Nuubu Lavender PRIVACY POLICY (U.S.)

1. ABOUT THIS PRIVACY POLICY

In Short: This Policy explains how we handle your Personal Information. It helps you understand what we do with it and your privacy rights.

Welcome! This Privacy Policy (“Policy”) explains how WELLNOVA SOLUTIONS INC, trading as Nuubu Lavender brand and other Household brands (“Company”, “we”, “us”, or “our”) handles your Personal Information (“Personal Information” or “Data”) when you:

  • Besök våra försäljningswebbplatser (“Webbplats”);

  • Köp våra produkter eller tjänster (“Varor” eller “Tjänster”);

  • Annars interagera med oss (support, sociala medier, tävlingar, affiliateprogram osv.).

This Policy applies only if you are resident of United States and it outlines what Personal Information we collect, its purposes, how we use and share it, how long we retain it, your rights, and how we protect your Data. We are fully committed to process your Personal Information lawfully, fairly, and transparently in accordance with:

  • the California Consumer Privacy Act (CCPA/CPRA);

  • U.S. state privacy laws (e.g. VCDPA, CPA, CTDPA, UCPA);

If you do not agree with our practices, please refrain from using the Website, purchasing our Goods or Services or submitting your Data in any other way. This Policy is effective as of 19th of November 2025.. We may update this Policy occasionally all updates take effect upon publication, so we encourage you to review it regularly to stay informed.

2. WHO IS RESPONSIBLE FOR YOUR PERSONAL INFORMATION?

We are: WELLNOVA SOLUTIONS INC, your Personal data Controller

Vårt org.-nummer är: 001530076

Vår registrerade adress: 354 Downs Blvd, Suite 101A Franklin, TN 37064

Vår support-e-postadress: support@nuubu.com

We have appointed a Privacy Officer to oversee our Data protection obligations. You can contact the Privacy Officer directly at dpo@nuubu.com, or use any of the communication methods provided in Section 11 of this Policy.

3. CATEGORIES OF INFORMATION COLLECTED AND HOW IT IS USED

Kortfattat: Vi samlar i huvudsak endast in de uppgifter som behövs för att tillhandahålla våra varor eller tjänster och för att driva vår webbplats. Detta avsnitt förklarar varför vi samlar in dem och hur vi använder dem.

We only collect the Data we truly need – and only use it for clear, lawful reasons. Below, you’ll find a detailed list of the categories of information we collect, how we use it, and how long we keep it. This section also serves as our Notice at Collection under the California Privacy Rights Act (CPRA) and Summary of Processing for the 12 Months Preceding.

We may collect or process the following categories of information, depending on how you interact with us. More detailed information provided in tables below:

1. IDENTIFIERS & COMMERCIAL DATA

Purpose of collection / use

When you purchase Goods or Services via our Website, we process your Data to manage your order, arrange delivery, handle payments, send transactional communication and provide other related services (e.g., order confirmation, updates, returns, or refunds).

We also use Identifiers and Commercial Information to detect and prevent fraud, maintain security, provide customer service, and comply with legal obligations.

Category examples

Identifierings- och kontaktuppgifter: fullständigt namn, leveransadress, e-postadress, telefonnummer.

Teknisk information: IP-adress, språk, enhetstyp.

Commercial information: products purchased, order/return history, subscription status, cart data, feedback.

Data retention period

Order- och betalningsuppgifter sparas i 10 år i enlighet med juridiska, skatte- och redovisningsskyldigheter.

Sold or Shared for cross-context behavioral advertising?

No. We do not sell or share this information for cross-context behavioral advertising.

2. PAYMENT & FINANCIAL DATA

Purpose of collection / use

We process your Data when handling payments related to your orders, subscriptions, discounts, returns, chargebacks or refunds. This processing also includes the performance of tax obligations, such as issuing invoices, maintaining accounting records, and fulfilling other legal statutory requirements e.g. fraud detection, transaction security.

Category examples

Payment Information: Payment method/type, masked card digits, payment token, transaction amount/time, refund reasons; billing address; bank/IBAN (if used); customs data where required, invoices, VAT and other required accounting documentation.

Data retention period

Order- och betalningsuppgifter sparas i 10 år i enlighet med juridiska, skatte- och redovisningsskyldigheter.

Fraud logs retained for 5 years after transaction.

Sold or Shared for cross-context behavioral advertising?

No.

3. MARKETING & PREFERENCE DATA

Purpose of collection / use

We process your Personal Information to inform you about our Goods, Services, promotions, new features, or to request your feedback. This includes sending general or personalized marketing content (e.g., newsletters, promotional messages, surveys) via email, SMS, or phone calls.

When we send communications from the Company, they may include marketing information and offers about this brand and other brands operated by the Company (“Wellness brands”). We may tailor our marketing based on information we already maintain about you - such as your purchase history, browsing activity, or stated preferences - to make our offers more relevant. This practice is sometimes referred to as personalized or targeted marketing.

In compliance with the California Consumer Privacy Act (CCPA/CPRA) and other U.S. state privacy laws (VCDPA, CPA, CTDPA, UCPA), we send marketing communications only where permitted by law and provide clear options to opt-out at any time:
Email: We may send promotional or informational emails without prior consent, provided that each message clearly identifies the sender, includes our contact details, and offers a simple unsubscribe option.
SMS or phone calls: We only send marketing text messages or automated calls if you have given us express written consent (for example, by checking a box or signing up). However, we may contact you by phone or text about your existing order or product (e.g., delivery updates, support, or warranty reminders) without separate marketing consent, as these are considered transactional or service communications.

Remember! You have the right to object for direct marketing at any time, free of charge, by:

  • using the unsubscribe link in any email;
  • using the unsubscribe link on the “Thank You” page;
  • replying “STOP” or the specified keyword to an SMS;
  • informing our representative during a call to be added to our Do Not Call list; or
  • emailing us with your request.

Opting out will not affect important transactional or service-related messages (such as order confirmations, product updates, or safety notices).

Category examples

Kontaktuppgifter: fullständigt namn, e-postadress, telefonnummer, land

Loggar: loggar över insamling av samtycke (datum, metod, preferenser, information om avregistrering, begäran om att välja bort).

Uppgifter om marknadsföringsinteraktioner: information om hur du interagerar med vårt marknadsföringsmaterial, såsom leverans- och öppningsstatus för meddelanden, klick på länkar, deltagande i kampanjer, kommunikationspreferenser, avregistrerings- eller opt-out-åtgärder samt tidsstämplar för interaktioner.

Köp- och engagemangshistorik (i förekommande fall): information som härleds från dina tidigare transaktioner eller marknadsföringsinteraktioner, såsom köpta produkter, hänvisningskällor, använda länkar eller svar på kampanjer.

Teknisk information (för e-post- eller SMS-leverans): enhetstyp, IP-adress, land.

Data retention period

5 years from contact received date, unless you opt-out earlier.

Recordings of conversations - 6 months from the moment of creation.

The suppression lists may be kept longer to comply with legal requirements.

Sold or Shared for cross-context behavioral advertising?

Yes. We may share limited identifiers (for example, cookie IDs or advertising device IDs) with analytics and ad partners to measure the effectiveness of our campaigns and deliver advertising relevant to your interests. You can opt out of cross-context advertising through Your Privacy Choices link. Where required by law, we honor browser- or device-based opt-out signals, including Global Privacy Control (GPC).

We do not sell Personal Information for monetary consideration.

4. COMMUNICATION DATA

Purpose of collection / use

If you contact us by phone and/or in writing (via Live Chat, customer support, email, social media or otherwise), we will keep a record of the fact of your contact and the information you have provided to us, including your Personal Information, to properly process your request and respond to your question, request or complaint.

We use artificial intelligence (AI)-based tools (fully or semi-automated) to assist our customer support team. These tools are used for suggesting draft responses, guiding or answering calls before transfer to a human agent, transcribing and summarising conversations, and providing automated replies to frequently asked or trained questions.

Obs! Alla AI-genererade resultat granskas och valideras av mänsklig personal när beslut kan påverka dina rättigheter. Vi förlitar oss inte enbart på automatiserat beslutsfattande som medför rättsliga eller på liknande sätt betydande effekter. Vi använder inte dina uppgifter för att träna AI-modeller om de inte är fullständigt anonymiserade.

Category examples

Vid kontakt via telefonsamtal: namn, efternamn, mobiltelefonnummer, e-postadress, bostadsadress, köpuppgifter och annan information som krävs för att verifiera din identitet (om det behövs). Datum och tid för samtalet, samtalets längd och en inspelning av samtalet.

Kontakt via e-post eller via Livechat, kundsupport: namn, efternamn, mobiltelefonnummer, e-postadress, bostadsadress. Köpuppgifter och annan information som krävs för att verifiera din identitet (om det behövs). Andra uppgifter relaterade till den skriftliga förfrågan, bifogade dokument eller annat visuellt innehåll, all korrespondenshistorik.

Data retention period

Inspelningar av samtal – 6 månader från tidpunkten för skapandet.

Skriftlig kommunikation – 3 år efter att din förfrågan har avslutats.

Vi kan komma att lagra viss information under en längre period om vi är skyldiga att göra det enligt tillämplig lagstiftning eller på grund av berättigade intressen.

Sold or Shared for cross-context behavioral advertising?

No.

5. LEGAL CLAIMS DATA

Purpose of collection / use

We may process your Personal Information in case we become a party or concerned party in legal proceedings to which you are subject to, or we are statutorily required to collect and/or provide information about you in order to comply with the applicable law.

Also, in all cases where we suspect fraud, theft, unlawful reselling, misuse of marketing activities with our brand names, or other unlawful activities involving our Website, Company, brands and or services, we report such cases to the appropriate pre-trial investigation authorities (such as the police or prosecutor’s office).

Category examples

Detta omfattar all information som vi innehar om dig och som utgör en del av den rättsliga processen, t.ex. redovisnings- och ärendehandlingar, juridiska dokument, annan information som du tillhandahåller oss samt annan information som vi enligt lag är skyldiga att samla in och/eller lämna ut. Även inlagor, yrkanden och domstolsavgöranden.

Om fallet uppstår – information om brott och domar.

Data retention period

As long as the legal proceedings are going and 5 years from the date of entry into force of the court or authority's decision, or the date on which the legally binding decision is fully implemented.

Sold or Shared for cross-context behavioral advertising?

No.

6. INTERNET & NETWORK ACTIVITY DATA

Purpose of collection / use

När du besöker och surfar på vår webbplats behandlar vi vissa personuppgifter för statistiska, analytiska, marknadsförings- och prestationsövervakningsändamål. Detta hjälper oss att förbättra funktionaliteten, stabiliteten, säkerheten och den övergripande användarupplevelsen på vår webbplats.

Beroende på dina cookieinställningar och samtyckesval kan vi samla in olika typer av information via cookies och liknande spårningstekniker, med hjälp av betrodda verktyg såsom Google Analytics 4 eller andra auktoriserade analys- och marknadsföringsplattformar. Detaljerad information finns i vår Cookie Policy.

Category examples

Identifierare: IP-adress eller andra enhetsidentifierare;

Teknisk information: enhetstyp, webbläsartyp, språkinställningar, hårdvaru-/programvaruinställningar och konfigurationer, hänvisande URL:er (webbplatser som besökts före/efter);

Use information: pages visited on our Website, interactions, clicks, or session behavior, visit timestamps, session duration, selected interface or account preferences (if applicable).

Data retention period

För mer information om lagringstider för cookies, vänligen se vår Cookie Policy.

Sold or Shared for cross-context behavioral advertising?

Yes (ads/analytics). Opt-out via Your Privacy Choices link. Where required by law, we honor browser- or device-based opt-out signals, including Global Privacy Control (GPC).

7. VISUAL DATA

Purpose of collection / use

We process your Personal Information when you submit, create, or allow us to use content that features you for promotional purposes. This includes:

  • Användargenererat innehåll (UGC), såsom vittnesmål, recensioner, foton eller videor som du delar med oss direkt eller taggar oss i på sociala medier.

  • Deltagande i foto- eller videoinspelningar som organiseras av oss, där din bild, röst eller andra personliga identifierare kan användas i marknadsförings- eller reklamkampanjer.

Där det är tillämpligt kommer ett separat avtal om användning av bild eller innehåll att undertecknas före publicering eller spridning, eller så kommer samtycke att inhämtas via ett särskilt formulär.

Category examples

Identifierare: fullständigt namn, användarnamn eller profilnamn;

Medieinnehåll: foto-, video- eller ljudinspelningar

Deltagande: omdömen, recensioner eller annat innehåll som du tillhandahåller eller ger oss tillåtelse att använda, identifierare i sociala medier (taggar, omnämnanden, användarnamn), avtal om användning av bild eller marknadsföringsinnehåll (om tillämpligt), samtyckesloggar.

Data retention period

UGC och kampanjinnehåll: lagras i upp till 2 år från insamlings- eller samtyckesdatumet, om inte en kortare eller längre period anges eller samtycke återkallas.

Innehåll i reklamkampanjer – arkiveras i upp till 10 år för rättsliga, avtalsmässiga eller regelefterlevnadsändamål.

Sold or Shared for cross-context behavioral advertising?

No.

8. SENSITIVE PERSONAL INFORMATION (SPI)

Purpose of collection / use

We do not intentionally collect sensitive Personal Information such as health, biometric, or religious data.

However, certain information like payment details, government identifiers, or precise geolocation may be classified as SPI under specific stale law. We do not use or disclose Sensitive Personal Information to infer characteristics or for any non-exempt purpose. As a result, a “Limit the Use of My Sensitive Personal Information” control is not presented.

Category examples

Payment tokens, limited payment metadata, government identifiers.

Data retention period

Payment records are retained for 10 years. Tokens normally retained only as long as necessary to complete transactions and handle refunds or chargebacks, no longer than 2 years.

Sold or Shared for cross-context behavioral advertising?

No.

9. CONTEST & PROMOTIONAL DATA

Purpose of collection / use

We process your Personal Information when you participate in our contests, competitions, games, or events. This is done to manage your participation, communicate with you, and (where applicable) publish or promote the outcome of the activity.

Category examples

Identifierare: fullständigt namn, e-postadress, telefonnummer;

Deltagande: engagemang i sociala medier (kommentarer, delningar, ”gilla”-markeringar, ”följningar”, reaktioner), tävlingsbidrag, svar, utvärderingar/betyg, närvaro vid evenemang;

Medieinnehåll: inskickade eller tagna foton/videor, bild/röst i inspelning.

Data retention period

Contest participant data – retained for 1 year after the announcement of winners or as described in specific contest terms.

Sold or Shared for cross-context behavioral advertising?

No.

10. AFFILIATE & PARTNER DATA

Purpose of collection / use

When you participate in our Affiliate Program (e.g., promoting our Goods or Services via links, campaigns, or other agreed methods), we process your Personal Information to manage your participation, track referrals, calculate commissions, and make payments. We may also use your Data to communicate with you about affiliate program updates, compliance checks, complaints or performance reporting.

Category examples

Identifierare: namn, efternamn och kontaktuppgifter (e-postadress, telefonnummer), affiliate-kontots kontouppgifter/inloggningsuppgifter;

Betalnings- och faktureringsuppgifter: bankkonto eller andra betalningsidentifierare, fakturor;

Prestanda- och spårningsdata: hänvisningskoder, kampanjstatistik, genererade leads/försäljningar, IP-adress, cookies där så är tillämpligt;

Cookies: spårningsdata där så är tillämpligt (i enlighet med cookiepolicyn och lokala bestämmelser).

Data retention period

Uppgifter om affiliateprogrammet – lagras under hela din deltagandeperiod i programmet och i upp till 5 år efter avslut (för redovisnings-, juridiska och bedrägeriförebyggande ändamål).

Betalningsuppgifter – lagras i 10 år för att uppfylla finansiella och redovisningsrättsliga krav.

Affiliate-foton och -videor – enligt vad som avtalats i det specifika affiliate-programmet eller genom ömsesidig överenskommelse.

Sold or Shared for cross-context behavioral advertising?

Sometimes (attribution tools may rely on advertising identifiers/cookies). Opt-out via Your Privacy Choices link. Where required by law, we honor browser- or device-based opt-out signals, including Global Privacy Control (GPC).

11. SOCIAL MEDIA DATA

Purpose of collection / use

We manage our business profiles and accounts on various social networks. If you are interested in our Services and follow our profiles on social networks, participate in our games, promotions, share your photos with us or tag us in your photos, public posts, etc., we collect and use your Data, which we receive directly from you, when you are active in our accounts.

Please note that our accounts are integrated into social networking platforms (e.g. Facebook, Instagram, Linkedin, etc.) and therefore all social platform providers as independent data controllers have full access to collect your Personal Information. You can find detailed information on the data processing, purposes and scope of data use by each social networking platform in the privacy policy of the respective social network. Also if you want to exercise your rights in relation to data processed by social networks, it is more efficient to contact the controller of the social network directly.

Category examples

Identifierare: namn, efternamn och profilbild;

Offentliga interaktioner: gilla-markeringar, följningar, kommentarer, delningar

Deltagande: meddelanden som du skickar (innehåll, tidpunkt, bilagor, historik), aktivt deltagande i spel/evenemang, samt alla foton du skickar till oss eller taggar oss i.

Data retention period

The provider of the social network concerned shall set the time limits for the retention of data.

We recommend that you check the privacy policy of the social network concerned. We normally retain and don’t delete them unless you withdraw consent, request deletion, or the platform enforces earlier deletion.

Sold or Shared for cross-context behavioral advertising?

No.

Here are also few important things for you to know:

  • Automated tools and AI: We may use AI or other fully or semi-automated technologies to support service delivery (e.g., chatbots, ChatGPT, Gemini, AI tools providers and etc.), but we do not use automated decision-making that produces legal or similarly significant effects on you. All AI-assisted or automated responses are reviewed by humans when decisions could impact your rights.

  • Cross-Context: We may combine information from different sources (e.g., your Website activity, purchase history, and customer-service interactions) to improve your experience and our service.

  • We may “sell” or “share” Data: Under California law, a “sale” includes making Personal Information available to a third party for any form of value, not only for money, and “sharing” refers to disclosing Personal Information for cross-context behavioral advertising. We do not sell Personal Information for monetary consideration, but in some cases we share limited data - such as internet or network activity and inferences - with advertising and analytics partners to measure performance and deliver relevant ads. You can opt out at any time through our “Your Privacy Choices” link, and where required by law, we honor browser- or device-based opt-out signals (e.g., Global Privacy Control).

  • Children’s data: Our Website and Services are not intended for minors. We do not knowingly collect, sell, or share Personal Information of individuals under the age established by law. If we become aware of such a collection, we will delete the information promptly.

4. PERSONAL INFORMATION COLLECTION SOURCES

In Short: We get your Data directly from you, through your use of our Website, or from trusted third parties, public sources, etc. This helps us operate our business and stay in touch with you.

We collect Personal Information from the following categories of sources:

  • Directly from you: When you place an order, contact us for support or inquiries, complete forms or surveys, participate in contests or promotional campaigns, communicate with us by email, phone, chat, or social media, or otherwise use our Services.

  • Automatically via technology: When you visit or interact with our Website or other online platforms, we automatically collect certain Data, including identifiers and information regarding your activity using cookies, pixels, SDKs, log files, and similar technologies. We use these tools to improve functionality, enhance your experience, analyze usage patterns, and secure our systems.

  • From third parties, vendors, and service providers: We collaborate with carefully selected partners (e.g., payment processors, shipping carriers, analytics and marketing platforms, and customer-support providers). They may share limited Personal Information with us when they collect them during service.

  • From our affiliate and referral partners: If you follow a referral link, use a partner discount code, we may receive information that might contain your Personal Information.

  • From other Intra-Group companies (if applicable): Where necessary for internal administrative, service provision, or business development purposes, we may receive your Data from other entities within our corporate group.

  • From publicly available sources (if applicable): Where appropriate and permitted by law, we may collect Personal Information from public registers (e.g. company registries, professional association websites), official government databases, or social media profiles (e.g. LinkedIn), particularly in the context of business-to-business (B2B) communication, professional outreach or due diligence.

Note! This Policy does not govern the privacy practices of unaffiliated third parties that operate independently, such as external social networks, advertising providers, or linked websites. We encourage you to review their privacy policies to understand how they process your information.

5. CATEGORIES OF INFORMATION DISCLOSED & SHARED WITH THIRD PARTIES

In Short: We share your Data but only when necessary and with strong safeguards - always ensuring your privacy is protected.

We share your Personal Information when necessary, and with your privacy in mind.

We may share limited Data with trusted third parties to provide our Services, meet legal obligations, or support business daily operations. Whenever we do, we ensure that your Data is protected and handled responsibly. We may share your Data with:

  • Service Providers, Contractors: We engage with various service providers to support our business functions (e.g. IT support, hosting, payments, shipping, analytics, customer service, marketing, auditing, legal services, etc.). These providers may access only the Data required to perform their duties and are contractually prohibited from using it for any other purpose.

  • Intra-Group Companies: We may share your Data with other entities within our corporate group for internal administrative purposes, centralized services, or to provide integrated services. All intra-group transfers are covered by internal data-protection agreements ensuring consistent safeguards across all locations.

  • Advertising/ Analytics Partners or Third Parties: We may share limited Data with platforms that deliver marketing campaigns and analytics. Under California law, this type of disclosure may be considered “sharing” for cross-context behavioral advertising. You can opt out at any time by using our link placed at the bottom of the Website footer “Your Privacy Choices”.

  • Public or governmental authorities: In certain circumstances, your Data may be shared with third parties such as public authorities, law enforcements, courts, insurers, fraud prevention services agencies, independent service providers etc.

  • Other corporates or auditors: In the context of a potential or actual merger, acquisition, asset sale, or restructuring, we may disclose limited Data to potential investors, buyers, or their auditors, and advisors.

  • Andra tredje parter med ditt samtycke: När det krävs enligt lag delar vi endast dina uppgifter med tredje parter om du uttryckligen har gett oss ditt informerade, frivilliga samtycke.

6. PERSONAL INFORMATION RETENTION PERIODS

In Short: We keep your Data only as long as needed for legal, contractual, or Services-related purposes - then we delete or anonymize it securely.

Vi behåller dina uppgifter endast så länge som det är nödvändigt för att:

  • Uppfylla de ändamål för vilka de samlades in.

  • tillhandahålla våra varor eller tjänster

  • uppfylla rättsliga, regulatoriska eller avtalsenliga skyldigheter

  • Lösa tvister eller upprätthålla våra avtal.

Detaljerade lagringsperioder för varje ändamål med personuppgiftsbehandling anges i avsnitt 3 i denna policy. När den tillämpliga lagringsperioden har löpt ut kommer vi antingen att radera dina uppgifter på ett säkert sätt eller anonymisera dem irreversibelt inom en skälig tidsram, i enlighet med bästa branschpraxis och rättsliga krav.

7. SECURITY OF PERSONAL INFORMATION

Kortfattat: Vi använder starka tekniska och organisatoriska åtgärder för att hålla dina data säkra och arbetar kontinuerligt för att förhindra obehörig åtkomst och skydda din integritet.

We are committed to protecting your Data and take the security of your information seriously. We apply a combination of technical and organisational measures to prevent unauthorised access, accidental loss, misuse, alteration, or disclosure of Personal Information. These safeguards reflect the principles of privacy laws, including accountability, limiting collection, accuracy, openness, and safeguards:

  • Processing Personal Information fairly, lawfully, and transparently;

  • Limiting collection and retention to what is necessary;

  • Restricting access to authorized employees only;

  • Requiring service providers to meet strict security standards;

  • Providing regular privacy and security training to staff;

  • Conducting periodic internal and external audits;

  • Using encryption and other safeguards where sensitive information may be involved;

  • Performing regular Data backups and logging activity for security purposes;

  • Continuously monitoring our systems for threats and vulnerabilities;

  • Updating our processes as risks and technology evolve.

Note! Even with strong safeguards, no system or internet transmission is completely risk-free. To help protect yourself, use strong and unique passwords, keep them confidential, secure your devices, and be cautious with suspicious links. If a data breach occurs that poses a risk of significant harm, we will notify affected individuals and regulators as required by law.

8. INTERNATIONAL PERSONAL INFORMATION TRANSFERS

In Short: Sometimes we need to transfer your Personal Information outside your country or state, but only when necessary and always with strong legal safeguards to keep your Data protected.

Our Company works with partners and service providers around the world. This means your information may be transferred outside the United States - for example, to the EU, the UK, or other countries where our Intra-group companies or service providers are located.

Whenever we transfer Personal Information internationally, we apply appropriate contractual, organizational, and technical safeguards to ensure an equivalent level of protection consistent with the privacy laws of your jurisdiction. These safeguards may include:

  • Data-transfer agreements incorporating Standard Contractual Clauses (SCCs) or their local equivalents approved by regulators;

  • Intra-group data-protection agreements binding all affiliated entities to the same high standards of confidentiality and security;

  • Vendor due diligence to confirm that third-party processors maintain adequate security and privacy controls; and

  • Risk assessments and ongoing monitoring of cross-border data flows.

9. AUTOMATED DECISION MAKING AND ARTIFICIAL INTELLIGENCE

In Short: We use some AI and automated tools to support our Services, but we do not rely on them to make decisions that have legal or similarly significant effects on you.

We may use certain Artificial Intelligence (AI) - based tools and fully or semi-automated systems - for example, AI may help our customer service team by suggesting draft replies or transcribing a call to enhance the speed and accuracy of our services.

However, we do not engage in automated decision-making, including profiling, that produces legal, financial or similar effects concerning you. Specifically:

  • Alla rekommendationer, svar eller information som genereras av AI-verktyg tillhandahålls endast i informationssyfte och är föremål för granskning och validering av vår personal.

  • Vi använder inte algoritmer eller automatiserade system för att fatta beslut om dig som får rättsliga följder (t.ex. avslag på en tjänst) utan meningsfull mänsklig inblandning.

  • You have the right to request human intervention and express your point of view if you believe any decision or response has been generated through automated means that significantly affects you, and to obtain an explanation and review of such a decision by a human member of our staff;

  • We try to be transparent and inform you when AI or automation was used to help deliver a service;

  • We never use your identifiable Personal Information to train AI models. If any Data is used for improvement, it is anonymized so it can no longer identify you;

  • We keep this information only as long as needed to deliver the service, protect it under strict contracts with our vendors, and prohibit those vendors from using identifiable data for their own model training.

10. YOUR RIGHTS OVER YOUR PERSONAL INFORMATION

In Short: You have rights over your Personal Information, including access, correction, deletion, objection, and more. This section explains what those rights are and how they work.

If we process your Data as set out in this Policy, or you believe we may be doing so, you have the following rights. These rights apply regardless of whether we process your Data as a client, supplier, contractor, or professional contact:

If you are a U.S. resident or our processing relates to U.S. individuals, your rights under State Privacy Laws (which may vary by state):

  • Right to know/access – Request information about the categories and specific pieces of Personal Information we have collected, used, disclosed, sold, or shared about you, and obtain a copy of that Data.

  • Right to deletion – to request the deletion of Personal Information we hold about you, subject to certain exceptions ((e.g., to complete a transaction, detect fraud, or comply with recordkeeping laws).

  • Right to correction – to request correction of inaccurate Personal Information.

  • Right to data portability – to request receive a copy of your Personal Information in a portable format.

  • Right to Opt-out of Sale or Sharing (California law and other states) – Opt-out of the "sale" or "sharing" of Personal Information, including use for cross-context behavioral advertising. We provide a link in footer "Your Privacy Choices" where you can easily execute your right.

  • Right to Limit the Use of Sensitive Personal Information (CPRA) – Request that we restrict the use and disclosure of your sensitive information (e.g., precise geolocation, health data, or financial details) beyond what is necessary to provide requested services.

  • Right to Opt-Out of Profiling (where applicable by state law) – Object to profiling that produces legal or similarly significant effects concerning you.

  • Right to Non-Discrimination – You should not receive any discriminatory treatment for exercising your privacy rights.

  • Right to Appeal (Virginia, Colorado, Connecticut) – If we deny your privacy rights request, you may appeal our decision by contacting us through the same request channel. If your appeal is denied, you may contact your state Attorney General.

  • Right to limit use of sensitive Personal Information (CPRA only) – to request restrictions on how we use sensitive information (e.g., precise geolocation, health data, financial data).

  • Right to non – discrimination – You will not be treated differently for exercising your privacy rights.

  • Right to appeal – You have the right to appeal if we deny your privacy rights request (as required by Virginia, Colorado, and Connecticut laws). If the appeal is denied, you may contact your state Attorney General.

Observera: Dina rättigheter är inte absoluta. I vissa fall kan utövandet av dina rättigheter begränsas enligt tillämpliga dataskyddslagar – till exempel om att uppfylla din begäran skulle påverka andra personers rättigheter och friheter negativt, eller när vi enligt lag är skyldiga att behålla vissa personuppgifter (t.ex. för regelefterlevnad, rättsliga anspråk eller tillsynsändamål).

11. HUR UTÖVAR DU DINA RÄTTIGHETER ELLER KONTAKTAR DU OSS?

If you have any general questions about this Policy, how we process Data, complaint or if you wish to exercise any of your Data Subject rights, you can contact us by email at: dpo@nuubu.com or via post address: 354 Downs Blvd, Suite 101A Franklin, TN 37064.

För att hjälpa oss att hantera din begäran effektivt, vänligen:

  • clearly express your question or complaint,

  • specify which right you wish to exercise (if applicable),

  • provide enough information to identify you (we may ask for proof of identity or proceed identity verification process), and

  • include any relevant details that will help us respond quickly.

You may also authorize someone to act on your behalf. If so, please ensure your authorized person provides us with written and signed permission confirming they are allowed to act for you. We may deny a request if sufficient proof of authorization is not provided.

We aim to respond without undue delay within 45 days of receiving your request. This time is extendable by an additional 45 days where reasonably necessary in which case, we will inform you in advance and explain the reason for the delay.

SLUTET PÅ POLICYN

Dina cookie-inställningar

Cookies och liknande tekniker hjälper oss att förbättra din upplevelse, analysera webbplatsens prestanda och leverera personligt anpassat innehåll och annonser genom våra analys- och reklampartners. Läs mer i vår cookiepolicy.

Du har kontrollen. Du kan välja vilka cookies som ska tillåtas och förbjuda oss att dela eller sälja din personliga information: