
Please do not submit sensitive personal information that is not necessary for the purpose of your interaction with Nurvia.
2.13 Cookies and similar technologies
We may use:
- Cookies
- Local storage
- Session storage
- Pixels
- Software development kits
- Log files
- Device identifiers
- Similar technologies
These technologies may be used to:
- Keep you signed in
- Authenticate your session
- Remember preferences
- Prevent fraud and unauthorized access
- Apply access permissions
- Generate document analytics
- Support session replay
- Identify security events
- Diagnose technical problems
- Measure performance
- Improve the Data Room
Where applicable law requires consent before using a non-essential technology, we will request consent before activating that technology.
Refusing certain technologies may prevent us from authenticating you or providing access to secured Materials.
3. Sources of personal information
We may collect personal information from:
3.1 You
This includes information you enter, submit, sign, communicate, or generate through your interaction with the Data Room.
3.2 The person or organization that invited you
A founder, employee, advisor, administrator, investor, partner, or other authorized person may provide your name, email address, company, role, or other access-related information.
3.3 Your device and browser
We automatically receive technical, security, access, and usage information when your device connects to the Data Room.
3.4 Our service providers
Authentication, hosting, email, security, analytics, session-replay, database, electronic-signature, and infrastructure providers may generate or return information necessary to operate the Data Room.
3.5 Public and professional sources
When reasonably necessary to verify a business identity or relationship, we may obtain limited professional information from:
- Company websites
- Professional networking profiles
- Public business records
- Publicly available investment information
- Publicly available professional directories
We do not use the Data Room to build consumer advertising profiles.
4. How we use personal information
We use personal information for the following purposes.
4.1 Provide Data Room access
We use information to:
- Create and administer access
- Deliver invitations
- Authenticate recipients
- Display authorized Materials
- Apply access permissions
- Process access requests
- Maintain sessions
- Provide technical support
- Communicate about access
4.2 Protect confidential information
We use information to:
- Prevent unauthorized access
- Detect credential sharing
- Identify suspicious activity
- Apply document restrictions
- Generate watermarks
- Attribute unauthorized disclosures
- Investigate suspected copying or capture
- Protect trade secrets and confidential Materials
- Enforce nondisclosure agreements and Data Room Terms
4.3 Analyze recipient engagement
We may use viewing and interaction information to understand:
- Whether Materials were opened
- Which Materials received attention
- How long a recipient reviewed particular information
- Whether a recipient completed a recommended review sequence
- Which parts of a document were viewed
- Whether follow-up may be appropriate
- The general level of interest in a potential relationship or transaction
These analytics may be reviewed by authorized Nurvia founders, employees, advisors, legal counsel, or administrators.
We do not use document engagement analytics as the sole basis for making a legally significant decision about an individual.
4.4 Execute and administer agreements
We use electronic-signature and consent information to:
- Deliver agreements
- Obtain signatures
- Verify acceptance
- Maintain audit records
- Establish agreement history
- Enforce contractual rights
- Respond to disputes
- Meet recordkeeping obligations
4.5 Communicate with you
We may use your information to:
- Respond to questions
- Schedule meetings
- Send requested information
- Provide security notices
- Communicate changes to access
- Provide administrative messages
- Follow up concerning a potential transaction or relationship
- Respond to privacy and legal requests
4.6 Operate and improve the Data Room
We use information to:
- Diagnose errors
- Monitor availability
- Improve performance
- Test features
- Understand how interfaces are used
- Fix technical problems
- Improve document organization
- Develop security controls
- Maintain internal records
4.7 Comply with law and protect rights
We may process information to:
- Comply with legal obligations
- Respond to lawful process
- Establish, exercise, or defend legal claims
- Enforce contracts
- Protect Nurvia, recipients, and third parties
- Investigate fraud or unlawful conduct
- Cooperate with regulators and law enforcement
- Maintain records required by law
4.8 Corporate transactions
We may use or disclose information in connection with:
- Financing
- Due diligence
- Merger
- Acquisition
- Reorganization
- Sale of assets
- Bankruptcy
- Change of control
- Similar corporate transaction
Any recipient of personal information in such a transaction will be expected to handle it consistently with applicable law.
5. Legal bases for processing
For people located in the European Economic Area, United Kingdom, Switzerland, or another jurisdiction requiring a legal basis, we rely on one or more of the following.
5.1 Performance of a contract
We process information when necessary to provide requested Data Room access, execute an agreement, or administer our contractual relationship with you.
5.2 Steps before entering into a contract
We may process information to evaluate or discuss a potential investment, partnership, employment relationship, acquisition, customer relationship, or other transaction at your request or the request of the organization you represent.
5.3 Legitimate interests
We may process information based on our legitimate interests in:
- Protecting confidential information
- Securing the Data Room
- Preventing fraud and unauthorized access
- Understanding engagement with Materials
- Managing potential business relationships
- Maintaining evidence of access and consent
- Improving Data Room performance
- Protecting our legal rights
- Establishing, exercising, or defending claims
We consider the nature of the information, the purposes of processing, the risks to individuals, and reasonable expectations when relying on legitimate interests.
5.4 Consent
We may rely on consent for:
- Non-essential cookies or tracking technologies where required
- Optional marketing communications
- Specific information you voluntarily choose to provide
- Other processing for which consent is legally required
You may withdraw consent at any time. Withdrawal does not affect processing that occurred before withdrawal.
5.5 Legal obligations
We may process information when necessary to comply with applicable law, court orders, regulatory requirements, tax obligations, or valid legal process.
5.6 Protection of vital interests
In rare situations, we may process information where necessary to protect a person’s life or physical safety.
6. When we disclose personal information
We may disclose personal information to the following categories of recipients.
6.1 Authorized Nurvia personnel
Authorized founders, employees, contractors, advisors, and administrators may access personal information when necessary to:
- Operate the Data Room
- Review recipient engagement
- Manage a potential transaction
- Respond to questions
- Investigate security activity
- Enforce agreements
- Maintain legal and business records
Access should be limited to people with a legitimate need to know.
6.2 Service providers and contractors
We may disclose information to providers supporting:
- Cloud hosting
- Content delivery
- Database services
- Authentication
- Email delivery
- Electronic signatures
- Security monitoring
- Session replay
- Product analytics
- Error monitoring
- Customer support
- Communication services
- Document processing
- Legal compliance
- Backup and storage
- IT administration
These providers may process personal information only as needed to perform services for Nurvia, subject to contractual and legal obligations.
6.3 Professional advisors
We may disclose information to:
- Attorneys
- Accountants
- Auditors
- Insurers
- Bankers
- Financial advisors
- Security consultants
- Other professional advisors
Disclosure is limited to what is reasonably necessary for their services.
6.4 Business-transaction participants
Information may be disclosed to prospective or actual investors, lenders, purchasers, successors, or transaction advisors in connection with a corporate transaction, subject to appropriate confidentiality protections where applicable.
6.5 Legal and regulatory recipients
We may disclose information when we believe in good faith that disclosure is reasonably necessary to:
- Comply with law
- Respond to a subpoena, court order, or compulsory request
- Respond to a regulator
- Investigate unlawful activity
- Protect a person’s safety
- Prevent fraud
- Protect Nurvia’s rights or property
- Enforce an agreement
- Defend against a legal claim
Where legally permitted and appropriate, we may provide notice before disclosing information in response to compulsory legal process.
6.6 At your direction or with your consent
We may disclose information when you direct us to do so or provide consent.
7. Sale, sharing, targeted advertising, and profiling
Nurvia does not sell personal information collected through the Data Room in exchange for money.
Nurvia does not share Data Room personal information for cross-context behavioral advertising.
Nurvia does not use Data Room activity to serve targeted advertisements on unrelated websites or services.
Nurvia does not knowingly sell or share the personal information of people under 16.
We may disclose personal information to service providers and contractors for the business purposes described in this Privacy Policy. Such disclosures are not treated as sales when the provider is contractually restricted from using the information for unrelated purposes.
We do not use sensitive personal information collected through the Data Room to infer characteristics about you.
8. Information visible to Data Room administrators
Authorized Nurvia administrators may be able to view:
- Your name and email address
- Your organization and role
- When you received or opened an invitation
- Your access status
- Your approximate location
- IP address
- Device and browser information
- Documents and pages viewed
- Viewing duration
- Number of visits
- Viewing order
- Completion status
- Links selected
- Session and security events
- Watermark identifiers
- Agreement and signature status
- Session-replay information, when enabled
You should assume that activity performed inside the Data Room is visible to Nurvia.
9. Data retention
We retain personal information only for as long as reasonably necessary for the purposes described in this Privacy Policy, subject to legal, contractual, security, and recordkeeping requirements.
Our typical retention periods are:
Identity, invitation, and access records
Generally retained for up to three years after your last Data Room access.
Document-viewing and engagement analytics
Generally retained for up to three years after your last Data Room access.
Session-replay records
Generally retained for up to 24 months after collection, unless a shorter period is configured.
Security and forensic records
Generally retained for up to three years after collection.
Records associated with a suspected breach, unauthorized disclosure, legal dispute, or investigation may be retained until the matter is fully resolved and any applicable limitation period has expired.
Watermark attribution records
Generally retained for up to five years after your last Data Room access, or longer when necessary to protect confidential information or enforce a continuing confidentiality obligation.
Signed agreements and electronic-signature audit trails
Generally retained for the duration of the agreement and for up to seven years after its termination or expiration.
Agreements may be retained longer when required by law or reasonably necessary to establish or defend legal rights.
Communications and support records
Generally retained for up to three years after the communication or completion of the relevant relationship.
Cookies and similar identifiers
Retained for the duration stated in the applicable cookie or technology configuration, generally no longer than 13 months, unless a shorter or longer period is required for security or legal compliance.
Privacy-request records
Generally retained for up to two years after the request is completed to demonstrate compliance and prevent unauthorized disclosures.
We may retain information longer when necessary to:
- Comply with law
- Resolve disputes
- Enforce agreements
- Investigate security incidents
- Establish or defend legal claims
- Preserve evidence
- Fulfill a continuing confidentiality obligation
When information is no longer required, we may delete, aggregate, or de-identify it.
De-identified information may be retained for research, analytics, security, and statistical purposes when it cannot reasonably be linked back to an individual.
10. Security
We use administrative, technical, and organizational safeguards designed to protect personal information from:
- Unauthorized access
- Unauthorized disclosure
- Loss
- Misuse
- Alteration
- Destruction
These safeguards may include:
- Access controls
- Authentication
- Permission management
- Encrypted connections
- Logging
- Monitoring
- Watermarking
- Limited employee access
- Service-provider controls
- Incident-response procedures
- Backup and recovery measures
No online service, transmission method, or storage system is completely secure. We cannot guarantee absolute security.
You are responsible for protecting your device, email account, passwords, verification codes, and Data Room access links.
Please notify legal@nurvia.app promptly if you believe that:
- Your access link has been shared
- Your credentials have been compromised
- Someone accessed the Data Room through your identity
- Personal information has been exposed
- A security vulnerability may exist
11. International transfers
Nurvia is based in the United States.
Your personal information may be processed in the United States and in other countries where Nurvia or its service providers operate.
These countries may have privacy laws that differ from those in your jurisdiction.
When legally required, we may use safeguards such as:
- Standard contractual clauses
- Contractual data-protection obligations
- Adequacy decisions
- Transfer assessments
- Other legally recognized transfer mechanisms
You may contact us for additional information about applicable transfer safeguards.
12. Your privacy rights
Your rights depend on where you live and the laws that apply to Nurvia’s processing.
Subject to applicable law, you may have the right to:
- Confirm whether we process your personal information
- Access personal information we maintain about you
- Receive information about the categories and sources of personal information
- Receive information about why we process or disclose personal information
- Correct inaccurate personal information
- Request deletion
- Obtain a portable copy of certain personal information
- Object to certain processing
- Restrict certain processing
- Withdraw consent
- Opt out of sale, sharing, targeted advertising, or certain profiling
- Limit certain uses of sensitive personal information
- Appeal the denial of a privacy request
- Lodge a complaint with a privacy or data-protection authority
- Receive equal service without unlawful discrimination for exercising a privacy right
These rights are subject to exceptions.
For example, we may retain information when reasonably necessary to:
- Complete a transaction
- Provide requested access
- Detect security incidents
- Prevent fraud
- Exercise free-speech rights
- Comply with law
- Maintain signed agreements
- Establish, exercise, or defend legal claims
- Enforce confidentiality obligations
- Investigate an unauthorized disclosure
- Maintain internal records permitted by law
13. How to exercise your rights
Submit a privacy request to legal@nurvia.app using the subject line “Privacy Request.”
Please include:
- Your full name
- The email address used to access the Data Room
- Your organization, when applicable
- The right you wish to exercise
- Sufficient information for us to locate your records
We may request additional information to verify your identity.
Verification helps prevent personal information from being disclosed to an unauthorized person.
We will not request more verification information than reasonably necessary.
Where permitted, an authorized agent may submit a request on your behalf. We may require proof that the agent is authorized and may ask you to verify your identity directly.
We will respond within the period required by applicable law.
We may deny or limit a request when legally permitted. When applicable, we will explain the reason for the denial.
Appeals
When applicable law provides a right to appeal, you may appeal a denied request by replying to our decision and using the subject line “Privacy Request Appeal.”
We will review the appeal and respond within the period required by law.
14. Additional information for California residents
This section applies to personal information subject to the California Consumer Privacy Act, referred to as the “CCPA.”
14.1 Categories collected during the preceding 12 months
Depending on your interaction with the Data Room, we may have collected:
Identifiers
Examples include name, email address, IP address, account identifier, access-link identifier, authentication information, and electronic-signature records.
Personal information described by California Civil Code Section 1798.80
Examples may include name, address, telephone number, employment information, and electronic signature.
Commercial and professional information
Examples include your organization, job title, professional relationship, investment interest, diligence activity, and potential transaction information.
Internet or electronic-network activity
Examples include browsing activity, document views, pages viewed, clicks, scrolling, pointer movement, session duration, session replay, and security events.
Geolocation information
This generally consists of approximate location inferred from your IP address.
Audio, electronic, visual, or similar information
This may include signature images, uploaded materials, communications, video engagement information, and session-replay representations.
Professional or employment-related information
Examples include your company, professional role, title, and business relationship.
Inferences
We may infer a recipient’s general level of engagement or interest based on Data Room activity.
We do not use those inferences for cross-context behavioral advertising.
Sensitive personal information
Depending on how the Data Room is configured, this may include account login credentials or information used to authenticate access.
We use sensitive personal information only for providing and securing the Data Room, authenticating recipients, preventing misuse, and other legally permitted purposes.
14.2 Sources
We collect these categories from:
- You
- The person or organization inviting you
- Your device and browser
- Nurvia systems
- Service providers
- Limited public professional sources
14.3 Purposes
We use these categories to:
- Provide access
- Authenticate users
- Protect confidential information
- Measure document engagement
- Administer electronic agreements
- Communicate with recipients
- Prevent fraud and security incidents
- Improve the Data Room
- Comply with law
- Establish and defend legal rights
14.4 Categories disclosed for business purposes
We may disclose the categories described above to:
- Cloud and infrastructure providers
- Authentication providers
- Security providers
- Analytics and session-replay providers
- Electronic-signature providers
- Email and communication providers
- Professional advisors
- Other contractors providing services to Nurvia
14.5 Sale and sharing
During the preceding 12 months, Nurvia has not sold personal information collected through the Data Room.
During the preceding 12 months, Nurvia has not shared Data Room personal information for cross-context behavioral advertising.
14.6 California rights
Subject to applicable exceptions, California residents may have the right to:
- Know the categories and specific pieces of personal information collected
- Know the categories of sources
- Know the purposes for collection, use, or disclosure
- Know the categories of recipients
- Delete personal information
- Correct inaccurate personal information
- Opt out of sale or sharing
- Limit certain uses of sensitive personal information
- Receive equal treatment when exercising privacy rights
Because Nurvia does not sell or share Data Room personal information for cross-context behavioral advertising, an opt-out of sale or sharing is not ordinarily necessary for Data Room processing.
We do not use sensitive personal information for purposes that require a separate right-to-limit mechanism, unless otherwise disclosed at collection.
15. Additional information for people in the EEA, United Kingdom, and Switzerland
Subject to applicable law, you may have the right to:
- Access your personal information
- Correct inaccurate information
- Request erasure
- Restrict processing
- Object to processing based on legitimate interests
- Object to direct marketing
- Receive certain information in a portable format
- Withdraw consent
- Lodge a complaint with a supervisory authority
Where we rely on legitimate interests, you may object based on circumstances particular to you.
We may continue processing when we demonstrate compelling legitimate grounds or when processing is necessary for legal claims.
You may lodge a complaint with the data-protection authority in the country where you live or work, or where you believe an infringement occurred.
16. Marketing communications
We may send administrative communications concerning:
- Data Room access
- Security
- Agreements
- Privacy
- Meetings
- Requested information
- A potential relationship or transaction
These communications are not marketing and may continue while your access or relationship remains active.
We may send promotional communications only where legally permitted.
You may opt out of promotional email by using the unsubscribe mechanism provided or by contacting legal@nurvia.app.
Opting out of marketing does not prevent us from sending necessary administrative, transactional, legal, or security communications.
17. Third-party services and links
The Data Room may contain links to websites or services that Nurvia does not control.
This Privacy Policy does not govern information collected independently by those third parties.
Please review the privacy policy of a third-party service before providing personal information to it.
18. Children
The Data Room is intended for business and professional recipients who are at least 18 years old.
We do not knowingly provide Data Room access to children or knowingly collect personal information from children through the Data Room.
Contact us if you believe a child has provided personal information through the Data Room.
19. Automated decision-making
Nurvia may use automated tools to:
- Detect unusual access patterns
- Flag potential credential sharing
- Identify possible security events
- Restrict suspicious sessions
- Generate engagement summaries
- Apply access rules
These tools may inform a human review.
Nurvia does not intend to use Data Room activity in a solely automated process that produces legal or similarly significant effects concerning an individual.
A Data Room administrator may manually suspend or revoke access based on security information, contractual rights, or the status of a potential relationship.
20. Changes to this Privacy Policy
We may update this Privacy Policy to reflect:
- Changes to the Data Room
- New security or analytics features
- Changes to our service providers
- Legal requirements
- Operational changes
- Clarifications to our practices
The updated policy will state its effective date.
When a change materially affects how we process personal information, we may provide notice through the Data Room, by email, or before you next access Materials.
21. Contact us
Questions, requests, or complaints concerning this Privacy Policy may be sent to:
Nurvia Inc.
Attention: Privacy
813 Mission Street
San Francisco, California 94103
United States
Email: legal@nurvia.app