Privacy and Cookie Policy
Part I – Privacy Policy
The following privacy policy (“Policy”) is provided pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (“GDPR”) by Now4real S.r.l. (“N4R”, “we”, “us”, the “Company” or the “Controller”), as data controller, to natural persons who visit the now4real.com website (“Website”), use the Services, create or use a Publisher account, or otherwise act as a Publisher’s contact person (each a “User” or “you”).
By “Services” we mean the functionalities made available through N4R widgets embedded in third-party websites (each a “Publisher’s Website”) operated by our clients (each a “Publisher” and collectively the “Publishers”), which may allow Users to participate in chats and/or view counters, maps and rankings relating to Users’ presence on the relevant websites. For a detailed description of the Services, please refer to N4R’s Terms of Service at https://now4real.com/terms (“Terms”).
Capitalized terms used in connection with the Services and not otherwise defined in this Policy have the meanings given to them in the Terms. “White Label Mode”, “Dashboard”, “Subscription” and, when used in relation to a Publisher, “Agreement” have the meanings given to them in N4R’s Publisher Terms of Service at https://now4real.com/publisher-terms/.
This Policy applies to the Services in relation to Users only where N4R provides them directly under the Terms. It does not apply to the processing of Users’ personal data where the Services are provided under the Publisher’s name and branding in White Label Mode and N4R has no direct contractual relationship with those Users. In that case, the Publisher acts as data controller, N4R acts as data processor on its behalf, and the Publisher’s privacy notice applies. This limitation does not affect the application of this Policy to individuals who visit the Website, create or use a Publisher account, or otherwise interact directly with N4R.
Each Publisher independently operates its website and may process the User’s personal data in connection with that website for purposes determined by the Publisher, including through internet communication protocols and for activities such as e-commerce or profiling. The Publisher also determines certain aspects of the Services made available on its website, including their configuration and availability, the available Access Procedures, moderation rules and activities, any authentication system provided by the Publisher, and any Automated Agents configured by the Publisher. To the extent that the Publisher determines the purposes and means of any processing of personal data, it acts as an independent data controller. N4R acts as data controller for the processing operations that it determines and that are described in this Policy. Users should therefore also consult the Publisher’s privacy notice.
If you require any further information or have any questions about our Policy, please feel free to contact us by email at privacy@now4real.com.
Unless otherwise indicated, references to Sections in this Privacy Policy are to sections of this Privacy Policy.
1. What Personal Data We Collect and Why. Legal Basis of the Processing and Legitimate Interests
1.1. When You Navigate Our Website or Use Our Services
Through the Website and the Services, N4R automatically collects technical data generated by browsers, devices, servers and network components and stores them in server logs. Depending on the component involved, such data may include the User’s IP address, the date and time of the request, the requested host or resource, the HTTP method and protocol, the response status code, the amount of data transferred, the referrer URL, user-agent information such as browser, device and operating system, and other technical data ordinarily generated in connection with HTTP requests.
N4R uses Google reCAPTCHA on specified forms and Access Procedures to distinguish legitimate requests from automated activity and prevent spam and abuse. When reCAPTCHA is used, Google processes on N4R’s behalf technical and interaction data necessary for its risk analysis, which may include IP addresses, browser and device information, HTTP request data, cookie identifiers, interaction signals and verification or risk results. N4R does not include information entered in the protected form or Access Procedure in the reCAPTCHA verification request and does not use reCAPTCHA for advertising or profiling. reCAPTCHA is loaded only on the pages on which the relevant security check is required.
These data are processed to deliver and operate the Website and the Services; maintain their security and integrity; prevent, detect and investigate abuse, unlawful conduct and cyber-attacks; diagnose technical problems and provide assistance; establish, exercise or defend legal claims; respond to legally binding requests from competent authorities; and produce irreversibly anonymous statistics.
The processing is necessary for the legitimate interests of the Controller in operating reliable and secure services, protecting its systems and Users, preventing abuse, resolving technical issues and protecting its legal rights, pursuant to Article 6(1)(f) of the GDPR. Where processing is necessary to comply with a specific legal obligation, including a legally binding request from a competent authority, it is based on Article 6(1)(c) of the GDPR. The User’s consent is not required.
1.2. When You Contact Us
If a User contacts N4R by email or through a contact form, N4R processes the personal data voluntarily provided by the User, together with the related correspondence and technical information, to respond to the request, manage subsequent communications and provide any requested assistance.
Where the communication relates to an existing or potential agreement, the processing is necessary for the performance of that agreement or to take steps at the User’s request before entering into it, pursuant to Article 6(1)(b) of the GDPR. In other cases, the processing is necessary for N4R’s legitimate interest in responding to inquiries and managing its communications, pursuant to Article 6(1)(f) of the GDPR. Where processing is required to comply with a specific legal obligation, it is based on Article 6(1)(c) of the GDPR. The User’s consent is not required.
1.3. When You Subscribe to Our Newsletter
Through the Website, Users may subscribe to N4R’s newsletter to receive news and updates concerning N4R. Users are asked to provide only their email address. Subscriptions and newsletter delivery are managed through Mailchimp, a service provided by The Rocket Science Group LLC, which acts as a data processor on behalf of N4R. The subscription is completed through a double opt-in procedure. In addition to the email address, Mailchimp records technical subscription data, including the date, time and IP address associated with the subscription and its confirmation, to verify the User’s consent and manage the mailing list.
Unless the User has requested newsletters without tracking as described below, newsletters contain technologies provided by Mailchimp that measure email opens and link clicks. These technologies may record whether and when a newsletter is opened, which links are clicked and related technical information, such as the IP address and information concerning the device or email client, and may associate these events with the relevant subscriber.
N4R uses the resulting information exclusively to produce general statistics concerning campaign performance. N4R does not use it to profile individual Users, segment the mailing list according to observed behavior, personalize newsletter content or make decisions concerning individual Users.
The processing of personal data for sending the newsletter and measuring email opens and link clicks is based on the User’s consent, pursuant to Article 6(1)(a) of the GDPR and, with regard to tracking technologies, Article 122 of Legislative Decree No. 196 of June 30, 2003, as amended. Consent to receiving the newsletter and to the associated tracking is collected through a single informed subscription choice and confirmed through the double opt-in procedure.
Users may unsubscribe at any time by using the unsubscribe link included in each newsletter. A User who wishes to continue receiving the newsletter but withdraw consent only to open and click tracking may contact N4R at privacy@now4real.com. N4R will record and implement the User’s choice without undue delay, so that subsequent newsletters are sent without such tracking.
Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
1.4. When You Register for Our Forum
Users may register for N4R’s public discussion forum by providing an email address, a username and a password. N4R sends a verification message to the email address provided to confirm that the address belongs to the User. Passwords are stored only in cryptographically hashed form. IP addresses and other technical data generated when accessing or using the forum are processed as described in Section 1.1.
The User’s username and any discussions or messages published through the forum are publicly accessible and may be indexed by search engines or collected and used by third parties. The User’s email address and password are not made public. Users should therefore avoid including personal data that they do not wish to disclose publicly in their username or published content.
These personal data are processed to create and manage the User’s forum account; authenticate the User; enable participation in discussions; associate published content with its author; operate and moderate the forum; prevent and investigate abuse or unlawful conduct; maintain security; and establish, exercise or defend legal claims.
Processing necessary to create and manage the account and enable the User to participate in the forum is based on the performance of the agreement with the User, pursuant to Article 6(1)(b) of the GDPR. Processing for security, abuse prevention, moderation and the protection of N4R’s legal rights is based on N4R’s legitimate interests, pursuant to Article 6(1)(f) of the GDPR. Where processing is necessary to comply with a specific legal obligation, it is based on Article 6(1)(c) of the GDPR. The User’s consent is not required.
Users may request deletion of their forum account by contacting N4R at privacy@now4real.com. Messages and discussions previously published may remain publicly accessible after the account has been deleted, where necessary to preserve the integrity and intelligibility of the forum, after their association with the User’s account and username has been removed. This is without prejudice to the User’s rights under the GDPR and to the removal of personal data where required by applicable law.
1.5. When You Use the Services
When a User visits a Publisher’s Website on which the Services are available, N4R processes the technical connection and session data necessary to establish and maintain the connection, provide the Services and calculate real-time presence information.
The User’s presence may contribute to aggregate counters and statistics made available to Users and Publishers. N4R may also use the User’s IP address in real time to determine the apparent country from which the User is connecting and represent the aggregate geographical distribution of Users on a world map. N4R does not attempt to determine the User’s location below country level and does not retain individual geolocation or presence records outside the technical server logs described in Section 1.1. The resulting counters, maps and statistics do not identify individual Users.
N4R does not use information about the pages visited by Users to track their navigation within or across Publishers’ Websites or to create browsing profiles. Technical server logs may nevertheless contain information about the website or page from which a request originated, as described in Section 1.1.
Depending on the Publisher’s configuration, a User may be able to view some or all of the Services without completing an Access Procedure. Interactive functions require the User to complete one of the Access Procedures described below and accept the Terms.
The processing described above is necessary for N4R’s legitimate interests in operating and providing the Services, generating real-time aggregate presence information, maintaining the security and reliability of its systems and preventing abuse, pursuant to Article 6(1)(f) of the GDPR. The User’s consent is not required.
1.5.1. If You Use the Services Without Completing an Access Procedure
A User who has not completed an Access Procedure may, depending on the Publisher’s configuration, view chats, counters, maps or other non-interactive elements of the Services. N4R does not create an account or collect profile information for such a User.
N4R processes only the technical connection and session data necessary to provide these functions, as described above and in Section 1.1. Cookies, LocalStorage and similar technologies may also be used as described in the Cookie Policy.
1.5.2. If You Complete an N4R-Managed Access Procedure
Depending on the Publisher’s configuration, N4R may allow Users to complete an Access Procedure through social login, email login or the selection of a nickname without registration.
When social login is used, the User may choose Google, Facebook, X or LinkedIn. The relevant provider authenticates the User and provides N4R with a provider-specific identifier, the User’s display name, the URL of the User’s profile picture and, where made available by the provider, the User’s email address. N4R also retains the access token issued by the provider and, where provided, a refresh token or equivalent credential. N4R uses these credentials exclusively to verify that the connection between the User’s provider account and N4R remains active and to obtain updated versions of the User’s display name and profile picture. N4R requests only permissions relating to the User’s basic identity, profile and email address and does not use the credentials to access contacts, private messages, posts, status updates or other content associated with the User’s provider account. These data and credentials are retained for as long as the social-login identity remains associated with the Services. The User may request deletion of their personal data by contacting N4R at privacy@now4real.com. When the request is processed, any access token, refresh token or equivalent credential is deleted immediately and the social-login identity is removed from N4R’s active systems. Limited data may be transferred to a segregated archive and retained exclusively under the conditions and for the periods described in Section 3.
When email login is used, N4R collects the User’s email address and verifies it by sending a unique code to that address. The User is then asked to choose a display name. If the User chooses to use Gravatar, N4R derives a hash from the email address and uses it to retrieve and display the public profile picture associated with that address. No request is made to Gravatar unless the User selects this option, and N4R does not send the email address to Gravatar in clear text. The User may disable Gravatar at any time and use an image generated from the User’s initials instead. N4R uses Google reCAPTCHA on the email-entry page as described in Section 1.1. Further information about Gravatar, Google reCAPTCHA and the related technologies is provided in the Cookie Policy.
When the Publisher allows access without registration, the User may complete the Access Procedure by choosing a nickname. N4R stores the nickname and remembers it on subsequent visits to the same Publisher’s Website from the same browser. The nickname is not automatically available from another browser or device and will no longer be remembered if the relevant browser data are deleted.
Social login and email login may allow the User to remain signed into the Services across different Publishers’ Websites on which N4R directly provides the Services. An identity created through the selection of a nickname is instead limited to the relevant Publisher’s Website. The User may sign out at any time through the appropriate function in the N4R interface and may also revoke a social login authorization through the relevant provider.
These data are processed to complete and maintain the Access Procedure; identify the User within the Services; associate the User’s identity with messages and other interactions; maintain the User’s access state; provide the requested interactive functions; and prevent, detect and investigate abuse and security incidents.
Processing necessary to complete the Access Procedure and provide the interactive functions requested by the User is based on the performance of the agreement with the User, pursuant to Article 6(1)(b) of the GDPR. Processing necessary to prevent abuse and protect the security and integrity of the Services is based on N4R’s legitimate interests, pursuant to Article 6(1)(f) of the GDPR. The User’s consent is not required.
1.5.3. If the Access Procedure Is Provided by the Publisher
A Publisher may configure a Publisher’s Website to use its own authentication system, referred to as Custom Authentication, instead of the N4R-managed Access Procedures described above. In this case, a User who is signed into the Publisher’s Website may also be given access to the interactive functions of the Services on that Publisher’s Website.
Through Custom Authentication, the Publisher provides N4R with:
- an identifier chosen by the Publisher that uniquely identifies the User within that Publisher’s Websites;
- the display name selected by the Publisher; and
- a profile picture selected by the Publisher, where provided.
The identifier is opaque to N4R, which does not determine its meaning or use it to obtain additional information about the User. If the Publisher uses the same identifier for more than one of its websites, N4R may recognize the User as the same User across those websites.
The Publisher may also provide information determining whether the User is authorized to view or interact with particular chats. N4R processes the authentication token and its authorization information only as necessary to validate the Access Procedure and apply the Publisher’s configuration. N4R does not retain the complete authentication token or its authorization information after validation.
N4R stores the identifier, display name and profile picture to maintain the User’s access to the Services and associate the User’s identity with messages and other interactions.
The Publisher independently determines and manages its authentication system, the identity information associated with the User and the information provided to N4R. The Publisher acts as an independent data controller for these activities. N4R processes the information it receives as data controller for the purposes described in this Policy. Users should therefore also consult the Publisher’s privacy notice.
Processing necessary to complete and maintain the Access Procedure and provide the requested interactive functions is based on the performance of the agreement between N4R and the User, pursuant to Article 6(1)(b) of the GDPR. Processing necessary to verify the authentication token, apply access restrictions, prevent abuse and protect the security and integrity of the Services is based on N4R’s legitimate interests, pursuant to Article 6(1)(f) of the GDPR. The User’s consent is not required.
1.5.4. When You Publish or Otherwise Interact with Content
When a User posts a message through a Chat, N4R processes and stores the message, the User’s display name and profile picture, where available, the date and time of publication, the Publisher’s Website and Chat to which the message relates, the relevant page address or other Chat identifier, and the information necessary to associate the message with the User. N4R also retains the complete history of any changes made to the message.
Depending on the Publisher’s configuration, a Chat may be accessible to anyone visiting the Publisher’s Website or only to Users authorized by the Publisher. The Publisher also determines how long messages remain visible to that audience, up to a maximum of 12 months after they are posted. Messages, display names, profile pictures and reactions may accordingly be publicly visible or visible only to authorized Users for the period configured by the Publisher.
When a Gravatar profile picture is displayed in a Chat, the viewer’s browser requests the image directly from Gravatar. Gravatar receives the image address, which contains a hash derived from the profile owner’s email address, and ordinary technical connection data, such as the viewer’s IP address and browser information. The request originates from an N4R-hosted iframe and does not disclose the identity or address of the Publisher’s Website or the viewer’s N4R identifier. As currently implemented, the integration does not involve cookies. Gravatar is provided by Automattic, which processes the data it receives under its own Privacy Policy at https://automattic.com/privacy/.
Irrespective of the period for which messages remain visible to the audience of a Chat, N4R makes the transcripts of all Chats taking place on the Publisher’s Websites available to that Publisher for 12 months after the relevant messages are posted. The Publisher may therefore access messages after they are no longer visible to the Chat audience. The User’s email address is not included in the transcripts made available to the Publisher.
When a User reacts to a message, N4R records the reaction and associates it with the reacting User and the relevant message. The reaction and information identifying the reacting User may be visible to the audience of the relevant Chat.
When a User opens the GIF picker or when a GIF supplied by KLIPY is displayed in a Chat, the User’s browser connects directly to Kikliko, Inc. (“KLIPY”), a company established in the United States, through an iframe operated by N4R. The request is made directly from the browser. Because it originates from an N4R-hosted iframe, the HTTP Referer header identifies only the iframe origin, https://cdn.now4real.com/, rather than the Publisher’s Website. The request therefore does not disclose the identity or address of the Publisher’s Website to KLIPY. KLIPY does not set or read cookies through this integration. N4R supplies a randomly generated value in the API user-ID field. The value is generated independently of, and does not contain, any N4R or Publisher user identifier.
KLIPY may receive the User’s IP address and related browser and HTTP request data, the identity of N4R as the third-party integration, search terms, GIFs viewed or selected, timestamps and diagnostic or usage information. N4R does not use KLIPY’s Ads/Revenue API and does not display KLIPY advertising through the integration. KLIPY independently determines the purposes and means of its processing of these data. According to the KLIPY Privacy Policy at https://klipy.com/support/privacy-policy, those purposes may include providing and securing the service, localization, optimizing results, statistics, product improvement and advertising-related purposes. KLIPY acts as an independent data controller for that processing. Its processing, including processing in the United States and the exercise of data-subject rights against KLIPY, is governed by that policy.
When a User reports a message, N4R stores a report containing the display name of the reporting User, the display name of the User who posted the reported message, the reported message and the reason provided by the reporting User. N4R sends the same information by email to the Publisher so that the report can be reviewed and handled. Reports are not displayed to other Users.
The Publisher may process the transcripts and reports for purposes independently determined by it, including moderation, security and the analysis of Chat activity. The Publisher acts as an independent data controller for such processing and is responsible for identifying an appropriate legal basis and describing the relevant purposes, processing operations and retention periods in its own privacy notice.
The Services are not intended to be used to disclose special categories of personal data referred to in Article 9 of the GDPR or personal data relating to criminal convictions and offenses referred to in Article 10 of the GDPR. A User must not submit special categories of personal data concerning another person, special categories of personal data concerning the User in a Chat that is not publicly accessible, or personal data relating to criminal convictions or offenses, unless the relevant processing is permitted by applicable law. If N4R becomes aware that Content has been submitted contrary to these restrictions, it may restrict or remove that Content in accordance with the Terms and applicable law.
Messages, including their complete edit history, and the associated reactions and reports are physically deleted from N4R’s databases no later than 12 months after the relevant message was originally posted. A shorter visibility period configured by the Publisher does not reduce the period for which the transcript remains available to the Publisher. Any copies of transcripts or reports retained by the Publisher, and any results derived from them, are processed under the Publisher’s responsibility and retention policies.
Processing by N4R that is necessary to post messages, make them available to the intended audience, enable reactions and reporting functions, and provide the Gravatar and GIF functions actively requested by the User is based on the performance of the agreement between N4R and the User, pursuant to Article 6(1)(b) of the GDPR. The limited initiation by N4R of a direct browser connection to Gravatar or KLIPY when a profile picture or KLIPY GIF selected by another User is displayed in a Chat is based on the legitimate interests of N4R and Users in displaying Chat content as submitted, pursuant to Article 6(1)(f) of the GDPR. Automattic and KLIPY independently determine the purposes and legal bases for their own processing, as described in their respective privacy notices. The continued storage of Chat transcripts and their availability to the Publisher, as well as processing necessary to preserve message history, support moderation, maintain the security and integrity of the Services, investigate abuse, handle reports and establish, exercise or defend legal claims, is based on the legitimate interests of N4R and the Publisher, pursuant to Article 6(1)(f) of the GDPR. Where processing is necessary to comply with a specific legal obligation, it is based on Article 6(1)(c) of the GDPR.
Where a User deliberately includes special categories of personal data concerning themselves in a Chat that is clearly publicly accessible, the processing of those data to display, store and moderate the message relates to personal data manifestly made public by the User and is permitted under Article 9(2)(e) of the GDPR. N4R does not analyze Content for the purpose of inferring or profiling special categories of personal data.
1.5.5. When Moderation or Automated Agents Are Used
Depending on the Publisher’s configuration, Content may be subject to review by human moderators, automated rules and filters, N4R’s AI Moderation and/or Automated Agents configured by the Publisher. The Publisher determines the applicable moderation policy and which moderation tools and Automated Agents are enabled on its Publisher’s Website.
These operations may process Content and the related information described in Section 1.5.4 to apply the Publisher’s moderation policy, provide interactive functions, prevent and investigate abuse, protect Users and maintain the security and integrity of the Services.
When N4R’s AI Moderation is enabled, the content of a new message is analyzed before publication together with recent messages from the relevant Chat, the title of the page and the moderation policy established by the Publisher. In the information submitted to the AI provider, N4R replaces Users’ display names with pseudonyms and does not include Users’ N4R identifiers, email addresses, profile pictures, IP addresses or other connection data.
N4R currently uses OpenAI Ireland Ltd. as a data processor to provide AI Moderation. API requests are configured not to be stored as application state, and the data submitted by N4R are not used to train or improve OpenAI’s models. OpenAI may nevertheless retain inputs and outputs in abuse-monitoring logs for up to 30 days, unless a longer retention period is required by law or is reasonably necessary to protect its services or third parties from harm.
AI Moderation determines whether the submitted message should be published or blocked and, if the message is blocked, generates a reason explaining the refusal. If a message is blocked, it is not published and cannot be restored through the Services. No review or appeal procedure is available through the Services. The reason for the refusal is not displayed to the User but may be accessed by N4R and the Publisher for moderation, security and abuse-prevention purposes.
The submitted message, the moderation outcome and, where the message is blocked, the reason for the refusal are stored by N4R in accordance with the lifecycle applicable to Chat messages and are physically deleted from N4R’s databases no later than 12 months after the message was submitted. AI Moderation is not used to profile the User or to infer special categories of personal data, and its outcome is used only to determine how the submitted message is handled.
A Publisher may also configure one or more Automated Agents, which may generate messages or suggestions or determine whether a message should be published. When a User submits a message in a Chat in which an Automated Agent is enabled, N4R transmits, over HTTPS and to an endpoint selected by the Publisher, information relating to the relevant Publisher’s Website and page, the content and technical metadata of the new message, and a limited number of recent messages from the relevant Chat. No transmitted Chat message will be older than 12 months. The transmitted information may include Users’ display names, internal message and User identifiers and, where Custom Authentication is used, the opaque User identifier previously provided to N4R by the Publisher. N4R does not transmit Users’ email addresses, profile pictures, IP addresses, connection data or social-login credentials to the Automated Agent.
The Publisher independently determines the purposes, operation and provider of its Automated Agents and acts as an independent data controller for the processing performed by or through them, including any further storage or use of the information transmitted by N4R. The Publisher is responsible for providing the relevant information in its own privacy notice and for ensuring that any third-party provider used for an Automated Agent is engaged in accordance with applicable data-protection law.
Messages and suggestions returned by an Automated Agent and published in a Chat are processed and retained as Content in accordance with Section 1.5.4. N4R does not maintain separate logs specifically for Automated Agents, without prejudice to the technical server logs described in Section 1.1.
Processing necessary to provide the interactive functions requested by the User, including messages or suggestions generated by an Automated Agent, is based on the performance of the agreement between N4R and the User, pursuant to Article 6(1)(b) of the GDPR. Processing for moderation, enforcement of the Publisher’s policy, prevention and investigation of abuse, protection of Users and maintenance of the security and integrity of the Services is based on the legitimate interests of N4R and the Publisher, pursuant to Article 6(1)(f) of the GDPR.
1.5.6. Use of Your Email Address
Where N4R obtains the User’s email address through an N4R-managed Access Procedure, N4R may use it to complete and manage that Access Procedure, send authentication codes and communicate with the User where reasonably necessary concerning the operation or security of the Services or other matters requiring the User’s attention. Since an email address is not available for every User, such communications are sent only where N4R has an email address for the relevant User.
N4R does not use an email address collected through an Access Procedure to send advertising or newsletters unless the User has separately subscribed to the newsletter described in Section 1.3. N4R does not make that email address available to the Publisher through the Services or Chat transcripts. It may use service providers acting as data processors where technically necessary to send emails.
Processing necessary to complete and manage the Access Procedure or provide communications relating to the agreement with the User is based on Article 6(1)(b) of the GDPR. Processing necessary to protect the security and integrity of the Services and communicate important operational or security information is based on N4R’s legitimate interests pursuant to Article 6(1)(f) of the GDPR. Where processing is necessary to comply with a specific legal obligation, it is based on Article 6(1)(c) of the GDPR.
1.6. When You Create or Use a Publisher Account
When a Publisher account is created or used, N4R processes the account holder’s name and email address, authentication credentials or identifiers associated with the selected sign-in method, billing information such as the business or legal name, address, country and VAT number or tax ID, information concerning the Publisher’s Websites registered through the account and their relevant configuration, and information concerning the Subscription, invoices, payments and account status. These data may be provided directly by the User, by the Publisher on whose behalf the User acts or by the selected sign-in provider.
N4R processes these data to create, authenticate and administer the account; provide access to the Dashboard and the Services; manage the Subscription, billing, payments, taxation and the Publisher’s Websites registered through the account; send operational communications and provide support; protect the security of the account and prevent misuse; document which Publisher was responsible for each registered website; and establish, exercise or defend legal claims.
Where the Publisher is a natural person, processing necessary to create and perform the account and Subscription is based on Article 6(1)(b) of the GDPR. Where the User acts on behalf of a legal entity, processing is based on N4R’s legitimate interest in entering into, administering and performing the Agreement with the Publisher pursuant to Article 6(1)(f) of the GDPR. Processing required for accounting, taxation and other legal obligations is based on Article 6(1)(c) of the GDPR. Processing for security, prevention of misuse, record keeping and the establishment, exercise or defense of legal claims is based on N4R’s legitimate interests pursuant to Article 6(1)(f) of the GDPR.
Subscription and payment transactions are managed through third-party billing and payment providers. For card payments, complete card numbers and security codes are provided directly to the relevant payment provider and neither transit through nor are stored on N4R’s systems. N4R receives only the card type, last four digits, expiration date and payment status, together with the transaction records necessary to administer the Subscription. For payments made through PayPal, N4R receives the information necessary to identify and administer the transaction.
2. Nature of the Provision of Personal Data
Except where otherwise expressly indicated or required by applicable law, the provision of personal data is not a statutory obligation.
The technical connection and session data described in Sections 1.1 and 1.5 are generated automatically when the User accesses the Website or the Services. Their processing is necessary to establish the connection, operate and secure the Website and the Services and provide the requested functions. Without processing these data, N4R cannot provide the relevant Website or Service functions.
Other personal data are provided voluntarily by the User, or made available by a provider or Publisher, when the User chooses a specific activity or function, such as contacting N4R, subscribing to the newsletter, registering for the forum, creating or using a Publisher account, completing an Access Procedure or interacting with Content. The data required for the selected activity are necessary only to provide that activity. Failure to provide them may prevent N4R from responding to the request, sending the newsletter, creating or managing the forum or Publisher account, completing the selected Access Procedure or providing the relevant interactive function, as applicable, but does not affect other functions for which those data are not required.
Where processing is based on consent, giving consent is voluntary. Refusing or withdrawing consent prevents only the processing or optional function for which that consent is required and does not affect the lawfulness of processing carried out before its withdrawal.
3. Data Retention
N4R retains personal data only for as long as necessary for the purposes described in this Policy, in accordance with the following criteria.
The technical server logs described in Section 1.1 are retained for a maximum of six months. A separate record containing the IP address, TCP source port and date and time of a connection may be retained for a maximum of 12 months for security, abuse-prevention, investigation and legal-compliance purposes.
Personal data contained in ordinary correspondence described in Section 1.2 are retained for a maximum of 24 months after the last communication. Correspondence relating to agreements, payments, disputes or legal obligations may be retained for up to ten years after the relevant relationship or matter has ended.
Publisher account information and the associated contractual, Subscription, billing, payment and tax records, including records identifying the Publisher’s Websites registered through the account and their relevant configuration, are retained for up to ten years after the account is closed. This retention is necessary to comply with legal, accounting and tax obligations, document the contractual relationship and identify the Publisher responsible for each registered website, and establish, exercise or defend legal claims.
Active authentication credentials, password verifiers and sign-in tokens are deleted or revoked when the account is closed and are not included in the ten-year archive. N4R may retain a non-operational internal account identifier where necessary to link the archived records. Other data not required for the purposes described above are deleted or anonymized.
Newsletter subscription data and associated campaign data are retained while the subscription remains active. Following an unsubscribe request or withdrawal of consent, N4R may retain only the minimum information necessary to document the subscription and withdrawal, prevent further communications and demonstrate compliance for as long as necessary for those purposes. Other personal data relating to the newsletter are deleted. Aggregate campaign statistics that do not identify Users may be retained without a time limit.
Forum account data are retained while the account remains active and are deleted following a deletion request. As explained in Section 1.4, previously published forum content may remain available after its association with the User’s account and username has been removed, where necessary to preserve the integrity and intelligibility of the forum.
Identity and profile data associated with an Access Procedure are retained for as long as the relevant identity remains associated with the Services. Data stored only in the User’s browser remain there until they are deleted by the User or the browser or are replaced or expire.
In the ordinary course of providing the Services, messages and their complete edit history, associated reactions and reports, and AI Moderation submissions, outcomes and refusal reasons are retained by N4R for no longer than 12 months from the date on which the relevant message was originally submitted. The period during which a message is visible to the Chat audience may be shorter, as determined by the Publisher, but N4R makes Chat transcripts available to the Publisher for up to 12 months as described in Section 1.5.4.
When N4R processes a request for deletion of personal data associated with the Services, it immediately removes the User’s identity and profile and all messages and associated data relating to the User from its active systems. Those data are no longer accessible through the Services to the Chat audience or the Publisher. Any access token, refresh token or equivalent credential is deleted immediately.
Messages and associated data that were submitted more than six months before the deletion request are physically deleted immediately. More recent messages and associated data may be transferred to a segregated archive and retained exclusively until six months have elapsed from the date on which the relevant message was originally submitted. The deletion request does not restart or extend the retention period applicable to any message.
The User’s display name, email address, profile-picture information, provider-specific identifier and any other identifier associated with the Access Procedure may also be transferred to the segregated archive and retained for a maximum of six months from the deletion request. All data held in the segregated archive are inaccessible through the Services and may be accessed only by authorized N4R personnel where necessary to preserve evidence, respond to lawful requests from competent authorities or establish, exercise or defend legal claims. At the end of the respective retention periods, the archived data are physically deleted.
After the archived identity and profile data have been deleted, N4R may retain only a pseudonymized identifier and information concerning an active moderation restriction, and only for as long as necessary to prevent circumvention of that restriction. If no moderation restriction remains active, those data are deleted.
As described in Section 1.5.5, data submitted to N4R’s AI Moderation provider may be retained in abuse-monitoring logs for up to 30 days, subject to the limited exceptions stated there. N4R does not maintain separate logs specifically for Automated Agents. Any copies independently retained by a Publisher or its Automated Agent provider are subject to the Publisher’s own responsibility and retention policies.
If, before the scheduled deletion, N4R receives a binding measure from a competent authority requiring the preservation of specified data, N4R may retain only those data and only for the period required by that measure. At the end of each applicable retention period, the personal data are physically deleted.
4. How We Process Personal Data
N4R processes personal data primarily by electronic and automated means and, where necessary, through authorized personnel. N4R implements technical and organizational measures appropriate to the risks presented by the processing and designed to protect the confidentiality, integrity, availability and resilience of its systems and personal data. These measures include access restrictions, authentication and authorization controls, encrypted TLS connections, backup and recovery procedures, logging, monitoring and security-incident management.
N4R’s primary application infrastructure, databases, server logs and backups are hosted through a cloud infrastructure provider in data centers located in the European Economic Area. N4R also uses a cloud email-delivery service to send authentication codes and other operational emails.
N4R uses content delivery network providers to supply fonts, software libraries and other resources required by the Website and the Services. When the User’s browser requests these resources, the relevant provider necessarily receives technical connection data, such as the IP address, date and time of the request, requested resource, referrer information and user-agent information. Such data may be processed for content delivery, security and aggregate statistical purposes.
Personal data may be accessed only by persons and service providers that require such access for the purposes described in this Policy and are subject to appropriate confidentiality and data-protection obligations.
5. Categories of Recipients
Depending on the activity or function used by the User, personal data may be disclosed or otherwise made available to the following categories of recipients:
- providers of cloud infrastructure, hosting, database, backup, operational email-delivery and content delivery network services;
- providers of communications, newsletter delivery, website analytics, authentication, security, anti-abuse, profile-image, GIF search and content delivery, and AI Moderation services;
- providers of Subscription management, billing and payment services;
- Publishers, their authorized moderators and providers of Automated Agents, to the extent described in Sections 1.5.3, 1.5.4 and 1.5.5;
- Users and other persons forming part of the intended audience of a Chat or forum discussion, according to the applicable access configuration;
- professional advisors and service providers assisting N4R with legal, accounting, compliance, security or technical matters; and
- courts, law-enforcement bodies, supervisory authorities and other public authorities where disclosure is required by law, by a binding measure or where necessary to establish, exercise or defend legal claims.
Where a recipient processes personal data on N4R’s behalf, N4R appoints it as a data processor under an agreement complying with Article 28 of the GDPR. Kikliko, Inc., in relation to KLIPY, and Automattic, in relation to Gravatar, act as independent data controllers for the processing operations they determine. Other recipients, including social-login providers, Publishers and providers independently selected by Publishers, may also act as independent data controllers. Their processing is governed by their respective privacy notices.
Information published in a publicly accessible Chat or forum discussion may be viewed, copied or otherwise collected by persons outside N4R’s control. Content made available only to a restricted audience is disclosed through the Services only to persons authorized under the Publisher’s configuration, without prejudice to any independent copies made by those persons.
6. Transfers of Personal Data Outside the European Economic Area
N4R’s primary application infrastructure, databases, server logs and backups are hosted in the European Economic Area. However, some service providers or their sub-processors may process personal data outside the European Economic Area, in particular in the United Kingdom and the United States, including through global content delivery networks and providers of technical support, security, communications, newsletter, authentication, Subscription management, billing, payment, analytics and AI services.
Where personal data are transferred to a country recognized by the European Commission as providing an adequate level of protection, the transfer is based on the relevant adequacy decision pursuant to Article 45 of the GDPR. This includes transfers to organizations in the United States that are validly certified under the EU-US Data Privacy Framework, where applicable.
Where no adequacy decision applies, N4R relies on appropriate safeguards under Article 46 of the GDPR, normally the Standard Contractual Clauses approved by the European Commission through Implementing Decision (EU) 2021/914, together with supplementary contractual, technical or organizational measures where appropriate.
The KLIPY integration described in Section 1.5.4 operates differently from N4R’s use of processors described above. The relevant data are sent directly from the User’s browser to Kikliko, Inc., which collects and processes them in the United States as an independent controller; N4R does not export data stored in its user-account or server databases to KLIPY through this integration. The HTTP Referer header associated with the direct requests identifies only the N4R iframe origin, https://cdn.now4real.com/, and does not disclose the identity or address of the Publisher’s Website. The requests contain no user identifier derived from N4R or Publisher records; the value supplied in KLIPY’s API user-ID field is randomly generated. Kikliko, Inc. is responsible for the international processing it carries out as controller. Further information is provided in the KLIPY Privacy Policy at https://klipy.com/support/privacy-policy.
Further information concerning the relevant destinations and transfer mechanisms, and a copy of the applicable safeguards, may be requested by contacting N4R at privacy@now4real.com. Commercially confidential information may be redacted from copies of contractual safeguards.
7. Data Controller and Data Processors
The data controller is Now4real S.r.l., with registered office at Viale Andrea Doria No. 7, 20124 Milan, Italy.
For any question concerning this Policy or the processing of personal data, the User may contact N4R at privacy@now4real.com.
An updated list of N4R’s data processors, including their respective processing activities and locations, and further information concerning the safeguards applicable to international transfers may be requested using the same email address.
8. Rights of the Data Subject
Subject to the conditions and exceptions provided by the GDPR, the User has the right to:
- obtain confirmation as to whether N4R processes personal data concerning the User and, where this is the case, obtain access to such data, a copy of them and the information required by Article 15 GDPR;
- obtain the rectification of inaccurate personal data and the completion of incomplete personal data;
- obtain the erasure of personal data where the conditions of Article 17 GDPR are met, subject to the limited retention described in Section 3 and to any other applicable exception;
- obtain the restriction of processing where the conditions of Article 18 GDPR are met;
- receive personal data provided to N4R in a structured, commonly used and machine-readable format and transmit those data to another controller, where the processing is based on consent or a contract and is carried out by automated means;
- object, on grounds relating to the User’s particular situation, to processing based on legitimate interests. In such a case, N4R will no longer process the personal data unless it demonstrates compelling legitimate grounds for the processing which override the User’s interests, rights and freedoms, or the processing is necessary for the establishment, exercise or defense of legal claims;
- withdraw consent at any time, where the processing is based on consent, without affecting the lawfulness of processing carried out before its withdrawal; and
- lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it) or with another competent supervisory authority.
The User may exercise these rights by contacting N4R at privacy@now4real.com or now4real@legalmail.it (certified email address, PEC). N4R may request information reasonably necessary to verify the User’s identity and locate the relevant personal data.
N4R will respond without undue delay and, in any event, within one month of receiving the request. This period may be extended by up to two further months where necessary, taking into account the complexity and number of requests. N4R will inform the User of any such extension within one month of receiving the request.
N4R can respond only in relation to processing activities for which it acts as data controller under this Privacy Policy. Where the Publisher independently determines the purposes and means of a processing activity, the User must exercise the relevant rights directly against the Publisher, in accordance with the Publisher’s privacy notice.
Part II – Cookie Policy
Unless otherwise indicated, references to Sections in this Cookie Policy are to sections of this Cookie Policy.
1. Scope of This Cookie Policy
This Cookie Policy explains how N4R uses cookies and similar technologies in two distinct contexts:
- on the now4real.com website and the other websites and web applications operated directly by N4R, including the Dashboard, the forum and N4R’s documentation pages (collectively, the “N4R Websites”); and
- through the Services embedded in websites operated by Publishers (“Publishers’ Websites”).
The provisions concerning the N4R Websites are relevant to visitors to those Websites, including Publishers using the Dashboard. The provisions concerning the Services on Publishers’ Websites are relevant to Users accessing those Services, even if they never visit an N4R Website.
The provisions concerning the Services apply only where N4R provides the Services directly to Users under the Terms. Where the Services are provided in White Label Mode, the Publisher determines the use of cookies and similar technologies and the Publisher’s privacy and cookie policies apply.
Publishers may also use their own cookies and similar technologies on their Websites independently of N4R. Such technologies are governed by the relevant Publisher’s policies and are not covered by this Cookie Policy.
2. Cookies and Similar Technologies
Cookies are small text files stored on a browser or device and transmitted back to the relevant server during subsequent visits. Similar technologies include LocalStorage, SessionStorage and IndexedDB, which allow information to be stored within the browser for different periods and purposes.
These technologies may be:
- technical, when they are necessary to provide a service requested by the User, maintain a session, remember a choice, ensure security or enable a function; or
- non-technical, when they are used for purposes such as analytics or advertising measurement.
Technical technologies do not require consent. Where required by applicable law, non-technical technologies are used only with the User’s consent.
3. Technologies Used on the N4R Websites
3.1. Technical Cookies and Similar Technologies
The following technologies are necessary for the operation, security or requested functions of the N4R Websites:
|
Cookies or Storage Keys |
Provider |
Purpose |
Duration |
|
analytics_storage |
N4R |
Remember whether the visitor accepted or rejected optional measurement technologies. |
Up to 6 months, unless the choice is changed or the browser data are deleted earlier. |
|
flarum_session and flarum_remember |
N4R |
Manage the User’s session and login on N4R’s forum. |
For the session or until the remembered login expires, the User signs out or the browser data are deleted. |
|
Dashboard authentication storage |
N4R |
Store authentication information in LocalStorage to allow Publishers to sign in to and use the Dashboard via Amazon Cognito. |
Until the relevant token expires, the Publisher signs out or the browser data are deleted. |
|
Chargebee cookies and browser storage |
Chargebee |
Enable subscription, billing and payment-management functions requested by Publishers through the Dashboard. |
For the duration required by the relevant session or billing workflow. |
|
_GRECAPTCHA |
|
Protect contact-form submissions and forum registration against automated activity, spam and abuse. |
Up to six months. |
Further information about Chargebee is available at https://www.chargebee.com/privacy/.
N4R uses Google reCAPTCHA on the contact form and during forum registration. reCAPTCHA is loaded only on the relevant pages and is used solely to prevent automated submissions, spam and abuse. It processes technical and interaction data necessary for risk analysis and may set the necessary _GRECAPTCHA cookie listed above. N4R does not use reCAPTCHA for advertising or profiling.
3.2. Google Analytics and Advertising Measurement
N4R uses Google Tag Manager to deploy Google Analytics and Google Ads measurement technologies and manage consent choices. Google Tag Manager does not itself set cookies.
Subject to the visitor’s consent where required, Google Analytics is used to understand how the N4R Websites are used. Google Ads measurement is used to determine whether advertising campaigns result in visits or other relevant actions and to evaluate and optimize campaign performance.
|
Cookies |
Provider |
Purpose |
Duration |
|
_ga, _ga_<container ID> |
|
Distinguish browsers and sessions and produce Website usage statistics. |
Up to six months. |
|
_gcl_au, _gcl_aw |
|
Measure and attribute visits or conversions resulting from Google advertising campaigns. |
Up to three months. |
Google Analytics may provide N4R with information concerning general location, such as country, region or city, and information concerning the browser, device and operating system used. N4R does not receive the visitor’s complete IP address through Google Analytics.
N4R uses Google Consent Mode in its advanced configuration. Where prior consent is required, Analytics and advertising storage are disabled by default. Before consent is given, or if consent is refused, Google tags may transmit limited cookieless signals concerning the consent status, page or event and technical information such as the timestamp, browser user agent and referrer. These signals do not read or write Analytics or advertising cookies and do not use persistent browser identifiers. Google uses them to model aggregate Website and campaign results.
N4R does not use cookieless signals to identify individual visitors. To the extent that their transmission involves the processing of personal data, such processing is based on N4R’s legitimate interest in obtaining limited aggregate information about Website and campaign performance without storing or accessing information on the visitor’s device, pursuant to Article 6(1)(f) of the GDPR and to the extent permitted by applicable law.
The use of Analytics and advertising cookies and the processing of personal data obtained through them are based on the visitor’s consent, pursuant to Article 6(1)(a) of the GDPR and Article 122 of Legislative Decree No. 196 of June 30, 2003, as amended.
N4R uses Google Signals to obtain aggregated cross-device, demographic and interest reports. Google may associate Website activity with visitors signed in to their Google accounts who have enabled Ads Personalization in their Google settings. N4R does not receive their identities or send Google any User ID, email address, including in hashed form, or other user-provided data.
N4R does not use Google Analytics data for advertising personalization or remarketing. Advertising personalization remains disabled regardless of the visitor’s consent choice.
User-level and event-level Google Analytics data, including Google signed-in data used for Google Signals, are retained for two months. The retention period is not reset by subsequent activity. Aggregated statistical and campaign reports may be retained for longer.
Further information about Google’s processing is available at https://policies.google.com/privacy.
3.3. Third-Party Functions Requested by the User
Publishers may choose to sign in to the Dashboard using Google Login. In that case, the Publisher is redirected to Google. Cookies and similar technologies used on Google’s website are governed by Google’s policies and are not controlled by N4R.
Videos embedded in the N4R Websites are not loaded directly from YouTube when the page is opened. N4R initially displays a thumbnail that is not retrieved from YouTube and loads the video from youtube-nocookie.com only after the visitor chooses to play it. YouTube may then process technical information and use cookies or similar technologies in accordance with Google’s policies.
4. Technologies Used by the Services on Publishers’ Websites
This Section applies to Users accessing the Services through a Publisher’s Website. The technologies described below may be stored on the User’s browser even if the User never visits an N4R Website.
N4R uses only technical cookies and similar technologies for the operation of the Services. N4R does not use the Services to set Analytics, advertising-measurement or profiling cookies, or to track Users’ navigation within or across Publishers’ Websites.
4.1. N4R Cookies and Storage
|
Cookies or Storage Keys |
Provider |
Purpose |
Duration |
|
n4r, n4rAuth, n4rAuthMain and n4rAuth@<website> |
N4R |
Maintain the relevant Service session, remember that the User completed an Access Procedure and, where applicable, remember the nickname selected for a particular Publisher’s Website. |
For the active session. Remembered access information in LocalStorage remains until the User signs out, it is replaced or the browser data are deleted. |
|
n4rFels |
N4R |
Remember the most recent N4R server instance successfully used by the browser and make subsequent connections more efficient. |
Until it is replaced or the browser data are deleted. |
|
n4rSitePreferences |
N4R |
Remember the User’s preferences for the Services on the relevant Publisher’s Website. |
Until the preferences are changed or the browser data are deleted. |
|
n4rVisible |
N4R |
Allow test Users to display a Widget that the Publisher has configured as not generally visible. |
Until it is removed or the browser data are deleted. |
|
n4rLogger |
N4R |
Remember a log-level setting selected for technical or diagnostic purposes. |
Until it is changed or the browser data are deleted. |
|
PicMo-* and emojibase/* |
N4R |
Store the data required by the emoji search and selection function. |
IndexedDB data remain until deleted. SessionStorage data are removed when the relevant browser session ends. |
Deleting these data may sign the User out, remove a remembered nickname or saved preferences, or temporarily affect the operation of certain Service functions.
4.2. Third-Party Functions Used Within the Services
If the User chooses a social-login Access Procedure, the User is redirected to Google, Facebook, X or LinkedIn. The relevant provider may use cookies and similar technologies on its own website in accordance with its policies:
- Google: https://policies.google.com/technologies/cookies
- Facebook: https://www.facebook.com/help/cookies/
- X: https://help.x.com/en/rules-and-policies/x-cookies
- LinkedIn: https://www.linkedin.com/legal/cookie-policy
When a User opens the GIF picker or when a GIF supplied by KLIPY is displayed in a Chat, the browser connects directly to KLIPY through an iframe operated by N4R. KLIPY does not set or read cookies through this integration. Because the request originates from an N4R-hosted iframe, its HTTP Referer header identifies only the iframe origin, https://cdn.now4real.com/, and does not disclose the identity or address of the Publisher’s Website to KLIPY. N4R supplies a randomly generated value in the API user-ID field; the value is generated independently of, and does not contain, any N4R or Publisher user identifier. N4R does not use KLIPY’s Ads/Revenue API and does not display KLIPY advertising through the integration. KLIPY processes the data it receives as an independent controller. Further information is provided in Section 1.5.4 of the Privacy Policy above and in the KLIPY Privacy Policy at https://klipy.com/support/privacy-policy.
When a User chooses to use a Gravatar profile picture, the image is requested directly from Gravatar whenever it is displayed in a Chat. The request transmits the image address, which contains a hash derived from the profile owner’s email address, and ordinary technical connection data, such as the viewer’s IP address and browser information. It originates from an N4R-hosted iframe, does not disclose the identity or address of the Publisher’s Website or the viewer’s N4R identifier and, as currently implemented, does not involve cookies. Gravatar is provided by Automattic. Further information is available in Automattic’s Privacy Policy at https://automattic.com/privacy/ and in Section 1.5.4 of the Privacy Policy above.
Google reCAPTCHA is loaded on the email-entry page of the email-based Access Procedure to distinguish legitimate requests from automated activity and prevent spam and abuse. It processes technical and interaction data necessary for risk analysis and may set the necessary _GRECAPTCHA cookie for up to six months. N4R does not include the User’s email address or other profile information in the reCAPTCHA verification request and does not use reCAPTCHA for advertising or profiling. Because reCAPTCHA is used exclusively for this security purpose, it does not require consent.
Where an Access Procedure or another function is provided directly by the Publisher, any cookies or similar technologies used by the Publisher are governed by the Publisher’s privacy and cookie policies.
5. Managing Consent and Browser Storage
Where applicable law requires prior consent, visitors to the N4R Websites are shown a banner that allows them to accept or reject optional Analytics and advertising-measurement technologies.
Selecting Accept enables Analytics and advertising measurement, but does not enable advertising personalization or remarketing. Selecting Reject leaves optional storage disabled. Limited cookieless signals may still be transmitted through Google Consent Mode as described in Section 3.2.
In countries where prior consent is not required, optional measurement technologies may be enabled by default, subject to applicable law.
The Cookie settings link available in the footer of every N4R Website allows visitors to reopen the banner and change or withdraw their choice at any time. The new choice takes effect immediately. Withdrawing consent does not affect the lawfulness of processing carried out before its withdrawal.
Visitors and Users may also block or delete cookies, LocalStorage, SessionStorage, IndexedDB and other browser data through their browser settings. Blocking or deleting technical storage may prevent sign-in, remove saved preferences or affect the operation of the Dashboard, forum or Services.
The cookie banner and the Cookie settings link on the N4R Websites govern only the technologies used on those Websites. Users accessing the Services on a Publisher’s Website should use the Publisher’s consent controls for technologies managed by the Publisher and their browser settings for N4R’s technical storage.
6. Further Information
Further information concerning the processing of personal data, recipients, international transfers and the exercise of data-protection rights is provided in the Privacy Policy above.
Questions concerning this Cookie Policy may be sent to privacy@now4real.com.
Changes to This Privacy and Cookie Policy
N4R may update this Privacy and Cookie Policy to reflect changes in applicable law, its websites or Services, its processing activities or the technologies it uses. Non-material updates may be made by publishing the revised text without individual notice. Where an update materially affects the use of cookies, the processing of personal data or the exercise of data-protection rights, N4R will bring the change to the attention of affected individuals before the relevant change is implemented, including, where appropriate, through a notice displayed when Users complete the Access Procedure again. Where consent is required, the relevant processing will begin only after consent has been obtained.
Add Now4real to your site today
Easy. Free. Instant.
Let visitors chat, discover hot pages, and build instant communities—right on your website.
