Privacy Notice
Last updated 2026-07-10
Controller
Gnosova (Jason Boeglen, Founder & Principal Architect) is the controller for personal data processed through this site and the client portal. Privacy and data-subject requests: support@gnosova.com. Security contact: support@gnosova.com.
What we collect and why
We process the fields below to operate accounts, deliver client services, and keep the platform secure. The lawful basis is performance of our contract with you and our legitimate interest in operating and securing the service; email marketing (newsletter) is processed on consent, which you may withdraw at any time.
| Field | Purpose | Provider | Sensitivity | Retention |
|---|---|---|---|---|
| name | Account identity and portal personalization | Neon (Postgres) | Personal | Life of account; erased on deletion |
| Authentication, login, transactional email | Neon (Postgres), Resend (email) | Personal | Life of account; erased on deletion | |
| password (bcrypt hash) | Credential authentication | Neon (Postgres) | Secret (one-way hashed) | Life of account; erased on deletion |
| company | Client/project association | Neon (Postgres) | Personal | Life of account; erased on deletion |
| role | Authorization / access scope | Neon (Postgres) | Internal | Life of account; erased on deletion |
| OAuth provider metadata (accounts) | Federated sign-in (Google) | Neon (Postgres), Google | Secret (tokens) | Life of account; erased on deletion (cascade) |
| session tokens | Maintaining an authenticated session | Neon (Postgres) | Secret | Until expiry; erased on deletion (cascade) |
| error / performance telemetry | Reliability and security monitoring | Sentry, Vercel Analytics | Internal (scrubbed of PII) | Provider default rolling window (~90 days) |
Retention
Account data is retained for the life of your account and erased when you delete your account, unless a legal or financial hold requires us to preserve specific records for a defined period. Session and OAuth tokens are removed automatically on expiry or account deletion. Operational telemetry (error and performance logs) is scrubbed of personal data and expires on our providers’ rolling retention windows.
Subprocessors
We share data with the following processors solely to deliver the service. Each is bound to process data only on our instructions.
- Vercel — Application hosting and analytics (US)
- Neon — Managed Postgres database (US)
- Google — OAuth federated sign-in (US)
- Resend — Transactional and newsletter email (US)
- Sentry — Error and performance monitoring (US/EU)
- Onomaco — Embedded forms and booking widgets (US)
Your rights
Signed-in users can export a machine-readable copy of their personal data, correct their details, and permanently delete their account from portal › account & data. You may also make any of these requests, including access or correction, by emailing support@gnosova.com. Deletion is propagated to our subprocessors; residual copies in encrypted backups age out on the backup rotation.
Client & project data
Data you provide about your organization and projects belongs to you. On offboarding we will, at your election, transfer an export of your project data and then delete it, subject to any legal or financial hold.