Privacy Policy - FernNola

Last updated: 19 April 2026  ·  Effective date: 3 April 2026


1. Who We Are

FernNola Limited (NZBN 9429053630490) ("we", "us", or "our") is a New Zealand limited liability company that builds and operates integration applications connecting popular business platforms. Our products help businesses automate workflows and synchronise data between the tools they use every day.

Contact details:
Email: support@fernnola.com
Website: www.fernnola.com
Registered office: 1222 State Highway 16, RD3, Waimauku, New Zealand


2. Scope of This Policy

This Privacy Policy explains how FernNola collects, uses, stores, and protects personal information through:

  • The FernNola platform - including account registration, sign-in, and use of tools such as the Timesheet Exporter and Holiday & Events Calendar
  • Our website at www.fernnola.com (including our blog)
  • Our social media presence
  • Our support and communication channels

For information about how personal data is handled by specific FernNola applications that integrate with third-party platforms, please refer to the privacy policy for each individual app. Each app‑specific policy supplements this policy and governs data processed through that product.

Currently published app‑specific policies:

As additional applications are released, their privacy policies will be listed here.


3. Our Role Under Privacy Law

FernNola acts in different roles depending on the source of the data:

  • Data Controller - for personal information collected directly through our platform, website, social media, and support channels. We determine how and why this data is processed.
  • Data Processor - for personal information processed through our applications on behalf of customers where those customers are the primary controllers of that data. That data is governed by the applicable app‑specific privacy policy.

4. What Personal Information We Collect

4.1 Platform Accounts

When you create a FernNola account and use the platform, we collect and store:

  • Your name, email address, and profile image (provided via Google sign-in or email authentication)
  • Your account role and access permissions
  • The date and time you last used the platform
  • A record of sign-in events (login timestamps)

4.2 Fergus Connection Credentials

To connect your Fergus account to FernNola tools, we store:

  • Your Fergus Personal Access Token (PAT), stored encrypted at rest
  • Your Fergus company name, company ID, and company GUID (used to identify your account when calling the Fergus API)

Your PAT is used solely to make API requests to Fergus on your behalf. It is never shared with third parties and is permanently deleted if you disconnect your Fergus account.

4.3 Tool-Specific Data

Holiday & Events Calendar: We store your selected region (locale), whether holiday sync is enabled, sync history, and any custom company events you create (name, description, date).

Timesheet Exporter: We store per-employee payroll notes you add. Notes are shared with all users in your company and persist until you manually clear them.

4.4 Fergus API Call Logs

We record metadata about outbound calls made to the Fergus API on your behalf, including the endpoint called, HTTP status code, and response time. These logs do not include the content of API responses and are used for operational monitoring and error diagnosis. Logs are retained for 30 days.

4.5 Website

Our website is primarily informational. We do not currently use analytics tools, advertising pixels, or marketing cookies. As part of standard web server operation, we may collect limited server‑level request logs (such as IP addresses and page requests). These logs are retained for a short period for security and operational purposes only.

4.6 Support and Direct Communications

When you contact us via email or another support channel, we may collect your name and email address, the content of your message and any attachments, and communication history. This information is used solely to respond to enquiries and to maintain a record of support interactions.

4.7 Information We Do Not Collect

We do not collect:

  • Payment or financial information (billing is handled by marketplace platforms)
  • Sensitive personal information (such as health data, ethnicity, or religious beliefs)
  • Precise geolocation data
  • Personal information from children under 18
  • Email marketing or newsletter subscription data

5. How We Use Your Information

PurposeInformation UsedLawful Basis (GDPR)NZ Privacy Act Principle
Providing and operating the platformAccount details, Fergus credentials, tool settingsPerformance of contractIPP 1, 2
Authenticating your identityEmail address, OAuth tokensPerformance of contractIPP 1, 2
Operating integrations with FergusEncrypted PAT, company identifiersPerformance of contractIPP 1, 2
Platform analytics and improvementApp usage events, API call logsLegitimate interestsIPP 1, 2
Operating and maintaining our websiteServer logsLegitimate interestsIPP 1, 2
Responding to support enquiriesContact details, message contentContract / legitimate interestsIPP 1, 2
Complying with legal obligationsAs requiredLegal obligationIPP 1

We will never use personal information for purposes incompatible with those listed above without consent, unless required by law.


6. Cookies and Tracking Technologies

We do not currently use tracking cookies, analytics tools, advertising pixels, or other third‑party tracking technologies on our public website.

The FernNola platform uses technically necessary cookies and session tokens to maintain your authenticated session. These are required for the platform to function and are not used for marketing or profiling.

If tracking technologies are introduced in the future, this policy will be updated and consent will be obtained where required by law.


7. Data Sharing and Third Parties

We do not sell, rent, or trade personal information. We share information only in the following limited circumstances:

RecipientPurposeLocation
Vercel Inc.Website hosting and application infrastructure (Next.js deployment, serverless functions)United States
Railway (Infrastructure as a Service)Database hosting - all platform data is stored in a PostgreSQL database hosted on RailwayUnited States
Google LLCOAuth sign-in provider - used when users authenticate via GoogleUnited States
Nager.DatePublic holiday data - a free public API used by the Holiday & Events Calendar to fetch official holiday datesAustria
Fergus SoftwareIntegration target - your Fergus PAT is used to make API calls to Fergus on your behalfNew Zealand / Australia
Legal or regulatory authoritiesWhere required by lawNew Zealand / International

All third‑party providers are selected with care and are required to handle data in accordance with applicable privacy laws.


8. International Data Transfers

FernNola is based in New Zealand. Our infrastructure is hosted by Vercel Inc. and Railway, both based in the United States.

When personal information is transferred overseas, we take reasonable steps to ensure appropriate safeguards, including:

  • Use of reputable, security‑certified service providers
  • GDPR‑compliant data processing agreements where applicable
  • Compliance with Information Privacy Principle 12 of the NZ Privacy Act 2020
  • Reliance on standard contractual clauses or applicable adequacy decisions for UK and EEA transfers

9. Data Retention

We retain personal information only for as long as necessary or as required by law.

Data TypeRetention Period
Account details (name, email, role)For the life of your account, then deleted within 30 days of account closure
Encrypted Fergus PAT and company identifiersDeleted immediately when you disconnect your Fergus account
Holiday sync settings and company eventsFor the life of your account
Employee payroll notesFor the life of your account, or until you manually clear them
App usage events (login)2 years
Fergus API call logs30 days
Server‑level request logs30 days
Support communications2 years from last contact
Social media direct messages2 years or until no longer relevant

When retention periods expire, information is securely deleted or anonymised.


10. Data Security

We use appropriate technical and organisational measures to protect personal information, including:

  • HTTPS encryption across all FernNola web properties (TLS 1.2 or higher)
  • Encryption of sensitive credentials (such as Fergus PATs) at rest
  • Access controls limiting access to authorised personnel
  • Use of reputable, security‑certified infrastructure providers
  • Periodic review of data handling practices

If you believe your information has been involved in a security incident, please contact us at support@fernnola.com.


11. Your Rights

New Zealand (Privacy Act 2020)

  • Right to access personal information
  • Right to request correction
  • Right to complain to the Office of the Privacy Commissioner

United Kingdom / European Union (GDPR)

  • Right of access
  • Right to rectification
  • Right to erasure
  • Right to restrict processing
  • Right to data portability
  • Right to object to processing
  • Right to withdraw consent
  • Right to lodge a complaint with a supervisory authority

To exercise any of these rights, contact support@fernnola.com. We respond within 20 working days (NZ) or 30 calendar days (GDPR).


12. Children's Privacy

Our services are intended for business users and not for individuals under 18. We do not knowingly collect personal information from children. If you believe we have collected such information, contact us and it will be deleted promptly.


13. Links to Third‑Party Websites

Our website may contain links to third‑party websites. We are not responsible for their privacy practices and encourage you to review their policies.


14. Changes to This Policy

We may update this Privacy Policy from time to time. When changes are made, the "Last updated" date will be revised. If materially new data practices are introduced, this policy will be updated before those practices begin.


15. Contact Us and Complaints

FernNola
Email: support@fernnola.com
Website: www.fernnola.com

New Zealand:
Office of the Privacy Commissioner
Website: www.privacy.org.nz
Phone: 0800 803 909

UK / EU:
You may lodge a complaint with your local supervisory authority, such as the UK Information Commissioner's Office (ICO): www.ico.org.uk