Nezzo.
Draft — this document is being finalised and may change before Nezzo launches.
Last updated [date the final version takes effect]

Privacy Policy

This policy explains what personal data Nezzo collects, why, who it is shared with, and the rights you have. Nezzo is operated by Mladen Dragic, trading as Momento Perfumery.

1. Who is responsible for your data

Mladen Dragic ([Registered business address]; [Company / registration number, if any]) is the controller of the personal data described in this policy. You can reach us at support@nezzolab.com.

When you enter information about your own clients into Nezzo (for example their names and contact details for commissions), you are the controller of that data and we process it on your behalf — see section 6.

2. What we collect

  • Account data: your email address and a password, which is stored only as a secure hash by our authentication provider — we never see it. If you sign in with Google, we receive your name, email address and profile picture from Google.
  • Content you create: formulas, materials, accords, inventory and costs, dilutions, batches and yields, strip tests, evaluation notes, compliance records (such as PIF checklists and constituent data) and anything else you save in the app.
  • Business details you choose to add: studio name, address, tax ID and invoice notes.
  • Your clients' data, if you use the business tools: names, email addresses, phone numbers, notes and commission details that you enter.
  • Connected shops: if you connect a storefront (such as Shopify), the access credentials you provide and order data we sync — order numbers, dates, totals, taxes and line items. We do not store your shoppers' names or addresses.
  • Billing data: your plan, subscription status and a customer reference from our payment provider. Payments are handled by Paddle, our merchant of record: your card or other payment details, billing address and tax details are entered on and held by Paddle, and we never receive them.
  • Usage data: daily counts of AI feature use (to apply fair-use limits), and technical logs kept by our hosting providers for security and troubleshooting.

3. Documents and AI features

When you import a document (a formula sheet, invoice, SDS or CoA) or use the assistant, the file or message is sent to our AI provider, Anthropic, to read it and return a result. Nezzo does not store the uploaded file itself — only the results you review and choose to save.

Anthropic processes this data under its commercial terms. [Confirm and state Anthropic's current retention period and that API data is not used to train models, per the terms in force.]

Please don't upload documents containing personal data that isn't needed for the task.

4. Why we use your data, and our legal basis

  • To provide the service you signed up for — your account, your saved work, calculations, exports and integrations (performance of a contract).
  • To take payments and keep billing records (performance of a contract; legal obligations such as tax record-keeping).
  • To keep the service secure, prevent abuse and apply usage limits (our legitimate interest in running a safe, sustainable service).
  • To send service emails you need, such as account confirmation and password reset (performance of a contract).

We do not sell your data, use it for advertising, or send marketing email. If we ever want to, we will ask for your consent first.

5. Who we share data with

We use these service providers (processors), who may only use your data to provide their service to us:

  • Supabase — database, authentication and file storage. Data is hosted in [Supabase project region, e.g. EU (Frankfurt)].
  • [Vercel — web hosting (once the app is deployed there).]
  • Paddle — our reseller and merchant of record for subscriptions. Paddle sells Pro to you, takes payment, handles sales tax and VAT, and issues receipts and refunds. For payment data it acts as an independent controller under its own privacy policy (paddle.com/legal/privacy). We share your email address and Nezzo account reference with Paddle so your purchase is linked to your account.
  • Anthropic — AI processing for document import and the assistant.
  • [Resend — sending account emails (once enabled).]
  • Google — only if you choose to sign in with Google.

If you connect a storefront or other integration, data is exchanged with that platform on your instruction, under its own terms and privacy policy.

The shop directory used to find stockists is shared between users. Shops you add to it (their public business details) are visible to other users, without your name. Your answers on whether a shop carries indie brands are only shown to others as totals. Shop listings come from OpenStreetMap (© OpenStreetMap contributors, Open Database Licence).

We may disclose data where the law requires it, or to protect our rights, our users or the public.

6. Your clients' data (Nezzo as processor)

For personal data you enter about your own clients, you act as the controller and we act as your processor. We process that data only to provide Nezzo to you and on your instructions; keep it confidential; use only the providers listed in section 5; help you respond to your clients' data requests; and delete it when you delete it or close your account.

You are responsible for having a lawful basis to store your clients' data and for informing them as required. [If you need a signed data processing agreement, contact support@nezzolab.com.]

Client approval links you share give anyone with the link access to that commission's preview. Only share them with the intended client.

7. International transfers

Some of our providers process data outside [your country / the EEA]. Where they do, the transfer is protected by appropriate safeguards such as the European Commission's Standard Contractual Clauses. [Confirm for each provider.]

8. How long we keep data

  • Your account and content: for as long as your account is open.
  • After you delete your account: removed from our live systems within 30 days, and from backups when they expire [state backup retention].
  • Billing records: for as long as tax and accounting law requires [state period, e.g. 10 years].
  • AI usage counts: kept per day to apply limits [state period, e.g. 90 days].

9. Your rights

Depending on where you live, you have the right to access your data, correct it, delete it, receive a copy in a portable format, restrict or object to certain processing, and withdraw consent where processing is based on consent.

You can correct most data directly in the app, download a copy of all of it, or delete your account and all its data, under Business → Account → Your data. For anything else, email support@nezzolab.com; we will respond within one month.

You also have the right to complain to a data protection authority — for us, the Office of the Privacy Commissioner of Canada, or the Office of the Information and Privacy Commissioner for British Columbia.

10. Cookies and local storage

Nezzo uses only essential cookies, which keep you signed in. We do not use analytics, advertising or tracking cookies.

The app also stores a little data in your own browser (local storage) — for example, your progress while weighing a batch in Lab Mode, so it survives a page reload. It stays on your device.

11. Security

Data is encrypted in transit, each user's records are isolated by database access rules, and access to production systems is restricted. No system is perfectly secure; if a breach affects your personal data, we will notify you and the authorities as the law requires.

12. Children

Nezzo is a professional tool and is not intended for anyone under 18. We do not knowingly collect data from children.

13. Changes to this policy

If we make material changes, we will notify you by email or in the app before they take effect. The date at the top shows when this policy was last updated.