Niiwaa — Privacy Policy

Effective date: 2026-06-09 · Data controller: 2IS (Inbound Intelligence Solutions) · Contact: contact@niiwaa.com

This policy explains what personal data the Niiwaa mobile app (com.niiwaa.app) processes, why, and the rights you have. Niiwaa is a professional news-monitoring (“veille”) app: members of an organization review and rate articles relevant to their monitored topics.

1. Who the app is for

Niiwaa is a business application. You sign in with an account provisioned by your organization; there is no public self-registration. Your organization owns the monitoring data.

2. Data we process

CategoryExamplesWhy

Account & identity

email, name, user ID, company ID, role, languages

authenticate you, scope content to your company

Authentication

password (verified, never stored by the app), access & refresh tokens

secure sign-in and session

Session security

device label, IP address at sign-in

detect/limit suspicious sessions, audit

App activity

relevance votes on articles, notification & language preferences

core functionality, customization

Device identifier

Firebase Cloud Messaging (FCM) push token

deliver push notifications

Audit log

key actions (sign-in, device changes, account events), integrity-chained

security, traceability, compliance

Diagnostics (optional)

crash & error reports

consent (off by default)

We do not collect location, contacts, photos, financial or health data, or advertising identifiers, and we do not use your data to advertise or sell it.

3. On-device storage

Data cached on your device is stored in a fully encrypted local database (SQLCipher). The key is held in the operating system’s secure storage, excluded from OS backups, and wiped at logout.

4. Transmission

All traffic is encrypted in transit (HTTPS/TLS).

5. Who we share data with

Only with service providers acting on our instructions:

  • Google / Firebase Cloud Messaging — to deliver push notifications (receives the device push token).
  • Sentry — to receive crash/diagnostic reports, only if you enable diagnostics; reports are scrubbed of personal identifiers.
  • Our hosting/infrastructure provider — to operate the backend.

We do not otherwise share your personal data with third parties.

6. Retention

  • Account and monitoring data are retained while your account is active.
  • Account deletion: deactivated immediately and permanently deleted/anonymized after a 30-day grace period; monitoring data belonging to your company is retained by the company.
  • Audit records: tiered retention by event type (from 3 months up to 3 years).

7. Your rights

Subject to applicable law (incl. the GDPR) you may request access, rectification, erasure, restriction, portability, and objection. The app provides in-app account deletion and a data export (sent to your email). To exercise other rights, contact contact@niiwaa.com. You may also lodge a complaint with your data-protection authority (in France, the CNIL).

8.Children

Niiwaa is not intended for children and is not directed at users under 16.

9. Changes

We may update this policy; the “Effective date” above reflects the latest version. Material changes are surfaced in the app.

10. Contact

2IS (Inbound Intelligence Solutions) — contact@niiwaa.com


Niiwaa — Privacy policy

Effective date: 2026-06-09 · Data controller: 2IS (Inbound Intelligence Solutions) · Contact : contact@niiwaa.com

This policy describes the personal data processed by the mobile application Niiwaa (com.niiwaa.app), their purposes and your rights. Niiwaa is a professional monitoring application: members of an organization consult and evaluate articles related to their monitored themes.

1. Target audience

Niiwaa is a professional application. You log in with an account provided by your organization; there is no public registration.

2. Data processed

CategoryExamplesPurpose

Account & identity

email, name, user/company credentials, role, languages

authentication, partitioning by company

Authentication

password (verified, never stored by the app), access and refresh tokens

secure connection and session

Session Security

device label, IP address at connection

detection of suspicious sessions, audit

Application activity

relevance votes, notification and language preferences

operation, customization

Device ID

Firebase push token (FCM)

sending notifications

Audit log

key actions (login, device change, account events), integrity chaining

security, traceability, compliance

Diagnostics (optional)

crash and error reports

consent (disabled by default)

We do not collect not : location, contacts, photos, financial or health data, advertising identifiers. No advertising, no resale of data.

3. On-device storage

Cached data is stored in a local database fully encrypted (SQLCipher), key in the system's secure vault, excluded from backups, erased upon disconnection.

4. Transmission

All exchanges are encrypted in transit (HTTPS/TLS).

5. Subcontractors

  • Google / Firebase (FCM) — sending notifications (receives the push token).
  • Sentry — crash reports, only if you enable diagnostics; redacted of personal identifiers.
  • Our host — operation of the backend.

6. Preservation

  • Account data retained as long as the account is active.
  • Account deletion: immediate deactivation then deletion/anonymization afterwards 30 days ; the company's monitoring data is kept by it.
  • Audit logs: conservation by type of event (from 3 months to 3 years).

7. Your rights

In accordance with the GDPR: access, rectification, erasure, limitation, portability, opposition. The application offers the account deletion and a data export (via email). Other rights: contact@niiwaa.com. You can contact the CNIL.

8. Children

Niiwaa is not intended for minors under 16 years of age.

9. Changes

This policy may evolve; “Effective Date” indicates the latest version.

10. Contact

2IS (Inbound Intelligence Solutions) — contact@niiwaa.com