LEGAL / LAST UPDATED 3 SEPTEMBER 2026
Privacy policy
This policy explains how Noviom Labs Limited uses personal information when you visit our website, contact us, become a client or use one of our digital services.
1. Who we are
Noviom Labs Limited is the controller responsible for the personal information described in this policy.
- Company number: 11618526
- Registered office: 4 Abbotts Close, Boxgrove, Chichester, England, PO18 0EL
- Privacy contact: [email protected]
2. Information we collect
Depending on how you deal with us, we may collect:
- your name, company, job title, email address and telephone number;
- enquiry details, project requirements, budgets, correspondence and meeting notes;
- account, authentication and support information if you use a client area;
- contract, invoice, payment-status and transaction information (payment-card details are handled by our payment provider rather than stored by us);
- technical information such as IP address, browser, device, referring page, security logs and cookie choices; and
- messages you enter into Novi, our website AI assistant, plus any contact details and project summary you choose to submit;
- marketing preferences and interaction information, where permitted.
We do not intentionally collect special-category information through this website. Please do not include sensitive information in an enquiry unless it is genuinely necessary.
3. How and why we use it
| Purpose | Usual lawful basis |
|---|---|
| Responding to enquiries, preparing proposals and taking requested pre-contract steps | Legitimate interests and steps requested before entering a contract |
| Operating Novi to answer service questions and help you prepare an enquiry | Legitimate interests in providing helpful pre-sales support; consent when you choose to submit contact details |
| Creating accounts and delivering websites, apps, marketing, support and other services | Performance of a contract |
| Billing, accounting, tax and statutory records | Contract and legal obligation |
| Operating, troubleshooting, securing and improving our services | Legitimate interests in running a safe, effective business |
| Optional analytics and advertising technologies | Consent |
| Electronic marketing | Consent, or the business-customer soft opt-in where permitted; you can opt out at any time |
| Legal claims and preventing misuse | Legal obligation and legitimate interests |
Where we rely on legitimate interests, we balance the benefit to our business and customers against your rights and reasonable expectations.
4. Where information comes from
Most information comes directly from you. We may also receive it from your employer or colleagues, public business sources, referral partners, service providers, advertising platforms or consented analytics tools.
5. Who we share information with
Recipients may include hosting and cloud providers, email and collaboration providers, payment providers, professional advisers, contractors working under appropriate obligations, consented analytics or advertising providers, and regulators, courts or law-enforcement bodies. We do not sell personal information.
When a supplier processes information for us, we require suitable contractual, confidentiality and security protections. Some suppliers may also act as an independent controller for their own regulated purposes.
Novi may send the text of your conversation to OpenAI so that a response can be generated. We configure the integration not to request sensitive information and not to store API responses for model training through our application. Conversation state is kept temporarily to operate the chat. It is added to our CRM only when you explicitly submit an enquiry, at which point the enquiry retention period below applies.
Google reCAPTCHA processes technical and interaction information when you start Novi to protect the service from automated abuse. Google acts under its own applicable privacy terms for that processing.
6. International transfers
Some suppliers may process information outside the UK. Where this happens, we use a lawful mechanism such as UK adequacy regulations, the UK International Data Transfer Agreement or the UK Addendum to standard contractual clauses, with supplementary safeguards where appropriate. Contact us for details relevant to your information.
7. How long we keep it
Our usual retention periods are:
- enquiries that do not become projects: up to 24 months after the last meaningful contact;
- client, contract and project records: for the engagement and normally up to 7 years afterwards;
- invoices and accounting records: normally 6 years after the relevant financial year;
- routine support correspondence: up to 24 months after resolution, unless part of a client record;
- routine security and server logs: normally up to 90 days, unless needed for an incident;
- marketing records: until you opt out, or after 24 months without meaningful engagement; and
- cookie choices: 6 months.
We may keep information longer for a dispute, legal hold or statutory obligation, and may delete or anonymise it earlier when no longer needed.
8. Your rights
Subject to applicable exemptions, you may request access, correction, erasure, restriction or portability; object to legitimate-interest processing or direct marketing; and withdraw consent without affecting earlier lawful use.
We do not make solely automated decisions with legal or similarly significant effects. Email [email protected] to exercise a right. We may verify your identity and usually respond within one month.
9. Complaints
Please contact us first. You can also complain to the Information Commissioner’s Office at ico.org.uk/make-a-complaint or on 0303 123 1113.
10. Security, children and changes
We use proportionate technical and organisational safeguards, although no internet service is completely secure. Our services are aimed at businesses and not directed to children. We may update this policy when our services, suppliers or legal duties change; the date above identifies the current version.