At Nivoq we are committed to protecting your privacy and processing your personal data with full transparency, in compliance with Regulation (EU) 2016/679 — General Data Protection Regulation (GDPR) and Spanish data protection law.
Please read this policy carefully before using the application. If you have any questions, you can contact us at soporte@nivoq.app.
01Controller
Company name: Naranjo Sosa S.L.
Tax ID (CIF): B24763294
Registered office: Bravo Murillo 204, 3rd Floor Left, 28020 Madrid, Spain
Email: soporte@nivoq.app
Activity: Development and distribution of mobile applications for mountain sports
02Data
Nivoq only collects the data necessary to provide you with the service. Each category is detailed below:
2.1 Account data
- Email address: To create and manage your account, authenticate you, and send you communications related to the service.
- Username: To identify you within the app and in social features (optional public profile).
- Password: Stored exclusively as a secure hash (bcrypt). We never have access to your password in plain text.
Sign-up and sign-in may also be performed through external identity providers (Apple, Google). When you use Sign in with Apple, we only receive the data you authorize to share (opaque identifier, optional name, optional email, or Apple's anonymous relay address).
When you delete your account, Nivoq requests Apple to revoke the associated Sign In token. This process is best-effort: if revocation fails (for example, due to a temporary outage of Apple services), the deletion of your data in Nivoq is completed regardless, but the link between your Apple ID and the deleted account may remain registered in Apple's systems until its natural expiration. In that case, if you later attempt to register again on Nivoq using the same Apple ID, Apple may reuse the original identifier. If this happens and you want to create a completely new account, you can manually revoke access from Settings > Apple ID > Sign in with Apple on your Apple device.
2.2 GPS location data
- The app requests access to your location only while it is in active use (session tracking mode).
- Real-time location is shared with your group only if you explicitly toggle the "Share location" feature.
- Session location data is stored to generate your activity history and statistics.
- We never track your location in the background without explicit consent.
2.3 Physical activity data
- Ski session records: duration, distance, maximum/average speed, vertical drop, number of runs.
- GPS tracks as coordinates (latitude, longitude, altitude, timestamp).
- This data forms your activity history and is necessary for the core functionality of the app.
2.4 Anonymous usage data
- Technical information about the device (model, OS version) and about app usage (screens visited, features used).
- This data is collected in aggregated and anonymous form, with no possibility of being linked to an identified person.
- Its purpose is to improve performance and user experience.
03Legal basis
| Purpose | Data involved | Legal basis (GDPR) |
|---|---|---|
| Account management and authentication | Email, name, password | Performance of contract (Art. 6(1)(b)) |
| Recording and analysis of ski sessions | GPS, physical activity | Performance of contract (Art. 6(1)(b)) |
| Sharing location with the group | Real-time GPS | Explicit consent (Art. 6(1)(a)) |
| Service improvement (analytics) | Anonymous usage data | Legitimate interest (Art. 6(1)(f)) |
| Service communications | Performance of contract (Art. 6(1)(b)) |
04Retention
Personal data is retained only for as long as strictly necessary for each purpose:
- Account data: While the account is active. After deletion of the account, it is erased within a maximum of 30 days.
- Session history: Available to the user while the account is active. Can be deleted manually at any time from the app.
- Anonymous usage data: Up to 24 months in aggregated form.
- Backups: Erased within 90 days from the deletion of the account.
05Recipients
Nivoq does not sell or transfer your data to third parties. We share it only with the following service providers, acting as data processors:
- Cloud infrastructure services (server hosting): compliance with Art. 46 GDPR through Standard Contractual Clauses.
- Transactional email service: For account notifications.
We do not transfer data to countries outside the European Economic Area (EEA) without adequate safeguards.
06Your rights
As a data subject, you have the right to exercise the following rights at any time in relation to your personal data:
- Right of access: Obtain confirmation as to whether we process your data, and a copy of it.
- Right to rectification: Correct inaccurate or incomplete data.
- Right to erasure ("right to be forgotten"): Request the deletion of your data when it is no longer necessary.
- Right to restriction of processing: Request that we suspend processing in certain circumstances.
- Right to data portability: Receive your data in a structured, commonly used and machine-readable format (JSON/CSV).
- Right to object: Object to processing based on legitimate interest.
- Withdrawal of consent: Where processing is based on your consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, send an email to soporte@nivoq.app indicating the right you wish to exercise and attaching a copy of your national ID or other identification document. We will respond within a maximum of 30 days.
You may also lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos, AEPD), the competent supervisory authority, at www.aepd.es.
07Security
We apply appropriate technical and organizational measures to protect your data against unauthorized access, accidental loss or destruction, including:
- Encrypted transmission via HTTPS/TLS on all communications.
- Passwords stored with bcrypt hash.
- JWT session tokens with expiration.
- Server access restricted by multi-factor authentication.
- Encrypted backups with periodic rotation.
08Minors
Nivoq is not intended for children under 16 years of age. If you are under 16, you need the consent of your parent or legal guardian to use the app. If we become aware that we have collected data from a minor without appropriate consent, we will proceed to delete it immediately.
09Changes
We may update this privacy policy from time to time. We will notify you of relevant changes through in-app notification or email. The "last updated" date at the top of the document reflects the current version.
10Contact
For any query regarding this policy or the processing of your personal data, please contact us at:
Email: soporte@nivoq.app
Recommended subject: "Data protection – [your request]"