Navinua

Legal

Privacy Policy

Last updated: 29 May 2026

Swiss nDSGGDPR-alignedEU Data ResidencyNo data selling

1. Controller Identity

The data controller for your personal data is:

Navinua
Switzerland
Email: privacy@navinua.com

2. Data We Collect

Account data: Email address, name, authentication provider (Google or email/password).

Questionnaire responses: Your answers to financial planning questions, including income ranges, asset categories, life goals, and behavioural indicators. We store these to generate your scores and recommendations.

Usage data: Pages visited, features used, session duration — collected via PostHog (EU Cloud, Frankfurt, Germany) for product analytics.

Payment data: Payment processing is handled entirely by Stripe, Inc. We do not store card numbers or bank details. We receive only a tokenised reference and transaction status.

Communications: Emails you send us and transactional emails we send you (via Resend).

3. Legal Basis for Processing

We process your data under the following legal bases:

  • Contract performance — to provide you with the service you signed up for (Art. 6(1)(b) GDPR / nDSG Art. 31)
  • Consent — for optional analytics and marketing communications
  • Legitimate interests — to improve the platform, prevent fraud, and maintain security
  • Legal obligation — to comply with Swiss and EU law where required

4. How We Use Your Data

  • To generate your Wealth Clarity Check score and module results
  • To provide AI-generated planning summaries (financial data is anonymised before processing — no CHF amounts or identifying details are sent to AI providers)
  • To process payments and manage your subscription
  • To deliver transactional emails (account confirmation, results, receipts)
  • To facilitate expert review requests
  • To analyse product usage and improve the Platform
  • Newsletter (with your explicit consent): if you sign up for the Navinua newsletter, we store your email address, the consent timestamp, and the confirmation of your double opt-in. We use it only to send the newsletter and any content you requested with it (such as a guide). Every issue contains a one-click unsubscribe link; unsubscribing never affects your account or any content you already received. Newsletter data of unsubscribed or never-confirmed addresses is deleted within 30 days.

5. Data Residency and Transfers

We are committed to keeping your data within the European Economic Area:

  • Infrastructure: Hosted on Vercel (global edge, data processed in EU)
  • Database: Supabase Postgres (eu-west-2, London, United Kingdom)
  • Analytics: PostHog EU Cloud (Frankfurt, Germany)
  • Email delivery: Resend (EU infrastructure)

Where third-party processors are located outside Switzerland/EEA, we ensure adequate safeguards via Standard Contractual Clauses (SCCs) or equivalent mechanisms under nDSG Art. 16.

AI processing: We use the Anthropic API for two purposes. For coaching and report narratives, identifying details are sanitised before any data leaves our servers. For the optional document upload feature, the document you upload is transmitted to the Anthropic API to extract the financial figures you then review and confirm — do not upload documents you do not want processed this way; entering the figures manually is always available as an alternative.

6. Data Retention

We retain your personal data for as long as your account is active. After account deletion:

  • Account data is deleted within 30 days
  • Questionnaire responses are deleted within 30 days
  • Transaction records are retained for 10 years as required by Swiss accounting law (CO Art. 958f)
  • Anonymised, aggregated analytics data may be retained indefinitely

7. Your Rights

Under Swiss nDSG and GDPR, you have the right to:

  • Access — request a copy of all personal data we hold about you
  • Rectification — correct inaccurate data
  • Erasure — request deletion of your data ("right to be forgotten")
  • Portability — receive your data in a machine-readable format
  • Restriction — limit how we process your data
  • Objection — object to processing based on legitimate interests
  • Withdraw consent — at any time, for consent-based processing

Exercise your rights via your account Settings page (Data Export / Delete Account) or by emailing privacy@navinua.com. We will respond within 30 days.

8. Cookies and Tracking

We use the following cookies and local storage:

  • Essential: Supabase authentication session cookies — required for login to function
  • Analytics (optional): PostHog — captures page views and feature usage. You can opt out via the cookie consent banner or your browser settings.

We do not use advertising or cross-site tracking cookies. We do not sell data to advertisers.

9. Security

We implement industry-standard security measures including:

  • TLS encryption for all data in transit
  • Row-Level Security (RLS) on all database tables — ensuring you can only access your own data
  • Signed URLs for all PDF reports (private storage)
  • Rate limiting on all API endpoints
  • Audit logging for sensitive data access

10. Children

The Platform is not directed at children under 18. We do not knowingly collect data from minors. If you believe a minor has created an account, contact us and we will delete it promptly.

11. Changes to This Policy

We may update this Privacy Policy. We will notify you of material changes by email or in-app notification with at least 14 days' notice before changes take effect.

12. Supervisory Authority

If you believe we are processing your data unlawfully, you have the right to lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC) at edoeb.admin.ch.

13. Contact

For any privacy-related questions or to exercise your rights: privacy@navinua.com

Terms of Service← Back to Navinua