1. General information
This notice describes how BETA Technologies SRL, as controller for the processing activities under its responsibility, collects, uses, stores, protects and shares personal data belonging to users of the Nebulas ERP software.
Nebulas is intended primarily for companies, professionals and organisations. It manages customers and suppliers, quotations, orders, invoicing, payments, products, services, inventory, documents, communications and appointments, and may integrate with Google Authentication, Gmail, Google Drive and Google Calendar.
2. Data controller
| Item | Detail |
|---|---|
| Legal name | BETA Technologies SRL |
| Registered office | Via Predda Niedda 22/B, 07100 Sassari, Italy |
| EU VAT number | IT02412440907 |
3. Privacy roles when using Nebulas
For data entered by users on behalf of their organisation, the Nebulas customer normally determines the purposes and essential means of processing and acts as controller. BETA Technologies SRL normally acts as processor under Article 28 GDPR, subject to the applicable contract and data processing agreement.
For its own purposes—including contract management, platform security, account administration and legal compliance—BETA Technologies SRL acts as an independent controller.
4. Categories of data processed
Account data includes name, contact details, organisation, role, permissions, authentication identifiers, preferences and login events. Business data may include identification, tax and contact details; quotations, orders, contracts, invoices and payments; products, inventory, documents, notes, communications and appointments.
Technical and security data includes IP and session identifiers, browser and device information, operation dates, features used, authentication and synchronisation logs, security events, errors and diagnostics. Support requests may contain contact details, communications, screenshots, files and the technical information needed to resolve the issue.
The customer is responsible for the lawfulness, accuracy, relevance and updating of data entered into Nebulas and for information supplied to data subjects.
5. Data obtained through Google and Google Workspace
Users may connect a Google account through OAuth 2.0 and OpenID Connect to authenticate and enable specific integrations. Access takes place only after the Google consent screen has displayed the requested permissions and the user has authorised them. Nebulas requests only the scopes required by enabled features.
5.1 Google Authentication
“Sign in with Google” may provide the unique Google account identifier, name, verified email address, profile picture and basic information shown on the consent screen. Nebulas uses this information to identify the user, create or associate an account, manage the session and prevent unauthorised access. It does not receive or store the Google password.
5.2 Gmail
Within authorised scopes, Nebulas may access addressing fields, message subject and body, headers, metadata, dates, labels, status, threads, identifiers, attachments, drafts and information needed to send messages.
Enabled features may display and search business messages, associate messages and attachments with ERP records, import selected content, create drafts, send, reply to or forward messages, update labels or status and synchronise necessary information.
Gmail data is not used for personalised advertising, sale of data, unsolicited commercial profiling, creditworthiness assessment or general-purpose AI model training. Messages and attachments are stored only when required for a requested feature or association with a business record.
5.3 Google Drive
Within authorised scopes, Nebulas may access file and folder names, identifiers, types, sizes, dates, owners, sharing permissions, metadata, links, folder structure and the content of selected, created or otherwise accessible files.
Enabled features may select, import, associate, create, export, update, replace, share or expressly delete files. Where technically possible, access is limited to files created or selected through the application, for example through the drive.file scope and Google selection tools.
5.4 Google Calendar
Within authorised scopes, Nebulas may access calendar names and settings and event titles, descriptions, dates, times, time zones, locations, organisers, attendees, attendance status, free/busy availability, recurrence, reminders, attachments, conferencing links and identifiers.
Enabled features may display availability, synchronise, create, modify or delete events, invite attendees, update attendance, manage recurrences and associate events with business activities or records.
5.5 Tokens and authorisation information
To keep integrations active, Nebulas may store protected access and refresh tokens, connected-account identifiers, granted scopes, integration status, last synchronisation date and technical errors. Tokens are used only to communicate with authorised Google APIs.
6. Purposes and legal bases
| Item | Detail |
|---|---|
| Service provision | Contract or pre-contractual measures |
| Security and abuse prevention | Legitimate interest and legal obligations |
| Support and service communications | Contract and legitimate interest |
| Administration and legal compliance | Legal obligation and legitimate interest |
| Service improvement | Legitimate interest; consent where required |
| Commercial communications | Consent or another basis permitted by law |
7. Use and protection of Google data
Use of information received from Google APIs complies with the Google API Services User Data Policy and Limited Use requirements. Google data is used only to provide or improve user-requested features that are visible in the application.
- Only permissions needed for available features are requested.
- Google data is not sold, licensed to data brokers or advertising platforms, or used for personalised advertising or incompatible purposes.
- Internal access is limited to people and systems that genuinely require it.
- Data is retained only as necessary and then deleted or anonymised, subject to legal or contractual obligations.
7.1 Human access and artificial intelligence
Personnel do not normally access Google email, file or calendar content. Human access may occur only with explicit support consent, to resolve a reported issue, investigate security incidents or fraud, meet a legal requirement, or where data has been aggregated or anonymised.
Google data is not used to train general-purpose AI models. If a user-requested AI feature processes Google data, processing is limited to that feature and necessary data; providers are bound by data-protection and use-limitation duties. Training use would require separate explicit consent and an updated notice.
8. Recipients and data sharing
Processors are appointed where required. Google data is not transferred to advertising platforms, data brokers or parties that use it for independent commercial purposes.
- Hosting, cloud infrastructure, backup and security providers.
- Google, for authentication and authorised APIs.
- Email, communication, monitoring and support providers.
- Technical, legal, tax and administrative advisers.
- Affiliated companies or partners involved in service delivery.
- Public, judicial or supervisory authorities where required by law.
9. International transfers
Where providers process data outside the European Economic Area, the controller uses safeguards under Articles 44 and following GDPR, such as adequacy decisions, Standard Contractual Clauses, the Data Privacy Framework where applicable and supplementary measures.
10. Processing and security
No system can guarantee absolute security. Users must protect credentials, use trusted devices and report suspected unauthorised access promptly.
- HTTPS/TLS encryption and protection of credentials, secrets and OAuth tokens.
- Authentication, role-based access and logical separation between customers.
- Logging, monitoring, backups, recovery and business continuity.
- Updates, vulnerability and incident management, and restricted administrative access.
11. Retention periods
| Item | Detail |
|---|---|
| Account data | For the relationship and the later period required by contract or law. |
| Business data | According to customer instructions, settings and contract. |
| Tax and accounting documents | For the period required by applicable law. |
| Google tokens | While the integration is active or until revocation or disconnection. |
| Imported email and files | According to the associated business record and contractual rules. |
| Calendar events | While the integration or relevant business activity remains active. |
| Technical and security logs | For a period proportionate to security and diagnostic needs. |
| Backups | Until natural rotation or overwriting under technical procedures. |
12. Revoking Google authorisations
A user may revoke authorisations through Nebulas integration settings, by disconnecting the account, through Google security settings or through the support portal. New access and synchronisation then stop and tokens are revoked or deleted.
Revocation does not automatically delete the Nebulas account or previously imported information that forms part of business, accounting or legally retained records.
13. Account and Google data deletion
Users may request deletion through the support portal. After identity and authority checks, Nebulas will where applicable revoke tokens, disconnect the account, stop synchronisation, delete or anonymise unnecessary Google data, remove temporary copies through rotation and confirm completion.
Information may be retained for accounting, tax or legal duties, customer instructions, rights protection, fraud prevention, service security or backup rotation.
14. Provision of data
Data needed for registration, authentication and service delivery is required. Individual Google connections are optional unless a purchased or configured feature depends on them.
15. Rights of data subjects
Where provided by law, data subjects may request access, correction, deletion, restriction, objection, portability, consent withdrawal and protection from solely automated decisions. Requests may be made through support and identity checks may be required. Where a customer is the controller, the request may need to be addressed or forwarded to that customer.
16. Complaint to a supervisory authority
Data subjects may complain to the Italian Data Protection Authority or the authority in the Member State where they live or work. Judicial remedies remain available.
17. Cookies and similar technologies
Nebulas may use strictly necessary technologies for authentication, sessions, security, technical preferences, fraud prevention and operation. Non-essential analytics or profiling technologies are used only as permitted by law and, where required, with prior consent.
18. Minors
Nebulas is intended for companies, professionals and authorised organisational users and is not directed specifically at minors. Customers entering minors’ data must establish an appropriate legal basis and meet applicable obligations.
19. Third-party services and links
External services conduct independent processing under their own terms and notices. Use of Google services also involves processing by Google under the terms applicable to the user’s account.
20. Changes to this notice
The controller may update this policy for legal, feature, technical, organisational, provider or processing changes. The current version and update date will be published, and material changes may also be communicated through Nebulas, email or other appropriate channels.