How NUA actually handles your data.
Not a badge wall: a straight answer to what happens to your business and guest data, and why.
This page describes NUA's architecture and data-handling practices in plain language. It is not a substitute for a signed data processing agreement or a specific compliance certificate. If your venue needs a formal certification reference (e.g. a specific PCI-DSS level or SOC 2 report) for procurement, and we'll provide current documentation.
Encryption, in transit and at rest
Data moving between a terminal and NUA's cloud platform is encrypted over TLS. Stored data (menus, guest records, sales history) is encrypted at rest.
Card payments, handled by PCI-compliant processors
Card details are never stored on the terminal or in NUA's own database. Payments route through PCI-DSS compliant payment processors built for this exact purpose.
Role-based access, per staff member
Every login gets exactly the access their role needs. A server isn't a manager isn't an owner. No shared blanket-admin logins by default.
A full audit trail on every AI action
Every action the AI Agent takes (automatic or approved) is timestamped, logged, and reviewable. Nothing acts invisibly.
Offline-first, by architecture
Core operations write to the device first and sync after, so a dropped connection is a sync delay, not a data-loss event or a stalled checkout.
Continuous, cloud-side backups
Your data is backed up continuously on the cloud side, independent of what's happening on any single venue's terminal.
Reporting a concern
Found something that looks like a security issue? Email info@nuapos.com.au directly: a real person on the engineering team reads that inbox, and we'd rather hear it from you first.