Privacy Policy
Last updated: August 4, 2026
This policy describes what data Nyvel collects when your organization uses the Service, why we collect it, and the choices you have.
Who we are. Nyvel is operated by MB „Mobilus sprendimas" ("we", "us"), a small partnership registered in Lithuania, company code 304959201, registered at Pastogės g. 8, LT-45475 Kaunas, Lithuania. That company is the controller for the data described in section 2 as ours, and your processor for the rest. Questions, requests, or to exercise a right under section 8: support@nyvel.io.
1. Data we collect
- Account and team data. Your name and email address, provided through our sign-in provider (WorkOS) when you authenticate with Google or GitHub; your organization's name; and the team directory your organization's admins configure — memberships, invitations and role assignments.
- Device inventory and security posture. When you connect an MDM, we read the device information your MDM exposes for the devices you choose to observe: serial number, device name, model, OS version, tags and device-group membership, enrollment state, and the state of security settings (for example FileVault, firewall, Gatekeeper, System Integrity Protection, screen lock, and update status). We do not collect the contents of files, messages, browsing history, or geolocation from your devices. Where a device shows a location, that is the site or group label your MDM reports — not the device's whereabouts.
- MDM API credentials. Stored encrypted at rest and used only to read from your MDM. You can rotate or revoke them at any time.
- Billing data. Payments are processed by Stripe. We store your subscription state and invoicing identifiers; we never see or store full card numbers.
- Service logs. Standard operational logs (such as API requests and sync outcomes) used to run and secure the Service.
- Free Mac check submissions. If you use the free check on our website, we store the security-settings output you paste (which contains no serial number, device name, or other device identity — you can read exactly what the script prints before you run it), your answer to which MDM you use, a random browser identifier, and the resulting rating. The pasted output itself is kept only until your report is produced — at most 24 hours — after which we keep the individual setting values, unlinked from the paste, as statistics about how Mac fleets are typically configured. Records of a check are deleted or anonymized within 365 days.
- Requesting the PDF report subscribes you. When you enter an email address to receive the report, we store that address and treat it as your consent to receive product email from us about Nyvel. Every message we send you carries an unsubscribe link; using it stops all of it, immediately and permanently, and you can also write to support@nyvel.io to be removed.
Note that a device name set in your MDM often contains a person's name ("Anna's MacBook Pro"). We treat device names as personal data for that reason. Please do not put special categories of personal data — health, religion, and the other categories listed in Article 9 GDPR — into MDM device names or location fields, as the Service is not designed to handle them.
2. Our role: controller and processor
Which data-protection role we hold depends on the data:
- Account data — the role depends on the operation. We are an independent controller where we process business-contact and account information for contracting, billing, tax and accounting, fraud prevention, security of our own systems, legal compliance and our own service communications — this policy governs that processing. To the extent we process authorised-user identity, organization membership, invitations, role assignments or access configuration solely to provide the Service on your organization's instructions, we act as your processor, and our Data Processing Agreement covers that data alongside your fleet data.
- Device and evidence data — we are a processor acting on your organization's instructions. Your organization is the controller: you choose which MDMs to connect, which device groups are in scope, which devices are tracked, and which frameworks apply. We process that data only to provide the Service to you.
As your processor we are also limited by how the Service is built: it is read-only and agentless. We run no agent, daemon, or background process on your devices, and the MDM connectors have no ability to write to your MDM or to change any device setting. We observe and report; we never enforce.
To be precise about one thing, because it matters: some security settings are not exposed by MDM APIs at all. To read those, you deploy a short shell script to your Macs through your own MDM, as a custom command or job. We never install it, it runs only when your MDM runs it, it only reads settings, and you can read every line of it before you deploy it — the full source is shown to you in the app. If you choose not to deploy it, the Service still works; the checks that depend on it simply report as unknown rather than guessing.
If you need a Data Processing Agreement under Article 28 GDPR — most organizations do before connecting an MDM — request one at support@nyvel.io.
3. How we use data, and our legal bases
Solely to provide, secure, support, and improve the Service: rendering your compliance evidence, generating exports you request, sending alerts you subscribe to, billing, and responding to support requests. We do not sell personal data, and we do not use your fleet data for advertising. We do not use your data to train machine-learning models.
Where we act as controller, we rely on these legal bases under Article 6 GDPR:
- Performance of a contract (Art. 6(1)(b)) — creating and administering your account, providing the Service, and billing.
- Legitimate interests (Art. 6(1)(f)) — securing the Service, operational logging, preventing abuse, and improving the product. We balance these against your interests and use the least data that achieves the purpose.
- Legal obligation (Art. 6(1)(c)) — retaining invoicing and tax records.
Where we act as your processor, the legal basis for the processing is your organization's to determine, not ours.
4. Subprocessors
Where we act as your processor, our sub-processors are: WorkOS (authentication, and your team directory), Fly.io (API hosting), Neon, an affiliate of Databricks (database hosting), Cloudflare (web delivery, and storage of our encrypted database backups in a bucket pinned to the European Union), and Resend (invitation and alert email — alerts can include device names). Stripe (payments) processes billing data for us in our controller capacity, so it is a vendor of ours rather than a sub-processor of your data. Each processes only what its role requires.
The MDM platforms are your own systems rather than our subprocessors — you instruct us to read from them. Separately, if you configure a Slack or Telegram endpoint to receive compliance alerts, those alerts include device names, and sending them is a disclosure to a provider you chose.
5. International transfers
Your device and evidence data is stored in the European Union. Both our database (Neon) and our API (Fly.io) run in Frankfurt, Germany. Storage is not the whole picture, though, so to be clear about the rest: the providers of those two services are US companies, and our web layer runs on Cloudflare's global network, so pages are served from wherever you happen to be. Data at rest stays in the EU; serving and support access are not confined to it.
Some supporting providers process personal data outside the EEA — authentication, billing and transactional email in the United States, and content delivery on a global network. Where a provider processes personal data in a country without an EU adequacy decision, we rely on the European Commission's Standard Contractual Clauses as incorporated into that provider's data processing terms, together with the UK International Data Transfer Addendum for data subject to UK law. You can ask us which safeguard applies to a specific provider at support@nyvel.io.
6. Retention and deletion
Fleet and evidence data is retained while your organization's account is active — retaining history is the point of a compliance-evidence service. Disconnecting an MDM stops collection from it immediately.
When you delete your account or ask us to, we delete your organization's records from the live database within 30 days. Deletion is not instantaneous everywhere, and we would rather set out the tail than imply it does not exist: recoverable database history purges within 30 days, encrypted off-provider backups within 90 days, and operational logs at our hosting provider within 90 days. Complete erasure therefore completes within 90 days, except where law requires longer retention (for example invoicing records).
7. Security
MDM credentials are encrypted at rest with AES-256-GCM under a key held outside the database, access to production systems is restricted, and connections use TLS. No system is perfectly secure; if we learn of a breach affecting your data we will notify you without undue delay.
Our Security page sets this out in full — including data residency, key handling and rotation, access control, backup and a measured restore time, and a plain list of the assurances we do not yet have.
8. Your rights
Depending on where you are, you may have rights to access, correct, export, or delete personal data, and to object to or restrict processing. Contact support@nyvel.io and we will respond. If you are in the EU/EEA you may also lodge a complaint with your supervisory authority.
If your request concerns device or evidence data, we act as a processor for your organization, so we will refer you to your organization's administrator, who controls that data.
9. Cookies
We do not use advertising or cross-site tracking cookies. Our web analytics (Cloudflare Web Analytics) is cookieless. Every cookie set when you use the Service is either strictly necessary or stores a preference you chose, which is why you see no cookie consent banner. In full:
- wos-session (set by our authentication provider, WorkOS AuthKit) — keeps you signed in. Lasts for your session and is refreshed while you are active.
- wos-auth-verifier-… (WorkOS AuthKit) — secures the sign-in exchange with your identity provider, so the response cannot be substituted by anyone else. Short-lived, one per sign-in attempt.
- cf_clearance (set by Cloudflare, which delivers the site) — records that your browser passed an automated security check, so you are not challenged repeatedly. A security measure, not tracking; we do not use it to identify you.
- nyvel_org — remembers which organization you are viewing when you belong to more than one. Cleared when you change or leave an organization.
- nyvel_theme and nyvel_theme_resolved — remember your light/dark appearance preference so pages render correctly on first paint. 400 days.
- nyvel-oauth-provider — remembers which sign-in provider you chose so a retry uses the same one. 15 minutes.
- nyvel-invite-token — carries an invitation through sign-in so it can be accepted. 10 minutes.
10. Changes
We may update this policy as the Service evolves. For material changes we will give notice before they take effect. The "last updated" date above always reflects the current version.