We use cookies to understand how visitors use this site and to improve it. Analytics stays off unless you accept. See our Privacy Policy.

Privacy Policy

Last updated: June 22, 2026

This Privacy Policy describes how Nevee collects, uses, shares and protects personal data when you use our websites and the Nevee platform.

1. Who we are

Nevee ("Nevee", "we", "us") provides software for schools and institutions, including Nevee Connect (admissions CRM) and related modules, available at neveeos.com and suite.neveeos.com (the "Service"). This Policy explains how we handle personal data.

2. Controller and processor roles

For information about visitors to our websites and our own account holders, Nevee acts as a data controller.

For the lead, contact, student, parent and message data that a school or institution ("Customer") loads into or receives through the Service, the Customer is the data controller and Nevee acts as a data processor, processing that data only on the Customer's documented instructions and on their behalf. The Customer is responsible for having a lawful basis and any necessary consents for that data.

3. Information we collect

  • Account data: name, email, role, school details, and authentication data.
  • Customer data (processed on the Customer's behalf): enquiry and lead details, contact names, phone numbers, email addresses, messages from Facebook, Instagram and WhatsApp, and any information the Customer chooses to store.
  • Messaging metadata from Meta platforms (e.g., page-scoped IDs, conversation timestamps, ad/campaign attribution) used to deliver inbox and attribution features.
  • Usage and technical data: log data, device/browser information, IP address, and cookies necessary to run and secure the Service.
  • Billing data: plan, transactions and status. Card details are handled by our payment processors and are never stored by Nevee.

4. How we use information

We do not sell personal data, and we do not use Customer data to train generative AI models or for advertising.

  • To provide, operate, secure and improve the Service.
  • To authenticate users and prevent fraud or abuse.
  • To communicate about the Service, including service and security notices.
  • To process the Customer data strictly as instructed by the Customer.
  • To comply with legal obligations and enforce our Terms.

5. Legal bases (where GDPR applies)

We rely on: performance of a contract (to provide the Service); legitimate interests (to secure and improve the Service); consent (where required); and legal obligation. Customers determine the legal basis for the Customer data they control.

6. Sharing and sub-processors

We share data only with service providers that help us run the Service, under contractual confidentiality and data-protection obligations. Current sub-processors include: Supabase (database, authentication and hosting), Vercel (application hosting), Meta Platforms (Facebook/Instagram/WhatsApp messaging and lead APIs), and our payment processors. We may also disclose data where required by law or to protect our rights and users.

7. Meta platform data

When a Customer connects Facebook, Instagram or WhatsApp, we access only the data needed to deliver leads and messages (such as lead form submissions and conversations) in accordance with Meta's Platform Terms and Developer Policies. We use this data solely to provide the Service to that Customer and retain it only as needed for those features.

8. International transfers

Data may be processed in countries other than yours. Where required, we use appropriate safeguards (such as standard contractual clauses) for international transfers.

9. Data retention

We retain account and Customer data for as long as the account is active and as needed to provide the Service. Customers may request deletion of Customer data; we will delete or return it within a reasonable period after account termination, subject to legal retention requirements and routine backup cycles.

10. Security

We use industry-standard measures including encryption in transit, row-level access controls, role-based permissions, and least-privilege access. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

11. Children and student data

The Service is intended for use by schools and institutions, not by children. Where a Customer stores information about students who may be minors, the Customer is the controller of that data and is responsible for obtaining any consent required by law. We do not knowingly collect personal data directly from children.

12. Your rights

Depending on your location, you may have rights to access, correct, delete, port, or restrict your personal data, and to object to certain processing (GDPR), or to know, delete, correct and opt out of "sale"/"sharing" (CCPA/CPRA — note we do not sell or share personal data as defined). To exercise rights, contact us using the details below. If your data is held by Nevee on behalf of a Customer, we will refer your request to that Customer.

13. Cookies

We use only the cookies and local storage necessary to run the Service (such as keeping you signed in). We do not use third-party advertising cookies.

14. Changes to this Policy

We may update this Policy from time to time. Material changes will be posted here with a new "Last updated" date and, where appropriate, communicated to account holders.

15. Contact

Questions or requests: support@neveeos.com.