NOVA PRIVACY POLICY
LAST UPDATED: 13.04.25
Nova ("NOVA", "we", "us" or "our") is an AI-powered software-as-a-service platform designed to assist businesses in automating finance and other operational workflows. Nova provides intelligent digital teammates that help streamline activities such as document processing, reconciliations, reporting, and compliance checks through secure, cloud-based technology.
At Nova, we recognize that trust is fundamental to the adoption of AI-driven platforms. We are committed to safeguarding the privacy, confidentiality, and security of information processed through our platform.
This Privacy Policy ("Policy") explains how Nova collects, uses, discloses, stores, and protects Personal Data when you access or use our platform, websites, applications, software, and related services (collectively, the "Services"). It also describes choices and rights available to individuals in relation to their Personal Data.
1. Scope
This Policy applies to Personal Data that Nova collects and uses directly (for example, when you visit our website, create an account, contact us, or subscribe to communications), as well as Personal Data that is included in customer data and processed by Nova on behalf of its customers while providing the Services.
For Personal Data that forms part of customer data processed through the Services, Nova's obligations are further governed by its agreements with customers.
2. Definitions
- "Personal Data" means any information relating to an identified or identifiable natural person.
- "Processing" means any operation performed on Personal Data, whether automated or not, such as collection, storage, use, disclosure, or deletion.
- "Services" means Nova's AI-powered SaaS platform and related offerings, including websites and support channels.
- "Subscriber" means the entity or individual that has subscribed to the Services.
- "Subscriber Data" means Data submitted, stored, sent, or made available by or on behalf of a Subscriber through the Services, which may include Personal Data.
- "Terms of Use" means the agreement governing access to and use of the Services.
3. Personal Data We Collect
The Personal Data we collect depends on how you interact with Nova and the Services.
3.1 Information You Provide Directly
This may include:
- Name, business email address, and phone number
- Organization details and job title
- Account credentials
- Support communications
- Billing contact details
- Any other information you choose to provide when you register, contact us, attend trainings/webinars, submit forms, or communicate with us
3.2 Information We Collect Automatically
This may include:
- IP address
- Device and browser information
- Log data and approximate location derived from IP
- Identifiers and cookies
- Usage data (pages viewed, features used, clicks)
- Diagnostic data used to maintain security and improve performance
3.3 Information from Third Parties
We may receive information from service providers and partners that help us provide the Services (such as hosting, payment processors, email/communications, analytics, customer support tools) or from public sources where permitted by law.
4. How We Use Personal Data
We use Personal Data for the following purposes, or as otherwise described at the time of collection, in connection with providing and improving the Nova platform and Services.
4.1 Service Delivery and Operations
We use Personal Data to:
- Provide, operate, and manage the Nova platform and our business, including creating and administering user accounts, managing subscriptions, and maintaining our relationship with you.
- Process payments, handle billing or financial issues, and respond to customer queries or support requests.
- Communicate with you about your use of the Services, including sending service-related notices, updates to our terms or policies, and other important communications.
- Understand your needs and preferences, personalize your experience with the Services, and enable features you request.
- Authenticate users, manage access controls, and register participants for events, training sessions, or webinars.
- Ensure the security of our premises and digital infrastructure.
4.2 Research, Development and Improvement
We use Personal Data to improve and develop our products and Services by analysing how they are used and interacted with. This includes:
- Performing analytics to understand usage trends, improve functionality, enhance user experience, and develop new features.
- Where applicable, using Personal Data to train and improve our artificial intelligence and machine learning systems that power Nova's Services.
- Combining and anonymising data to create aggregated statistics for research, product development, and business insights, provided such data no longer identifies individuals.
4.3 Marketing and Communications
We may send you marketing communications relating to our Services, product updates, new offerings, events, or promotions only where we have obtained your prior consent, as required under applicable law.
At the time of collecting your Personal Data, we will provide you with a clear option to consent to receiving such communications. You may withdraw your consent at any time by:
- Clicking the "unsubscribe" link in our communications; or
- Contacting us at privacy@novahq.ai
Withdrawal of consent will not affect the lawfulness of Processing carried out prior to withdrawal. We may personalise communications and content based on your interactions with Nova, subject to your consent where required by law.
4.4 Compliance, Protection and Legal Obligations
We may use Personal Data to:
- Protect the security and integrity of the Nova platform and prevent fraud or misuse.
- Ensure compliance with our Terms of Use and applicable laws.
- Comply with legal or regulatory requirements and respond to lawful requests from authorities.
- Protect the rights and safety of Nova, our users, employees, or others.
- Exercise or defend legal claims.
4.5 With Your Consent
In certain cases, we may request your consent to use Personal Data for specific purposes where required by law. Where Processing is based on consent, you may withdraw such consent at any time.
We may also Process Personal Data for other purposes that are compatible with the above and permitted under applicable law.
5. AI and Model Training
Nova may use data to operate, maintain and improve features of the Services, including AI/ML systems that support the Services.
Nova does not use Personal Data or Subscriber Data to train or improve general-purpose AI models outside the scope of providing the Services, unless:
- Expressly agreed with the Subscriber; or
- Permitted by applicable law.
Where we use data to improve the Services, we use appropriate safeguards such as access controls, minimization, and (where feasible) aggregation or de-identification.
6. How We Share Personal Data
We may share your Personal Data with third parties only where necessary to operate and deliver the Nova platform and Services. This includes sharing with:
- Our affiliates, authorized employees and contractors on a need-to-know basis.
- Integration partners expressly enabled by the customer.
- Trusted service providers who assist us with hosting, payments, customer support, analytics, security, communications, and similar business functions. These service providers process Personal Data on our behalf pursuant to contractual arrangements with Nova and are required to implement appropriate technical and organisational safeguards.
We may also disclose Personal Data in the following circumstances:
- Where you choose to connect third-party applications or integrations with Nova, your Personal Data may be shared with those providers and will be governed by their respective privacy policies.
- Where required by law, regulation, or legal process, or to protect the rights and safety of Nova, our users, or others.
- In the event of a merger, acquisition, or sale of assets, Personal Data may be shared as part of such transaction.
- Where you access Nova through a Subscriber (such as your employer), information relating to your use of the Services may be shared with that Subscriber as necessary to provide and manage the Services.
7. Legal Bases for Processing
Where required by applicable law, Nova processes Personal Data based on one or more of the following:
- Performance of a contract
- Compliance with legal obligations
- Consent (for example, where required for certain marketing or cookie uses)
- Other lawful grounds permitted under applicable law
8. Cross-Border Data Transfers
Nova is headquartered in India and primarily processes Personal Data within India. However, in order to operate and deliver the Services effectively, Personal Data may be transferred to, stored, or processed in countries outside India, including in locations where Nova, its affiliates, or its service providers maintain operations.
Where Personal Data is transferred outside India, such transfers shall be made in accordance with the Digital Personal Data Protection Act, 2023 and applicable rules thereunder, and subject to any restrictions notified by the Government of India from time to time.
We implement appropriate safeguards to protect Personal Data during cross-border transfers, which may include:
- Contractual data protection obligations binding the recipient to process data only on documented instructions.
- Technical safeguards such as encryption in transit and at rest.
- Access controls, logging, and monitoring mechanisms.
- Organisational security policies and confidentiality obligations.
- Reliance on legally recognized transfer mechanisms, including standard contractual clauses or equivalent contractual protections, where applicable.
Where applicable law recognizes certain jurisdictions as providing an adequate level of data protection, transfers may be made on that basis.
9. Data Retention
We retain your Personal Data only for as long as it is necessary to fulfill the purposes for which it was collected, in accordance with our records management and Data Retention practices. Personal Data will be deleted or archived after a reasonable period, guided by the following criteria:
- We may retain your Personal Data for the duration of our ongoing relationship with you, such as when you hold an account with us.
- We may retain your Personal Data as long as you remain engaged with our service provider, and we provide services to you pursuant to contractual obligations with those service providers.
- We may retain your Personal Data to the extent necessary to comply with applicable legal, regulatory, and contractual requirements.
- We may retain your Personal Data if we believe it is necessary to prevent fraud or future abuse, or if required by law, such as during the pendency of any legal or regulatory proceedings, or upon receiving a legal or regulatory directive.
Upon the expiration of the applicable retention period, your Personal Data will be securely deleted or archived in compliance with legal retention requirements and statutory limitation periods.
10. Data Accuracy
We take reasonable steps to ensure that Personal Data we process is accurate, complete, and kept up to date, particularly where such data is used to provide the Services or make decisions affecting you.
You are responsible for ensuring that the information you provide to us is accurate and current. You may update your account information at any time through your account settings, or by writing to us at privacy@novahq.ai.
11. Security
Nova safeguards your Personal Data using reasonable security standards and procedures and in compliance with applicable privacy laws. Our websites and Services use industry-recognized physical, technical, and organizational safeguards to protect Personal Data throughout its lifecycle within our systems.
12. Data Breach Notification
In the event of a Personal Data breach, Nova will take appropriate steps to contain and investigate the incident. Where required under applicable law, Nova will notify affected individuals and relevant authorities, including the Data Protection Board of India, within prescribed timelines.
13. Your Rights and Choices
Subject to applicable law, you may have rights to:
- Access, correct, update, or delete your Personal Data.
- Request a copy of your Personal Data.
- Object to or restrict certain Processing.
- Withdraw consent where Processing is based on consent.
To exercise your rights, please contact us at privacy@novahq.ai. We will acknowledge receipt of your request and respond within 30 days of receipt, unless a longer period is permitted or required under applicable law. If we require additional time, we will inform you of the reason for the delay and the expected response timeframe.
If you use the Services through a Subscriber (e.g., employer), requests relating to Subscriber Data may need to be directed to the Subscriber, as they control that data. Nova will support Subscribers in responding to such requests where required under applicable law.
14. Cookies and Tracking
We use cookies and similar technologies for core functionality, security, performance, and to understand usage of our Services. You can manage cookies through browser settings. Where required by law, we will seek consent for non-essential cookies. Disabling cookies may affect certain features.
15. Children's Information
Nova's Services and website are not intended for individuals under the age of 18 years ("Children") without the consent of a parent or legal guardian. We do not knowingly collect, solicit, or process Personal Data from Children. If any such data is identified without appropriate consent, it will be promptly deleted. Where required under applicable law, verifiable parental consent would be obtained prior to Processing Children's data.
16. Contact and Grievances
If you have questions, requests, or concerns about this Policy or our privacy practices, you may contact us at:
Email: privacy@novahq.ai
Address: Nova Technologies Private Limited 905, Runwal Square, LBS Road Mulund (West), Mumbai — 400080 Maharashtra, India
We aim to respond to grievances promptly and within a reasonable period in accordance with applicable law. Where additional time is required, we will inform you accordingly.
Do you have questions?
Reach out to our team and start a discussion.