Privacy Policy
Last Updated: July 27, 2026
Novent AB ("Novent", "we", "us", or "our") respects your privacy and is committed to protecting it. This Privacy Policy explains how we collect, use and protect personal data when you visit noventsystem.com and use the Novent System (including office.noventsystem.com, shopfloor.noventsystem.com and dashboard.noventsystem.com). It is written to meet the transparency requirements of the EU General Data Protection Regulation (GDPR, Regulation 2016/679).
1. Controller and contact
The data controller for personal data processed about visitors to our website and prospects who contact us is:
Novent AB
c/o Salim Jasarevic, Ringblommegatan 10, 426 68 Västra Frölunda, Sweden
Email: support@noventsystem.com
Phone: +46 701 456 936
Organisationsnummer: 559266-3966
When you use the Novent System as an authenticated user of a customer organization, that organization is the controller of the operational data it stores in the System, and Novent acts as a processor on its behalf under a Data Processing Agreement (DPA).
We have not appointed a Data Protection Officer as we are not required to do so under Article 37 GDPR. Privacy questions can be sent to the email above.
2. Personal data we collect
- Account data: name, work email, company name, role, phone number, chosen sub-domain and login credentials (passwords are stored hashed, never in plain text).
- Contact and demo-request data: the information you submit through our contact or Get Started forms, including your goals and any free-text message.
- Usage and technical data: IP address, browser type, device information, pages visited and security-relevant events (audit logs). Collected only when strictly necessary to operate and secure the site.
- Cookies and similar technologies: only strictly-necessary cookies by default. Preference cookies (e.g. Google Translate) load only after you opt in via the cookie banner.
3. Purposes and legal bases (GDPR Art. 6)
| Purpose | Legal basis |
|---|---|
| Providing and operating the Novent System for account holders. | Contract - Art. 6(1)(b). |
| Responding to contact requests, demos and quotes. | Consent - Art. 6(1)(a); pre-contractual steps - Art. 6(1)(b). |
| Security, fraud prevention, audit logging. | Legitimate interest - Art. 6(1)(f). |
| Product analytics and preference cookies. | Consent - Art. 6(1)(a). |
| Compliance with legal obligations (e.g. accounting). | Legal obligation - Art. 6(1)(c). |
4. Cookies and consent
We use only strictly necessary cookies by default. Preference cookies (currently used to remember your Google Translate language) are loaded only after you opt in via our cookie banner. No analytics or advertising trackers are loaded before consent.
You can change or withdraw your cookie choices at any time by clicking the button below or by opening our GDPR & Data Privacy page.
5. Sub-processors and recipients
We do not sell personal data. We share it only with vetted service providers acting as processors on our behalf, under written data-processing terms:
- Amazon Web Services (AWS) - cloud hosting infrastructure (EU regions).
- Supabase - managed PostgreSQL, authentication and object storage.
- Resend - transactional email delivery.
- Google (Google Translate) - optional in-page translation; loaded only with your preferences consent.
We may also disclose personal data to competent authorities where required by law, and to advisors or acquirers in connection with a corporate transaction.
6. International data transfers
Customer data is hosted within the European Union. Where a sub-processor processes limited data outside the EU/EEA (for example U.S.-based support infrastructure), we rely on the European Commission's Standard Contractual Clauses (SCCs) and additional safeguards required by the Schrems II ruling.
7. Retention
- Account data: for the duration of the subscription and up to 12 months after termination, unless a longer period is required by law.
- Contact and demo-request data: up to 24 months from your last interaction, then deleted or anonymized.
- Security and audit logs: up to 12 months.
- Invoices and accounting records: 7 years (Swedish Bookkeeping Act).
- Cookie consent record: up to 12 months.
8. Security
We apply appropriate technical and organizational measures including TLS encryption in transit, encryption at rest, PostgreSQL Row-Level Security, role-based access control, least-privilege operational access, continuous backups and monitoring. See our GDPR & Data Privacy page for more detail.
9. Your rights under the GDPR
Subject to applicable conditions, you have the right to:
- Access your personal data (Art. 15).
- Rectify inaccurate or incomplete data (Art. 16).
- Erase your data ("right to be forgotten", Art. 17).
- Restrict processing (Art. 18).
- Data portability (Art. 20).
- Object to processing based on legitimate interests (Art. 21).
- Withdraw consent at any time, without affecting the lawfulness of prior processing (Art. 7(3)).
To exercise these rights, contact support@noventsystem.com. We respond within one month of receipt.
You also have the right to lodge a complaint with your local supervisory authority. In Sweden this is the Integritetsskyddsmyndigheten (IMY) - www.imy.se.
10. Automated decision-making
We do not carry out automated decision-making, including profiling, that produces legal or similarly significant effects on you within the meaning of Article 22 GDPR.
11. Children's privacy
The Novent System is a business-to-business product not intended for children under 16, and we do not knowingly collect personal data from them.
12. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be announced on this page with an updated effective date.