Legal

Privacy Policy

Effective July 29, 2026  ·  Last updated July 29, 2026

The short version: Your employee data never touches our servers. It stays entirely in your browser. We collect only what is necessary to run your account, answer your enquiry and invoice you. We do not sell your data. This policy covers GDPR, CCPA, and other applicable privacy laws.

1. Who we are

Noveli is an HR tooling platform accessible at noveli.io, operated from Romania, European Union. For privacy questions contact privacy@noveli.io.

2. What we collect

Enquiry data

When you submit the contact form on our website we collect your name, work email address, company name, the size of your organisation, anything you write in the free text field, and the IP address the request came from. We use this to respond to you, to prepare a quote, and to keep a record of who we have spoken to.

This data is stored in our database in the EU region and is accessible only to Noveli. It is not shared with any third party for marketing, and we do not add you to a mailing list on the strength of an enquiry.

Account data

When you create an account we collect your email address (for authentication and communication), your name (optional, for workspace personalisation), and your workspace name and settings.

Billing data

If you enter into a paid subscription we collect the details needed to issue a legally compliant invoice: billing contact name and email, company legal name, registered address, and VAT or tax identification number where applicable.

We never handle payment card data. Noveli has no checkout, no card on file and no payment processor. Invoices are settled by bank transfer, so the only payment information we hold is what appears on the invoice and on the incoming transfer.

Usage data

We collect basic usage data to operate and improve Noveli, including IP address, browser type, pages visited, timestamps, and error logs. We do not use third party analytics trackers or advertising pixels.

Employee and workforce data

Your employee data is processed entirely within your browser. CSV files, org chart data, and workforce information are never uploaded to, transmitted to, or stored on Noveli's servers. Our backend has zero access to your employee data at any point. This is a core architectural principle.

3. How we use your data

We use collected data to respond to enquiries, provide and improve the Service, authenticate your account, issue and collect invoices, send transactional emails, respond to support requests, detect and prevent fraud, and comply with legal obligations. We do not use your data for advertising and do not sell it to any third party.

4. Sub-processors

We share data only with the following service providers, strictly as necessary to operate Noveli:

All sub-processors are contractually required to handle data in accordance with applicable privacy laws including GDPR. We no longer use a payment processor, as invoicing is handled directly by Noveli.

5. International data transfers

Some of our sub-processors operate data centres in the United States. Where personal data is transferred outside the European Economic Area, we rely on Standard Contractual Clauses approved by the European Commission, or the sub-processor's participation in a recognised adequacy framework. You may request details of applicable safeguards by contacting privacy@noveli.io.

6. Your rights under GDPR (EU and EEA users)

If you are located in the EEA you have the right to access, rectify, erase, and port your personal data; to object to or restrict processing; and to withdraw consent at any time. To exercise any of these rights, contact privacy@noveli.io. We respond within 30 days. You may also lodge a complaint with your local data protection authority.

Where we rely on legitimate interests, including for enquiry records, you have the right to object. If you object we will delete your enquiry record unless we have a compelling reason not to, such as an active contract or a legal obligation.

7. Your rights under CCPA (California users)

If you are a California resident you have the right to know what personal information we collect and how we use it, to request deletion of your personal information, and to opt out of the sale of personal information. We do not sell personal information. To exercise these rights, contact privacy@noveli.io. We respond within 45 days as required by law.

8. Legal basis for processing

9. Data retention

10. Security

We use TLS 1.2 or higher for all data in transit, hashed passwords, row level security in our database, and SOC 2 certified infrastructure providers. Enquiry records are readable only by our backend service role and are not exposed to any client application. For security concerns, contact security@noveli.io. Further detail is on our Security page.

11. Cookies

Noveli uses only strictly necessary functional cookies, specifically authentication session tokens to keep you logged in. We do not use advertising cookies, tracking pixels, or third party analytics cookies. No cookie consent banner is required for strictly necessary cookies under GDPR.

12. Data Protection Officer

Noveli does not currently meet the thresholds requiring a mandatory DPO under GDPR Article 37. For all data protection enquiries please contact privacy@noveli.io.

13. Children

Noveli is a B2B platform for HR professionals and is not directed at individuals under 16. We do not knowingly collect data from minors. If you believe a minor has provided us with personal data, contact privacy@noveli.io and we will delete it promptly.

14. Changes

We will notify account holders by email of material changes at least 14 days before they take effect. Continued use constitutes acceptance of the updated policy.

Privacy contacts

Privacy enquiries: privacy@noveli.io

Data controller: Noveli, Romania, European Union

GDPR response time: Within 30 days

CCPA response time: Within 45 days