Privacy Policy
This policy covers two separate things: this website, and the internal applications Neravo Systems operates that connect to third-party APIs on our own behalf.
This website
This site is static. It sets no cookies, includes no analytics, loads no third-party scripts or fonts, and has no forms. It does not collect personal information from visitors. Our hosting provider may record standard server request logs, which we do not control, combine with other data, or use for any purpose of our own.
Google user data
What the application does
Neravo Systems operates an internal, automated backup service. It uses Google OAuth to obtain access to a Google Drive account that we ourselves own, so that the service can store and manage backup copies of data from systems we operate.
The service runs unattended on a schedule. There are no end users signing in: the only Google Account involved is our own, and the only data written is the backup archives the service produces.
What it accesses, and why
Within the designated Drive folder, the service performs exactly these operations:
- Create — upload a compressed backup archive.
- Read — download an archive it has just uploaded, to verify that the stored copy is intact and can be restored.
- List — enumerate existing backup archives so retention can be applied.
- Delete — remove archives older than the retention limit.
Access is limited to what those functions require. The service does not read, index, or process unrelated files, and it does not access Gmail, Contacts, Calendar, Photos, or any other Google service.
How Google user data is used
- It is used only to store, verify, and manage backups of systems we operate.
- It is not sold, and never will be.
- It is not used for advertising, ad targeting, or personalisation of any kind.
- It is not used to train generalised artificial-intelligence or machine-learning models.
- It is not transferred to third parties, except as strictly necessary to provide the service, to comply with applicable law, or as part of a merger or acquisition — in which case this policy, or a successor at least as protective, continues to apply.
- No human reads the data, other than our own authorised personnel where required to operate the service, resolve a fault, comply with the law, or where the data has been aggregated and made non-identifiable.
Neravo Systems' use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Credentials and tokens
The OAuth client credentials and refresh token used by the service are stored as encrypted secrets in our deployment platform and are injected into the automated job at run time. They are not present in this website, in any page or script it serves, or in any public source repository. Our automation is written not to print them, and its logs are checked so that connection strings and tokens do not appear in output.
Access can be revoked at any time from the Google Account permissions page, which immediately stops the service from reaching Drive.
Retention
Backup archives are kept in the Drive folder up to a fixed retention count, currently the most recent eight weekly archives. Older archives are deleted automatically once a newer archive has been stored and verified. Deletion is never performed before a replacement has been confirmed restorable. Access tokens are short-lived and held only in memory for the duration of a job; the refresh token is retained until it is rotated or revoked.
Security
Data is transmitted over TLS to Google's APIs. Credentials are held as encrypted secrets rather than in source code, and the automation is restricted to the specific project and folder it is configured for, with a check that refuses to run if it is pointed anywhere else.
We do not claim that any system is immune to compromise. No provider can guarantee absolute security, and we make no such guarantee here. What we state is what we do: least access necessary, secrets kept out of source and out of logs, and backups that are verified rather than assumed.
Your rights
The Google Account used by this service belongs to Neravo Systems, so no third party's Google data is involved. If you believe personal data relating to you is held in a system we operate on behalf of a client, that client is the data controller and requests should be directed to them; we will assist them in responding.
Changes to this policy
If this policy changes materially, the date at the top of this page will be updated. Continued operation of the service after a change indicates the practices described here as of that date.
Contact
Questions about this policy, or about data handled by a service we
operate:
contact@neravosystems.com