Legal document
Data Processing Addendum
This Addendum applies automatically where Novas processes personal information on a customer’s behalf in connection with the Service. It is intended to provide the mandatory controller-to-processor terms required by Article 28 UK GDPR.
1. Parties and priority
This Addendum is between the Customer identified by the account or applicable order (the “Controller”) and Jack Dickson trading as Novas Agency, the sole trader at 89 Killyleagh Street, Crossgar, County Down, BT30 9DQ, Northern Ireland, United Kingdom (“Novas” or the “Processor”). It forms part of the Terms of Service or other written agreement governing the Service (the “Agreement”).
If this Addendum conflicts with the Agreement on processing Customer Personal Data, this Addendum controls. Terms such as Controller, Processor, Personal Data, Data Subject, processing, Personal Data Breach and Supervisory Authority have the meanings given by applicable data-protection law.
2. Scope and roles
Customer is the Controller, or a Processor acting for another Controller, for Customer Personal Data. Novas processes that data only as a Processor to provide, secure, maintain and support the Service and to follow lawful documented instructions.
Novas remains a separate Controller for account administration, billing, security, fraud prevention, legal compliance and its own business records, as described in the Privacy Notice.
3. Processing details
| Item | Description |
|---|---|
| Subject matter | Hosting and operating a business outreach CRM, Gmail-connected drafting/reply management, tasks, calls, campaigns, records and AI-assisted CRM functions. |
| Duration | For the Agreement term and the deletion/return period in section 11. |
| Nature and purpose | Collection, recording, organisation, storage, retrieval, consultation, transmission, matching, analysis, generation, updating, restriction, deletion and other processing necessary to provide the Service on Customer instructions. |
| Data subjects | Customer users, staff, contractors, clients, prospective business contacts, suppliers, correspondents and other people whose information Customer lawfully places in the Service. |
| Personal Data | Names, roles, work emails, business phone numbers, business addresses and locations, employer/business details, public professional information, websites, communications, notes, call and email activity, tasks, campaign status, outcomes, opt-outs, user prompts and AI action history. |
| Sensitive data | Not intended. Customer must not submit special-category data, criminal-offence data, children’s data, payment-card details, passwords, secrets or other highly sensitive data unless expressly agreed in writing with appropriate safeguards. |
| Frequency | Continuous or as initiated by authorised users during the Agreement. |
4. Customer instructions and obligations
The Agreement, account configuration, authorised feature use and documented support requests are Customer’s instructions. Novas will notify Customer if it believes an instruction infringes applicable data-protection law, unless prohibited by law.
Customer must ensure its instructions and Customer Personal Data are lawful, accurate and limited to what is necessary; provide required notices; establish a lawful basis; handle objections and rights; and obtain any permissions needed for Novas and its Subprocessors to process the data.
5. Processor commitments
Novas will:
- process Customer Personal Data only on documented instructions, unless UK law requires otherwise; where permitted, Novas will notify Customer before legally required processing;
- ensure people authorised to process the data are bound by confidentiality;
- implement and maintain appropriate technical and organisational measures proportionate to risk;
- assist Customer, taking account of the nature of processing and information available, with Data Subject rights, security, breach notification, impact assessments and regulatory consultation;
- keep records and provide information reasonably necessary to demonstrate compliance; and
- not sell Customer Personal Data or use it for advertising.
6. Security measures
- verified Firebase Authentication, isolated customer workspaces, roles and revocation-checked server sessions;
- HTTP-only, Secure production session and CSRF cookies; origin validation and bounded request bodies;
- server-only Firestore access with deny-all browser database rules;
- encryption in transit and provider-managed encryption at rest;
- application-layer encryption for Gmail access and refresh tokens;
- rate limiting, signed Stripe webhooks, secret separation, security headers and restricted external integrations;
- AI data minimisation, restricted tools, server-side usage caps and
store: falsefor OpenAI Responses API requests; and - logging and audit records appropriate to authentication, CRM actions, sending, billing and AI usage.
Customer is responsible for its endpoints, user access, credentials, source data, exported data and configuration decisions.
7. Subprocessors
Customer gives general written authorisation for the Subprocessors in the Subprocessor Register. Novas will impose data-protection obligations appropriate to the services each Subprocessor provides and remains responsible for its own obligations under this Addendum.
Novas will publish updates to the register and, where reasonably possible, notify account contacts at least 15 days before a new Subprocessor begins materially different processing of Customer Personal Data. Customer may object during that period on reasonable data-protection grounds. The parties will work in good faith; if the concern cannot reasonably be resolved, Customer may stop the affected feature or terminate the affected Service before the change takes effect.
8. International transfers
Novas will not make a restricted transfer of Customer Personal Data unless the transfer complies with applicable law. Depending on the destination and provider, safeguards may include UK adequacy regulations, the UK International Data Transfer Agreement (“IDTA”), or the UK Addendum to EU Standard Contractual Clauses, together with the required data-protection test and supplementary measures.
If Customer Personal Data is transferred from the UK to Novas in a country without adequacy protection, the then-current ICO-approved IDTA is incorporated by reference as permitted by its mandatory clauses, with Customer as exporter and Novas as importer. If EU SCCs apply, the then-current UK Addendum is incorporated. The processing details and security measures in this Addendum complete the relevant annex information to the extent permitted.
9. Data Subject requests
If Novas receives a request relating to Customer Personal Data, it will notify Customer and not respond on Customer’s behalf unless instructed or legally required. Novas will provide reasonable assistance through available functionality and support. Customer remains responsible for the response and legal assessment.
10. Personal Data Breaches
Novas will notify Customer without undue delay after becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data. The notice will include information reasonably available about the nature, likely consequences, affected data and subjects, and mitigation. Novas may provide information in phases and will take reasonable steps to contain, investigate and remediate the breach.
Notification is not an admission of fault. Customer is responsible for deciding whether and how to notify regulators or affected people, and Novas will reasonably assist.
11. Return and deletion
During the Agreement, Customer may use available Service functions or request reasonable export assistance. A customer may start account and active-workspace deletion from Account settings after a recent verified sign-in. On another verified request after termination, Novas will delete or return Customer Personal Data, at Customer’s choice where technically reasonable, and normally complete any remaining deletion from active systems within 90 days unless law requires retention.
Legally preserved, security and financial records remain isolated and protected until their retention need ends. Data held in provider backups is put beyond normal use and expires under the provider’s backup cycle.
12. Audits and compliance information
On reasonable written request, no more than once in a 12-month period unless a breach or regulator requires more, Novas will provide information reasonably necessary to demonstrate compliance. If that is insufficient, Customer may request an audit by an independent, qualified auditor under confidentiality, during normal business hours, with reasonable notice and without access to other customers’ data or security-sensitive material. Customer bears its audit costs unless a material breach by Novas is found.
13. Liability, term and contact
This Addendum begins when Customer accepts the Agreement and continues until Novas has deleted Customer Personal Data as described above. Liability is subject to the Agreement except where applicable data-protection law prohibits that limitation.
Data-protection contact: Jack Dickson trading as Novas Agency, 89 Killyleagh Street, Crossgar, County Down, BT30 9DQ, Northern Ireland, United Kingdom, help@novasagency.com.