Legal
Privacy policy
We collect the minimum we need to run your business page, appointments and payments — and nothing we can't explain.
Last updated: 2026
1. Controller
Golden Roots Management LTD is the controller for data about Nosweb account holders. For the customers of a business using Nosweb, that business is the controller and we act as processor on their instructions.
2. What we collect
- Account data: name, e-mail address, optional company name and country, password hash, user ID.
- Business data: your services, prices, opening hours, page content and uploaded images.
- Customer data you enter or receive: names, contact details, appointments, orders and notes.
- Payment data: amounts, status and references. Card details are handled by our payment provider — we never see or store them.
- Usage data: aggregated, cookie-less page views and events on public business pages.
3. Why we use it
To provide the service you asked for (contract), to send transactional e-mails such as booking confirmations and reminders (contract), to keep the platform secure and prevent abuse (legitimate interest), and to meet tax and accounting obligations (legal obligation).
4. Sharing
We share data only with processors that make the service work: our hosting and database provider, our payment provider, our e-mail delivery provider and, where you use them, content-generation providers. They act on our instructions and may not use your data for their own purposes. We never sell personal data.
5. Retention
Account and business data are kept while your account is active and deleted within 30 days after you delete it, except where longer retention is legally required (invoices and payment records are typically kept for seven years).
6. Your rights
You can access, correct, export or delete your data, restrict or object to processing, and lodge a complaint with your supervisory authority. Exports are available directly in your dashboard; for anything else, contact us.
7. International transfers
Where a processor operates outside the EEA, transfers are covered by adequacy decisions or standard contractual clauses.
8. Security
Data is encrypted in transit, access is restricted per account through row-level security, and administrative access is limited to staff who need it.
9. Contact
Privacy questions or requests go through our contact form. See also our cookie policy.