NNuvio
A Tonomous.IO platform

Data Residency & Compliance

Your data. Your region. Your control.

Sovereignty isn’t a feature we bolt on later. This page explains how Nuvio hosts, secures and governs data — where it lives, who can reach it, and the controls that keep growth from running ahead of governance.

Last updated: 15 July 2026 Applies to: the Nuvio platform and Tonomous.IO infrastructure

01Our approach

Nuvio runs the entire guest journey — ticketing, F&B, retail, loyalty and operations — through one data model. That concentration is powerful, and it raises the bar for how the data is protected. We design for residency, least-privilege access and resilience from the ground up, so that a Client can grow across venues and regions without losing control of where their data sits or who can reach it.

02Regional data residency

Data residency in Nuvio means a Client’s data is stored and processed within a chosen region, and stays there. For Clients in the GCC, this includes in-region residency built to meet local requirements by default rather than by exception. The applicable region for a deployment is set out in the Client’s order.

Residency governs where data lives and is processed. It works alongside — not instead of — the access controls, encryption and monitoring described below.

03Sovereign Stack

Sovereign Stack is our deployment option for Clients who need strict control over their infrastructure and data. It provides:

  • Regional hosting: data stored and processed inside the Client’s jurisdiction.
  • Compliance built in: GCC residency and regulatory requirements applied by default, not configured after the fact.
  • Access control: the Client decides who can touch their data, and when.
  • Isolation: for Clients with strict segregation needs, a dedicated deployment keeps compute and data separated to their requirements.

04Cross-border transfers

Where a deployment is region-locked, data does not leave that region in the normal course of providing the Services. For arrangements that are not region-locked, we and our sub-processors may process data in more than one country. When personal data crosses borders, we apply appropriate safeguards — such as standard contractual clauses or equivalent mechanisms recognised under applicable law — so a comparable level of protection travels with the data. See the Privacy Policy for how this fits into our overall data handling.

05Infrastructure & uptime

The Services run on reliable cloud infrastructure with redundancy across availability zones. We target high availability for production workloads, with any committed service levels set out in the applicable order or service-level schedule. Live venues can’t wait for yesterday’s systems, so the platform is built to keep the gate moving even under peak load.

06Encryption

Data is encrypted in transit using current TLS standards, and encrypted at rest using strong, industry-standard algorithms. Keys are managed through a dedicated key-management service with rotation and restricted access.

07Access control

Access to systems and data follows the principle of least privilege. Internal access is role-based, granted only where needed, logged, and reviewed periodically. Administrative access requires strong authentication, including multi-factor authentication. Client-side, administrators control Authorized Users, roles and permissions within their own environment.

08Payment security

Card payments and payouts are handled by established payment providers. Nuvio does not store full card numbers; sensitive cardholder data is processed within the payment provider’s environment, and we retain only limited, non-PCI transaction metadata needed to operate the Services.

09Monitoring & resilience

We monitor the platform for availability, performance and security events, and maintain backups and recovery procedures designed to restore service and data after disruption. Just as the platform senses a queue before it forms, we watch for operational and security pressure before it reaches Clients.

10Incident response

We maintain an incident-response process to detect, contain, investigate and remediate security incidents. Where an incident affects personal data, we will notify affected Clients and, where required, regulators, in line with applicable law and our contractual commitments — with the information needed to meet their own obligations.

11Sub-processors

We use a limited set of vetted sub-processors — such as hosting, payment and communications providers — to deliver the Services. Each is bound by contract to protect data and to process it only as instructed. A current list of sub-processors is available to Clients on request, and we provide a means to be informed of changes as set out in our Data Processing Terms.

12Compliance

We align our controls with recognised security and privacy practices and applicable regional regulation, including GCC data-protection requirements. Where we hold formal certifications or attestations, we will name them here and make relevant reports available to Clients under confidentiality.

AreaPosition
Regional regulationDesigned to meet GCC data-protection and residency requirements; specifics depend on deployment.
CertificationsTo be listed once verified — claim only what is held and current.
Audit reportsAvailable to Clients under NDA where applicable.
Data processingGoverned by the Data Processing Terms referenced in the order.

13Shared responsibility

Security is a partnership. We secure the platform, infrastructure and the controls described here. Clients are responsible for how they configure the Services — managing their Authorized Users and permissions, protecting credentials, and ensuring the data they submit is collected and used lawfully. The strongest outcomes come from both sides holding their part.

14Report a security issue

Found a vulnerability or have a security question? Email us at support@tonomous.io and we’ll route it to the right team. Please include enough detail to reproduce the issue, and give us a reasonable opportunity to investigate before any public disclosure.

Tonomous.IO — registered entity name and address to be confirmed before publication.