Privacy Policy
Last updated 20 August 2026 · EU General Data Protection Regulation (GDPR) · Suomeksi
This policy explains how the Novavalo service (novavalo.net) processes personal data. Novavalo is operated by Servixo Oy. We process personal data carefully, in accordance with the EU General Data Protection Regulation (GDPR), and we do not sell your data.
1. Data controller
2. What data we process and why
| Category | Examples | Purpose |
|---|---|---|
| Account data | Email, name, password hash, company name, subscription plan | Sign-in, account management, billing |
| Website content | Texts, images, page structure, settings, domain | Building, storing and publishing your website |
| Usage & log data | Actions in the service, IP address, browser (security logs) | Operating the service, security, abuse prevention |
| Payment data | Subscription tier, transaction identifier | Managing subscriptions (card details are NOT stored by us — they are handled by the payment provider) |
| Communications | Support messages, emails | Customer support |
| Google Search Console data (optional) | See section 5 | Search-visibility tracking, only when you connect your account yourself |
Legal basis: performance of a contract (providing the service), legitimate interest (developing the service and security), and consent where separately requested (e.g. connecting your Google account).
3. Cookies and analytics
For visitor analytics we use Umami, a privacy-friendly tool that does not set tracking cookies and does not build personal profiles. Technical cookies required for the service to work (e.g. a sign-in session) may be used. We do not use advertising trackers.
4. Service providers we may share data with
We use trusted subprocessors to operate the service. They process data only on our behalf and under our instructions:
- Microsoft Azure — cloud infrastructure (application, database, files, email)
- Anthropic (Claude) — AI that creates and edits website content
- Replicate and Black Forest Labs (Flux) — AI image and video generation
- Google (Gemini / Search Console API) — AI-visibility testing and (optional) search-visibility tracking
- Stripe and PayPal — payment processing (they handle card details; we never see them)
- Cloudflare — domain routing and protection
Data is processed primarily within the EU/EEA. If any data is transferred outside the EEA, the transfer relies on appropriate safeguards (e.g. the EU Standard Contractual Clauses).
5. Google user data (Search Console)
When you connect your Google account yourself for search-visibility tracking, we request read-only access to your Search Console data (scope webmasters.readonly). We never request write or delete permissions, and we never request access to your email or any other Google service.
- What we read: the search-performance data of the Search Console property you choose (search queries, impressions, clicks, positions, pages).
- How we use it: to show you your search-visibility trends, target-keyword positions, and AI suggestions for improving your content. The data is used only to provide this feature to you.
- Storage: the Google refresh token that enables access is stored strongly encrypted. Retrieved visibility data is stored as aggregates so we can show trends over time.
- No sharing: we do not share Google user data with third parties, and we do not use it for advertising, selling, profiling, or training AI/ML models.
- Deletion / revoke: you can disconnect at any time in the service settings, which deletes the stored token. You may also revoke access from your Google account security settings.
Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
6. Retention
We retain data for as long as your account exists and as required to provide the service. When you delete your account or a website, we delete the associated data (including website content, images and any Google token) within a reasonable time. Security logs and statutory accounting records are retained for the period required by the applicable retention obligation.
7. Your rights
Under the GDPR you have the right to access your data, rectify it, erase it, restrict or object to processing, and to data portability. You may also withdraw a consent you have given. Requests: support@servixo.net. You also have the right to lodge a complaint with a supervisory authority (in Finland, the Office of the Data Protection Ombudsman).
8. Security
We use appropriate technical and organisational safeguards: encrypted transport (HTTPS), password hashing, encryption of sensitive credentials (such as the Google token), access control and logging.
9. Changes and contact
We may update this policy as the service evolves. We will notify you of significant changes in the service or by email. Questions and data-protection requests: support@servixo.net.