Legal document
Privacy Notice
This notice explains how personal information is handled in Novas HQ, including account access, business-contact records, connected Gmail accounts, subscription billing and Novas Agent.
1. Who we are and when this notice applies
Jack Dickson trading as Novas Agency is the sole trader operating Novas HQ (the “Service”). Our contact address is 89 Killyleagh Street, Crossgar, County Down, BT30 9DQ, Northern Ireland, United Kingdom. Privacy questions and rights requests can be sent to help@novasagency.com.
This notice applies to account users, people who contact us, and business contacts whose information is stored or used through the Service.
We act as a controller for account, security, billing, support and our own business operations. Where a customer uses the Service for its own contacts and decides why and how their information is used, that customer is the controller and we act as its processor under our Data Processing Addendum.
2. Information we handle
- Account information: name, work email, profile image, authentication provider, role, access status and login/security events.
- CRM information: business and contact names, work contact details, trade, location, websites, public-source research, notes, calls, outcomes, tasks, campaigns, suppression records and activity history.
- Gmail information: the connected account address, granted scopes, encrypted OAuth tokens, message and thread identifiers, draft content, inbound reply content and delivery/sync status.
- AI information: prompts, responses, tool actions, conversation history, model and usage metadata, and the minimum relevant CRM context needed for the requested task.
- Billing information: Stripe customer and subscription identifiers, plan, status, billing period and payment-related events. Full card details are handled by Stripe and are not stored in the Service.
- Technical information: IP address, device/browser information, security tokens, request metadata, error information and service logs.
- Support and legal information: enquiries, requests, complaints, consent/terms records and information needed to establish or defend legal claims.
3. Where information comes from
Information may come directly from an account user, the user’s organisation, a connected Google account, Stripe, communications with us, customer imports, CRM activity, and public business sources such as business websites, directories, professional profiles and public social pages.
If a customer adds another person’s information, the customer is responsible for having a lawful basis, providing any required privacy information and respecting objections or opt-outs.
4. Purposes and lawful bases
| Purpose | Typical lawful basis |
|---|---|
| Create, approve and secure accounts; provide the Service and support. | Contract; legitimate interests in operating and securing the Service. |
| Store and organise customer CRM data; carry out user-requested tasks. | Processor instructions under the customer agreement; contract. |
| Connect Gmail, create drafts, sync replies and record outreach history. | User instruction; contract; legitimate interests. Google data is used only for disclosed Service features. |
| Process subscriptions, prevent payment fraud and keep accounting records. | Contract; legal obligation; legitimate interests. |
| Operate Novas Agent, research public business information and perform approved CRM actions. | Contract; user instruction; legitimate interests, subject to human review. |
| Prevent abuse, investigate incidents, enforce terms and defend legal claims. | Legitimate interests; legal obligation. |
| Send service notices and material legal or subprocessor updates. | Contract; legal obligation; legitimate interests. |
Where we rely on legitimate interests, we consider the purpose, necessity and likely impact on people. Consent is used where applicable law specifically requires it and may be withdrawn without affecting earlier lawful processing.
5. Gmail and Google API data
The Service requests Gmail Compose and Gmail Readonly access so authorised users can create and send approved drafts, read replies, match them to CRM records and maintain outreach history. OAuth credentials are encrypted before storage. Disconnecting Gmail revokes the Service’s ongoing mailbox connection and removes stored tokens; CRM records already created remain subject to the retention rules below.
We do not sell Google user data, use it for advertising, or allow humans to read it except where necessary for support, security, legal compliance or with the user’s affirmative permission. Our use and transfer of Google API data follows the Google API Services User Data Policy, including its Limited Use requirements.
6. Novas Agent data use
Novas Agent may receive a user prompt and a limited, task-relevant CRM summary. Its tools do not expose passwords, API keys, Firebase or Gmail tokens, billing secrets, or authentication data. CRM read tools are designed to avoid returning raw contact addresses, phone numbers and full email bodies unless a specific user-approved feature requires them.
OpenAI API requests use store: false. OpenAI states that API content is not used to train its models unless the API customer opts in; default abuse-monitoring logs may be retained for up to 30 days. AI conversations and action records may also be stored in our Firestore account history so the Service can preserve context and provide an audit trail.
The Service does not use AI to make solely automated decisions that produce legal or similarly significant effects. Users must review researched facts, classifications, drafts and proposed CRM changes.
7. Sharing and service providers
We disclose only what is reasonably necessary to operate the Service, comply with law, protect rights and security, or complete a transaction. Providers include Google Cloud/Firebase, Google APIs/Gmail, Vercel, OpenAI and Stripe. Optional email-delivery infrastructure may be used only when configured by the account operator.
Our current provider list, purpose and processing-location information is maintained in the Subprocessor Register. Stripe and Google may also act as independent controllers for activities they determine, such as payment fraud prevention or their own account administration.
8. International transfers
Some providers process information outside the United Kingdom, including in the United States and other countries. Where a restricted transfer requires a safeguard, we rely on applicable adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or another lawful mechanism, together with risk assessment and supplementary measures where required.
9. Retention
- Account and CRM data: while the account is active and as needed to provide the Service. Following a verified closure request, customer data is normally deleted or anonymised within 90 days unless law, a dispute, security needs or a customer instruction requires longer.
- Gmail tokens: until the account is disconnected or access is revoked. CRM copies of messages and activity follow the CRM retention period.
- AI conversations and action logs: while the account is active, or until an earlier valid deletion request, subject to security and legal records.
- Billing and accounting records: generally six years after the relevant financial year or longer where law requires.
- Security and support records: for the period reasonably needed to investigate incidents, prevent abuse, answer enquiries and defend claims.
- Suppression and opt-out records: for as long as reasonably necessary to avoid contacting someone who has objected or opted out.
Account users can start full-account deletion from Account settings after a recent verified sign-in. This removes the Firebase login, CRM workspace, stored Gmail credentials and AI history, and cancels any active subscription. A non-identifying deletion receipt and records required for accounting, security, legal claims or compliance may be retained. Provider backups and legally preserved records may take additional time to expire and remain protected while retained. Other access, export or rights requests can be made through the verified contact route below.
10. Security
Controls include verified Firebase Authentication, short-lived HTTP-only sessions, isolated customer workspaces and roles, server-only database access, deny-all browser Firestore rules, encryption in transit, provider encryption at rest, encrypted Gmail tokens, CSRF and origin checks, bounded request bodies, rate limiting, signed Stripe webhooks and restricted AI tools. No system is completely secure, so users must protect their credentials and promptly report suspected compromise.
11. Your rights
Depending on the circumstances, you may have rights to be informed, access information, correct it, erase it, restrict or object to processing, receive portable information, and complain. You can object at any time to direct marketing. Where we process customer CRM data only on behalf of a customer, we may refer the request to that customer.
Send requests to help@novasagency.com. We may need to verify identity and normally respond within one month. You may complain to the UK Information Commissioner’s Office.
12. Children and sensitive information
The Service is for business users aged 18 or over and is not directed to children. Users must not intentionally enter children’s information, payment-card details, account credentials, highly sensitive personal information, or special-category data into the CRM or Novas Agent unless a separate written agreement and lawful safeguards expressly permit it.
13. Changes and contact
We may update this notice when the Service, providers or law changes. Material changes will be brought to account users’ attention and, where required, fresh acknowledgement will be requested before new processing begins.
Contact: Jack Dickson trading as Novas Agency, 89 Killyleagh Street, Crossgar, County Down, BT30 9DQ, Northern Ireland, United Kingdom, help@novasagency.com.