Data Processing Agreement
Controller-to-processor Data Processing Agreement under Article 28 GDPR for NOVATRADE SOLUTIONS Sp. z o.o. services.
- LAST UPDATED
- 13 August 2026
- COMPANY REGISTRATION
- NOVATRADE SOLUTIONS Sp. z o.o., Hoża 86 lok. 410, 00-682 Warszawa, Poland · KRS: 0001255864, NIP: 7011324158, REGON: 54531482500000
- CONTROLLER
- NOVATRADE SOLUTIONS Sp. z o.o., Hoża 86 lok. 410, 00-682 Warszawa, Poland
- CONTACT
- [email protected]
This Data Processing Agreement forms part of the agreement governing the provision of NOVATRADE services to a customer where NOVATRADE SOLUTIONS Sp. z o.o. processes personal data on behalf of that customer.
This document is published in English for NOVATRADE business customers. Translations may be provided for convenience only; in case of any discrepancy the English version prevails.
1. Introduction
This Data Processing Agreement ("DPA") forms part of the agreement governing the provision of NOVATRADE services to a customer where NOVATRADE SOLUTIONS Sp. z o.o. processes personal data on behalf of that customer.
This DPA is intended to satisfy the requirements applicable to agreements between controllers and processors under Article 28 of Regulation (EU) 2016/679, the General Data Protection Regulation ("GDPR"), where the GDPR applies.
This DPA also applies to comparable controller-processor or business-service-provider relationships under other applicable data-protection laws to the extent appropriate to the relevant processing.
2. Parties
Customer
The legal entity that has entered into the applicable Service Agreement, Order Form, subscription agreement, or other agreement for NOVATRADE services ("Customer").
Processor
NOVATRADE SOLUTIONS Sp. z o.o.
Hoża 86 lok. 410, 00-682 Warszawa, Poland
KRS: 0001255864
NIP: 7011324158
REGON: 54531482500000
Email: [email protected]
NOVATRADE and Customer may each be referred to as a "Party" and together as the "Parties".
3. Relationship to the Service Agreement
This DPA applies where NOVATRADE processes Customer Personal Data as a processor on behalf of Customer in connection with the NOVATRADE services.
The commercial agreement governing the services is referred to in this DPA as the "Service Agreement".
The Service Agreement may include:
- Terms & Conditions;
- an Order Form;
- subscription confirmation;
- commercial proposal;
- Statement of Work;
- Service Level Agreement;
- another written agreement accepted by the Parties.
This DPA does not independently expand the commercial scope of the services purchased by Customer.
4. Incorporation and Effect
This DPA becomes binding between NOVATRADE and Customer when:
- the Service Agreement expressly incorporates this DPA;
- an Order Form incorporates this DPA;
- Customer accepts a service under contractual terms that expressly incorporate this DPA;
- or the Parties otherwise agree in writing that this DPA applies.
The current publicly available version may be referenced by URL in the applicable Service Agreement.
If the Parties execute a separately negotiated DPA, that separately executed DPA will take precedence over this public version for the processing it governs.
5. Definitions
For purposes of this DPA:
"Applicable Data Protection Law" means data-protection and privacy law applicable to the processing covered by this DPA.
"Customer Data" means information submitted to, stored in, transmitted through, or otherwise processed within the NOVATRADE services by or on behalf of Customer.
"Customer Personal Data" means Customer Data that constitutes Personal Data and that NOVATRADE processes on behalf of Customer.
"Controller", "Processor", "Personal Data", "Processing", "Data Subject", "Personal Data Breach", and "Supervisory Authority" have the meanings given to them by the GDPR where the GDPR applies.
"Subprocessor" means another processor engaged by NOVATRADE to process Customer Personal Data on behalf of Customer.
"Services" means the NOVATRADE services purchased or used by Customer under the Service Agreement.
6. Roles of the Parties
For Customer Personal Data covered by this DPA:
Customer acts as Controller or, where Customer itself processes data on behalf of another controller, as the relevant processor instructing NOVATRADE as a further processor.
NOVATRADE acts as Processor on behalf of Customer.
Customer determines the purposes for which Customer Personal Data is processed.
NOVATRADE processes Customer Personal Data on Customer's documented instructions, subject to the terms of this DPA and the Service Agreement.
The Parties acknowledge that NOVATRADE may separately act as an independent controller for certain processing carried out for its own legitimate business purposes, such as:
- managing its contractual relationship with Customer;
- billing;
- accounting;
- fraud prevention;
- security of NOVATRADE's own systems;
- legal compliance;
- business administration.
Such independent-controller processing is governed by NOVATRADE's Privacy Policy and applicable law rather than by this DPA.
7. Customer Instructions
Customer instructs NOVATRADE to process Customer Personal Data as reasonably necessary to:
- provide the Services;
- host Customer Data;
- store Customer Data;
- organize Customer Data;
- retrieve Customer Data;
- display Customer Data to Authorized Users;
- transmit Customer Data according to Customer-configured functionality;
- back up Customer Data where applicable;
- secure Customer Data;
- provide technical support;
- perform maintenance;
- enable integrations selected by Customer;
- perform other processing initiated or configured by Customer through the Services;
- comply with other documented instructions consistent with the Service Agreement.
The Service Agreement, Customer's use and configuration of the Services, support requests, and other documented communications may constitute Customer instructions.
NOVATRADE will not process Customer Personal Data for materially unrelated purposes except:
- on Customer's documented instruction;
- where required by applicable law;
- where NOVATRADE acts separately as an independent controller for a lawful purpose outside the scope of this DPA.
8. Unlawful Instructions
If NOVATRADE reasonably believes that a Customer instruction infringes Applicable Data Protection Law, NOVATRADE will inform Customer unless applicable law prohibits such notification.
NOVATRADE may suspend the affected processing instruction while the Parties work in good faith to resolve the issue.
Nothing in this DPA requires NOVATRADE to carry out an instruction that NOVATRADE is legally prohibited from performing.
9. Customer Responsibilities
Customer is responsible for:
- determining the purposes and lawful basis for its processing;
- providing legally required privacy notices;
- obtaining required permissions or consents;
- ensuring Customer has the right to provide Customer Personal Data to NOVATRADE;
- determining which individuals may access Customer Data;
- configuring access rights appropriately;
- ensuring Customer instructions comply with Applicable Data Protection Law;
- assessing whether the Services are suitable for Customer's intended processing;
- responding to Data Subjects where Customer is responsible for the response;
- avoiding unnecessary collection of Personal Data;
- complying with requirements applicable to sensitive or regulated data.
NOVATRADE does not determine the lawfulness of Customer's underlying business relationship with individual Data Subjects.
10. Details of Processing
The subject matter, duration, nature, purpose, categories of Data Subjects, and categories of Personal Data are described in Annex I — Details of Processing.
Annex I forms part of this DPA.
11. Confidentiality
NOVATRADE will ensure that persons authorized to process Customer Personal Data are subject to appropriate confidentiality obligations.
Access to Customer Personal Data will be limited to persons who require access for legitimate responsibilities connected with:
- providing the Services;
- maintaining the Services;
- supporting Customer;
- securing the Services;
- fulfilling applicable legal obligations.
Confidentiality obligations will continue to apply where appropriate after a person's access to Customer Personal Data ends.
12. Security of Processing
NOVATRADE will implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against:
- accidental destruction;
- unlawful destruction;
- accidental loss;
- unauthorized alteration;
- unauthorized disclosure;
- unauthorized access;
- other unlawful processing.
Security measures will take into account, as applicable:
- state of the art;
- implementation costs;
- nature of processing;
- scope of processing;
- context of processing;
- purposes of processing;
- risks to the rights and freedoms of individuals.
Relevant security measures are described in Annex II — Technical and Organizational Measures.
13. Security Is Risk-Based
The Parties acknowledge that no information system can provide an absolute guarantee against every possible security event.
NOVATRADE's obligation is to maintain measures appropriate to the relevant risks and applicable contractual and legal requirements rather than to guarantee that a Personal Data Breach can never occur.
14. Access Control
NOVATRADE will maintain controls designed to limit access to Customer Personal Data to authorized persons and systems.
Access should be based on legitimate operational requirements and appropriate authorization.
Where supported by the Services, Customer is responsible for configuring Customer-side:
- users;
- administrators;
- roles;
- permissions;
- organization access.
Customer should promptly remove access that is no longer required.
15. Authentication
NOVATRADE will maintain authentication controls appropriate to the systems used to provide the Services.
Customer is responsible for:
- protecting account credentials;
- maintaining appropriate administrator access;
- requiring users to follow reasonable credential-security practices;
- notifying NOVATRADE of suspected unauthorized access.
Where additional authentication features are available, Customer should evaluate them according to its security requirements.
16. Transmission Security
NOVATRADE will use appropriate protections for transmission of Customer Personal Data across public networks.
Where supported by the relevant system, encrypted transport protocols should be used for web and application communications carrying Customer Personal Data.
The specific protocol, configuration, and cryptographic implementation may evolve over time as infrastructure and security requirements change.
17. Data Storage and Infrastructure
Customer Personal Data may be stored or processed through infrastructure and service providers used to provide the Services.
NOVATRADE will select providers based on considerations that may include:
- security;
- reliability;
- functionality;
- legal requirements;
- contractual protections;
- data-protection requirements.
This DPA does not state that all Customer Personal Data is physically stored in Poland or within the EEA unless that location is specifically agreed for the applicable Customer.
18. Backups and Recovery
Where applicable to the relevant service architecture, NOVATRADE will maintain backup and recovery processes designed to support service resilience and restoration.
Backup schedules, retention, recovery targets, and architecture may vary depending on:
- the relevant system;
- service configuration;
- infrastructure provider;
- applicable Service Agreement.
No specific recovery time or recovery point is guaranteed by this DPA unless separately agreed in writing.
19. Monitoring and Logging
NOVATRADE may maintain appropriate technical, security, authentication, administrative, and operational records for purposes such as:
- security monitoring;
- troubleshooting;
- incident investigation;
- access administration;
- abuse prevention;
- service reliability;
- accountability.
NOVATRADE does not represent that every user action or every data operation is necessarily recorded unless such logging is specifically included in the applicable Service.
20. Personnel Security
NOVATRADE will take reasonable measures appropriate to personnel with access to systems processing Customer Personal Data.
Such measures may include, as appropriate:
- access authorization;
- confidentiality obligations;
- security awareness;
- access removal when responsibilities change;
- access limitation according to role.
21. Subprocessors
Customer provides NOVATRADE with general authorization to engage Subprocessors for the processing of Customer Personal Data where necessary to provide the Services.
NOVATRADE remains responsible for ensuring that a Subprocessor processing Customer Personal Data on NOVATRADE's behalf is subject to data-protection obligations that provide an appropriate level of protection for the relevant processing.
NOVATRADE will not appoint a Subprocessor with the intention of materially reducing the protection applicable to Customer Personal Data.
22. Subprocessor Information
NOVATRADE will maintain information concerning Subprocessors used for material processing of Customer Personal Data.
Current Subprocessor information may be provided:
- through a designated NOVATRADE webpage;
- through a customer portal;
- in contractual documentation;
- or upon reasonable request.
Customer may request current Subprocessor information at: [email protected]
Do not interpret this DPA as identifying a provider as a Subprocessor merely because that provider's service is mentioned elsewhere on the website.
Subprocessor status depends on the provider's actual processing role.
23. New and Replacement Subprocessors
Where required by Applicable Data Protection Law or the applicable customer agreement, NOVATRADE will provide Customer with information concerning an intended new or replacement Subprocessor before that Subprocessor begins material processing of Customer Personal Data.
Customer may raise a reasonable written objection based on legitimate data-protection grounds.
The Parties will work in good faith to address a valid objection.
Possible solutions may include:
- reasonable configuration changes;
- alternative processing arrangements where commercially and technically feasible;
- contractual safeguards;
- discontinuation of the affected optional feature;
- another mutually acceptable solution.
If the Parties cannot reasonably resolve a legitimate objection concerning a material Subprocessor, the applicable Service Agreement will govern the available contractual remedies.
This DPA does not create an unconditional right for Customer to prohibit every infrastructure or service-provider change for reasons unrelated to data protection.
24. Subprocessor Obligations
Where NOVATRADE appoints a Subprocessor to carry out specific processing activities on behalf of Customer, NOVATRADE will impose appropriate data-protection obligations on that Subprocessor through a contract or other legally binding arrangement as required by Applicable Data Protection Law.
NOVATRADE remains responsible to Customer for performance of the Subprocessor obligations to the extent required by applicable law and the Service Agreement.
25. Data Subject Requests
Where Customer receives a request from a Data Subject concerning Customer Personal Data, NOVATRADE will provide reasonable assistance appropriate to the nature of the processing and functionality available to Customer.
Such requests may concern:
- access;
- correction;
- deletion;
- restriction;
- portability;
- objection;
- other rights available under Applicable Data Protection Law.
Where technically available, Customer should first use self-service functionality provided through the Services.
If NOVATRADE directly receives a request relating to Customer Personal Data for which Customer is the Controller, NOVATRADE may refer the Data Subject to Customer and will not independently respond on Customer's behalf unless:
- Customer instructs NOVATRADE to do so;
- Applicable Data Protection Law requires NOVATRADE to respond directly.
26. Assistance With Compliance
Taking into account the nature of processing and information available to NOVATRADE, NOVATRADE will provide reasonable assistance to Customer with applicable obligations relating to:
- security of processing;
- Personal Data Breach assessment;
- Data Protection Impact Assessments;
- prior consultation with a Supervisory Authority;
- Data Subject rights;
where the assistance relates to Customer Personal Data processed under this DPA.
Additional assistance that requires material custom work may be subject to reasonable fees where permitted by the Service Agreement and applicable law.
NOVATRADE will not charge separately for ordinary cooperation necessary to comply with mandatory processor obligations.
27. Personal Data Breaches
NOVATRADE will maintain processes designed to identify, evaluate, and respond to security incidents.
If NOVATRADE becomes aware of a confirmed Personal Data Breach involving Customer Personal Data processed under this DPA, NOVATRADE will notify Customer without undue delay as required by Applicable Data Protection Law.
NOVATRADE does not commit through this DPA to an arbitrary fixed notification period shorter than the period required by applicable law or a separately agreed contract.
28. Breach Notification Information
To the extent reasonably available, a Personal Data Breach notification may include information such as:
- nature of the incident;
- affected systems or processing;
- categories of affected Personal Data;
- categories of affected Data Subjects;
- approximate scale where known;
- likely consequences where known;
- measures taken or proposed;
- mitigation steps;
- contact point for additional information.
Where all relevant information is not immediately available, NOVATRADE may provide information in phases without undue further delay.
29. Breach Responsibilities
NOVATRADE's notification to Customer does not constitute:
- an admission of fault;
- an admission of liability;
- a determination that Customer must notify a Supervisory Authority;
- a determination that Customer must notify Data Subjects.
Customer remains responsible for determining its own notification obligations where Customer is the Controller.
NOVATRADE will provide reasonable assistance with that assessment where required by this DPA and applicable law.
30. Data Protection Impact Assessments
Where Customer is required to conduct a Data Protection Impact Assessment concerning processing performed through the Services, NOVATRADE will provide information reasonably available to NOVATRADE that is relevant to the processing.
Customer remains responsible for:
- determining whether a DPIA is required;
- completing the DPIA;
- determining Customer's lawful processing purposes;
- determining whether prior consultation with a Supervisory Authority is required.
31. International Transfers
NOVATRADE may use infrastructure, Subprocessors, support resources, or other processing arrangements that involve processing Customer Personal Data outside the country in which Customer or its Data Subjects are located.
Where GDPR transfer restrictions apply to a transfer outside the EEA, NOVATRADE will ensure that an appropriate transfer mechanism or legal basis is used where required.
Depending on the circumstances, an appropriate mechanism may include:
- an adequacy decision;
- Standard Contractual Clauses approved by the European Commission;
- another recognized transfer mechanism;
- a lawful statutory derogation applicable to the specific transfer.
NOVATRADE does not represent that the same transfer mechanism applies to every Subprocessor or every transfer.
32. Transfer Assessments and Supplementary Measures
Where required by Applicable Data Protection Law, NOVATRADE will take reasonable steps appropriate to its role to assess relevant international-transfer requirements.
Depending on the transfer and risks involved, supplementary measures may include contractual, organizational, or technical safeguards where appropriate.
Nothing in this section creates a guarantee that every jurisdiction has laws identical to those of the EEA.
34. Return and Deletion
Upon termination or expiry of the Services involving Customer Personal Data, NOVATRADE will, according to the applicable Service Agreement and Customer instructions:
- make available reasonable means for Customer to export Customer Data where the applicable Service supports export;
- delete or return Customer Personal Data as required by applicable contractual and legal obligations.
NOVATRADE may retain Personal Data where required by applicable law.
Where continued retention is legally required, NOVATRADE will limit further processing to the purposes requiring retention.
35. Deletion From Backups
Deletion from active production systems and deletion from backup systems may occur on different technical schedules.
Where Customer Personal Data remains temporarily in backup systems after deletion from active systems:
- the data will remain protected;
- it will not be intentionally restored for ordinary business use except where necessary for legitimate recovery purposes;
- it will be removed according to the applicable backup lifecycle.
This DPA does not state an invented universal backup-deletion period.
Any customer-specific deletion commitment must be stated in the applicable Service Agreement or other binding documentation.
36. Customer Export Responsibilities
Customer is responsible for exporting Customer Data it requires before account termination where export functionality is available.
NOVATRADE is not required to retain Customer Personal Data indefinitely after the contractual relationship has ended.
Customer should plan its own legal and operational retention requirements before termination.
37. Demonstrating Compliance
NOVATRADE will make available information reasonably necessary to demonstrate compliance with processor obligations applicable under this DPA.
Information may include, where appropriate and available:
- relevant contractual information;
- security documentation;
- policies;
- responses to reasonable compliance questionnaires;
- independent reports or certifications if NOVATRADE obtains them;
- other appropriate evidence.
The absence of a particular voluntary certification does not by itself mean that NOVATRADE fails to meet its contractual or legal obligations.
38. Audits
Customer may conduct or commission an audit where reasonably necessary to verify NOVATRADE's compliance with this DPA and where Customer's audit right is required by Applicable Data Protection Law.
Audits should ordinarily:
- be requested in writing;
- identify the relevant scope;
- avoid unnecessary disruption;
- protect the confidentiality and security of other customers;
- avoid access to information unrelated to Customer;
- take into account relevant documentation already provided by NOVATRADE.
Where appropriate, the Parties may first seek to satisfy an audit request through:
- documentation;
- questionnaires;
- independent assurance reports;
- remote review.
An on-site inspection should be used where reasonably necessary and proportionate.
39. Audit Costs
Each Party will bear its ordinary internal costs of complying with mandatory audit obligations.
If Customer requests:
- repeated audits without reasonable cause;
- unusually extensive custom evidence;
- an on-site audit where available documentation reasonably demonstrates compliance;
- work materially beyond ordinary legal requirements,
NOVATRADE may charge reasonable costs where permitted by the Service Agreement and applicable law.
No fee will be used to prevent Customer from exercising a mandatory audit right.
40. Confidentiality of Audit Information
Information disclosed during an audit or compliance review may contain:
- security information;
- confidential architecture;
- trade secrets;
- information concerning other customers;
- vulnerability information.
Customer and its auditor must protect such information and use it only for legitimate compliance purposes.
NOVATRADE may reasonably restrict disclosure that would:
- compromise security;
- expose another customer's data;
- violate another legal obligation.
NOVATRADE will seek to provide an appropriate alternative where possible.
41. Special Categories and Highly Sensitive Data
The standard NOVATRADE Service is not designed to require Customer to process special categories of Personal Data or similarly highly sensitive information unless the relevant functionality and contractual framework are appropriate for that processing.
Customer is responsible for determining whether its intended use involves:
- health information;
- biometric information;
- genetic information;
- racial or ethnic origin;
- political opinions;
- religious beliefs;
- trade-union membership;
- information concerning sex life or sexual orientation;
- criminal-conviction data;
- other specially protected information.
Customer must not use the Service for categories of data that are prohibited by the applicable Service Agreement.
Where special-category processing is permitted, Customer remains responsible for establishing an appropriate legal basis and satisfying additional legal requirements applicable to that processing.
42. Children's Data
The NOVATRADE Service is a business service and is not designed as a service directed to children.
If Customer processes Personal Data relating to minors through the Service, Customer is responsible for ensuring that such processing is lawful and appropriate for the relevant business purpose.
43. AI-Assisted Processing
Where Customer enables NOVATRADE functionality involving artificial intelligence or machine-learning services, Customer instructs NOVATRADE to perform the processing reasonably necessary to provide the enabled functionality.
AI-related processing may involve a Subprocessor where an external provider is used.
Applicable Subprocessor, security, international-transfer, and confidentiality obligations under this DPA continue to apply to such processing.
The handling of data by an AI-related provider depends on:
- the provider actually used;
- the configured service;
- contractual terms;
- technical configuration.
This DPA does not state that all AI providers have identical:
- retention practices;
- training practices;
- data locations;
- security models.
NOVATRADE will not represent an AI provider's practices inaccurately.
44. Customer Configuration
Customer acknowledges that certain privacy and security outcomes depend on Customer configuration.
This may include:
- assigning user roles;
- granting permissions;
- selecting integrations;
- choosing information entered into the Service;
- configuring communication functions;
- deciding which individuals receive account access.
NOVATRADE is not responsible for an unauthorized disclosure caused solely by Customer intentionally granting access to an unauthorized person or configuring the Service contrary to available security controls, except to the extent NOVATRADE is otherwise responsible under applicable law or the Service Agreement.
45. Records of Processing
NOVATRADE will maintain records of processing activities required of processors under Applicable Data Protection Law where applicable.
Customer is responsible for maintaining records required of Customer as Controller.
47. Liability
Liability arising under or in connection with this DPA is subject to the liability framework contained in the applicable Service Agreement, except to the extent that Applicable Data Protection Law requires a different result.
Nothing in this DPA excludes liability that cannot lawfully be excluded or limited.
48. Indemnification
This DPA does not independently create an indemnification obligation beyond obligations contained in the Service Agreement or required by applicable law.
Any contractual indemnification arrangement between the Parties is governed by the applicable Service Agreement.
49. Term
This DPA remains in effect for as long as NOVATRADE processes Customer Personal Data on behalf of Customer under the Service Agreement.
Provisions that by their nature must survive termination will remain applicable for as long as NOVATRADE retains Customer Personal Data covered by this DPA.
50. Precedence
If this DPA conflicts with the Service Agreement concerning the protection or processing of Customer Personal Data, this DPA will take precedence for that subject matter unless a separately negotiated data-processing provision expressly states otherwise.
If a separately executed DPA exists between the Parties, that executed DPA takes precedence over this public DPA for the processing it governs.
51. Changes to the DPA
NOVATRADE may update the publicly available DPA where reasonably necessary to reflect:
- changes in law;
- regulatory guidance;
- Services;
- infrastructure;
- security practices;
- processing arrangements.
An update will not retroactively remove mandatory data-protection obligations applicable to processing already performed.
Material changes affecting an active contractual relationship will be handled according to the change procedure in the applicable Service Agreement and Applicable Data Protection Law.
52. Governing Law
Unless a separately executed agreement provides otherwise, this DPA is governed by the law applicable to the Service Agreement.
Where the Service Agreement is governed by Polish law, this DPA is governed by the laws of Poland, subject to mandatory provisions of Applicable Data Protection Law.
53. Contact
Questions relating to this DPA may be sent to:
NOVATRADE SOLUTIONS Sp. z o.o.
Hoża 86 lok. 410, 00-682 Warszawa, Poland
Email: [email protected]
Phone: +48 22 273 95 89
Annex I — Details of Processing
A. Subject Matter
Processing of Customer Personal Data as necessary to provide, maintain, secure, support, configure, and administer the NOVATRADE Services purchased or enabled by Customer.
B. Duration
Processing continues for the duration of the applicable Service Agreement and for any limited period afterward during which NOVATRADE is required or permitted to retain Customer Personal Data in accordance with:
- Customer instructions;
- the Service Agreement;
- backup lifecycle requirements;
- applicable law.
C. Nature of Processing
Depending on Customer's use of the Services, processing may include:
- collection;
- recording;
- organization;
- structuring;
- storage;
- adaptation;
- retrieval;
- consultation;
- display;
- transmission;
- synchronization;
- integration;
- use;
- restriction;
- backup;
- deletion;
- other processing initiated through Customer's configuration or instructions.
D. Purpose of Processing
The purpose is to provide the Services to Customer, which may include:
- CRM functionality;
- customer-management functionality;
- operational workflows;
- scheduling;
- workforce or user administration;
- communication functionality;
- reporting;
- analytics;
- document functionality;
- automation;
- integrations;
- API functionality;
- AI-assisted functionality;
- implementation;
- technical support;
- security;
- service administration.
The exact purposes depend on the functionality enabled and used by Customer.
E. Categories of Data Subjects
Depending on Customer's use of the Services, Data Subjects may include:
- Customer employees;
- Customer users;
- Customer administrators;
- Customer contractors;
- Customer representatives;
- Customer's customers;
- Customer's prospective customers;
- Customer's suppliers;
- Customer's business partners;
- Customer's service providers;
- other individuals whose Personal Data Customer lawfully enters into or processes through the Service.
F. Categories of Personal Data
Depending on Customer's configuration and use, Customer Personal Data may include:
Identity Data
- names;
- internal identifiers;
- account identifiers.
Contact Data
- email addresses;
- telephone numbers;
- postal addresses;
- other contact information.
Professional Data
- employer;
- role;
- job title;
- department;
- work location.
Customer and CRM Data
- lead information;
- customer records;
- prospective-customer records;
- service history;
- notes;
- relationship information;
- preferences;
- custom CRM fields.
Operational Data
- assignments;
- tasks;
- schedules;
- workflow records;
- service records;
- location-related business information;
- operational notes.
Workforce Data
Where Customer uses workforce-related functionality:
- employee or contractor information;
- roles;
- assignments;
- scheduling;
- attendance or time-related information;
- operational performance information entered by Customer.
Communication Data
- emails;
- messages;
- notes;
- communication history;
- notification information.
Financial and Transaction-Related Business Data
Where used by Customer:
- invoice references;
- payment status;
- amounts;
- transaction references;
- expense information;
- operational financial records.
The Service should not be used to store full payment-card credentials unless the relevant functionality is expressly designed and approved for that purpose.
Technical Data
- account activity;
- authentication information;
- access records;
- system events;
- device or browser-related information where relevant.
Documents and Custom Data
- documents uploaded by Customer;
- data contained in Customer-defined fields;
- other Personal Data Customer chooses to process within permitted functionality.
G. Special Categories
Special-category Personal Data is not required for the standard use of the Service.
Customer must assess whether it intends to process special-category or otherwise highly sensitive Personal Data and whether such processing is permitted by:
- Applicable Data Protection Law;
- the Service Agreement;
- the functionality used.
H. Processing Frequency
Processing may occur continuously or as initiated by:
- Customer;
- Authorized Users;
- enabled integrations;
- configured automation;
- ordinary system operation.
Annex II — Technical and Organizational Measures
NOVATRADE will maintain measures appropriate to the risks associated with the Services and processing.
The following describes the security-control framework applicable to Customer Personal Data.
The implementation of an individual control may depend on the relevant system, architecture, functionality, and configuration.
1. Access Management
Measures designed to:
- restrict access to authorized persons;
- manage roles and permissions;
- apply least-privilege principles where appropriate;
- remove or change access when responsibilities change.
2. Authentication
Measures designed to:
- authenticate users;
- protect administrative access;
- reduce unauthorized account access;
- support secure credential handling.
3. Transmission Protection
Appropriate encrypted transport mechanisms for Customer Personal Data transmitted across public networks where supported by the relevant technology.
4. Infrastructure Security
Measures appropriate to the infrastructure used to provide the Service, which may include:
- network protections;
- environment separation;
- infrastructure access control;
- system configuration controls;
- security updates.
5. Application Security
Measures appropriate to the application environment, which may include:
- input validation;
- authorization checks;
- session-management controls;
- dependency management;
- secure-change processes;
- remediation of identified security issues.
6. Data Access Separation
Controls designed to restrict users and customer organizations to information they are authorized to access.
The specific implementation depends on the Service architecture.
7. Logging and Monitoring
Selected security, authentication, administrative, error, and operational events may be logged and monitored for:
- security;
- investigation;
- troubleshooting;
- reliability.
8. Backup and Recovery
Where applicable to the relevant infrastructure:
- backup processes;
- recovery processes;
- protected backup access;
- lifecycle management.
Specific recovery commitments apply only where stated in an applicable Service Level Agreement or customer agreement.
9. Change Management
Processes designed to reduce risk when modifying production systems, which may include:
- controlled deployment;
- testing;
- access restrictions;
- review appropriate to the nature of the change.
10. Vulnerability and Security Maintenance
Processes appropriate to the Service for:
- maintaining software dependencies;
- responding to identified vulnerabilities;
- applying security updates;
- reviewing material security issues.
11. Incident Management
Processes designed to:
- identify potential security incidents;
- assess incidents;
- contain or mitigate incidents;
- investigate relevant events;
- support required notifications.
12. Personnel Controls
Measures appropriate to personnel with access to systems, including:
- confidentiality;
- authorization;
- security awareness;
- access limitation;
- access removal.
13. Data Deletion and Export
Processes and functionality appropriate to the Service for:
- Customer Data export where supported;
- account termination;
- deletion from active systems;
- lifecycle-based removal from backups.
14. Subprocessor Management
Processes designed to assess and contractually manage service providers that process Customer Personal Data on NOVATRADE's behalf.
15. Physical Security
Physical security for data-center and infrastructure facilities may be provided in whole or in part by infrastructure providers operating the relevant facilities.
NOVATRADE evaluates such arrangements as part of its provider-management process.
16. Security Review
NOVATRADE may update technical and organizational measures as:
- technologies evolve;
- threats change;
- infrastructure changes;
- Services develop.
Updates will not intentionally result in a material overall reduction of protection for Customer Personal Data during an active contractual relationship.