Tnuvia Privacy Policy
Version 1 · Effective 2026-07-23
Who we are
This policy is issued by TNUVIA ("Tnuvia", "we"), the provider of the Tnuvia platform for dental clinics. Our registered address is Tátra utca 5/D, 1136 Budapest, Hungary. For any privacy question, or to exercise your rights, contact our privacy team / Data Protection Officer at dpo@tnuvia.com. If you are a patient of a clinic that uses Tnuvia, the clinic — not Tnuvia — is the controller of your data; please see that clinic's own privacy notice.
Our two roles: controller and processor
Tnuvia acts as a data CONTROLLER for the data of our own customers — clinic staff accounts, authentication, billing and support records, and product-usage information we need to run and improve the service. For this data, we decide the purposes and means, and this policy governs it.
For PATIENT data that clinics collect through Tnuvia (booking requests, contact details, appointment preferences, chat interactions), Tnuvia acts only as a PROCESSOR on the clinic's documented instructions. The clinic is the controller. That processing is governed by our Data Processing Agreement (DPA), which sets out our obligations, the sub-processor list, and the safeguards for international transfers.
What we collect, why, and our lawful basis
Account and identity data (name, work email, hashed password, role) — to provide and secure the service; lawful basis: performance of our contract with the clinic. Billing and business-contact data — to administer the customer relationship; lawful basis: contract and our legitimate interests in running the business. Support communications — to answer requests; lawful basis: legitimate interests. Product-usage and diagnostic data — to keep the service reliable and to improve it; lawful basis: legitimate interests, balanced against your rights. Any optional marketing to business contacts is sent only on the basis of consent or a soft opt-in you can withdraw at any time.
Sub-processors
We use a small set of vetted service providers to run the platform: cloud hosting and database (infrastructure), Cloudflare (DNS, network security and delivery), Resend (transactional email), Twilio (SMS and WhatsApp), Google (calendar synchronisation where a clinic connects it), Gemini / HeyGen and similar providers (optional AI content generation), and monitoring/error-reporting tools. Each acts on our instructions under a data-processing contract. A current, maintained list of sub-processors — with purpose and processing location — is available on request from dpo@tnuvia.com; we notify clinics of material changes before a new sub-processor starts.
International transfers
We aim to process data within the European Economic Area (EEA) or the United States. Where a sub-processor processes data outside it, we rely on an appropriate transfer mechanism for that provider — an adequacy decision where one exists, otherwise the European Commission's Standard Contractual Clauses together with supplementary measures. The maintained sub-processor list records the location and transfer mechanism for each provider. For the US pilot clinic, data residency is configured to a US region; the mechanism relied on for any transfer is documented there.
How long we keep data
We keep account and product data for as long as the clinic's subscription is active, and delete or anonymise it within a defined period after termination, except where a longer period is required by law (for example, billing records for tax purposes). Support and communication logs are kept for a limited period. Patient data processed on a clinic's behalf is retained and deleted according to the clinic's instructions and the DPA; on termination we return or delete it as the clinic directs.
Your rights
Subject to applicable law, you have the right to access your data, to have it rectified or erased, to restrict or object to processing, to data portability, and to withdraw consent where processing is based on consent. To exercise any of these, contact dpo@tnuvia.com; we respond within the statutory period (generally one month). You may also lodge a complaint with your supervisory authority. If you are a patient, direct requests about your data to the clinic, which is the controller; we will assist the clinic in responding.
Security and data breaches
We apply technical and organisational measures appropriate to the risk (Article 32-style), including encryption in transit, hashed credentials, encryption of sensitive tokens at rest, access controls and tenant isolation, a content-security policy, rate limiting, and audit logging. No system is perfectly secure, but we work to protect your data. If a personal-data breach occurs, we will act without undue delay: where Tnuvia is the controller we notify the supervisory authority and, where required, affected individuals; where Tnuvia is a processor we notify the affected clinic so it can meet its own obligations.
Changes to this policy
We may update this policy as the service or the law evolves. Each version carries a version number and effective date, and previous versions remain retrievable. For material changes we notify clinics in advance by email or in the app, and where a change requires renewed acceptance we ask for it before continued use.