Privacy & Data Protection

    Privacy Policy

    Last Updated: August 20, 2026

    Your privacy is important to us. This policy explains how we collect, use, and protect your information.

    1. Introduction

    Welcome to namponi. We are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform, services, and website.

    namponi is a digital business card and lead management platform operated by NAMPONI LTD (ΗΕ 492548), registered in the Republic of Cyprus. As a Cyprus-based company, we are subject to the General Data Protection Regulation (GDPR) and applicable data protection laws of the European Union. We provide QR code generation, business card creation, AI-powered scanning, lead capture, workflow automation, CRM integrations, and an AI-powered assistant (namponi AI).

    By using namponi, you agree to the collection and use of information in accordance with this policy. If you do not agree with our policies and practices, please do not use our services.

    2. Information We Collect

    We collect several types of information to provide and improve our services:

    Personal Information:

    • Name, email address, phone number, and contact information
    • Profile photos, Organization logos, and business card content
    • Job title, company name, and professional information
    • Social media profiles and website URLs
    • Payment and billing information (processed securely through Stripe)

    Lead Data:

    • Contact information submitted through lead capture forms
    • Custom field data as configured by Organizations
    • Tags and categorization data
    • Lead activity and interaction history

    AI Processing Data:

    • Business card images uploaded for AI scanning (via camera or photo library)
    • Text extracted from scanned cards using optical character recognition (OCR)
    • Company domain information extracted from lead email addresses for enrichment
    • Publicly available company information gathered from company websites
    • Generated content (bios, headlines, taglines, company profiles)
    • AI chat conversation history (messages you send and AI responses)

    Usage Data:

    • QR code scans and business card views
    • Device information (type, browser, operating system)
    • IP address and approximate geolocation (resolved via third-party IP geolocation services)
    • Referrer information and traffic sources
    • Time and date of interactions
    • Feature usage and navigation patterns

    Mobile Application Data:

    • Camera images captured for business card scanning and QR code scanning
    • Photos selected from your device library (for profile photos or card uploads)
    • Device identifiers for analytics and crash reporting (opt-in only, with your consent)
    • App interaction data and screen views (opt-in only, with your consent)
    • Crash diagnostics including stack traces, device model, and OS version (opt-in only, with your consent)

    Account Information:

    • Organization details and team member information
    • User roles, permissions, and access logs
    • Integration credentials (encrypted at rest using AES-256-GCM)
    • Workflow configurations and automation rules
    • Push notification preferences and device push tokens
    • Custom settings and preferences

    3. How We Use Your Information

    We use the collected information for various purposes:

    • Service Delivery: To provide, maintain, and improve our services including QR codes, business cards, and lead management
    • AI Processing: To power AI features including business card scanning, headline generation, and company intelligence
    • Analytics: To generate insights and analytics reports for your QR codes, business cards, and leads
    • Lead Management: To capture, store, organize, and manage leads on your behalf
    • Workflow Automation: To execute automated workflows and trigger integrations
    • CRM Integrations: To sync data with your connected CRM platforms (HubSpot, Salesforce, Zoho, etc.)
    • Communication: To send you transactional emails, updates, notifications, and support communications
    • Security: To protect against fraud, abuse, and security threats
    • Legal Compliance: To comply with legal obligations and enforce our terms
    • Business Operations: To manage your account, process payments, and provide customer support
    • Product Improvement: To analyze usage patterns and improve our features

    4. Data Sharing and Disclosure

    We do not sell your personal information. We may share your information only in the following circumstances:

    • Service Providers: With trusted third-party service providers who assist in operating our platform:
    • Google Cloud Platform (application hosting, serverless functions, database hosting, AI services, and cloud storage)
    • Google Cloud Identity Platform / Firebase Authentication (user authentication and identity management)
    • Stripe (payment processing, PCI DSS compliant)
    • Cloudflare (content delivery network and asset storage)
    • OneSignal (push notification delivery to mobile devices)
    • Mailtrap (transactional email delivery — billing receipts and notifications)
    • Cloudflare Turnstile (bot protection on public forms)
    • CRM Integrations: When you configure integrations, lead data is shared with your connected CRM platforms (HubSpot, Salesforce, Zoho) according to your workflow settings
    • AI Processing: Business card images, extracted text, and chat messages may be processed by Google Cloud AI services (under enterprise data processing agreements) for scanning, enrichment, content generation, and conversational AI
    • Company Enrichment: When enriching lead data, we may access publicly available company information from company websites based on email domain names
    • Legal Requirements: When required by law, court order, or government regulation
    • Business Transfers: In connection with a merger, acquisition, or sale of assets (with notice to users)
    • Consent: When you explicitly consent to sharing your information
    • Organization Members: Within your Organization, information is shared according to role-based permissions
    • Multiple Organizations: A single account may belong to more than one Organization. Your profile information is visible to each Organization you are a member of, and data you create within an Organization (cards, leads, QR codes) belongs to that Organization. We store your active-organization preference so your selection stays in sync across web and mobile devices
    • Public Business Cards: Information on public business cards is accessible to anyone with the link or QR code

    5. AI Features — Data Processing

    namponi uses artificial intelligence to power several features across the platform. All AI features process data through Google Cloud AI services under enterprise data processing agreements.

    AI-Powered Features:

    • Business Card Scanning: Images you upload are processed using optical character recognition (OCR) and AI models to extract contact information (names, emails, phone numbers, job titles, company names)
    • Company Enrichment: Email domains from your leads are used to gather publicly available company information from the internet, which is then structured by AI
    • Content Generation: AI generates professional bios, headlines, and taglines based on profile information you provide
    • AI Chat Assistant (namponi AI): An optional conversational assistant that can help manage your business cards, leads, and QR codes

    namponi AI Chat — Additional Details:

    • Use of namponi AI requires explicit consent before first use
    • namponi AI can only read messages you send within the chat interface — it cannot access any other information on your device
    • namponi AI may perform actions on your behalf (creating or modifying cards, QR codes, leads) within your Organization scope, based on your instructions
    • AI-generated responses may be inaccurate and should always be verified before use

    Data Storage and Retention:

    • Conversation history is stored in our database and associated with your user account
    • Conversations are retained until you delete them or delete your account
    • You can delete individual conversations at any time from the AI chat interface
    • Scanned business card images are stored securely for the duration of your account

    Consent and Opt-Out:

    • You must explicitly accept namponi's AI terms before using the AI chat assistant
    • If our terms or privacy policy are updated, you will be asked to re-accept before continued use
    • You may stop using namponi AI at any time — the service is entirely optional
    • Business card scanning and company enrichment are core features that do not require separate AI consent
    • To request deletion of all AI conversation data, contact privacy@namponi.com

    AI Provider and Data Handling:

    • All AI processing is performed by Google Cloud AI services (including Gemini models and Vertex AI OCR)
    • Data sent to Google AI is processed under Google Cloud's enterprise data processing terms and is not used to train Google's general AI models
    • Your data is encrypted in transit between our servers and Google's AI infrastructure
    • namponi does not share your AI data with any other third-party services beyond Google Cloud

    6. Data Security

    We implement industry-standard security measures to protect your information:

    • Encryption in Transit: All data is transmitted over TLS (Transport Layer Security). Database connections enforce SSL-only mode to prevent unencrypted communication.
    • Encryption at Rest: All data stored in our database (Google Cloud SQL) is encrypted at rest using Google-managed encryption keys. Database backups are also encrypted. File storage services (Google Cloud Storage, Cloudflare R2) encrypt data at rest by default.
    • Application-Layer Encryption: Highly sensitive credentials (such as integration OAuth tokens) are additionally encrypted at the application layer using AES-256-GCM before storage.
    • Access Controls: Role-based access control and authentication
    • Regular Audits: Security audits and vulnerability assessments
    • Secure Infrastructure: Enterprise-grade hosting and infrastructure on Google Cloud Platform
    • Employee Training: Staff trained on data protection and privacy

    However, no method of transmission over the internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your information, we cannot guarantee absolute security.

    7. Your Privacy Rights

    Depending on your location, you may have the following rights:

    • Access: Request access to your personal information
    • Correction: Request correction of inaccurate or incomplete data
    • Deletion: Request deletion of your personal information
    • Portability: Request transfer of your data to another service
    • Objection: Object to processing of your personal information
    • Restriction: Request restriction of processing
    • Withdrawal: Withdraw consent where processing is based on consent

    Right to Deletion (Right to Erasure):

    You can delete your account at any time through the Account settings page on the web or mobile app. Account deletion works as follows:

    • A 30-day cooling-off period applies. During this period, you may cancel the deletion by signing back in.
    • After 30 days, your personal data will be permanently deleted or anonymized. This includes your profile information, business cards, QR codes, leads, scan history, and chat conversations.
    • Billing and payment records (invoices, payment history, subscription records) are retained for a minimum of 7 years as required by EU/Cyprus tax law (Income Tax Law, Cap. 297, Section 19).
    • Organization data belonging to a sole-owner organization will be anonymized (personal identifiers stripped) but the structure retained.
    • Data that has already been shared with third parties via integrations (e.g., CRM syncs) is not within our control to delete.

    To exercise any other rights, please contact us at privacy@namponi.com. We will respond to your request within 30 days.

    8. Cookies and Tracking Technologies

    We use cookies and similar technologies on our platform:

    Strictly Necessary Cookies:

    • Session authentication cookie (required for login and secure access)
    • Theme preference cookie (remembers your light/dark mode setting)
    • Cookie consent preference (remembers your cookie choices)

    These cookies are essential for the platform to function and cannot be disabled.

    Analytics Cookies (Website — Opt-In):

    • Google Analytics is used on our website to understand visitor behavior and improve our services
    • Analytics cookies are blocked by default and only activated after you provide consent via our cookie banner
    • You can withdraw consent at any time by clearing your cookies or using your browser settings
    • Google Analytics data is anonymized and not linked to your personal account

    Analytics (Mobile App — Opt-In):

    • Firebase Analytics and Crashlytics are used in our mobile application to understand usage patterns and diagnose crashes
    • These are opt-in only — you are asked for consent via the in-app consent banner before any analytics data is collected
    • You can change your preference at any time in the app settings

    We do not use marketing cookies, advertising trackers, or third-party tracking pixels. You can manage cookies through your browser settings, though disabling essential cookies may prevent you from using the platform.

    9. Third-Party Services

    Our platform may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies.

    We use the following third-party services:

    Infrastructure and Hosting:

    • Google Cloud Platform (application hosting via Cloud Run, serverless functions, cloud storage, task scheduling)
    • Google Cloud SQL (managed PostgreSQL database hosting)
    • Cloudflare (content delivery network and asset/image storage)

    Authentication and Identity:

    • Google Cloud Identity Platform / Firebase Authentication (user authentication, email/password, and social sign-in)
    • Microsoft Entra ID / Azure AD (enterprise single sign-on and directory synchronization — when configured by your Organization)

    Payment Processing:

    • Stripe (secure payment processing, PCI DSS compliant — we never store your full card details)

    AI and Machine Learning:

    • Google Cloud AI services, including Gemini models and Vertex AI (optical character recognition, business card data extraction, content generation, company intelligence, and conversational AI assistant)

    Mobile App Analytics and Diagnostics (opt-in only):

    • Firebase Analytics (app usage analytics — collected only with your explicit consent)
    • Firebase Crashlytics (crash reporting and diagnostics — collected only with your explicit consent)

    Email Services:

    • Mailtrap (transactional email delivery — billing receipts, account notifications, and support communications)

    Push Notifications:

    • OneSignal (push notification delivery to mobile devices — you can control notification preferences in Settings or disable push notifications via your device settings)

    CRM Integrations (when configured by you):

    • HubSpot, Salesforce, Zoho CRM

    Website Analytics (opt-in only):

    • Google Analytics (website visitor analytics — activated only after you consent via our cookie banner)

    Bot Protection:

    • Cloudflare Turnstile (verifies that public form submissions come from humans — may process technical browser signals; does not track you across sites)

    IP Geolocation:

    • IP geolocation services — ipapi.co (primary) and ip-api.com (fallback) — used server-side to determine the approximate location of QR code and business card scan events for analytics purposes. These providers receive only the visitor's IP address, and only for visitors who open shared card or QR links on the web — never for users of our mobile application.

    Each third-party service has its own privacy policy and data processing terms. By using features that rely on these services, you acknowledge their respective privacy practices. We maintain data processing agreements with our key infrastructure providers.

    10. Mobile Application

    Our mobile application (available on iOS and Android) provides access to namponi features on your device. This section describes additional data practices specific to the mobile app.

    Device Permissions:

    • Camera: Required for scanning business cards and QR codes. Images are sent to our servers for AI processing and are not stored on your device beyond the scanning session.
    • Photo Library: Used to select existing photos for profile pictures or business card uploads. We only access photos you explicitly select.
    • Push Notifications: Used to notify you of new leads, scan processing results, and engagement milestones. You can manage notification types in Settings or disable them via your device settings.
    • We do not request access to your location, contacts, microphone, or biometric data. The IP-based approximate geolocation described in Section 9 applies only to visitors who open shared card or QR links on the web; the mobile app never collects or derives your location.

    Local Storage:

    • Authentication credentials are stored in encrypted device storage (iOS Keychain / Android Keystore)
    • Theme preferences and consent status are stored locally
    • No business data is cached on your device

    Analytics and Crash Reporting (Opt-In):

    • On first launch, you are presented with a consent banner asking permission for analytics and crash reporting
    • If you consent, Firebase Analytics collects anonymized usage data (screens viewed, feature interactions) and Firebase Crashlytics collects crash diagnostics (stack traces, device model, OS version)
    • You can withdraw consent at any time — analytics and crash reporting will be disabled immediately
    • If you decline, no analytics or diagnostic data is collected

    Over-the-Air (OTA) Updates:

    • The app may receive updates delivered over the air to fix bugs or add features without requiring an app store update
    • Updates are delivered via secure, authenticated infrastructure
    • Continued use of the app after an OTA update constitutes acceptance of the update

    App Security:

    • All API communication uses TLS encryption
    • Firebase App Check is used to verify that requests originate from our genuine mobile app
    • Authentication tokens are refreshed automatically and stored securely

    11. Children's Privacy

    Our services are not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately at privacy@namponi.com, and we will take steps to delete such information.

    12. International Data Transfers

    namponi is operated from the Republic of Cyprus (EU). Your data is primarily processed within the European Union and European Economic Area (EEA).

    Your information may be transferred to and processed in countries outside the EU/EEA in the following circumstances:

    • Google Cloud Platform services may process data in EU and non-EU regions (governed by Google Cloud's EU Data Processing Addendum and Standard Contractual Clauses)
    • Stripe processes payment data in accordance with the EU-US Data Privacy Framework
    • IP geolocation providers (ipapi.co and ip-api.com) are operated from outside the EU/EEA and receive only the visitor's IP address, solely for the scan-analytics purpose described in Section 9
    • CRM providers (when you configure integrations) may process data outside the EU according to their own data processing agreements

    We ensure appropriate safeguards are in place for all international transfers, including:

    • Standard Contractual Clauses (SCCs) approved by the European Commission
    • EU adequacy decisions where applicable
    • Binding Corporate Rules where available
    • Data processing agreements with all sub-processors

    You may request information about the specific safeguards applied to your data transfers by contacting privacy@namponi.com.

    Data Processing Roles:

    namponi's role under applicable data protection law depends on the type of data being processed:

    • Data Controller: namponi acts as the Data Controller for individual user account data, including registration information, authentication credentials, billing details, and platform usage analytics. As Controller, namponi determines the purposes and means of processing this data to provide and improve the Service.
    • Data Processor: Where an Organization uses the Service to collect and manage data (including leads, business card content, workflow configurations, and CRM integration data), namponi acts as a Data Processor on behalf of the Organization. The Organization, as the Data Controller, determines the purposes for which such data is collected and processed through the Service.

    Where namponi acts as a Data Processor, processing is governed by the applicable Data Processing Agreement (DPA) between namponi and the Organization. Organizations may request a DPA by contacting legal@namponi.com.

    namponi imposes contractual data protection obligations on its Sub-processors consistent with applicable law. A list of categories of Sub-processors engaged by namponi is described in Section 9 of this Privacy Policy.

    For transfers of personal data outside the EU/EEA in connection with Sub-processor activities, namponi relies on Standard Contractual Clauses (SCCs), adequacy decisions, and other transfer mechanisms approved under applicable data protection law.

    13. Data Retention

    We retain your personal information for as long as necessary to:

    • Provide our services to you
    • Comply with legal obligations
    • Resolve disputes and enforce agreements
    • Maintain security and prevent fraud

    Retention Periods:

    • Account data: Retained for the duration of your account and generally deleted or anonymized within 30 days of account deletion, unless otherwise required by law
    • Financial and billing records: Retained for up to 7 years after the transaction, as required by applicable tax and accounting legislation (including Cyprus and EU regulations)
    • AI conversation history: Retained until you delete individual conversations or your account
    • Scan images and extracted data: Retained for the duration of your account
    • Analytics and usage data: Retained in aggregated, anonymized form indefinitely; identifiable records retained for up to 24 months
    • Security and audit logs: Retained for up to 7 years for legal compliance and fraud prevention

    When you delete your account, we will generally delete or anonymize your personal information within 30 days, except where we are required to retain it for legal, tax, or regulatory purposes as described above.

    14. Changes to This Privacy Policy

    We may update this Privacy Policy from time to time. We will notify you of any changes by:

    • Posting the new Privacy Policy on this page
    • Updating the "Last Updated" date
    • Sending you an email notification (for material changes)

    You are advised to review this Privacy Policy periodically for any changes. Changes are effective when posted on this page.

    15. GDPR and CCPA Compliance

    For EU/EEA Residents (GDPR):

    • namponi is operated from the Republic of Cyprus, a member state of the European Union. As such, we are directly subject to the General Data Protection Regulation (EU) 2016/679 (GDPR)
    • Legal basis for processing: Contract performance, legitimate interests, and consent
    • The supervisory authority for data protection in Cyprus is the Commissioner for Personal Data Protection (www.dataprotection.gov.cy)
    • You have rights to access, rectify, erase, restrict, and port your data
    • You may lodge a complaint with the Cyprus Commissioner for Personal Data Protection or with your local data protection authority
    • We process data in accordance with EU data protection requirements

    For California Residents (CCPA):

    • You have the right to know what personal information we collect
    • You have the right to request deletion of your personal information
    • You have the right to opt-out of the sale of personal information (we do not sell data)
    • You will not be discriminated against for exercising your privacy rights

    Data Processing Roles:

    • namponi's role as Data Controller or Data Processor depends on the type of data being processed — see Section 12 (International Data Transfers) for full details
    • Where namponi acts as a Data Processor on behalf of an Organization, the Organization remains responsible as the Data Controller for ensuring a valid legal basis for processing and for fulfilling data subject rights requests
    • namponi imposes contractual data protection obligations on its Sub-processors consistent with applicable law

    Data Processing Agreements:

    • Organizations and enterprise customers may request a Data Processing Agreement (DPA)
    • Contact legal@namponi.com for DPA requests

    16. Contact Us

    If you have any questions about this Privacy Policy or our privacy practices, please contact us:

    namponi

    Operated by NAMPONI LTD (ΗΕ 492548)

    Registered Address:

    Spyrou Kyprianou 5, VACANAS MAKEDONIAS COURT, Floor 5, Mesa Geitonia, 4001 Limassol, Cyprus

    Privacy Inquiries: privacy@namponi.com Data Protection Officer: dpo@namponi.com General Legal: legal@namponi.com Support: support@namponi.com

    Supervisory Authority:

    Commissioner for Personal Data Protection Republic of Cyprus — www.dataprotection.gov.cy

    We are committed to addressing your privacy concerns and will respond to your inquiries within 30 days.

    Key Privacy Commitments

    Secure Data Storage
    Enterprise-grade encryption and security
    Transparent Practices
    Clear disclosure of data usage
    Your Rights Protected
    GDPR and privacy law compliance
    No Data Selling
    We never sell your personal information