Updated 23 September 2026. Security · Subprocessors · Data Processing Agreement · Privacy Policy
Studios trust Naayya with their business and their customers’ data. This page summarises how we protect it.
Data hosting in the EU
Your database and uploaded files are hosted in Frankfurt, Germany. Backups are stored separately, within the EU.
Encryption
Data is encrypted in transit with TLS and at rest, including backups.
Access control
Access to customer data is limited to authorised staff who need it for their work, and multi-factor authentication is required on our systems.
Backups and recovery
Your data is backed up daily to separate, encrypted storage in the EU, and we test restoration. Retention periods are available to business customers under the DPA.
Payments
Card payments are processed by Stripe, a PCI DSS Level 1 certified provider. Card details are never stored on Naayya servers.
Secure development
Changes are reviewed and tested before release, with automated checks for exposed secrets and vulnerable dependencies.
Incident response
We maintain a documented incident response plan. If a personal-data breach affects your business, we notify you without undue delay.
Policies and assessments
Naayya maintains a written Information Security Policy and Incident Response Plan. We take part in the SME cybersecurity programme of Luxembourg’s National Cybersecurity Competence Center (NC3), including its CyberCheck assessment.
Your part in security
Businesses control who on their team has access, and should give each person their own login and keep their devices secure. Card details entered in Stripe’s payment fields are protected by Stripe.
Reporting a vulnerability
If you believe you have found a security issue, email support@naayya.com with the subject “Security” and enough detail to reproduce it. We acknowledge reports within three business days. Please do not access other people’s data, disrupt the service or disclose the issue publicly before we have had a reasonable chance to fix it. We will not take legal action over good-faith research that follows these rules.
See our subprocessor list for the providers we use. Our Data Processing Agreement and your service agreement are the binding terms; this page is a summary.