Privacy Policy
Last updated 9 July 2026
This policy explains how Nellio(“we”) handles personal data in connection with Nellio. We act as a data controller for your account and our own use of the service, and as a data processor for the client information you enter to manage your bookings. For that client data, you are the controller.
1. Data we collect
- Account data — your name, business name, email, category and booking-page settings.
- Client data you enter — your clients’ names, email addresses and booking details.
- Payment data — processed by Stripe. We receive transaction metadata (amount, status, identifiers) but not full card numbers.
- Usage data — basic technical information such as log data needed to run and secure the service.
2. How we use it
We use personal data to:
- provide and operate Nellio, including booking pages and payment links;
- send transactional emails (e.g. booking links and confirmations);
- take subscription payments and prevent fraud;
- provide support and improve the service;
- meet legal and accounting obligations.
3. Legal bases (UK GDPR)
We rely on: contract (to provide the service you sign up for), legitimate interests (to secure, support and improve the service), legal obligation(e.g. tax records), and consent where required (e.g. certain communications).
4. Service providers we share with
We use trusted sub-processors to run the service, including:
- Clerk — authentication and account management.
- Convex — application database and backend hosting.
- Stripe — payment processing.
- Resend — transactional email delivery.
- Google — optional calendar integration, only if you connect it.
We do not sell personal data.
5. Data retention
We keep account and booking data for as long as your account is active and as needed to provide the service. After closure we delete or anonymise data within a reasonable period, except where we must retain it for legal, accounting or fraud-prevention reasons.
6. Your rights
Under UK GDPR you have rights to access, correct, delete, restrict or object to processing of your personal data, and to data portability. To exercise these, email rehans.axis@gmail.com. You can also complain to the UK Information Commissioner’s Office (ico.org.uk). If your request concerns data we process on a business’s behalf, we will refer you to that business as the controller.
7. International transfers
Some providers may process data outside the UK/EEA. Where they do, we rely on appropriate safeguards such as adequacy decisions or standard contractual clauses.
8. Security
We use technical and organisational measures to protect personal data, including encryption in transit and access controls. No system is perfectly secure, but we work to keep your data safe and will notify you of a breach where the law requires.
9. Cookies
We use essential cookies needed to sign you in and keep the service working. We do not use the service for advertising tracking.
10. Changes & contact
We may update this policy and will revise the date above when we do. Questions or requests? Contact rehans.axis@gmail.com.