Privacy Policy
Owner-designated effective date: 1 October 2026 · Operational details and qualified review remain pending.
Who is responsible
The website operator is NOVAGREX LIMITED, using the NovaGrex brand under NovaGrex is the technology brand of NOVAGREX LIMITED. Its registered office is 66 Paul Street, London, England, United Kingdom, EC2A 4NA. Privacy contact: privacy@novagrex.co.uk. The address was supplied by the owner; mailbox receipt and request handling remain unverified.
Any required representative, data protection officer, registration or additional contact must be identified for the actual processing: {{PRIVACY_ROLES_AND_APPLICABILITY}}. Owner-designated effective date: 1 October 2026; final reviewed version remains pending.
Information in an inquiry
The intended inquiry form asks for a reply email and a description of the need. A name and company are optional. A division selection supplies routing context, including an option for visitors who are unsure or need more than one division.
The reply email and context are needed to respond meaningfully. Please avoid sensitive personal information, credentials, payment details and information about others unless it is necessary and you are entitled to share it. A separate appropriate channel must be agreed when a project needs more sensitive material.
Technical and abuse-prevention information
Delivering pages and protecting a contact route can involve connection information, request times, response status, browser information and security events. The implemented contact controls derive a keyed hash from the proxy-supplied IP address and use expiring quota counters and submission identifiers. The application event log records a random request reference, route category, status, outcome and duration; it excludes raw IP addresses, names, email addresses and message contents. An IP-derived value can still be personal information.
The site is hosted on Vercel. The final notice must also describe the actual mail service, any activated rate-limit store and logging configuration, including what each receives. Technical information must not be described as anonymous merely because direct contact details are absent. Confirmed data inventory: {{TECHNICAL_DATA_INVENTORY}}.
Purposes and applicable legal grounds
The intended purposes are to answer inquiries, discuss a potential engagement, route support or privacy requests, operate the website and protect it against misuse. Sending an inquiry is not intended to subscribe someone to marketing.
Where a legal basis is required, each purpose must be linked to a reviewed basis and any relevant justification: {{PURPOSE_AND_LAWFUL_BASIS_REGISTER}}. This draft does not assume that consent is the basis for every activity or that a general checkbox resolves the question.
Service providers and other recipients
Vercel serves the live website. Business correspondence uses owner-supplied company-domain mailboxes routed through cPanel webmail; the actual hosting company/legal entity, processing region and handling terms for that mailbox remain to be confirmed. The local preview sends no inquiry to a delivery provider. Resend mail and Upstash Redis abuse controls exist in the prepared, inactive backend; they are not active recipients of production inquiries. If activated, Resend would receive inquiry text, reply address and routing context; Redis would receive keyed identifiers, counters and expiring delivery records. Actual provider roles, data categories, regions and agreements remain open: {{APPROVED_PROCESSOR_REGISTER}}.
Sentry error monitoring is configured as an explicit environment opt-in and is disabled in production. A local setup test sent deliberate errors to the NovaGrex Sentry organization in its German ingestion region. If later enabled publicly, reports are configured to contain error types, sanitized code locations and release/environment identifiers, while excluding inquiry text, email addresses, cookies, headers, query strings, breadcrumbs and source context. Replay, tracing, logs, profiling and application metrics are disabled. The service would still receive network connection data. Provider retention, terms and transfer safeguards require review before public activation. An in-house CRM is planned but has not been established as an active recipient of website data.
Any sharing with advisers, authorities or other recipients must have a specific, reviewed purpose and be reflected in the approved notice. The intended V1 site contains no marketing analytics, advertising pixels or visitor-data sales feature. The deployed site must be checked before describing that intent as observed behavior.
Processing locations and transfers
The locations in which hosting, email, operational access and backups process information must be confirmed. A provider’s headquarters alone does not establish where processing takes place.
The approved notice must identify relevant international transfers, the applicable mechanism or safeguards and how further information can be obtained: {{PROCESSING_LOCATIONS_AND_TRANSFER_SAFEGUARDS}}. This draft makes no promise that all data remains in a particular country.
How long information is kept
The owner has selected 12 months for business inquiry and support correspondence. The point from which that period runs, who performs deletion and how mailbox copies and backups are handled still need an operational procedure. The selected period is not evidence that records are already being deleted on schedule.
Security logs, temporary abuse counters, delivery-provider copies and backups have different purposes and may require different periods. Implemented abuse-control TTLs are 10 minutes for the IP bucket, 1 hour / 24 hours / 30 days for aggregate attempt counters, 45 seconds for an in-flight lease and 24 hours for a completed submission record. The remaining approved schedule is unresolved: {{RETENTION_AND_DELETION_SCHEDULE}}. It must explain start points, legal-hold exceptions and provider or backup expiry. This draft does not promise immediate or universal deletion.
Your requests and choices
Depending on applicable law and the processing involved, you may have rights to access, correct, erase, restrict or obtain a copy of information. Contact privacy@novagrex.co.uk or use the Data Deletion Request page to describe the request. The approved notice must identify the rights that actually apply.
Where a right to object applies, you can raise an objection through the privacy contact. Where processing relies on consent, the approved process must explain how to withdraw it. Identity checks should be proportionate; do not send an identity document with an initial request unless a secure, necessary process has been agreed.
Applicable response periods, escalation steps and complaint authority: {{PRIVACY_REQUEST_AND_COMPLAINT_PROCESS}}. These must be confirmed before the notice is published, including any right to contact a supervisory authority directly.
Children and product-specific information
The site explains technology services and digital products. The business owner must confirm the intended audience and whether any service is directed to, or likely to be used by, children. No age threshold or parental-consent mechanism is asserted in this draft: {{AUDIENCE_AND_CHILDREN_POLICY}}.
An app or SaaS product may process account details, product content, billing information or usage data that this corporate website does not. Each actual product needs a notice based on its own behavior before it is offered. This draft cannot substitute for an app-store privacy disclosure or a product data inventory.
Automated processing
The intended form may automatically reject invalid or excessive submissions to reduce abuse. That technical filtering should not be confused with a decision about whether a person is eligible to buy a service.
Any profiling or solely automated decisions with legal or similarly significant effects must be assessed and described if they actually exist: {{AUTOMATED_PROCESSING_REVIEW}}. No such business decision feature is planned for this V1 corporate website.
Security, cookies and changes
The implementation is intended to minimize collection, validate submissions, limit abuse and restrict operational access. These measures reduce specific risks; they are not a guarantee that information can never be lost, intercepted or misused. Actual deployment and operational controls require verification.
Read the Cookie Policy for the intended approach to browser storage and the inventory still to be checked. Material processing changes should prompt a review of this notice and any notice or choice required by applicable law. Versioning and notification procedure: {{PRIVACY_CHANGE_PROCESS}}.