PRIVACY POLICY
Last updated August 19, 2026
This Privacy Notice for Novara Software, LLC (“Novara,” “we,” “us,” or “our”) describes how and why we may access, collect, store, use, disclose, or otherwise process personal information when you access our website, use our services, or otherwise interact with us.
This Privacy Notice applies when you:
- Visit our website at www.novara.com;
- Access or use our hosted software products and related services;
- Engage with us regarding sales, marketing, support, or events; or
- Otherwise communicate or interact with Novara.
Our Products and Services
In this Privacy Notice, “Services” refers to Novara’s website, hosted software products, training programs and content, and related services, including the following offerings:
- Ensogo — an AI-native sustainability performance management platform that helps
customers collect, manage, and report environmental, social, and governance
(ESG) data for compliance and disclosure purposes; - Flex — an all-in-one environment, health, and safety (EHS) software platform
supporting employee engagement, safety culture, incident and risk management,
and regulatory compliance; - STS — safety training programs and related services, including video-based training
content developed for manufacturing and industrial workforces, together with
associated assignment, delivery, and completion tracking; and - RMC — risk management, safety, and compliance solutions provided to insurance
brokers, employers, and their workforces.
The personal information processed through each offering depends on the offering itself and on how the applicable customer configures and uses it. Unless a specific offering is identified, references in this Privacy Notice to “the Services” apply to all Novara offerings listed above.
Novara generally acts as a processor, service provider, or contractor with respect to personal information submitted to these offerings by or on behalf of our business customers, as described under “Our Roles.”
Our Roles
Novara processes personal information in different capacities depending on the circumstances.
Controller Data means personal information for which Novara determines the purposes and means of processing. This generally includes information relating to website visitors, prospective customers, customer representatives, vendors, business partners, event participants, and sales and marketing contacts.
Customer Data means personal information submitted to, stored in, transmitted through, or otherwise processed by Novara’s hosted software products and related services on behalf of a business customer. The applicable customer generally determines the purposes and means of processing Customer Data. Novara acts as a processor, service provider, or contractor on the customer’s behalf.
When Novara processes Customer Data, our processing is governed by our agreement with the applicable customer, including any applicable data processing agreement. We process Customer Data only in accordance with the customer’s documented instructions, except where otherwise required or permitted by law.
If you have concerns regarding Customer Data, you should ordinarily direct your request to the organization that collected or controls the information. If you submit a request to Novara concerning Customer Data, we may refer the request to the applicable customer or assist that customer in responding.
Our Services are designed for businesses and are not intended for personal or household use.
This Privacy Notice does not govern personal information Novara processes about its own employees, former employees, job applicants, or other workforce members in the context of Novara’s employment relationships. Such information is governed by separate internal notices and policies.
Please review this Privacy Notice carefully. If you have questions or concerns, contact us at [email protected].
SUMMARY OF KEY POINTS
What personal information do we process? We process personal information depending on how you interact with Novara and our Services. We also process Customer Data submitted by or on behalf of our business customers.
Do we process sensitive personal information? We do not intentionally request sensitive personal information through our public website, sales, or marketing channels. Customers may submit sensitive information through our hosted software products, including safety, incident, injury, health, location, or workforce-related information. We process that information on behalf of the applicable customer.
Do we collect information from third parties? We may receive information from public databases, marketing partners, social media platforms, data providers, business customers, customer-authorized integrations, and other sources.
How do we process personal information? We process Controller Data to provide, improve, secure, and administer our Services, communicate with you, conduct marketing, prevent fraud, comply with law, and operate our business. We process Customer Data to provide the Services and carry out the applicable customer’s documented instructions.
With whom do we share personal information? We may disclose personal information to service providers, subprocessors, professional advisers, business partners, regulators, and other parties in the circumstances described in this Privacy Notice. We do not disclose Customer Data to advertising partners for their independent advertising purposes.
Is personal information transferred internationally? Yes. Novara is based in the United States, and personal information may be transferred to and processed in the United States and other countries.
How do we protect personal information? We maintain technical and organizational safeguards designed to protect personal information. No system can be guaranteed to be completely secure.
What rights do individuals have? Depending on your location and the circumstances of the processing, you may have rights concerning your personal information. Requests involving Customer Data should ordinarily be submitted to the applicable Novara customer.
TABLE OF CONTENTS
- WHAT INFORMATION DO WE COLLECT?
- HOW DO WE PROCESS YOUR INFORMATION?
- WHAT LEGAL BASES DO WE RELY ON?
- WHEN AND WITH WHOM DO WE SHARE PERSONAL INFORMATION?
- DO WE USE COOKIES AND OTHER TRACKING TECHNOLOGIES?
- IS YOUR INFORMATION TRANSFERRED INTERNATIONALLY?
- DATA PRIVACY FRAMEWORK
- HOW LONG DO WE KEEP YOUR INFORMATION?
- WHAT DATA SECURITY STEPS DO WE TAKE?
- DO WE COLLECT INFORMATION FROM MINORS?
- WHAT ARE YOUR PRIVACY RIGHTS?
- DO WE MAKE UPDATES TO THIS NOTICE?
- HOW CAN YOU CONTACT US?
- OTHER IMPORTANT INFORMATION
1. WHAT INFORMATION DO WE COLLECT?
Personal information you disclose to us
In Short: We collect personal information that you provide to us.
We collect personal information that you voluntarily provide when you express an interest in obtaining information about Novara or our Services, request a demonstration, create or administer an account, request support, participate in an event, subscribe to communications, or otherwise contact us.
The personal information we collect depends on the context of your interactions with us and may include:
- Names;
- Telephone numbers;
- Email addresses;
- Job titles;
- Employer or company information;
- Mailing addresses;
- Account credentials;
- Communications and support requests; and
- Other information you choose to provide.
Sensitive information provided directly to Novara
We do not intentionally request sensitive personal information through our public website, contact forms, sales processes, or marketing activities. Please do not submit sensitive personal information through those channels unless Novara specifically requests it and provides an appropriate notice.
Customer Data
In Short: We process personal information submitted to or processed through our Services by our business customers.
Customers and their authorized users may submit, upload, transmit, integrate, or otherwise make personal information available through the Services. The Customer Data processed by Novara depends on how each customer configures and uses the Services.
Customer Data may include:
- Names, contact information, employee or contractor identifiers, and account information;
- Job titles, departments, managers, work locations, and assignments;
- Training assignments, course participation, completion records, qualifications, licenses, and certifications;
- Workplace safety, risk, incident, injury, claim, inspection, audit, investigation, and compliance information;
- Occupational health or medical information associated with workplace incidents or safety programs;
- Photographs, videos, audio recordings, documents, forms, statements, and attachments;
- Location, device, system, and usage information;
- Information contained in reports, notes, workflows, communications, and customer-configured fields;
- Information received through customer-authorized integrations; and
- Other personal information selected or submitted by a customer or its authorized users.
Customer Data may include information considered sensitive, special-category, or HR-related information under applicable law or the Data Privacy Framework Principles.
Novara processes Customer Data on behalf of the applicable customer and in accordance with the customer’s documented instructions, our contractual obligations, and applicable law.
The applicable customer is responsible for determining whether it has an appropriate legal basis to collect and process Customer Data and for providing required notices, choices, and consents to individuals.
Information automatically collected
In Short: Certain device, usage, and technical information is collected automatically when you access or use the Services.
We automatically collect certain information when you visit, use, or navigate the Services. This information may include:
- Internet Protocol address;
- Browser and device characteristics;
- Operating system;
- Language preferences;
- Referring URLs;
- Device name;
- Country or approximate location;
- Date and time of access;
- Pages, files, functions, or features accessed;
- Searches and actions performed;
- System activity;
- Error reports and crash information; and
- Other technical and diagnostic information.
This information is primarily used to maintain the security, availability, performance, and operation of the Services and for internal analytics and reporting.
Log and usage data
Log and usage data includes service-related, diagnostic, security, usage, and performance information recorded when you access or use the Services.
Device data
Device data may include information regarding the computer, phone, tablet, browser, or other device used to access the Services, including device and application identifiers, hardware model, Internet service provider, mobile carrier, operating system, and system configuration.
Location data
We may collect approximate location information, such as location inferred from an IP address.
Certain Services may process more precise location information where enabled by the applicable customer or user and permitted by device settings and applicable law.
You may be able to limit location collection through your device or browser settings. Disabling location functionality may affect the availability of certain features.
Information collected from other sources
In Short: We may collect information from public databases, marketing partners, customers, integrations, and other third parties.
We may obtain information from:
- Public databases;
- Joint marketing partners;
- Affiliate programs;
- Data providers;
- Social media platforms;
- Event sponsors;
- Business customers;
- Customer-authorized integrations; and
- Other third parties.
This information may include mailing addresses, job titles, email addresses, telephone numbers, intent or behavioral data, IP addresses, social media profiles, professional information, and custom profiles.
2. HOW DO WE PROCESS YOUR INFORMATION?
In Short: We process Controller Data for our own business purposes and process Customer Data on behalf of our customers.
Controller Data
We may process Controller Data for the following purposes:
- To deliver, facilitate, and improve our Services;
- To respond to inquiries and provide support;
- To administer accounts;
- To send administrative and service-related information;
- To request feedback;
- To send marketing and promotional communications;
- To provide targeted advertising where permitted by law;
- To maintain the security and integrity of the Services;
- To prevent fraud, abuse, and unauthorized activity;
- To identify usage trends;
- To measure marketing and promotional effectiveness;
- To conduct research and development;
- To comply with legal and regulatory obligations;
- To participate in legal proceedings and protect legal rights;
- To comply with contractual obligations; and
- To manage and administer our business, including mergers, acquisitions, financing, reorganizations, and divestitures.
Customer Data
We process Customer Data for the following purposes:
- To host, operate, maintain, secure, and provide the Services;
- To configure the Services as directed by the customer;
- To authenticate users and administer access;
- To deliver training, reporting, incident-management, inspection, audit, safety, compliance, and related product functionality;
- To provide customer support and troubleshoot technical issues;
- To monitor the performance, availability, integrity, and security of the Services;
- To prevent, detect, and respond to fraud, abuse, security incidents, and unlawful activity;
- To provide customer-requested integrations, exports, reports, and other functionality;
- To comply with the customer’s documented instructions;
- To comply with applicable legal obligations; and
- To protect legal rights and enforce applicable agreements.
We do not use Customer Data for Novara’s independent advertising or marketing purposes.
Where legally and contractually permitted, we may generate aggregated or de-identified information that is not reasonably capable of identifying an individual. We may use such information to operate, analyze, secure, and improve the Services.
3. WHAT LEGAL BASES DO WE RELY ON?
In Short: When Novara acts as a controller, we process personal information only when we have an appropriate legal basis.
Depending on the applicable law and circumstances, we may rely on:
- Consent. We may process personal information when you have provided consent for a specific purpose. You may withdraw consent at any time, subject to applicable law.
- Performance of a Contract. We may process personal information when necessary to enter into or perform a contract with you or take steps at your request before entering into a contract.
- Legitimate Interests. We may process personal information when reasonably necessary for our legitimate business interests, provided those interests are not overridden by your rights and interests.
- Legal Obligations. We may process personal information to comply with laws, court orders, regulatory requirements, or lawful requests.
- Protection of Rights and Interests. We may process personal information when necessary to protect the rights, safety, or property of individuals, Novara, our customers, or others.
Our legitimate interests may include:
- Responding to requests for information;
- Providing and improving our Services;
- Maintaining and securing our websites and systems;
- Understanding how our Services are used;
- Preventing fraud and abuse;
- Conducting business-to-business marketing; and
- Managing our business and contractual relationships.
When Novara processes Customer Data as a processor or service provider, the applicable customer is responsible for identifying the legal basis for the processing. Novara processes Customer Data under the customer’s documented instructions and applicable agreement.
Canada
If you are located in Canada, we may process personal information based on express or implied consent as permitted by applicable law.
Canadian law may permit collection, use, or disclosure without consent in limited circumstances, including:
- Investigations and fraud detection or prevention;
- Qualifying business transactions;
- Insurance claims;
- Situations involving suspected financial abuse;
- Investigations of contractual breaches or violations of law;
- Compliance with subpoenas, warrants, court orders, or legal process;
- Information produced during employment, business, or professional activities where processing is consistent with the purpose for which it was produced;
- Publicly available information specified by applicable regulations; and
- Approved research or statistical projects subject to applicable safeguards.
4. WHEN AND WITH WHOM DO WE SHARE PERSONAL INFORMATION?
In Short: We disclose personal information in the circumstances described below.
Service providers and subprocessors
We may disclose personal information to third-party service providers and subprocessors that perform services for us or on our behalf.
These parties may include:
- Cloud hosting and infrastructure providers;
- Data storage and backup providers;
- Security and performance-monitoring providers;
- Communication and collaboration tools;
- Customer-support platforms;
- Product engineering and design tools;
- Analytics providers;
- Payment, billing, and order-fulfillment providers;
- Professional advisers, auditors, insurers, and legal counsel;
- Sales and marketing tools;
- Advertising partners and networks;
- Social networks; and
- Other vendors necessary to operate our business or provide the Services.
Our service providers and subprocessors are authorized to process personal information only for specified purposes and subject to applicable contractual obligations.
Customer Data is disclosed to subprocessors only as necessary to provide, secure, support, and maintain the Services, as authorized by the applicable customer agreement, or as required by law.
We do not disclose Customer Data to advertising partners, marketing providers, or social networks for their independent advertising or marketing purposes.
Customer-authorized integrations and recipients
At a customer’s direction, we may disclose Customer Data to:
- Customer administrators and authorized users;
- Systems integrated with the Services;
- Customer-designated service providers;
- Insurers, claims administrators, regulators, compliance partners, or other recipients designated by the customer; and
- Other recipients selected or authorized by the customer.
The customer is responsible for its instructions and for determining whether disclosures to customer-designated recipients comply with applicable law.
Business transfers
We may disclose or transfer personal information in connection with or during negotiations concerning a merger, acquisition, financing, reorganization, divestiture, sale of assets, change of control, bankruptcy, or other business transaction.
Any successor that receives Customer Data will remain subject to the applicable customer agreements and applicable data-protection obligations.
Affiliates
We may disclose personal information to affiliates, subsidiaries, parent companies, joint ventures, or other entities under common control. We require covered affiliates to process the information consistently with this Privacy Notice and applicable contractual obligations.
Business partners
We may disclose Controller Data to business partners to provide jointly offered products, Services, events, content, or promotions.
Where required, we will provide appropriate notice and choice before disclosing personal information to a third party acting as an independent controller.
Legal and regulatory disclosures
We may disclose personal information where we believe disclosure is necessary or appropriate to:
- Comply with applicable law, regulation, legal process, or lawful government request;
- Respond to subpoenas, court orders, warrants, or regulatory inquiries;
- Meet national security or law-enforcement requirements;
- Investigate or prevent unlawful activity, fraud, abuse, or security threats;
- Protect the rights, privacy, safety, or property of Novara, our customers, individuals, or others;
- Enforce our agreements and policies; or
- Establish, exercise, or defend legal claims.
5. DO WE USE COOKIES AND OTHER TRACKING TECHNOLOGIES?
In Short: We use cookies and similar technologies to operate, secure, analyze, and, where permitted, personalize our websites and Services.
We may use cookies, web beacons, pixels, local storage, and similar technologies when you interact with our websites or Services.
Some technologies are necessary to:
- Authenticate users;
- Maintain sessions;
- Secure the Services;
- Prevent crashes;
- Detect and correct errors;
- Save preferences; and
- Provide core functionality.
We may also permit service providers to use technologies for analytics and advertising, including to measure website activity, manage advertisements, or tailor advertising to professional interests.
Where required by law, optional analytics or advertising technologies will not be activated unless you provide consent.
You may manage available choices through our cookie preference settings and Cookie Notice.
To the extent online tracking constitutes a sale, sharing, or targeted advertising under applicable U.S. state law, you may exercise available opt-out rights through our cookie preference settings, a “Do Not Sell or Share My Personal Information” link, or a recognized opt-out preference signal.
Google Analytics
We may use Google Analytics to measure and analyze use of our websites and Services.
Where legally required, Google Analytics will be used only after you accept applicable analytics cookies.
You may opt out through Google’s browser add-on:
https://tools.google.com/dlpage/gaoptout
You may manage Google advertising settings at:
https://adssettings.google.com
Additional industry opt-out resources may be available at:
http://optout.networkadvertising.org/
http://www.networkadvertising.org/mobile-choice
For additional information regarding Google’s privacy practices, visit:
https://policies.google.com/privacy
6. IS YOUR INFORMATION TRANSFERRED INTERNATIONALLY?
In Short: We may transfer, store, and process personal information in countries other than the country where it was collected.
Novara is located in the United States, and our primary servers are located in the United States. Personal information may be transferred to, stored in, or processed in the United States and in other countries where Novara, its affiliates, service providers, or subprocessors operate.
These countries may have data-protection laws that differ from the laws of your jurisdiction.
If you are located in the European Economic Area, the United Kingdom, Gibraltar, or Switzerland, we use legally recognized mechanisms for applicable transfers of personal information to the United States.
Novara participates in and has certified its compliance with:
- The EU-U.S. Data Privacy Framework;
- The UK Extension to the EU-U.S. Data Privacy Framework; and
- The Swiss-U.S. Data Privacy Framework.
Additional information is provided in the section “DATA PRIVACY FRAMEWORK.”
Where the applicable Data Privacy Framework does not apply, or where an additional transfer mechanism is appropriate, we may rely on:
- The European Commission’s Standard Contractual Clauses;
- The UK International Data Transfer Agreement;
- The UK Addendum to the European Commission’s Standard Contractual Clauses;
- Contractual safeguards recognized under Swiss data-protection law; or
- Another legally recognized transfer mechanism.
For transfers made solely for processing purposes, Novara and the applicable customer maintain contractual terms addressing the customer’s instructions, appropriate safeguards, onward transfers, and assistance with individual rights.
For more information regarding applicable transfer safeguards, contact [email protected].
7. DATA PRIVACY FRAMEWORK
Novara Software, LLC complies with the EU-U.S. Data Privacy Framework (“EU-U.S. DPF”), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (“Swiss-U.S. DPF”) as set forth by the U.S. Department of Commerce.
Novara has certified to the U.S. Department of Commerce that it adheres to:
- The EU-U.S. DPF Principles with respect to personal data received from the European Union in reliance on the EU-U.S. DPF;
- The EU-U.S. DPF Principles with respect to personal data received from the United Kingdom and Gibraltar in reliance on the UK Extension to the EU-U.S. DPF; and
- The Swiss-U.S. DPF Principles with respect to personal data received from Switzerland in reliance on the Swiss-U.S. DPF.
If there is any conflict between this Privacy Notice and the applicable DPF Principles, the applicable DPF Principles will govern.
To learn more about the DPF program and view the DPF List, visit:
https://www.dataprivacyframework.gov
https://www.dataprivacyframework.gov/list
Scope of Novara’s certification
Novara’s certification covers personal data received in the United States from the European Union, European Economic Area, United Kingdom, Gibraltar, and Switzerland in reliance on the applicable DPF.
Corporate and business operations
For Novara’s corporate and business operations, the certification covers non-HR personal data, including information relating to:
- Website visitors;
- Prospective customers;
- Customer representatives;
- Vendors;
- Business partners;
- Event participants; and
- Sales and marketing contacts.
Novara’s certification and this public Privacy Notice do not cover personal information relating to Novara’s own employees, former employees, applicants, or other workforce members in the context of their employment relationship with Novara.
Customer Data processed through Novara products
The certification also covers Customer Data that Novara receives and processes as a processor or service provider through its hosted software products and related services.
The hosted software products and related services covered by Novara’s certification are the offerings identified under “Our Products and Services” above, namely Ensogo, Flex, STS, and RMC.
Customer Data may include both:
- Personal data other than HR data; and
- HR data relating to a customer’s current or former employees and other workforce members when collected and transferred in the context of the customer’s employment relationships.
Covered product data may include:
- Employee names and identifiers;
- Training assignments and completion records;
- Certifications, licenses, qualifications, and competencies;
- Workplace safety and compliance information;
- Incident and injury reports;
- Occupational health information;
- Investigations, corrective actions, claims, inspections, and audits;
- Work locations and assignments; and
- Related customer-configured information.
For Customer Data, the applicable customer determines the purposes and means of processing. Novara processes the data only for limited and specified purposes consistent with the customer’s documented instructions, the applicable customer agreement, the DPF Principles, and applicable law.
Purposes of processing
The types of personal data Novara processes and the purposes for which it processes the data are described in:
- “WHAT INFORMATION DO WE COLLECT?”
- “HOW DO WE PROCESS YOUR INFORMATION?”
- “WHEN AND WITH WHOM DO WE SHARE PERSONAL INFORMATION?”
Your choices
Where required by the DPF Principles, when Novara acts as a controller, we will provide individuals with an opportunity to opt out before we:
- Disclose covered personal data to a third party acting as an independent controller; or
- Use covered personal data for a purpose that is materially different from the purposes for which it was originally collected or subsequently authorized.
You may exercise this choice by contacting [email protected].
Cookie preference settings may be used to manage disclosures involving cookies and similar technologies. Unsubscribe mechanisms may be used to manage marketing communications.
When Novara processes Customer Data on behalf of a customer, the customer is responsible for providing applicable notices and choices.
Novara does not use or disclose Customer Data for materially different purposes except as instructed by the customer, permitted by the applicable agreement, required by law, or otherwise permitted by the DPF Principles.
For sensitive personal data, Novara will obtain affirmative express consent, or require the applicable customer to obtain such consent, where required by the DPF Principles.
Access, correction, amendment, and deletion
Individuals whose personal data Novara processes as a controller may have the right under the DPF Principles to access their personal data and to request that Novara correct, amend, or delete personal data that is inaccurate or processed in violation of the DPF Principles.
Requests may be submitted to [email protected].
When Novara processes Customer Data on behalf of a customer, individuals should ordinarily direct requests to the customer that controls or submitted the information.
If Novara receives a request involving Customer Data, Novara may:
- Refer the individual to the applicable customer;
- Notify the applicable customer of the request; or
- Assist the customer in responding in accordance with the customer’s instructions, the applicable agreement, and the DPF Principles.
Novara may limit access where permitted by the DPF Principles, including where access would interfere with another person’s rights, violate legal privileges, create a disproportionate burden, or conflict with another recognized limitation.
Accountability for onward transfers
Novara is responsible for personal data it receives under the applicable DPF and subsequently transfers to a third party acting as an agent or subprocessor on Novara’s behalf.
For transfers to agents or subprocessors, Novara:
- Transfers personal data only for limited and specified purposes;
- Requires the recipient to provide at least the same level of privacy protection required by the applicable DPF Principles;
- Takes reasonable and appropriate steps to ensure that the recipient processes the data consistently with Novara’s obligations;
- Requires the recipient to notify Novara if it determines that it can no longer provide the required level of protection; and
- Upon notice, takes reasonable and appropriate steps to stop and remediate unauthorized processing.
Novara remains liable under the applicable DPF Principles if an agent or subprocessor processes covered personal data in a manner inconsistent with the Principles, unless Novara proves that it was not responsible for the event giving rise to the damage.
When Novara transfers covered personal data to a third party acting as an independent controller, Novara complies with the Notice and Choice Principles and requires the recipient by contract to process the information only for limited and specified purposes consistent with the individual’s consent and to provide the same level of protection required by the applicable DPF Principles.
Disclosures to public authorities
Novara may be required to disclose personal data in response to lawful requests by public authorities, including requests made to meet national security or law-enforcement requirements.
Enforcement authority
Novara is subject to the investigatory and enforcement powers of the U.S. Federal Trade Commission with respect to its compliance with the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF.
Questions and complaints
If you have a question or complaint regarding Novara’s handling of personal data received in reliance on the applicable DPF, contact:
Novara Software, LLC
Data Protection Officer
11080 Circle Point Road
Suite 200
Westminster, Colorado 80020
United States
Email: [email protected]
Telephone: 1-866-356-1735
Novara will investigate and attempt to resolve DPF-related complaints promptly and will respond within 45 days of receiving a complaint.
If a complaint concerns Customer Data, Novara may coordinate with the applicable customer to investigate and resolve the complaint.
Independent recourse for non-HR data
In compliance with the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF, Novara commits to refer unresolved complaints concerning its handling of non-HR personal data received in reliance on the applicable DPF to JAMS, an alternative dispute-resolution provider based in the United States.
If you do not receive timely acknowledgment of your DPF-related complaint, or if Novara has not addressed your complaint to your satisfaction, visit:
https://www.jamsadr.com/DPF-Dispute-Resolution
JAMS services are provided at no cost to the individual.
Independent recourse for HR Customer Data
In compliance with the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF, Novara commits to cooperate and comply with the advice of:
- The panel established by the European Union data protection authorities;
- The United Kingdom Information Commissioner’s Office and, where applicable, the Gibraltar Regulatory Authority; and
- The Swiss Federal Data Protection and Information Commissioner;
with regard to unresolved complaints concerning Novara’s handling of HR personal data received in reliance on the applicable DPF in the context of an employment relationship.
The applicable customer remains primarily responsible for the personal data it collects and controls. Novara will cooperate with the customer and the applicable authority in investigating and resolving complaints concerning Customer Data.
Binding arbitration
Under certain conditions, individuals may be entitled to invoke binding arbitration to resolve residual claims regarding Novara’s compliance with the DPF Principles that have not been resolved through other available recourse and enforcement mechanisms.
Additional information is available in Annex I:
https://www.dataprivacyframework.gov/framework-article/ANNEX-I-introduction
Binding arbitration may not be available where an applicable data-protection authority has authority to resolve the claimed violation under the DPF Supplemental Principle on Human Resources Data.
8. HOW LONG DO WE KEEP YOUR INFORMATION?
In Short: We retain personal information for as long as reasonably necessary for the purposes described in this Privacy Notice, as directed by our customers, or as required or permitted by law.
Controller Data
We retain Controller Data only for as long as necessary for the purposes for which it was collected, unless a longer retention period is required or permitted by law.
When determining an appropriate retention period, we may consider:
- The amount, nature, and sensitivity of the information;
- The purposes for which it is processed;
- Whether those purposes can be achieved through other means;
- The potential risk of harm from unauthorized use or disclosure;
- Applicable legal, accounting, tax, regulatory, and contractual requirements; and
- Applicable limitation periods.
When we no longer have an ongoing legitimate need to process Controller Data, we will delete or anonymize it. If immediate deletion is not possible, such as where information is retained in backup archives, we will securely store and restrict further processing until deletion is possible.
Customer Data
We retain Customer Data in accordance with:
- The applicable customer agreement;
- The customer’s configuration and documented instructions;
- Applicable legal obligations; and
- Our backup, security, continuity, and deletion procedures.
Following termination or expiration of a customer relationship, we will return or delete Customer Data as required by the applicable agreement and law, subject to limited retention in backups, legal holds, security records, or compliance records.
9. WHAT DATA SECURITY STEPS DO WE TAKE?
In Short: We maintain technical and organizational safeguards designed to protect personal information.
We have implemented administrative, technical, physical, and organizational measures designed to protect personal information against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access.
These measures may include:
- Access controls;
- Authentication mechanisms;
- Encryption;
- Network and infrastructure security;
- Logging and monitoring;
- Vulnerability and patch management;
- Incident-response procedures;
- Business-continuity and disaster-recovery measures;
- Vendor-risk management;
- Security training; and
- Policies and procedures governing personal information.
Additional information regarding our security program is available through our Trust Center:
No electronic transmission, network, application, or storage technology can be guaranteed to be completely secure.
Users are responsible for protecting their credentials, using secure devices and networks, and promptly notifying Novara or the applicable customer of suspected unauthorized access.
10. DO WE COLLECT INFORMATION FROM MINORS?
In Short: Our Services are designed for businesses and are not directed to children.
We do not knowingly market our Services directly to children under 18 years of age or the applicable age of majority.
Business customers may submit Customer Data concerning minors where permitted by applicable law, such as information connected to dependents, students, trainees, visitors, claimants, or workplace incidents.
In those circumstances, Novara processes the information solely on behalf of the applicable customer.
The customer is responsible for obtaining any required parental consent, authorization, or other legal basis and for providing applicable notices.
If you believe Novara directly collected personal information from a child in violation of applicable law, contact [email protected].
11. WHAT ARE YOUR PRIVACY RIGHTS?
In Short: Depending on your location and the circumstances, you may have rights regarding your personal information.
Controller Data requests
Depending on applicable law, you may have the right to:
- Request information regarding our processing of your personal information;
- Access your personal information;
- Obtain a copy of personal information in a structured, commonly used, and machine-readable format;
- Request correction or rectification;
- Request deletion or erasure;
- Object to processing;
- Restrict processing;
- Withdraw consent;
- Request portability;
- Opt out of certain sales, sharing, targeted advertising, or profiling;
- Request human review of certain automated decisions; and
- Lodge a complaint with an applicable supervisory authority.
These rights are not absolute and may be subject to exceptions or limitations.
You may submit a request concerning Controller Data by contacting [email protected].
We may request information necessary to verify your identity and authority to make the request.
Customer Data requests
When Novara processes Customer Data as a processor, service provider, or contractor, the applicable customer is responsible for responding to individual rights requests.
You should submit requests concerning Customer Data directly to the organization that collected, controls, or submitted the information.
If you submit a Customer Data request to Novara, we may refer you to the applicable customer and notify the customer of the request. We will assist the customer where required by applicable law, the customer agreement, and the customer’s instructions.
EEA, United Kingdom, Gibraltar, and Switzerland
Individuals in these jurisdictions may have rights including:
- Access;
- Correction;
- Erasure;
- Restriction;
- Objection;
- Portability;
- Withdrawal of consent; and
- The right to lodge a complaint with a supervisory authority.
Individuals in the EEA may contact their national data-protection authority.
Individuals in the United Kingdom may contact the Information Commissioner’s Office.
Individuals in Gibraltar may contact the Gibraltar Regulatory Authority.
Individuals in Switzerland may contact the Federal Data Protection and Information Commissioner.
Automated decision-making
If Novara, acting as a controller, makes a decision producing legal or similarly significant effects solely through automated processing, we will provide information and an opportunity for human review where required by law.
For Customer Data, the applicable customer determines whether and how automated functionality is used and is responsible for fulfilling applicable legal requirements.
Marketing communications
You may unsubscribe from marketing communications by:
- Clicking the unsubscribe link in an email;
- Replying “STOP” or “UNSUBSCRIBE” to an applicable SMS message; or
- Contacting us using the information below.
We may continue to send non-marketing communications, such as service, account, security, transactional, and support messages.
Residents of California
This section applies to personal information that Novara processes as a business under California law.
It does not describe Customer Data that Novara processes solely as a service provider or contractor on behalf of a customer. The applicable customer is responsible for providing required notices regarding its collection and use of Customer Data.
Categories of personal information we collect and disclose
The table below describes categories of personal information Novara may have collected during the preceding 12 months in its capacity as a business.
| Category | Examples | Collected |
| Identifiers | Name, postal address, telephone number, online identifier, IP address, email address, and account name | Yes |
| California Customer Records information | Name, contact information, education, employment information, and financial information | Yes |
| Protected classifications | Age, race, ethnicity, national origin, marital status, and similar demographic information | No |
| Commercial information | Transaction information, purchase history, financial details, and payment information | Yes |
| Biometric information | Fingerprints and voiceprints used for identification | No |
| Internet or network activity | Browsing history, search history, online behavior, and interactions with websites and advertisements | Yes |
| Geolocation data | Approximate device location | Yes, but not precise geolocation for Controller Data |
| Audio, electronic, visual, or similar information | Images and audio, video, or call recordings | Yes |
| Professional or employment-related information | Business contact information, job title, work history, and professional qualifications | Yes |
| Education information | Student records and directory information | No |
| Inferences | Inferences concerning preferences and characteristics | Yes |
| Sensitive personal information | Sensitive personal information as defined by California law | No for Controller Data covered by this table |
We use these categories for the purposes described elsewhere in this Privacy Notice, including:
- Providing and improving Services;
- Responding to inquiries and providing support;
- Sending administrative communications;
- Requesting feedback;
- Marketing and advertising;
- Security and fraud prevention;
- Analytics and research;
- Compliance and legal proceedings;
- Contract administration; and
- Business management.
Recipients may include cloud providers, data-storage providers, communication and collaboration vendors, payment providers, marketing and analytics vendors, professional advisers, auditors, and other service providers and contractors.
Sale or sharing
The following categories of Controller Data may be sold or shared, as those terms are defined under California law, with advertising partners, marketing providers, social networks, retargeting platforms, or analytics providers:
- Identifiers;
- California Customer Records information;
- Internet or network activity;
- Geolocation data;
- Inferences; and
- Professional or employment-related information.
These disclosures may occur for marketing, advertising, analytics, and service-personalization purposes.
Novara does not sell or share Customer Data processed solely on behalf of customers for cross-context behavioral advertising.
California privacy rights
Subject to applicable exceptions, California residents may have the right to:
- Know whether Novara processes their personal information;
- Know the categories and specific pieces of information collected;
- Know the sources and purposes of the collection;
- Know the categories of third parties receiving the information;
- Access personal information;
- Correct inaccurate personal information;
- Delete personal information;
- Opt out of sale or sharing;
- Opt out of targeted advertising or certain profiling; and
- Exercise rights without unlawful discrimination.
We do not knowingly sell or share personal information of individuals under 16 years old.
Exercising California rights
To exercise applicable rights, you may:
- Email [email protected];
- Call 1-866-356-1735;
- Use our cookie preference settings; or
- Use a “Do Not Sell or Share My Personal Information” link where available.
We honor qualifying Global Privacy Control signals.
You may designate an authorized agent. We may require proof that the agent is authorized and may verify your identity directly.
Information submitted for verification will be used only to verify and respond to the request, prevent fraud, and comply with law.
Do Not Track and opt-out preference signals
Browsers may permit users to send Do Not Track or similar signals. Because no uniform standard applies to all such signals, we may not respond to every Do Not Track mechanism.
We honor qualifying Global Privacy Control signals and other legally recognized opt-out preference signals.
12. DO WE MAKE UPDATES TO THIS NOTICE?
In Short: We may update this Privacy Notice as necessary.
We may revise this Privacy Notice from time to time to reflect changes in our practices, Services, contractual requirements, or applicable law.
The updated version will be identified by the “Last updated” date at the beginning of this Privacy Notice.
If we make material changes, we may provide notice by:
- Posting a prominent notice;
- Providing an in-product notification;
- Sending a communication to affected customers or users; or
- Using another method required by applicable law.
Changes will become effective when posted or on the date otherwise identified in the notice.
13. HOW CAN YOU CONTACT US?
If you have questions, comments, complaints, or requests regarding this Privacy Notice or Novara’s privacy practices, contact:
Novara Software, LLC
Data Protection Officer
11080 Circle Point Road
Suite 200
Westminster, Colorado 80020
United States
Email: [email protected]
Telephone: 1-866-356-1735
For Customer Data, you should ordinarily contact the Novara customer that collected or controls your personal information.
14. OTHER IMPORTANT INFORMATION
Governing law
This Privacy Notice is governed by the laws of the State of Delaware, except to the extent that another law, regulation, contractual obligation, or applicable DPF Principle governs.
Except for matters subject to a legally required regulatory, supervisory, independent-recourse, or arbitration process, disputes regarding this Privacy Notice or use of the Services will be resolved in the state or federal courts located in Delaware.
Nothing in this provision limits:
- Rights or remedies that cannot lawfully be waived;
- An individual’s right to submit a complaint to a supervisory or regulatory authority;
- Rights available under the applicable DPF Principles;
- Access to JAMS under the DPF independent-recourse mechanism;
- Cooperation with the applicable European data-protection authorities; or
- The right to invoke binding arbitration under Annex I where the applicable conditions are satisfied.
Limitation of liability
To the extent permitted by applicable law, Novara will not be liable for losses arising solely from unauthorized or unlawful acts of third parties that are outside Novara’s reasonable control.
Nothing in this Privacy Notice excludes or limits:
- Liability that cannot lawfully be excluded or limited;
- Novara’s obligations under applicable data-protection law;
- Novara’s obligations under its customer agreements; or
- Novara’s responsibility or potential liability under the DPF Principles, including responsibility for personal data transferred to an agent or subprocessor acting on Novara’s behalf.
Third-party websites and services
The Services may contain links to or features provided by third-party websites, applications, integrations, or online services.
Links and integrations do not necessarily indicate that Novara endorses or is affiliated with the third party.
Novara does not control third-party websites or services and is not responsible for their independent actions, content, security, or privacy practices.
You should review the terms and privacy notices of third-party services before providing personal information or enabling an integration.