Skip to content
HomeSecurity
Security & Trust

How NUA actually handles your data.

Not a badge wall: a straight answer to what happens to your business and guest data, and why.

This page describes NUA's architecture and data-handling practices in plain language. It is not a substitute for a signed data processing agreement or a specific compliance certificate. If your venue needs a formal certification reference (e.g. a specific PCI-DSS level or SOC 2 report) for procurement, and we'll provide current documentation.

Encryption, in transit and at rest

Data moving between a terminal and NUA's cloud platform is encrypted over TLS. Stored data (menus, guest records, sales history) is encrypted at rest.

Card payments, handled by PCI-compliant processors

Card details are never stored on the terminal or in NUA's own database. Payments route through PCI-DSS compliant payment processors built for this exact purpose.

Role-based access, per staff member

Every login gets exactly the access their role needs. A server isn't a manager isn't an owner. No shared blanket-admin logins by default.

A full audit trail on every AI action

Every action the AI Agent takes (automatic or approved) is timestamped, logged, and reviewable. Nothing acts invisibly.

Offline-first, by architecture

Core operations write to the device first and sync after, so a dropped connection is a sync delay, not a data-loss event or a stalled checkout.

Continuous, cloud-side backups

Your data is backed up continuously on the cloud side, independent of what's happening on any single venue's terminal.

Reporting a concern

Found something that looks like a security issue? Email info@nuapos.com.au directly: a real person on the engineering team reads that inbox, and we'd rather hear it from you first.

Questions before you switch?
Talk it through with a real operator, not a script.