Privacy Policy
Effective date: 2 July 2026 · Version 1.1
1. Who we are (data controller)
Nullivo (“Nullivo”, “we”, “us”, “our”) provides a self-service tool that lets you check an email address you own for exposure in known data breaches and helps you reduce that exposure. For the personal data described in this policy, the data controller is Organic Village (UK) Limited, a company registered in England and Wales with company number 11783758, trading as Nullivo. Our registered office address is on the public register at Companies House. You can reach us at privacy@nullivo.com or through the Contact page, and we answer data protection requests from that address.
We are not required to appoint a Data Protection Officer and have not appointed one. Data protection questions go to privacy@nullivo.com and are handled by the founder directly.
2. The data we collect
We deliberately collect as little as possible. Depending on how you use Nullivo, we process:
- Identity & contact data: the email address you submit and verify, and (if you contact us) the content of your message.
- Verification data: the one-time passcode we send to confirm you control the address. The code itself is short-lived and is not stored in readable form.
- Exposure findings: the breach and data-broker results associated with your verified address, which we obtain from third-party breach data and broker listings.
- Account & subscription data: your plan, subscription status, and cleanup progress. Billing and card details are collected and stored by our payment processor, not by us; we receive only limited information (such as plan, status, and the last four digits or a payment token).
- Technical & usage data: limited information such as IP address, device/browser type, and basic logs needed to operate the service securely and prevent abuse.
- Cookie-consent choices and, with your consent, measurement data: if you accept optional cookies, our advertising-measurement and support tools (described in section 10) process limited data such as page visits and conversion events.
We do not ask for, and do not want, special-category data (health, racial or ethnic origin, political opinions, etc.). Please don’t send it to us.
3. Why we use your data and our legal bases
Under the UK/EU GDPR we rely on the following legal bases:
- Performance of a contract: to verify your address, run the scans you request, generate your report, provide cleanup tools, and manage your subscription.
- Consent: to send optional monitoring alerts, and any marketing beyond the follow-up series described below. You can withdraw consent at any time without affecting prior processing.
- The “soft opt-in” (PECR regulation 22(3)): to send the short follow-up series after a scan. When you run a free scan you are considering our paid plans, so we may email you about our own similar services without asking for consent first — provided we offer you a simple way to refuse when we take your address, and again in every message. We do both: there is a box on the scan form to decline before you start, and a one-click unsubscribe in every email. The series is five emails over about a month and then it stops on its own. It covers your own results and our plans, and nothing else — we do not use this basis for newsletters, partner offers or any other product, and we never sell or rent your address.
- Legitimate interests: to keep the service secure, prevent fraud and abuse, and improve Nullivo, balanced against your rights and freedoms.
- Legal obligation: to comply with accounting, tax, and lawful requests from authorities.
4. What we never do
We do not sell or rent your personal data. We do not “share” it for cross-context behavioural advertising. We do not let you (or anyone) look up other people: Nullivo only works on an address whose owner has just proven control of it. We do not use your data to train third-party advertising profiles.
5. Who we share data with
We share data only with the service providers (processors) needed to run Nullivo, under contracts that restrict their use of it:
- Breach-data provider: to check your address against known breaches.
- Email provider: to deliver verification codes and alerts.
- Payment processor: to take and manage payments securely. Card details are entered on the processor’s own checkout and never reach our servers.
- Hosting & database: to run the site and hold the database, in the United Kingdom.
- Support assistant: runs on our own servers with no third-party script and no cookie. Your questions are kept for 90 days so we can fix what it could not answer, then deleted. When no published answer clearly matches, the question text alone is sent to an AI model provider in the United States to choose between our closest published answers; it never receives your email address, your account or your scan results. If you leave a message for a person, it goes through the email provider.
- Reviews: a review platform whose widget loads only if you accept optional cookies.
- Analytics & advertising measurement: analytics and advertising conversion tags, loaded only with your consent (section 10). Our own cookieless usage measurement is not shared with anyone — it stays on our servers (section 10).
- Data holders and brokers: only when you ask us to. Two routes, and your cleanup page says which applies to each holder. Where a holder accepts a written request and you have given us a standing authorisation, we send the removal request to that holder as your authorised agent; it carries the details a request must carry to identify you (name, town and postcode area), and the holder is its recipient. Where a holder publishes no way to search it, the same authorisation lets us send a subject access request in your name — asking whether they hold anything about you — and we record the date it went and when their answer is due. Where a holder requires you to find and submit your own listing, we give you the steps and the link and nothing passes through us. You can withdraw the authorisation at any time from your dashboard, and every request we have sent is listed there with its date.
We name each of these providers in writing to any customer who asks. Write to privacy@nullivo.com and we will tell you exactly who they are, what they hold and where.
We may also disclose data if required by law, to enforce our terms, or as part of a merger or acquisition (in which case we’ll notify you).
6. International transfers
Some of our providers — the payment processor, the email provider, the breach-data provider and the AI model provider behind the support assistant — process data in the United States or other countries outside the UK/EEA. Hosting and the database stay in the United Kingdom. Where a transfer happens, we rely on appropriate safeguards such as the UK International Data Transfer Agreement (IDTA)/Addendum, the EU Standard Contractual Clauses, or an adequacy decision (including the UK/EU–US Data Privacy Framework where the provider is certified), plus additional measures where needed.
7. How long we keep it
We keep personal data only as long as necessary for the purposes above:
- Verification codes: minutes (they expire automatically).
- Account, scan, and cleanup data: for as long as your account is active, then deleted or anonymised within a reasonable period after closure.
- Billing records: for the period required by tax and accounting law.
- Security logs: for a limited period needed to detect and investigate abuse.
8. Your rights (UK/EU)
Subject to conditions, you have the right to: access your data; correct it; delete it (“right to be forgotten”); restrict or object to processing; data portability; and to withdraw consent. To exercise any of these, email privacy@nullivo.com or use the Contact page; we’ll respond within one month. Deletion requests are actioned against all of our systems: your account, scan history, cleanup progress, and monitoring settings are permanently removed. You also have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO) at ico.org.uk, or your local EU data protection authority.
9. Your rights (California / US states)
If you are a California resident, the CCPA/CPRA gives you the right to know what personal information we collect, to access and delete it, to correct it, and to opt out of any “sale” or “sharing”, although Nullivo does not sell or share personal information as those terms are defined. We will not discriminate against you for exercising these rights. Residents of other US states with comparable laws (e.g. Virginia, Colorado, Connecticut, Utah) have similar rights. To make a request, contact us as above; you may use an authorised agent.
10. Cookies & similar technologies
Essential cookies (always on) keep you signed in and remember your cookie choices; the site can’t work without them. Optional cookies load only if you accept them in our consent banner: support chat, the review widget, analytics (aggregate usage statistics), and advertising conversion-measurement tags, which help us measure whether our ads work. We do not use cookies to build cross-site advertising profiles or sell data to ad networks. You can change or withdraw your choices at any time via the cookie settings link in the footer, and declining optional cookies never affects the scan or your results.
Our own usage measurement runs without cookies. Separately from the above, we count page visits ourselves, on our own servers. It sets no cookie, writes nothing to your browser’s storage, and does not fingerprint your device — so there is nothing for you to consent to, and it is not covered by the banner. It records the page visited, the referring website’s domain, your country, whether you are on desktop or mobile, and any campaign tag in the link you arrived from.
To count visitors without identifying them, we take your IP address and browser type and convert them into a one-way code using a secret key and the current date. We never store your IP address — it exists only for the instant it takes to compute that code. Because the date is part of the key, the code changes at midnight every night, so today’s visits cannot be linked to yesterday’s. This lets us count how many people visited on a given day while making it impossible for us — or anyone reading our database — to follow you over time or work backwards to who you are. Our lawful basis is legitimate interest (understanding how our own site is used). We do not share this data with anyone, and it is never used for advertising. Raw records are deleted after 180 days.
11. Children
Nullivo is not directed to children. We do not knowingly collect data from anyone under 16 (or the minimum age in your country). If you believe a child has used the service, contact us and we’ll delete the data.
12. Security
We encrypt data in transit, minimise what we store, hash verification codes, restrict internal access, and use reputable hosting and payment providers. No system is perfectly secure, but we work continuously to protect your data.
13. Data breaches
If a breach of your personal data occurs that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours where required, and inform affected users without undue delay.
14. Changes to this policy
We may update this policy as the service evolves. We’ll post the new version here with a revised effective date and, for material changes, notify you by email or in-app.
15. Contact
Questions or requests about privacy? Email privacy@nullivo.com or use the Contact page. To complain to a regulator in the UK: the Information Commissioner’s Office, ico.org.uk.