Privacy Policy — Nuveo VR
Effective date: 24 August 2026
This Privacy Policy describes how Nuveo s.r.o., with its registered office at Žižkovská 1377, 691 02 Velké Bílovice, Czech Republic, Company ID (IČO): 29663865, registered in the Commercial Register maintained by the Regional Court in Brno, file no. C 152365 ("Nuveo", "we"), processes personal data in connection with the Nuveo VR platform, which consists of:
- the web portal at portal.nuveo.cz, and
- the Nuveo VR application for Meta Quest headsets (the "App").
Nuveo VR is a business (B2B) tool for presenting 3D architectural visualizations of real properties. It is not a consumer application.
Contact for privacy matters: info@nuveo.cz, tel. +420 736 119 773
This is an English translation provided for convenience. In case of any discrepancy between language versions of this policy, the Czech version prevails.
1. Who we are and how accounts work
Nuveo is the data controller for the personal data described in this policy, except for client project content, where we act as a processor (see Section 7).
You cannot create an account yourself. Public registration is disabled; accounts are created by Nuveo or by an administrator of the client company you work with. For this reason, the App contains no sign-up flow and no self-service account deletion — see Section 10 for how to exercise your rights, including erasure.
The App and platform are developed and maintained for Nuveo by Virtual Lab, which acts as our processor and accesses production data to the extent necessary for the development, maintenance and support of the platform.
2. What personal data we process
a) Account and profile data: username, e-mail address, first and last name, phone number, professional specialization (architects), user role, assigned company (including its contact and billing details), link to a supervising teacher (university students), e-mail notification preferences, password (stored only as a cryptographic hash), password reset tokens, and the time of your last login (used for activity statistics).
b) Audit log: for every action performed on a project, we record who did what and when. The record does not store a copy of the user's name — it only references the user account, for no longer than 24 months; after that, the record is anonymized automatically. Anonymization ("Deleted user") also occurs earlier if the account is deleted. An anonymized record no longer contains any personal data.
c) Project data: project name and description, the locality of the property, the name of the client company (studio), and the name of the architect who processed the model. If you are an architect, your first and last name is displayed to other authorized users of the platform alongside the projects you worked on.
d) Project content: 2D documents (PDF, DWG, images) and 3D models uploaded by clients — see Section 7.
e) Billing data (web portal only): company name, contact e-mail, address, Company ID (IČO) and VAT ID (DIČ), processed when a client administrator manages a subscription. This data never passes through the VR App.
3. The VR App on your headset — what it does and does not do
Login. The App signs you in against Nuveo's own server, not through your Meta account. Your username or e-mail and your password are transmitted over an encrypted connection (HTTPS) to portal.nuveo.cz. The server issues a login token valid for 7 days. The token is stored on the headset and is deleted when you log out.
Downloaded content. 3D models and preview images are downloaded to the headset so they can be displayed. This cached content is deleted from the headset when you log out or when your login session expires.
Camera (Passthrough) and spatial data. The App uses the headset's camera passthrough and Meta's scene understanding features (MRUK) for exactly two purposes: to show you your physical surroundings and to read QR codes that open a specific project. Camera images and data about your physical environment are not stored, are not used for any other purpose, and are never transmitted from the device — our server has no interface capable of receiving them. A QR code itself contains only a reference to a project, no personal data.
Meta account. The App does not use the Meta Platform SDK and does not access your Meta account ID or profile. Meta acts solely as the distributor of the App through the Meta Horizon Store; any processing performed by Meta when you download or run apps is governed by Meta's own privacy policy.
No analytics or tracking. The App contains no analytics, no crash or error reporting, no advertising identifiers and no trackers, and it writes no log files to the device. The same applies to our server and web portal — the web portal stores your login token in your browser's localStorage and uses no tracking cookies.
4. Purposes and legal bases
| Purpose | Data used | Legal basis |
|---|---|---|
| Providing the platform and App, managing access by role | account and profile data | performance of a contract with the client company; in relation to individual users, legitimate interest in providing and securing the work tool |
| Activity overview | time of last login | legitimate interest in administering and securing the service |
| Traceability of work on projects | audit log | legitimate interest in the demonstrability of who worked on a project |
| Presenting projects to authorized users | project data incl. architect's name | legitimate interest / performance of contract |
| Sending notification e-mails | e-mail address, notification settings | performance of contract; preferences can be adjusted in the profile |
| Subscription billing (web only) | billing data | performance of contract and compliance with legal obligations |
We do not use personal data for advertising, profiling, or automated decision-making.
5. Recipients and processors
| Recipient | Purpose | Notes |
|---|---|---|
| Google Cloud (Google Ireland Ltd. / Google LLC) | hosting, database, file storage, processing pipeline | data stored in region europe-west4 (Netherlands, EU) |
| Google Workspace | sending notification e-mails (SMTP relay) | triggered by our server |
| Stripe | subscription payments | web portal only — never involved in the VR App |
| Solitea (iDoklad) | invoicing | web portal only |
| Meta Platforms | distribution of the App via Meta Horizon Store | Meta processes data as an independent controller under its own policy |
| Virtual Lab | development, maintenance and support of the platform | accesses production data to the extent necessary |
6. Where data is stored and transfers outside the EU
Our application server, database and file storage are located in the European Union (Netherlands, Google Cloud region europe-west4). Project files are stored in a non-public storage bucket; they can be accessed only through signed links valid for 60 minutes.
Some of our processors (Google, Stripe, Meta) may transfer limited data outside the European Economic Area as part of their global operations; such transfers are safeguarded by EU Standard Contractual Clauses and/or the EU–U.S. Data Privacy Framework.
7. Project content — our role as processor
Clients upload project materials to the platform (floor plans, technical documents, 3D models, property descriptions). If these materials contain personal data of third parties — for example the property owner's name on a floor plan — the client company is the controller of that data and Nuveo processes it on the client's behalf as a processor, under the service agreement with the client.
8. How long we keep data
We retain personal data only for as long as necessary for the purposes described in this policy:
- Account and profile data: for as long as the user account exists. When the cooperation with the client company ends, or at the client company's request, the account is deactivated; deactivated accounts are submitted to an administrator for review and deletion no later than 12 months after deactivation. Account data is deleted when the account is deleted.
- Audit log: a record remains linked to a specific user account for no longer than 24 months from the action, after which it is anonymized automatically; anonymization also occurs when the account is deleted. An anonymized record ("Deleted user") no longer contains personal data.
- Password setup and reset tokens: the link is valid for 60 minutes; unused tokens are automatically removed by a daily cleanup.
- Project content: for the duration of the contract with the client company, which decides on its storage and deletion (see Section 7).
- Billing records: for the periods required by tax and accounting legislation.
9. Security
All communication between the App, the web portal and the server is encrypted (HTTPS). The backend is not directly exposed to the internet, project files are accessible only through short-lived signed links, passwords are stored only as cryptographic hashes, and access to data is restricted by user role, enforced on the server.
10. Your rights
You have the right to access your personal data, to rectification, erasure, restriction of processing, data portability, and to object to processing based on legitimate interest.
To exercise your rights, contact us at info@nuveo.cz. We will respond within 30 days (this may be extended in complex cases, as permitted by the GDPR). Because accounts are created and administered centrally, account deletion is carried out by a Nuveo administrator, or — for brokers — by the administrator of their organization. If your account was created through your employer or contracting company, we may coordinate the handling of your request with them. After account deletion, audit log records are anonymized as described in Section 8.
You also have the right to lodge a complaint with a supervisory authority — in the Czech Republic, the Office for Personal Data Protection (Úřad pro ochranu osobních údajů, uoou.gov.cz), or the authority in your place of residence.
11. Children
Nuveo VR is a professional B2B tool. Accounts are created exclusively for adult professionals and adult university students. The platform is not intended for children and we do not knowingly process children's personal data.
12. Changes to this policy
The current version of this policy is always available at https://portal.nuveo.cz/privacy-policy. We will inform you of material changes through the web portal or by e-mail.