Privacy Policy

Effective date: May 6, 2026  ·  Last updated: May 6, 2026

This Privacy Policy explains how NivasaPro Inc. collects, uses, shares, and protects information about you when you use the NivasaPro platform and Niva AI assistant. Please read it carefully.

1. Who We Are

NivasaPro Inc. ("NivasaPro", "we", "us", or "our") operates the NivasaPro property management platform, including the Niva AI assistant, available at https://www.nivasapro.ai and associated mobile and API interfaces (the "Service").

NivasaPro acts as the data controller for personal information collected through the Service. For questions about this policy or your data, contact us at privacy@nivasapro.ai.

2. Information We Collect

2.1 Information You Provide Directly

  • Account information — name, email address, password, and user type (landlord or tenant) when you register.
  • Property and portfolio data — property addresses, unit details, and related management information you enter.
  • Tenant information — names, contact details, and lease information for tenants you add to your portfolio.
  • Maintenance records — descriptions of issues, photographs, communications with service providers, and repair histories.
  • Financial data — rent amounts, payment records, cost entries, and expense details you record in the platform.
  • Communications — messages you send to Niva, support tickets, and any other correspondence with us.
  • ROMI Assessment responses — if you take the free NivasaPro ROMI Score™ assessment, we collect your conversational responses, name, and email address.

2.2 Information Collected Automatically

  • Usage data — pages visited, features used, session duration, click patterns, and navigation paths.
  • Device and technical data — IP address, browser type and version, operating system, device identifiers, and time zone.
  • Log data — server logs recording requests to our API, including timestamps and response codes.
  • Cookies and similar technologies — see Section 7 for details.

2.3 Information from Third Parties

  • Communication providers — if you interact with Niva via SMS or WhatsApp, we receive your phone number and message content from Twilio.
  • Payment processors — if you subscribe to a paid plan, our payment processor (Stripe) handles payment card data. We receive only limited transaction metadata; we do not store full card numbers.

3. How We Use Your Information

We use the information we collect to:

  • Provide, operate, and improve the NivasaPro platform and Niva AI assistant.
  • Process and respond to maintenance requests, approvals, and tenant communications on your behalf.
  • Send transactional emails such as maintenance approval requests, repair notifications, rent reminders, and account alerts via Mailgun.
  • Generate AI-powered insights, summaries, triage assessments, and the ROMI Score™ report.
  • Authenticate users and maintain account security using JSON Web Tokens (JWT).
  • Analyse usage patterns to improve product features and fix bugs.
  • Comply with legal obligations and enforce our Terms of Service.
  • Communicate with you about product updates, new features, and relevant content (you may opt out at any time).
  • Respond to ROMI Score™ assessment leads and send the personalised report to the email address you provide.

We do not sell your personal information to third parties. We do not use your property or tenant data to train AI models without explicit consent.

5. Sharing and Disclosure

We share your information only in the following circumstances:

5.1 Service Providers

We work with trusted third-party vendors who process data on our behalf under strict data processing agreements:

  • MongoDB Atlas — database hosting and storage.
  • Google Cloud / Firebase — application hosting and frontend delivery.
  • Mailgun — transactional email delivery.
  • Twilio — SMS and WhatsApp message routing.
  • Stripe — payment processing.
  • Anthropic / Google DeepMind — AI language model inference for Niva and the ROMI Assessment. Conversation content is sent to these providers solely to generate responses.
  • Cloudflare — bot protection and CDN.

5.2 Legal Requirements

We may disclose information where required by law, court order, or governmental authority, or where necessary to protect the rights, property, or safety of NivasaPro, our users, or the public.

5.3 Business Transfers

If NivasaPro is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you before your personal information is transferred and becomes subject to a different privacy policy.

5.4 With Your Consent

We may share information in other circumstances with your explicit consent.

6. AI and Automated Processing

NivasaPro uses AI language models (currently Claude by Anthropic and Gemini by Google) to power the Niva assistant and the ROMI Score™ assessment. When you interact with Niva, your messages and relevant context (property details, maintenance history) are sent to the AI provider to generate a response.

What this means for your data:

  • Conversation content is transmitted to AI providers for the sole purpose of generating responses.
  • We configure these providers under zero-data-retention policies where available, meaning conversation content is not used to train their models.
  • AI-generated outputs (maintenance summaries, triage assessments, ROMI scores) are stored in your account and may be seen by other authorised users of your organisation.
  • Automated decisions made by Niva (such as maintenance priority classification) can be reviewed, overridden, or appealed by contacting support.

No automated decision made by Niva produces legal or similarly significant effects without human review.

7. Cookies and Tracking Technologies

We use the following types of cookies and similar technologies:

  • Strictly necessary cookies — required for authentication (JWT session management) and security. These cannot be disabled.
  • Functional cookies — remember your preferences such as theme and language settings.
  • Analytics cookies — help us understand how the Service is used (e.g., page views, feature engagement). We use privacy-respecting analytics and do not share this data with advertising networks.
  • Bot protection — Cloudflare Turnstile is used on public forms to distinguish humans from automated bots. Turnstile may set cookies or use browser signals for this purpose.

You can control non-essential cookies through your browser settings. Disabling strictly necessary cookies will impair your ability to use the Service.

8. Data Retention

We retain your personal information for as long as your account is active or as needed to provide the Service. Specifically:

  • Account data — retained for the duration of your account plus 30 days after deletion to allow recovery.
  • Maintenance and financial records — retained for 7 years to support legal and tax obligations, unless you request earlier deletion.
  • AI conversation transcripts — retained for 12 months, then anonymised or deleted.
  • ROMI Assessment data — retained for 24 months from the date of assessment. You may request deletion at any time.
  • Server logs — retained for 90 days.
  • Marketing preferences — retained until you unsubscribe or request deletion.

When retention periods expire, data is securely deleted or anonymised so it can no longer be associated with you.

9. Security

We implement industry-standard technical and organisational measures to protect your personal information, including:

  • Encryption in transit (TLS 1.2+) for all data transmitted between your browser and our servers.
  • Encrypted storage for sensitive fields including passwords (bcrypt hashing) and API keys.
  • JWT-based authentication with short-lived tokens and secure signing secrets.
  • Role-based access controls limiting data access to authorised personnel.
  • Regular dependency updates and security patching.
  • MongoDB Atlas security features including network isolation and encryption at rest.

No method of transmission or storage is 100% secure. If you suspect a security incident, please contact us immediately at privacy@nivasapro.ai.

10. Your Privacy Rights

10.1 Rights under GDPR (EEA / UK users)

If you are located in the EEA or UK, you have the right to:

  • Access — request a copy of the personal data we hold about you.
  • Rectification — ask us to correct inaccurate or incomplete data.
  • Erasure — request deletion of your personal data ("right to be forgotten"), subject to legal retention requirements.
  • Restriction — ask us to limit processing of your data in certain circumstances.
  • Portability — receive your data in a structured, machine-readable format.
  • Objection — object to processing based on legitimate interests or for direct marketing.
  • Withdraw consent — where processing is based on consent, withdraw it at any time.

To exercise these rights, email dpo@nivasapro.ai. We will respond within 30 days. You also have the right to lodge a complaint with your local supervisory authority.

10.2 Rights under CCPA (California residents)

If you are a California resident, you have the right to:

  • Know what personal information we collect, use, disclose, and sell.
  • Delete personal information we have collected, subject to exceptions.
  • Opt out of the sale of personal information — we do not sell personal information.
  • Non-discrimination for exercising your privacy rights.

To exercise CCPA rights, email privacy@nivasapro.ai with the subject line "CCPA Request".

10.3 Email and Marketing Opt-Out

You may unsubscribe from marketing emails at any time by clicking the unsubscribe link in any email we send or by contacting privacy@nivasapro.ai. Transactional emails (maintenance alerts, approval requests, rent reminders) are necessary for the Service and cannot be disabled while your account is active.

11. Children's Privacy

The Service is not directed at children under 18 years of age. We do not knowingly collect personal information from anyone under 18. If you believe we have inadvertently collected such information, please contact us at privacy@nivasapro.ai and we will delete it promptly.

12. International Data Transfers

NivasaPro is operated primarily from the United States. If you access the Service from outside the United States, your information may be transferred to and processed in the United States or other countries where our service providers operate.

For transfers from the EEA or UK to the United States, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission, and/or the UK International Data Transfer Addendum, to ensure an adequate level of protection.

13. Third-Party Links and Services

The Service may contain links to third-party websites or integrations. This Privacy Policy does not apply to those third-party services. We encourage you to review the privacy policies of any third-party services you access through NivasaPro. We are not responsible for the privacy practices of third parties.

14. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:

  • Update the "Effective date" at the top of this page.
  • Notify registered users by email or in-app notification at least 14 days before the changes take effect.
  • For significant changes affecting how we process data you have already provided, seek your consent where required by law.

Continued use of the Service after the effective date constitutes acceptance of the revised policy. If you do not agree, you should delete your account before the changes take effect.

15. Contact Us

For privacy-related questions, requests, or concerns, please contact us at:

NivasaPro Inc.

Privacy Enquiries: privacy@nivasapro.ai

Data Protection Officer: dpo@nivasapro.ai

Website: https://www.nivasapro.ai

We aim to respond to all privacy requests within 30 days. For urgent security concerns, please mark your subject line "URGENT — Security".