Legal

GDPR & Data Privacy

Last Updated: July 27, 2026

At Novent, protecting our customers’ data is a fundamental part of how we build and operate our system. We are committed to supporting compliance with the General Data Protection Regulation (GDPR) and follow privacy-by-design principles throughout the development of the Novent System.

This page is maintained by Novent AB to answer common privacy questions about the Novent System. It is not a legal certification or substitute for a signed Data Processing Agreement.

Data Ownership

Your data always belongs to your company.

Novent does not claim ownership of any customer data and only processes information necessary to provide the agreed services.

Data Minimization

We only collect and process information required for the operation of the system, such as:

  • User accounts and permissions
  • Production and operational data
  • Documents and attachments uploaded by authorized users
  • Audit logs and system activity
  • Configuration and organizational data

We do not collect unnecessary personal information.

Secure Storage

Customer data is stored within secure cloud infrastructure hosted in the European Union.

Data is protected through:

  • Encryption in transit (HTTPS/TLS)
  • Encryption at rest
  • Role-Based Access Control (RBAC)
  • Database Row Level Security (RLS)
  • Secure authentication
  • Continuous backups

Access Control

Only authorized users within your organization can access your data based on assigned roles and permissions.

Novent employees do not access customer data unless explicitly authorized for support or troubleshooting purposes.

Customer Rights

Customers maintain full control over their data and may request:

  • Access to stored information
  • Correction of inaccurate information
  • Export of customer data
  • Deletion of customer data, subject to contractual and legal obligations

Data Processing

Novent acts as a Data Processor for customer data processed within the system, while the customer remains the Data Controller and determines how personal data is used.

Privacy by Design

Privacy considerations are integrated into the development process. New functionality is designed to minimize unnecessary processing of personal information while maintaining operational effectiveness.

Continuous Improvement

Security and privacy practices are continuously reviewed and improved to align with evolving regulations, customer requirements, and industry best practices.

Questions about GDPR or data privacy?

Contact us at support@noventsystem.com and we will be happy to help.

Read our Privacy Policy