Privacy Notice
Version 1 dated 12 August 2026
This Privacy Notice is intended to provide all information concerning the processing of personal data carried out by Nexify Limited when Users use the Application (as further described below).
1. Introduction – who are we?
Nexify Limited, with registered office at No. 4 Harbourmaster Place, Eir Building, Custom House Dock, Dublin 1, Ireland, D01 K6X5, Tax/VAT No. IE3393380OH (the “Controller”), owner of the web app (the “Application”, “App” or “Voyana”), acting as Controller of the personal data of users (the “Users” or “Data Subjects”) who, by creating and completing an account (the “Account”), access the travel-planning Application (the “Service”) and use its related features, hereby provides this Privacy Notice pursuant to Article 13 of EU Regulation 2016/679 of 27 April 2016 (the “Regulation” or “Applicable Law”).
Please note that the App, the Service and any features offered through the App are reserved for persons who are at least eighteen years old. The Controller therefore does not collect personal data relating to persons under the age of 18. At the request of Users, the Controller will promptly delete any personal data relating to persons under the age of 18 that has been collected inadvertently.
2. How can you contact us?
The Controller attaches the utmost importance to its Users’ right to privacy and protection of personal data. For any information concerning this Privacy Notice, Users may contact the Controller at any time in the following ways:
by sending a registered letter with acknowledgement of receipt to the Controller’s registered office: No. 4 Harbourmaster Place, Eir Building, Custom House Dock, Dublin 1, Ireland, D01 K6X5;
by sending an email to: info@nexify.io.
Users may also contact the Controller’s Data Protection Officer (DPO), whose contact details are as follows: Shibumi S.r.l., which may be contacted at dpo@youniversal.com.
3. What do we do? – Purposes, nature of the data, legal basis, processing methods and retention periods
The Controller will lawfully process Users’ personal data for the following processing purposes.
A) Main purpose: provision of the Service under the General Terms and Conditions for use of the Application, through the activities described below:
1) Creation and completion of the Account within the Application and the related sending of service communications (for example, confirmation of Account creation, password-change requests and amendments to the Privacy Notice). For this purpose, the Controller may process the following User data: first name, surname, email address and password, which together constitute login credentials; technical data (such as IP address and the type of browser and device used); and any other personal information that the User may voluntarily provide when creating and completing the Account.
Legal basis for processing: Article 6(1)(b) of the Regulation, namely performance of a contract to which the User is party.
Processing methods: the Controller will process Users’ personal data using manual and electronic means, according to procedures strictly connected with the purposes themselves and, in all cases, in a manner that ensures the security and confidentiality of the data.
Retention period: personal data collected when the Account is created and completed will be retained for the entire life of the Account. Following a deletion request, they will be removed from active systems, without prejudice to data whose retention is necessary to comply with legal obligations or protect the User’s and the Controller’s interests in civil proceedings.
2) Provision of Application features, namely to enable use of the App’s features, including, by way of example: (i) interaction with the virtual assistant available on the Application (the “Virtual Assistant”) to plan a trip, generate a possible travel itinerary and provide information requested by the User; (ii) viewing flights, hotels, destinations and activities; (iii) viewing images and geographical maps; (iv) saving travel plans to the Account and subsequently sharing them; (v) using the voice feature and related transcription; and (vi) contextualising and adapting the User’s experience in using the Service, for example by providing more relevant results. For this purpose, the Controller may process the following User data: first name, surname and email address (collected when the Account is created and completed as described under the preceding purpose A1)), as well as any additional data that the User may voluntarily provide while using the features, including the content and history of interactions with the Virtual Assistant and the User’s voice and voice transcripts. In all cases, the User is asked not to disclose personal data that are unnecessary for use of the Application’s features and, in particular, data belonging to the special categories under Article 9 of the Regulation, except where, at the User’s discretion, their provision is strictly necessary for use of the Service.
Legal basis for processing: the legal basis is Article 6(1)(b) of the Regulation, namely performance of a contract to which the User is party.
Processing methods: the Controller will process Users’ personal data using manual and electronic means, according to procedures strictly connected with the purposes themselves and, in all cases, in a manner that ensures the security and confidentiality of the data.
The Controller also uses artificial intelligence systems to: (i) plan trips; (ii) generate travel itineraries; and (iii) provide information requested by the User.
Users’ personal data will not be used to train the artificial intelligence system, and generated responses and processed voice transcripts may be inaccurate or incorrect.
The Application may also integrate and provide links to services, content and search engines operated by third-party partners. Where use of those services, content and search engines entails the processing of the User’s personal data, the User should refer to the privacy notices of the relevant third-party partners, which will process their data as independent data controllers.
Retention period: personal data collected while the Application is being used:
for the features referred to in points (ii), (iii) and (iv), for the entire life of the Account; following a deletion request, they will be removed from active systems, without prejudice to legal obligations and the protection of rights;
for the feature referred to in point (i), for the entire life of the Account; following a deletion request, they will be removed from active systems, without prejudice to legal obligations and the protection of rights;
for the feature referred to in point (v), the voice recording is retained only for the time needed to obtain the voice transcription.
B) Additional purposes:
1) Legal obligations, namely compliance with obligations imposed by law, an authority, a regulation or European legislation. For this purpose, the Controller may process the following User data: first name, surname and any additional personal information concerning the User that is necessary to pursue this processing purpose.
Legal basis for processing: Article 6(1)(c) of the Regulation, namely compliance with a legal obligation arising under European Union or national law.
Processing methods: the Controller will process Users’ personal data using manual and electronic means, according to procedures strictly connected with the purposes themselves and, in all cases, in a manner that ensures the security and confidentiality of the data.
Retention period: the Controller will retain Users’ personal data for the time necessary to achieve the processing purpose described.
4. Scope of data disclosure and dissemination
The User’s personal data may be transferred outside the European Union. In such cases, the Controller will ensure that the transfer takes place in accordance with Applicable Law and, in particular, Articles 45 (Transfers on the basis of an adequacy decision) and 46 (Transfers subject to appropriate safeguards) of the Regulation.
The Controller’s employees and/or contractors responsible for managing the Application and Users’ requests may have access to Users’ personal data. Those persons, who have been instructed accordingly by the Controller pursuant to Article 29 of the Regulation, will process Users’ data solely for the purposes stated in this Notice and in compliance with Applicable Law.
Third parties that may process personal data on behalf of the Controller as Processors may also have access to Users’ personal data, including, by way of example and without limitation, providers of outsourcing or cloud-computing services, professionals and advisers, and providers of IT and logistics services supporting operation of the Application.
The up-to-date list of suppliers and processors used to provide the Service, together with their respective functions, is available on the “Service providers” page at https://voyana.ai/legal-documents/service-providers/en.html. The list includes, among others, providers of artificial intelligence systems, search services, voice transcription, infrastructure, authentication, communications and measurement tools used by the Platform.
Users have the right to obtain a list of any processors appointed by the Controller by requesting it from the Controller using the methods set out in paragraph 5 below.
5. Data Subjects’ rights
Data Subjects may exercise the rights guaranteed by Applicable Law by contacting the Controller or DPO at the contact details stated above. The right to delete the Account and related data may also be exercised directly from the personal area by opening Settings, selecting “Delete Account” and confirming the request. Before deletion, the User may export available data using the features provided in the Account.
Pursuant to Applicable Law, the Controller informs Data Subjects that they have the right to obtain information regarding: (i) the source of the personal data; (ii) the purposes and methods of processing; (iii) the logic applied where processing is carried out with the aid of electronic means; (iv) the identification details of the controller and processors; and (v) the persons or categories of persons to whom the personal data may be disclosed or who may become aware of them in their capacity as processors or persons authorised to process data.
Furthermore, Data Subjects have the right to obtain:
a) access to, updating or rectification of the data and, where they have an interest in doing so, supplementation of the data;
b) erasure, anonymisation or restriction of data processed unlawfully, including data whose retention is unnecessary for the purposes for which they were collected or subsequently processed;
c) certification that the operations referred to in points a) and b), including their content, have been notified to those to whom the data were disclosed or disseminated, unless fulfilment of this requirement proves impossible or involves a manifestly disproportionate effort in comparison with the right protected.
Furthermore, Data Subjects have:
a) the right to withdraw consent at any time where processing is based on their consent;
b) the right, where applicable, to data portability (the right to receive all personal data concerning them in a structured, commonly used and machine-readable format);
c) the right to object:
i) on legitimate grounds, in whole or in part, to the processing of personal data concerning them, even where relevant to the purpose for which the data were collected;
ii) in whole or in part, to the processing of personal data concerning them for the purpose of sending advertising material, direct selling, market research or commercial communications;
iii) where personal data are processed for direct-marketing purposes, at any time to the processing of their data for that purpose, including profiling to the extent that it is related to such direct marketing.
d) where they consider that processing concerning them infringes the Regulation, the right to lodge a complaint with a Supervisory Authority (in the Member State in which they habitually reside or work, or in which the alleged infringement occurred). The Italian Supervisory Authority is the Garante per la protezione dei dati personali, with offices at Piazza Venezia No. 11, 00187 Rome (http://www.garanteprivacy.it/).
The Controller is not responsible for keeping all links displayed in this Notice up to date. Accordingly, whenever a link is not working and/or current, Data Subjects acknowledge and accept that they must always refer to the document and/or section of the websites referenced by that link.