01Our approach
Nuvio runs the entire guest journey — ticketing, F&B, retail, loyalty and operations — through one data model. That concentration is powerful, and it raises the bar for how the data is protected. We design for residency, least-privilege access and resilience from the ground up, so that a Client can grow across venues and regions without losing control of where their data sits or who can reach it.
02Regional data residency
Data residency in Nuvio means a Client’s data is stored and processed within a chosen region, and stays there. For Clients in the GCC, this includes in-region residency built to meet local requirements by default rather than by exception. The applicable region for a deployment is set out in the Client’s order.
03Sovereign Stack
Sovereign Stack is our deployment option for Clients who need strict control over their infrastructure and data. It provides:
- Regional hosting: data stored and processed inside the Client’s jurisdiction.
- Compliance built in: GCC residency and regulatory requirements applied by default, not configured after the fact.
- Access control: the Client decides who can touch their data, and when.
- Isolation: for Clients with strict segregation needs, a dedicated deployment keeps compute and data separated to their requirements.
04Cross-border transfers
Where a deployment is region-locked, data does not leave that region in the normal course of providing the Services. For arrangements that are not region-locked, we and our sub-processors may process data in more than one country. When personal data crosses borders, we apply appropriate safeguards — such as standard contractual clauses or equivalent mechanisms recognised under applicable law — so a comparable level of protection travels with the data. See the Privacy Policy for how this fits into our overall data handling.
05Infrastructure & uptime
The Services run on reliable cloud infrastructure with redundancy across availability zones. We target high availability for production workloads, with any committed service levels set out in the applicable order or service-level schedule. Live venues can’t wait for yesterday’s systems, so the platform is built to keep the gate moving even under peak load.
06Encryption
Data is encrypted in transit using current TLS standards, and encrypted at rest using strong, industry-standard algorithms. Keys are managed through a dedicated key-management service with rotation and restricted access.
07Access control
Access to systems and data follows the principle of least privilege. Internal access is role-based, granted only where needed, logged, and reviewed periodically. Administrative access requires strong authentication, including multi-factor authentication. Client-side, administrators control Authorized Users, roles and permissions within their own environment.
08Payment security
Card payments and payouts are handled by established payment providers. Nuvio does not store full card numbers; sensitive cardholder data is processed within the payment provider’s environment, and we retain only limited, non-PCI transaction metadata needed to operate the Services.
09Monitoring & resilience
We monitor the platform for availability, performance and security events, and maintain backups and recovery procedures designed to restore service and data after disruption. Just as the platform senses a queue before it forms, we watch for operational and security pressure before it reaches Clients.
10Incident response
We maintain an incident-response process to detect, contain, investigate and remediate security incidents. Where an incident affects personal data, we will notify affected Clients and, where required, regulators, in line with applicable law and our contractual commitments — with the information needed to meet their own obligations.
11Sub-processors
We use a limited set of vetted sub-processors — such as hosting, payment and communications providers — to deliver the Services. Each is bound by contract to protect data and to process it only as instructed. A current list of sub-processors is available to Clients on request, and we provide a means to be informed of changes as set out in our Data Processing Terms.
12Compliance
We align our controls with recognised security and privacy practices and applicable regional regulation, including GCC data-protection requirements. Where we hold formal certifications or attestations, we will name them here and make relevant reports available to Clients under confidentiality.
| Area | Position |
|---|---|
| Regional regulation | Designed to meet GCC data-protection and residency requirements; specifics depend on deployment. |
| Certifications | To be listed once verified — claim only what is held and current. |
| Audit reports | Available to Clients under NDA where applicable. |
| Data processing | Governed by the Data Processing Terms referenced in the order. |
14Report a security issue
Found a vulnerability or have a security question? Email us at support@tonomous.io and we’ll route it to the right team. Please include enough detail to reproduce the issue, and give us a reasonable opportunity to investigate before any public disclosure.
Tonomous.IO — registered entity name and address to be confirmed before publication.