Privacy statement · v2.1 · August 2026
Privacy. Not a page of clauses; what we do and don't.
Novot AI B.V. (KvK 42090389, Haarlem) builds AI colleagues for SMBs and runs on infrastructure in the EU. Below, per situation: what we do with personal data, why, and for how long — in plain language. Questions: info@novotai.nl.
First, two roles
For our own website, contact requests and customer administration we are the data controller: we decide how that data is used, and this statement describes it.
When Nova handles messages on behalf of a business that is our customer, we are the processor: that business decides the purpose, we act within the data processing agreement we signed with that business.
Are you a customer of a business that uses Nova? Then that business is responsible for your data, and it is your point of contact for questions and privacy requests. If such a request reaches us directly, we forward it to that business right away.
Our website and your first contact
- Contact form — name, email, company and your question. It arrives as an email in our secured business mailbox and is only used to respond (legal basis: steps taken at your request prior to a possible contract, art. 6(1)(b) GDPR). We keep it for up to 12 months after our last contact.
- If you book a conversation, we process the same data plus whatever you share about your business — needed to run the intake conversation.
- Cookies — we do not set cookies ourselves: no tracking, no third-party analytics, no ad pixels. Your language choice (Dutch/English) comes from the URL path (novotai.nl or novotai.nl/en), not a cookie.
- Technical logs — our servers keep short-lived technical logs for security and abuse prevention (legal basis: legitimate interest, namely keeping our systems secure).
Becoming or being a customer?
- Account and contract data — name and business contact details of you and your colleagues (sometimes provided to us by your organization), company registration details and agreements made. Legal basis: performance of the contract.
- Invoicing — we keep invoice and payment data for 7 years. That is a legal (tax) obligation.
- Service messages — as a customer you receive updates about the service and similar services from us; you can unsubscribe in every email (legal basis: legitimate interest, maintaining our customer relationship).
Without a name and email address we cannot respond or perform the contract; beyond that, we do not ask for more than necessary.
Nova at work: messages from your customers
If your business deploys Nova, we process on your behalf the messages your customers send through the channels you connect (email, WhatsApp Business, phone, calendar), plus metadata such as time, channel and language.
Our logs contain no message content. There we only keep a cryptographic hash — a fingerprint from which the content cannot be read back. For debugging we use synthetic samples that you approve in advance.
Our AI provider processes the content solely to generate the answer: contractually no training on your data, deletion typically within 30 days, with EU Standard Contractual Clauses as safeguard (see sub-processors).
If you use WhatsApp as a channel, delivery runs through Meta's WhatsApp Business platform under the terms you have with that platform — Nova plugs into it. With Nova Vault, processing runs on a server at your premises. We only have access to it insofar as needed for remote support or maintenance — outside of that, everything stays within your environment.
The full arrangements are in the data processing agreement (art. 28 GDPR). We do not publish it online: it is part of the agreement and you receive it as a signable document together with the proposal — well before you sign. It comes with a ready-made information text you can paste straight into your own privacy statement. Want to see it sooner? Request it via info@novotai.nl and we will send it to you.
AI transparency and automated decisions
- Nova always makes clear that you are talking to AI: at first contact in chat and email, and at the start of every phone call. Since 2 August 2026 this is also required under the European AI Act (art. 50), and this disclosure cannot be switched off.
- When Nova is unsure, the message goes to a human. Nova takes no decisions with legal effects concerning persons (art. 22 GDPR) and is not used for, for example, evaluating job applicants or employees.
- Metadata such as language and sentiment indication is only used to route messages correctly and monitor quality — not to build profiles of individuals.
Retention periods
- Message content: not stored beyond the processing itself.
- Hash logs: maximum 90 days, then auto-wiped.
- Anonymized metadata (volumes, languages): 24 months, for product improvement.
- Account data: for the duration of the contract; afterwards only what the law requires (invoicing: 7 years).
- Contact form and intake: up to 12 months after our last contact.
- Nova Vault (your own server): you decide — it sits with you.
Sub-processors
For our own website and business email — including the contact form — we work with Hostinger (hosting and storage in the EU). No Nova customer content is stored there.
When Nova processes messages on behalf of a customer, one more party joins that EU hosting: the AI provider that drafts the answer. It is based outside the EU. It processes the content solely in order to answer, is contractually barred from training on it, typically deletes processed messages within 30 days, and the transfer is covered by the EU Standard Contractual Clauses. Which party that is, and the safeguards that come with it, is named in the data processing agreement you sign with us as a customer; on request we send it to you beforehand.
We announce changes to this list to our customers at least 30 days in advance, so they can object. And still: no Google Analytics, no Meta Pixel, no ad networks on this site.
Your rights
You have the right to access, rectification, erasure, restriction of processing, data portability and objection. Where you gave consent, you can withdraw it at any time.
Email info@novotai.nl. We aim to reply within 7 business days and will in any case respond within the legal period of one month. Free of charge. If we cannot work it out together, you can lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
What we don't do
- No training of AI models on your data — nor by our AI provider (per contract).
- No selling or renting out data. Not to advertisers, not to data brokers.
- No advertising profiles and no tracking cookies.
- No message content in our logs — staff cannot read back customer conversations.
Data breaches
Where we process data on behalf of your business, we notify you of a data breach within 24 hours, with what is known about its nature, scope and measures taken — so you can meet your own notification duty in time. We help with that.
For processing we are responsible for ourselves, we report a breach to the Dutch Data Protection Authority within 72 hours where required (art. 33/34 GDPR) and inform you immediately in case of high risk. A post-mortem follows within 14 days.
Changes
Updates are published on this page with a changelog; on material changes we also actively email customers. If we want to use data for a new purpose, we inform you beforehand.
Changelog
- v2 · August 2026 · Revised: roles split out (controller/processor), legal bases and retention per purpose, rights completed (restriction, withdrawing consent, complaint to the DPA), AI transparency added (EU AI Act art. 50), website processing (contact form, demo, cookies) described and sub-processor arrangements tightened.
- v1 · May 2026 · Initial version.