Privacy Policy
Last updated: 16 August 2026
Draft — pending legal review. This document is a working draft and not yet legal advice. It must be reviewed by a qualified lawyer, and the bracketed placeholders completed, before it is relied upon.
This Privacy Policy explains how Grandhosting Ltd (“Nokk”, “we”, “us”) collects, uses and protects information when you use the Nokk mobile app and website. Nokk is a network for verified local businesses to source urgently-needed supplies from other businesses nearby. We are committed to handling your data in line with the EU General Data Protection Regulation (GDPR).
Who we are
The data controller is Grandhosting Ltd, a private company registered in Cyprus under registration number HE 488909, of Lordou Vyronos 36, 1096 Nicosia, Cyprus, VAT CY60338088T. You can reach us for any privacy matter at support@nokk.gr.
We have not appointed a Data Protection Officer. We are not required to: we do not carry out large-scale monitoring, and we do not process special categories of data. You can raise any privacy question with us at the address above and a person will answer it.
Whose data this covers
Nokk is a service for businesses. Most of what we hold is company information, which is not personal data. But a sole trader is both a business and a person, and every account has a named contact — so parts of what we hold are personal data and this policy treats them that way throughout.
What we collect
- Business & account details — business name, category, area and address, VAT number, contact first and last name, email, and a password (stored only as a cryptographic hash, never in readable form).
- Content you create — requests, offers, chat messages, photos and ratings.
- Location — the coordinates you set for your business and for each request, and the search radius you choose. Used to match you with nearby businesses.
- Product data — the stock you add by hand, import from a file, or connect through a product feed.
- Technical data — a device identifier issued by the push-notification service, and records of which notifications were sent to you.
- Crash reports — when the app or the site hits an error we record what went wrong, along with your business ID so we can tell whose problem it is. Deliberately not included: your name, email, VAT number, IP address, or any screen recording or screenshot. Chat messages and addresses are never sent.
We do not collect payment card details, bank details, or any special category of data (health, biometrics, political opinions and the like). We do not run advertising and we do not track you across other websites or apps.
Legal basis for each purpose
Under Article 6 GDPR we must have a lawful basis for each thing we do with your data. They are:
- Running the service — posting requests, delivering them to nearby businesses, offers, chat, bookings, ratings. Basis: performance of our contract with you (Art. 6(1)(b)).
- Verifying your VAT number against the EU VIES registry before approving your account. Basis: legitimate interests (Art. 6(1)(f)) — a closed network only works if members are real businesses.
- Sending you notifications about nearby requests, offers and deal progress. Basis: performance of our contract — these are the service, not marketing. You can switch off availability, and you can turn notifications off in your device settings.
- Security, fraud prevention, moderation and handling reports of abuse. Basis: legitimate interests (Art. 6(1)(f)).
- Crash and error reporting to keep the service working. Basis: legitimate interests (Art. 6(1)(f)), balanced by collecting the minimum described above.
- Invoicing and accounting once commission becomes payable. Basis: legal obligation (Art. 6(1)(c)).
Where we rely on legitimate interests, we have weighed them against your rights and concluded they do not override them. You can object to any of it — see Your rights below.
Automated decision-making
We do not make decisions about you by automated means that produce legal or similarly significant effects, and we do not profile you. Matching a request to nearby businesses is done by distance and stock, and it decides which requests you are shown — nothing about your rights, your rate, or your standing.
Sharing
Your business name, category, area, ratings and offers are shown to other verified businesses as part of the service. Your exact address is only revealed once you accept an offer — and that rule is enforced in our database, not merely in the app, so it cannot be bypassed by using the service in an unintended way.
We share data with the following processors, who act only on our instructions. We do not sell your data and we never share it for advertising.
- Supabase — database and file storage. EU (Frankfurt).
- Vercel — hosting for this website and the merchant dashboard.
- Expo — delivery of push notifications to your device.
- Sentry — crash and error reporting. EU region.
- Resend — sending service emails such as account and alert messages.
- EU VIES registry — VAT number validation, operated by the European Commission.
We may also disclose data where the law requires it, or to establish, exercise or defend legal claims.
International transfers
Your account data, content and crash reports are stored on EU-based infrastructure. Some of our processors are companies established in the United States, and a limited amount of data reaches them: Expo receives the device token and the notification text needed to deliver a push, and Resend receives the email address and content of service emails we send you.
Where data is transferred outside the European Economic Area, it is covered by the European Commission’s Standard Contractual Clauses or an equivalent safeguard under Chapter V GDPR. You can ask us for details of the safeguards that apply.
Storage & security
Data is encrypted in transit and at rest. Access is controlled per business at the database level, so one business cannot read another’s requests, offers, chats or stock even if the app is bypassed. Chat photos are private to the two businesses in that conversation and are served through short-lived links rather than public addresses. Passwords are stored only as hashes and cannot be recovered by us or by anyone else.
If a personal data breach occurs that is likely to result in a risk to your rights, we will notify the Office of the Commissioner for Personal Data Protection in Cyprus within 72 hours of becoming aware of it, and will tell you directly where the risk to you is high.
Cookies
We use a small number of strictly necessary cookies and equivalent local storage, and nothing else. They keep you signed in to the dashboard, keep your session secure, and remember your language choice.
We do not use analytics, advertising or tracking cookies, and we do not share cookie data with anyone. Because these cookies are strictly necessary to provide a service you have asked for, no consent banner is required under the ePrivacy Directive — but you can clear or block them in your browser, which will sign you out.
Your device
If you enable the app lock, your fingerprint or face data is checked by your phone’s own operating system and never leaves your device — we neither receive nor store it. We only store whether the lock is switched on.
The app asks for your location so it can centre the map on your business and match you with nearby requests. It is optional: decline it and the app still works. Location is read when you use those features, never continuously in the background.
Product feeds
If you connect a product feed, we fetch the file from the address you provide on a schedule and store the product data it contains so your stock stays current. We fetch only that address, and you can disconnect the feed at any time.
Your rights
Under the GDPR you have the right to:
- Access the personal data we hold about you, and receive a copy (Art. 15).
- Correct anything inaccurate — most of it you can edit yourself in the app (Art. 16).
- Erase your data (Art. 17). You can do this yourself: Account → Delete account removes your business profile, requests, offers, bookings, chats and ratings immediately.
- Restrict or object to processing based on legitimate interests (Arts. 18 and 21).
- Portability — receive your data in a structured, machine-readable format (Art. 20).
- Withdraw consent at any time, where we rely on consent.
Write to support@nokk.gr and we will respond within one month, as Article 12 requires. Exercising these rights is free; we will tell you in advance in the rare case a request is manifestly excessive.
You may also lodge a complaint with a supervisory authority — either the Office of the Commissioner for Personal Data Protection in Cyprus, where Nokk is established, or the authority in your own country. In Greece that is the Hellenic Data Protection Authority (Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα).
How long we keep it
- While your account is active — we keep your account, content and history.
- If you cancel — your account is paused and its data retained for 12 months so you can reactivate without losing your listings and history. After that it is deleted.
- If you delete your account — removal is immediate. Some content is unavoidably retained in the other party’s records: a message you sent stays in their conversation, and a completed deal stays in their history, because it is their data too.
- Notifications — pruned automatically on a rolling basis.
- Invoices and the accounting records supporting them — retained for six years, the period required of Cypriot companies by the Assessment and Collection of Taxes Law. This obligation overrides a deletion request for those specific records, as Article 17(3)(b) GDPR permits.
Children
Nokk is a service for businesses and is not intended for anyone under 18.
Changes
We may update this policy. Material changes will be notified in the app or by email before they take effect, and the date at the top of this page always shows the current version.
Contact
Grandhosting Ltd, Lordou Vyronos 36, 1096 Nicosia, Cyprus — support@nokk.gr
Questions about this document? Contact us at support@nokk.gr.