Nuborix
InicioServicios
IANOVAFacturación y gestión empresarialNuborix IA 606Facturas de compra y archivo 606
NosotrosContactoAcceder a aplicaciones
Legal document

IANOVA Privacy Policy

Version: 1.1 Identifier: IANOVA-PP-v1.1-2026-09-02 Effective from: 3 September 2026 Language: English (translation) · Español (controlling version)

This Policy explains what personal data Nuborix processes through IANOVA, for what purpose, on what basis, with whom it is shared, how long it is retained, and what rights you have, under Law No. 172-13 on the Comprehensive Protection of Personal Data of the Dominican Republic.

It supersedes version 1.0, which is archived as a record of what was accepted while it was in force.

English is a translation — Spanish controls This English text is provided for convenience. Unless a legal decision establishes otherwise, the Spanish version prevails in the event of any discrepancy. Legal names of persons and entities are not translated.
Two distinct roles: please read carefully For your account data (yours as a subscriber), Nuborix is the controller. For the data of your own customers that you enter into IANOVA, you are the controller and Nuborix acts as processor: we process it on your instructions and to provide the service to you. The duty to inform your customers and to have a lawful basis is yours.
Contents
  1. Controller
  2. Scope and roles
  3. Data we process
  4. Purposes
  5. Lawful basis
  6. Nuborix access to information
  7. Subscriber's customer data
  8. Providers and transfers
  9. Retention periods
  10. Storage on your device
  11. Security measures
  12. Data subject rights
  13. Complaints
  14. Minors
  15. Security incidents
  16. Automated decisions
  17. Languages and versions
  18. Changes and acceptance

1. Controller

Legal nameRichard Rosa Ulloa (sole proprietor)
Trade nameNuborix
RNC (tax ID)001-1161186-9
Registered addressCentro Olímpico 14, Residencial Celina, El Millón, Santo Domingo 10149, República Dominicana
Privacy email[email protected]
Contact channelWhatsApp +1 809-510-0597 · IANOVA support 1-829-426-5418
Websitewww.nuborix.com

Nuborix is the trade name under which the controller operates, acting as a sole proprietor in accordance with its RNC.

2. Scope and roles

This Policy applies to the Nuborix website, the IANOVA web application, and the IANOVA applications for macOS, Windows, Android, iPhone and iPad.

  • Nuborix as controller: for the subscriber's account, company, subscription and use of the Service.
  • Nuborix as processor: for the personal data of third parties — the subscriber's own customers — entered into IANOVA by the subscriber.

3. Data we process

3.1 Account and company

  • User and business name; email address; phone number; RNC or national ID; business type and contracted plan.
  • Password, stored only as an irreversible cryptographic digest. Nuborix does not know and cannot recover your password.
  • Two-step verification (TOTP) secret, stored encrypted; and recovery codes stored in non-reversible form.

3.2 Usage, access and security

  • IP address, access date and time, and browser or application user agent.
  • Session identifiers and authentication events, including failed attempts and temporary lockouts.
  • Record of acceptance of the legal documents: document identifier and version, date and time in UTC, source IP address and user agent (the latter truncated to 256 characters).
  • Activity records for certain administrative and messaging operations.

3.3 Business content

  • Customers, products, inventory, invoices, quotes, receipts and orders created by the subscriber.
  • Product images uploaded by the subscriber.
  • Tax and commercial configuration of the company.

3.4 Communications

  • Messages in the internal messaging system and administrative notices.
  • Transactional system emails, limited to: trial start, plan activation, password setup and temporary password. These emails do not include the subscriber's customer data.

Nuborix does not request or deliberately process sensitive data within the meaning of Law 172-13. The subscriber undertakes not to enter such data into free-text fields.

4. Purposes of processing

  • Create, maintain, authenticate and administer the account.
  • Provide the contracted functionality and enable issuing and managing documents.
  • Manage the subscription and verify the plan's validity.
  • Protect the Service: prevent unauthorised access, fraud and abuse, and apply usage limits.
  • Provide technical support when the subscriber requests it.
  • Send operational communications and notices about the service, the subscription and legal changes.
  • Comply with legal, accounting and tax obligations, and respond to requests from competent authorities.
  • Retain evidence of acceptance of the legal documents.
  • Diagnose faults and improve the Service, using the minimum data necessary.

Nuborix does not sell or transfer personal data for advertising purposes, and does not carry out commercial profiling with the subscriber's business content.

5. Lawful basis

  • Performance of the contract: providing the Service and managing the relationship.
  • Consent: given freely, expressly and on an informed basis when accepting the legal documents during registration.
  • Compliance with legal obligations: accounting retention and responding to requests.
  • Legitimate interest: information security, fraud prevention and defence of rights, balanced against the data subject's rights.

6. Nuborix access to information

Nuborix does not routinely consult or use the commercial content stored by subscribers in IANOVA. IANOVA automatically processes only the data necessary to operate, synchronise, protect and back up the service. Each subscriber's data remains isolated from that of others.

6.1 What is implemented and verified

  • Isolation between subscribers: every business query and mutation derives the company from the authenticated session; an identifier sent by the client does not change the effective company. Verified through negative tests across two companies.
  • Role-based permissions: distinct administrative roles exist, and administrative accounts are required to use two-step verification.
  • Activity logging: certain administrative operations are recorded: password resets, notice creation, product changes and messaging operations.

6.2 Nuborix staff access to business content

Honest statement of status A platform administrator account only sees a subscriber's account and subscription data. Access by Nuborix staff to a subscriber's business content (customers, invoices) requires a documented reason and a verification code, is limited to 30 minutes and is fully logged, as is any change that staff make to the account. Each time that access is opened, the subscriber receives a notice in their dashboard.

That access is used only on an exceptional basis to handle requested support, investigate a security incident, maintain the service or comply with a legal obligation.

Nuborix does not use, in this Policy or in its marketing, expressions such as "no one can access", "access is impossible", "end-to-end encryption", "zero knowledge" or "absolute security". None of them would truthfully describe how the system works.

7. Subscriber's customer data

When the subscriber records data about its own customers in IANOVA — name, RNC or national ID, phone, address, email:

  • The subscriber is the controller of that processing and warrants that it has authorisation or a lawful basis for it.
  • Nuborix acts as processor and processes that data solely to provide the Service, following the subscriber's documented instructions.
  • Nuborix does not use that data for its own purposes or transfer it to third parties outside the provision of the Service.
  • It is for the subscriber to inform its customers and to handle rights requests they address to it. Nuborix will provide reasonable assistance.

The processor–controller relationship must be formalised in a separate Data Processing Agreement (DPA), specifying instructions, sub-processors, security measures, assistance, incident notification, return or deletion, and audit. That agreement is pending drafting and approval and is not deemed incorporated merely by accepting this Policy.

8. Providers and international transfers

Providers confirmed by inspection of the system configuration:

ProviderFunctionCategories processedRole
Cloudflare, Inc.Application hosting and backend execution; database; product image storage; content delivery and attack protectionAccount, business content, technical and security records, imagesProcessor
ResendTransactional email deliveryRecipient email address and name; transactional message contentProcessor
Operating system and app store providersDistribution and installation of the desktop and mobile applicationsInstallation data managed by the provider, outside Nuborix's controlIndependent controllers

Processing region and sub-processors: Cloudflare's and Resend's infrastructure operates through internationally distributed servers. Nuborix does not contract an exclusive region, and each provider publishes its own list of sub-processors in its documentation.

Contractual safeguards: Nuborix relies on the data protection and security commitments each provider assumes in its terms of service. Signing specific processing agreements with each provider is in progress.

These providers' infrastructure operates through internationally distributed servers, so data may be stored or processed outside the Dominican Republic. By accepting this Policy, the subscriber consents to that international transfer, which is necessary to perform the contract.

9. Retention periods

Actual status: there is no automatic purge As of today, the system runs no automatic deletion process based on age. Data is retained while the account exists, and is deleted only when the subscriber deletes a record. The periods in the table below are the policy to be approved and implemented; they do not yet describe automated system behaviour.
CategoryPeriodStatus
Active accountWhile the account remains activeIn force
Cancelled accountWhile the account existsNot implemented
Grace period for recoveryWhile the account existsNot implemented
Invoices and tax documentsWhile the account exists, and in any case for the statutory tax retention period applicable to the taxpayerNot implemented
Legal acceptance recordsWhile claims under the contract remain actionableNot implemented
Activity and security recordsWhile the account existsNot implemented
Internal messagingWhile the account existsNot implemented
BackupsWhile the account existsFrequency and retention pending confirmation
Local cache and offline queueUntil sign-out, synchronisation, or clearing the application's dataIn force
Access session14 days from issuance, or until sign-outIn force
Documents generated for printing or PDFGenerated on the device at print time; not stored on Nuborix serversIn force
Support requestsWhile the account existsNot implemented

9.1 Four distinct situations

  • Immediate deletion: the data is removed from the active database at once.
  • Legal blocking: the data stops being used but is retained because a legal obligation or the defence of a claim requires it. It is restricted, not available for ordinary use.
  • Persistence in backups: data deleted from the active database may still exist in backups until they are rotated. Backups are not used for ordinary operation.
  • Definitive erasure: the data disappears from the active database and from current backups once the rotation cycle completes.

Status of closing functions: the system currently has no automated account deletion or bulk data export function. Requests are handled through the privacy channel by manual intervention.

10. Storage on your device

IANOVA uses only strictly necessary mechanisms. No advertising, third-party tracking or profiling cookies are used. The applications contain no advertising or third-party analytics SDKs.

MechanismWhat it storesOn sign-out
ianova_session cookieAuthenticated session identifier. It is HttpOnly (not accessible from JavaScript), SameSite=Lax and Secure over HTTPS. Maximum lifetime of 14 days.Deleted
Local database ianova-offline-v1 (IndexedDB)Data needed to work offline and the queue of operations pending synchronisationSession data and queue are emptied. The database and the device identifier remain.
Browser local storageOnly the thermal printer preference. No customer data or documents are stored.Remains (it is a preference, not business personal data)
Browser session storageOnly the temporary two-step verification challenge during sign-inDeleted

10.1 What remains and why

  • What remains: the local database continues to exist after sign-out, with its session contents and queue emptied, and retains a device identifier.
  • Why: the device identifier allows the device to be recognised at the next offline activation and avoids duplicating authorisations.
  • How it is protected: it resides in the browser or application storage, subject to operating system and user profile isolation. Additional protection of the local store via the system keychain (Keychain/Keystore) is identified as pending in the internal audit.
  • How you can delete it: on the web, by clearing the site's data in your browser; in the applications, by clearing the app's data or uninstalling it.
  • On uninstall: the application's local storage is removed according to the behaviour of the relevant operating system.

10.2 Several users on the same device

Local storage is per browser or per application installation, not per IANOVA user. If several people share the same browser profile or the same operating system user, they must sign out when finished. Signing out empties the session data and the local queue. For complete separation, use separate browser profiles or system accounts.

11. Security measures

Only controls verified in the system are described:

  • Encryption in transit: HTTPS with HSTS.
  • Passwords: PBKDF2-SHA256 with a random per-credential salt, at the maximum iteration count the execution platform allows. Never stored in clear text.
  • Two-step verification: mandatory for administrative roles; the TOTP secret is stored encrypted with AES-GCM.
  • Sessions: HttpOnly cookie, Secure over HTTPS and SameSite=Lax, with revocation on critical changes.
  • Company isolation: derived from the authenticated session, not from client-supplied values.
  • Role-based access control: distinct administrative roles.
  • Activity logging: for certain administrative and messaging operations (see section 6).
  • Abuse protection: per-IP request limiting on sign-in, registration, password setup, two-step verification, administrative email and internal tasks; temporary account lockout after failed attempts; and generic sign-in messages to prevent user enumeration.
  • Browser protection: content security policy, headers against framing, MIME sniffing and referrer leakage; size and type limits on file uploads.
  • Backups: a full copy of the database is made before every significant platform change, and the infrastructure provider also allows restoring the database to an earlier point in time. The copy made before each change does not follow a fixed schedule: it is made with every change. A daily encrypted backup with a weekly restoration test is being put in place, not yet operational. No backup automation exists within the application: the process is operational.
  • Encryption at rest: a property of the contracted infrastructure platform. It is a property of the contracted platform, not a control implemented by Nuborix in the application code.
  • Incident procedure: described in section 15. Its documentary formalisation is in progress.

No system is absolutely invulnerable. Security is an obligation of means and not of result. Protection also depends on the subscriber's diligence in safeguarding credentials and securing their devices.

12. Data subject rights

Under Law 172-13, the data subject may exercise the rights of access, rectification, updating, objection and deletion, and may withdraw consent given.

RightResponse deadline
AccessFive (5) business days
Rectification, updating or deletionTen (10) business days

12.1 How to submit a request

Send it to [email protected] stating at least:

  • the data subject's full name and contact details for the reply;
  • the right being exercised and a clear description of the request;
  • information that allows the data to be located, where applicable;
  • the identity evidence described below.

12.2 Proportionate identity verification

Verification will be proportionate to the risk of the request. Ordinarily it is enough to demonstrate control of the email address registered to the account. A full copy of an identity document is not required by default. Enhanced evidence will be requested only where the request carries elevated risk — for example, deletion of information or a change of contact details — or where there is well-founded doubt as to identity; in that case, the least intrusive sufficient means will be requested.

12.3 Notification to recipients

Where rectified or deleted data has been communicated to third parties, Nuborix will pass on the correction where appropriate and materially possible.

12.4 Limits and exceptions

Exercise may be limited, with reasons given, where there is:

  • a tax or accounting retention obligation falling on the subscriber or on Nuborix;
  • performance of a current contract;
  • prevention, detection or investigation of fraud or security incidents;
  • defence of claims or compliance with a request from a competent authority.

In such cases the data may be blocked rather than deleted, in accordance with section 9.1.

12.5 Exportable copy

Law 172-13 does not expressly recognise a general right to data portability. Independently of that, IANOVA may provide the subscriber with an exportable copy of certain data as an additional service, where technically and legally possible. There is currently no automated export function: requests are handled manually through the privacy channel.

12.6 If you are a customer of a business that uses IANOVA

Please contact that business, which is the controller. Nuborix, as processor, will forward the request to the relevant subscriber.

13. Complaints

  1. Direct request to Nuborix. Write to [email protected], which is the privacy channel. This is the first step and resolves most cases.
  2. Response deadlines. Five (5) business days for access; ten (10) business days for rectification, updating or deletion.
  3. Habeas data action. If your request is not addressed or the response is unsatisfactory, Law 172-13 allows you to bring a habeas data action before the competent court of the Dominican Republic, to know, update, rectify or delete your data.
  4. Pro Consumidor. Where there is a consumer relationship or an adhesion contract, the National Institute for the Protection of Consumer Rights (Pro Consumidor) may intervene within its consumer protection remit.

This Policy does not attribute to any institution the status of general data protection authority. The habeas data judicial route is the mechanism Law 172-13 expressly provides for the protection of these rights.

14. Minors

14.1 IANOVA accounts

IANOVA is intended for businesses and professionals. It is not directed at persons under eighteen (18) and Nuborix does not knowingly collect minors' data for account creation. If an account created by a minor without the relevant authorisation is detected, it will be deleted.

14.2 Minors recorded as customers by a subscriber

A subscriber may need to record a minor's data as a customer of its business. In that case the subscriber is the controller and must hold the authorisation of parents or guardians, or another lawful basis, under Law 172-13.

14.3 Subscriber responsibility

Nuborix, as processor, does not verify the age of the customers a subscriber records, nor does it replace the authorisations the subscriber must obtain. It is for the subscriber to obtain and retain them.

Any matter concerning minors' data may be reported to [email protected].

15. Security incidents

If a security breach affecting personal data occurs and poses a risk to data subjects, Nuborix will notify the affected subscribers without undue delay and, where appropriate, the competent authority or court, describing the nature of the incident, the categories of data affected, the measures taken and the applicable recommendations.

Where Nuborix acts as processor, it will notify the controlling subscriber so that the subscriber can meet its own notification obligations.

16. Automated decisions

Nuborix does not take decisions producing legal effects on the data subject based solely on automated processing, nor does it build profiles for that purpose. The existing automatic controls — request limits, temporary lockout after failed attempts and plan validity checks — are technical in nature and reversible by contacting support.

17. Languages and versions

This Policy is published in full in Spanish and in English, with the same numbering, scope and meaning.

Unless a legal decision establishes otherwise, in the event of any discrepancy between versions the Spanish version prevails. Legal names of persons and entities are not translated.

18. Changes and acceptance

The version in force is always published at this address, identified by version number and date. Previous versions are archived: version 1.0.

18.1 Acceptance record

Nuborix keeps an electronic record of each acceptance with: identifier and version of the accepted document, date and time in UTC, source IP address and truncated user agent. Each acceptance is bound to the specific version accepted; an acceptance of version 1.0 is not reassigned to or converted into an acceptance of version 1.1.

18.2 Minimisation of the evidence

The IP address and user agent are recorded for the sole purpose of evidencing acceptance. The user agent is truncated. Their retention period is the one stated in section 9 for legal acceptance records.

18.3 Renewed acceptance

Version 1.1 introduces substantial changes compared with version 1.0 — among them the statement on staff access, the deadlines for exercising rights, the retention table and the detail of local storage — and therefore requires a fresh, express acceptance. Minor or drafting changes will not, and will be communicated through the Service or by email with reasonable notice.

Document IANOVA-PP-v1.1-2026-09-02. Version 1.1. Effective date: 3 September 2026. Supersedes version 1.0. See also the Terms and Conditions and the Spanish version, which prevails. © 2026 Nuborix. All rights reserved.

Nuborix

Tecnología, inteligencia artificial y sistemas digitales para empresas modernas.

ProductosIANOVANuborix IA 606Servicios
LegalTérminos y CondicionesPolítica de PrivacidadPrivacy Policy (EN)
Contacto[email protected]WhatsApp · +1 809-510-0597

© 2026 Nuborix. Todos los derechos reservados.