Bezpieczeństwo i ochrona danych (Security & Data Protection)
How NOVATRADE SOLUTIONS Sp. z o.o. approaches security, access control, data protection, monitoring, and incident response.
- OSTATNIA AKTUALIZACJA
- 13 sierpnia 2026
- DANE REJESTROWE
- NOVATRADE SOLUTIONS Sp. z o.o., Hoża 86 lok. 410, 00-682 Warszawa, Polska · KRS: 0001255864, NIP: 7011324158, REGON: 54531482500000
- ADMINISTRATOR
- NOVATRADE SOLUTIONS Sp. z o.o., Hoża 86 lok. 410, 00-682 Warszawa, Polska
- KONTAKT
- [email protected]
This page describes NOVATRADE SOLUTIONS Sp. z o.o.'s risk-based security approach, the division of responsibility between NOVATRADE and its customers, and how security questions or suspected vulnerabilities can be reported.
Dokument jest publikowany w języku angielskim dla klientów biznesowych NOVATRADE. Tłumaczenia mogą być udostępniane wyłącznie dla wygody; w razie rozbieżności rozstrzygająca jest wersja angielska.
1. Our Security Approach
NOVATRADE SOLUTIONS Sp. z o.o. provides business software and digital services that may process commercially sensitive and personal information on behalf of its customers.
Security is therefore treated as an important part of the design, operation, and administration of NOVATRADE services.
NOVATRADE applies technical and organizational measures appropriate to:
- the nature of the relevant service;
- the types of data processed;
- the system architecture;
- the risks associated with the processing;
- applicable contractual obligations;
- applicable data-protection requirements.
Our security approach is risk-based.
No information system can be guaranteed to be completely secure, and this page does not represent that every security incident, service interruption, or unauthorized activity can be prevented.
Instead, NOVATRADE seeks to maintain reasonable preventive, detective, and responsive safeguards appropriate to its services and the risks involved.
2. Company
The service provider is:
NOVATRADE SOLUTIONS Sp. z o.o.
Hoża 86 lok. 410, 00-682 Warszawa, Poland
KRS: 0001255864 · NIP: 7011324158 · REGON: 54531482500000
Email: [email protected]
Phone: +48 22 273 95 89
Additional corporate information is available in our Legal Notice.
3. Security Governance
NOVATRADE's security approach is intended to support:
- confidentiality of information;
- integrity of systems and data;
- availability of services;
- appropriate resilience;
- prevention of unauthorized access;
- detection and investigation of relevant security events;
- recovery from operational or security incidents;
- appropriate protection of personal data.
Security measures may differ between systems depending on:
- system purpose;
- data sensitivity;
- technical architecture;
- external dependencies;
- customer configuration;
- applicable risk.
Security controls are reviewed and may evolve as the Service, technology, risks, and regulatory expectations change.
5. Identity and Access Management
NOVATRADE uses access-control principles intended to limit access to systems and information according to legitimate business and technical requirements.
Depending on the relevant system, controls may include:
- authenticated access;
- user roles;
- administrative roles;
- authorization checks;
- restricted administrative access;
- permission-based access;
- access revocation;
- session controls.
Access to customer environments should be limited according to the permissions associated with the relevant user or administrative role.
Customers remain responsible for assigning their own users and permissions appropriately where the Service provides those controls.
6. Least Privilege
NOVATRADE seeks to apply the principle of least privilege to administrative and operational access.
This means access should be limited to what is reasonably required for the relevant:
- role;
- task;
- system;
- support activity;
- operational responsibility.
Access requirements may change when personnel, systems, responsibilities, or technical environments change.
7. Authentication
NOVATRADE uses authentication controls appropriate to the systems through which users or administrators access the Service.
Users are responsible for:
- protecting credentials;
- avoiding password sharing;
- protecting authentication devices;
- notifying NOVATRADE of suspected unauthorized account activity.
Where additional authentication or account-security functionality is available, customers should evaluate and enable it according to their own risk requirements.
NOVATRADE may require additional verification when handling sensitive administrative or account-recovery requests.
8. Customer and Organization Access Separation
The NOVATRADE platform is designed to apply organization-level authorization so that users access data and functionality according to the organization and permissions associated with their account.
Authorization is enforced through application and system controls appropriate to the relevant architecture.
Customers must not attempt to:
- access another customer's environment;
- bypass authorization;
- manipulate identifiers to obtain unauthorized information;
- circumvent tenant or account restrictions.
Suspected unauthorized cross-organization access should be reported immediately.
9. Data Transmission
NOVATRADE uses secure communication mechanisms appropriate to the relevant web and application services.
Information transmitted across public networks should be protected using current encrypted transport mechanisms where supported by the relevant system and protocol.
NOVATRADE may update:
- supported protocols;
- certificates;
- cryptographic configurations;
- infrastructure
as security practices and technical requirements evolve.
This page does not claim that every data transfer occurring entirely within a third-party service or customer-controlled integration uses an identical technical configuration.
10. Data at Rest
Data stored by NOVATRADE is protected using the security controls available and appropriate within the configured application, database, storage, and infrastructure environment.
The exact protection mechanisms may depend on:
- storage technology;
- infrastructure provider;
- service architecture;
- data type;
- system configuration.
NOVATRADE does not use this public page to make an absolute statement that every individual storage location, backup, log, cache, or third-party integration uses an identical encryption configuration.
Customer-specific or architecture-specific encryption requirements may be addressed through the applicable customer agreement where necessary.
11. Application Security
NOVATRADE applies application-security practices intended to reduce unauthorized or unintended application behavior.
Depending on the relevant component, these practices may include:
- authorization checks;
- input validation;
- output handling;
- session management;
- dependency management;
- secure configuration;
- access restrictions;
- review of security-relevant changes;
- remediation of identified vulnerabilities.
Security measures are selected according to the relevant architecture and risk.
12. Secure Development and Change Management
NOVATRADE uses controlled processes for changes to production services.
The objective is to reduce the risk that:
- unreviewed changes;
- incorrect configuration;
- vulnerable dependencies;
- unintended functionality
materially affect production security or service operation.
Depending on the nature of a change, processes may include:
- development and production separation;
- testing;
- code review;
- deployment controls;
- release review;
- rollback planning;
- dependency review;
- post-deployment monitoring.
The exact process may differ according to the component and risk of the change.
13. Environment Separation
NOVATRADE seeks to separate development, testing, and production activities in a manner appropriate to the relevant architecture.
Production credentials and production access should not be treated as ordinary development resources.
Use of real Customer Data outside production environments should be limited to situations where:
- technically necessary;
- contractually permitted;
- appropriately protected.
Where possible and appropriate, non-production environments should use:
- test data;
- synthetic data;
- minimized datasets.
14. Secrets and Credentials
Sensitive credentials used to operate NOVATRADE systems should be protected from unauthorized disclosure.
Examples may include:
- API credentials;
- database credentials;
- service credentials;
- access tokens;
- signing secrets;
- infrastructure credentials.
Such information should not be intentionally exposed through:
- public source code;
- public repositories;
- customer-facing pages;
- browser logs;
- ordinary support communications.
Credentials should be replaced, revoked, or otherwise addressed where compromise is suspected.
15. Logging
NOVATRADE may record selected:
- authentication events;
- administrative events;
- security events;
- application errors;
- system events;
- operational events
for legitimate purposes including:
- security;
- troubleshooting;
- fraud prevention;
- service reliability;
- incident investigation;
- accountability.
NOVATRADE does not represent that every user action or every change in the Service is permanently recorded.
Logging scope and retention depend on the relevant system, purpose, and applicable requirements.
16. Monitoring
NOVATRADE uses operational and security monitoring appropriate to relevant systems and services.
Monitoring may be used to identify:
- service availability issues;
- application errors;
- unusual system behavior;
- security-relevant events;
- infrastructure problems;
- failures requiring investigation.
Monitoring does not guarantee that every security event will be detected immediately.
17. Vulnerability Management
NOVATRADE maintains processes intended to identify and address security weaknesses appropriate to the relevant systems.
Activities may include:
- reviewing security issues;
- monitoring relevant vulnerabilities;
- updating dependencies;
- applying patches;
- changing configurations;
- implementing compensating controls;
- prioritizing remediation according to risk.
Not every vulnerability has the same severity or requires the same remediation approach.
NOVATRADE does not publish a universal remediation deadline through this page.
Customer-specific vulnerability requirements may be addressed separately where contractually agreed.
18. Security Testing
Security validation may include technical and procedural review appropriate to:
- the system;
- the change;
- the vulnerability;
- the relevant risk.
This may include automated or manual testing where appropriate.
NOVATRADE does not claim through this page that:
- an independent penetration test is performed on a fixed schedule;
- every release receives external penetration testing;
- every component is continuously tested by an external auditor
unless such activity is separately verified and expressly published.
19. Infrastructure and Hosting
NOVATRADE may use professional infrastructure and cloud-service providers to host or support elements of the Service.
Such providers may provide services including:
- compute infrastructure;
- database infrastructure;
- storage;
- networking;
- content delivery;
- backup;
- security;
- operational tooling.
Provider selection may consider:
- security;
- reliability;
- contractual protections;
- technical capability;
- privacy;
- operational requirements.
The current Data Processing Agreement addresses Subprocessors where they process Customer Personal Data on NOVATRADE's behalf.
This Security page does not function as the authoritative Subprocessor list.
20. Provider and Supply-Chain Security
NOVATRADE's security depends in part on third-party technologies and service providers.
NOVATRADE seeks to manage material provider risk through measures appropriate to the relevant relationship.
These may include review of:
- service purpose;
- data access;
- technical dependency;
- contractual terms;
- security information;
- privacy obligations;
- operational importance.
A third party's independent systems remain subject to that provider's own security responsibilities.
21. Backups
Where appropriate to the relevant service architecture, NOVATRADE maintains backup processes intended to reduce the risk of permanent data loss resulting from certain operational or technical failures.
Backup architecture may vary according to:
- system;
- database;
- storage technology;
- provider;
- service configuration.
NOVATRADE does not make a universal public guarantee concerning:
- backup frequency;
- backup retention;
- recovery point;
- recovery time.
Specific recovery commitments apply only where expressly agreed in a customer agreement or Service Level Agreement.
22. Recovery and Resilience
NOVATRADE maintains operational processes intended to support recovery from material system failures.
Recovery procedures may include, depending on the relevant incident:
- restoring systems;
- restoring data from available backups;
- replacing affected infrastructure;
- rolling back changes;
- disabling affected functionality;
- using alternative technical arrangements.
Actual recovery depends on:
- incident type;
- affected systems;
- third-party dependencies;
- data involved;
- severity.
No guaranteed recovery objective is created by this public Security page.
23. Availability
NOVATRADE monitors the operation of relevant production services.
The Service may nevertheless be affected by:
- maintenance;
- software defects;
- infrastructure incidents;
- external network failures;
- third-party service failures;
- security events;
- emergency work;
- circumstances outside NOVATRADE's reasonable control.
No specific uptime guarantee applies unless it is expressly contained in an applicable Service Level Agreement or customer contract.
24. Incident Response
NOVATRADE maintains processes for evaluating and responding to suspected security incidents.
Depending on the circumstances, incident response may include:
- investigation;
- containment;
- access restriction;
- credential revocation;
- system isolation;
- remediation;
- recovery;
- monitoring;
- communication;
- post-incident review.
The appropriate response depends on:
- incident type;
- affected systems;
- data involved;
- severity;
- contractual obligations;
- legal requirements.
25. Personal Data Incidents
Where a security incident involves personal data, NOVATRADE evaluates the incident under applicable data-protection requirements.
Where NOVATRADE acts as a controller, regulatory or Data Subject notifications will be made where required by applicable law.
Where NOVATRADE acts as a processor for Customer Personal Data, notification and cooperation are governed by:
- applicable data-protection law;
- the Data Processing Agreement;
- the applicable customer agreement.
NOVATRADE does not create an arbitrary universal breach-notification deadline through this Security page.
26. Fraud and Abuse Prevention
NOVATRADE may use technical and operational controls to identify or reduce:
- unauthorized access;
- account abuse;
- fraudulent activity;
- automated abuse;
- malicious requests;
- attempts to circumvent security controls.
Where reasonably necessary, NOVATRADE may:
- restrict access;
- require additional verification;
- suspend activity;
- investigate an account;
- preserve relevant records;
- take other proportionate measures.
Security controls may change as abuse patterns and threats evolve.
Zobacz też: Polityka dopuszczalnego korzystania
27. Payment Security
Payments for NOVATRADE services may be processed through third-party payment service providers.
Depending on the integration, payment credentials may be collected directly by the payment provider rather than stored in NOVATRADE systems.
NOVATRADE may receive payment-related information necessary to administer:
- transactions;
- subscriptions;
- refunds;
- billing;
- disputes.
Customers must not send:
- complete card numbers;
- CVV or CVC codes;
- banking passwords;
- PINs;
- authentication codes
through ordinary NOVATRADE email or Contact forms.
NOVATRADE does not claim PCI DSS certification through this Security page unless such certification is separately verified and applicable to NOVATRADE's actual card-data environment.
28. Personal Data Protection
NOVATRADE processes personal data according to applicable data-protection requirements.
Security measures for personal data are selected according to factors including:
- nature of the data;
- volume;
- processing context;
- purpose;
- potential impact of unauthorized access or loss;
- applicable contractual requirements.
The Privacy Policy provides additional information about NOVATRADE's own processing of personal data.
The Data Processing Agreement addresses Customer Personal Data processed by NOVATRADE on behalf of customers.
29. Customer Data
As between NOVATRADE and Customer, Customer retains its rights in Customer Data subject to the applicable customer agreement.
NOVATRADE does not acquire ownership of Customer Data merely because the information is processed through the Service.
NOVATRADE processes Customer Data as required to:
- provide the Service;
- secure the Service;
- maintain the Service;
- support the Customer;
- comply with applicable legal obligations;
- perform other processing permitted by the applicable agreement.
30. Data Minimization
NOVATRADE encourages customers and users to process only information that is reasonably necessary for the relevant business purpose.
Customers should avoid entering:
- unnecessary sensitive information;
- complete payment credentials;
- authentication secrets;
- unrelated personal information
into fields not designed for that purpose.
Customer administrators are responsible for determining the information their organization chooses to process through configurable CRM functionality.
31. Data Export and Deletion
NOVATRADE provides processes or functionality appropriate to the relevant Service for:
- Customer Data export;
- account termination;
- deletion.
Specific export and deletion arrangements depend on:
- the applicable Service;
- customer agreement;
- Data Processing Agreement;
- legal-retention obligations;
- backup lifecycle.
Deletion from active systems and deletion from backups may occur on different technical schedules.
NOVATRADE does not state a universal deletion period through this Security page.
32. AI-Assisted Features
NOVATRADE may provide AI-assisted functionality.
Security and access controls applicable to AI-assisted functionality should respect the relevant:
- customer environment;
- user permissions;
- enabled functionality;
- contractual data-processing framework.
AI-generated information may be inaccurate or incomplete and should be reviewed by authorized users before being used for material decisions.
Critical business actions should remain subject to appropriate authorization and human review where required by the applicable workflow.
33. AI Providers
Where an external AI provider processes Customer Personal Data on behalf of NOVATRADE, the provider may qualify as a Subprocessor and is subject to the applicable contractual and data-protection framework.
Provider practices may differ concerning:
- data location;
- retention;
- model training;
- security;
- technical architecture.
NOVATRADE does not state on this page that every AI provider:
- has zero retention;
- operates only in the EEA;
- never uses data for model improvement;
- follows an identical security model.
Relevant provider terms must be evaluated according to the actual AI service used.
34. Customer Responsibilities
Customers have an important role in maintaining security.
Customers should:
- use strong unique credentials;
- protect administrative accounts;
- restrict administrator privileges;
- promptly disable unnecessary user access;
- review permissions;
- protect devices;
- maintain appropriate endpoint security;
- review integrations;
- secure API credentials;
- avoid sharing credentials;
- train Authorized Users;
- promptly report suspicious activity.
Customer-controlled security decisions remain the responsibility of Customer.
35. Integrations
Customers may connect NOVATRADE with third-party services.
An integration may allow information to move between NOVATRADE and the selected third party.
Customers are responsible for:
- selecting integrations;
- authorizing integrations;
- reviewing the third party;
- maintaining required third-party accounts;
- revoking integrations that are no longer required.
NOVATRADE cannot control the independent security practices of a third party after data has lawfully been transferred to that third party under Customer's instruction.
36. API Security
Where API access is available, customers are responsible for protecting:
- API keys;
- tokens;
- credentials;
- integration secrets.
Customers must not expose API credentials in:
- public code repositories;
- client-side code where inappropriate;
- public documentation;
- ordinary email;
- publicly accessible files.
NOVATRADE may revoke or replace credentials where compromise or misuse is suspected.
Zobacz też: Polityka dopuszczalnego korzystania
37. Support Access
In some circumstances, authorized NOVATRADE personnel may require limited access to systems or Customer Data to:
- investigate support issues;
- troubleshoot errors;
- perform maintenance;
- investigate security incidents;
- provide agreed services.
Such access should be limited according to:
- legitimate need;
- authorization;
- relevant confidentiality obligations;
- applicable contractual requirements.
NOVATRADE does not use support access as unrestricted ordinary access to Customer Data.
38. Confidentiality
Personnel authorized to access confidential information or Customer Personal Data are expected to be subject to appropriate confidentiality obligations.
Access should be limited to individuals whose responsibilities reasonably require it.
Confidentiality protections may also apply to relevant contractors and service providers.
39. Employee and Contractor Access
Access to production systems should be:
- authorized;
- role-appropriate;
- limited to legitimate responsibilities.
Access should be reviewed or changed when:
- responsibilities change;
- personnel change roles;
- access is no longer required;
- a security concern arises.
Access should be revoked when no longer justified.
40. Security Awareness
NOVATRADE promotes appropriate security awareness for persons with relevant access or operational responsibilities.
Security awareness may include topics such as:
- credential security;
- phishing;
- confidential information;
- access management;
- incident reporting;
- handling of customer information.
The level and frequency of training may vary according to role and risk.
41. Security Reviews and Customer Due Diligence
Business customers may request reasonable security information during procurement or due-diligence processes.
Subject to confidentiality, security, proportionality, and availability of information, NOVATRADE may provide appropriate information concerning:
- security practices;
- data processing;
- Subprocessors;
- architecture at an appropriate level;
- contractual protections;
- relevant policies.
NOVATRADE may decline to disclose information that would:
- expose another customer's information;
- expose credentials;
- materially weaken system security;
- reveal sensitive vulnerability details;
- violate another legal or contractual obligation.
42. Certifications and Independent Assurance
This Security page does not itself represent that NOVATRADE holds a particular voluntary certification.
A certification or independent assurance claim should be made only where:
- NOVATRADE actually holds the relevant certification or report;
- it is current;
- its scope covers the relevant service;
- publication of the claim has been approved.
Do not interpret the existence of:
- this Security page;
- a Privacy Policy;
- a Data Processing Agreement;
- GDPR obligations
as a security certification.
43. SOC 2
Unless NOVATRADE has a current SOC 2 report covering the relevant Service and the claim has been approved for publication, NOVATRADE does not claim SOC 2 certification or attestation on this website.
44. ISO 27001
Unless NOVATRADE holds a current ISO/IEC 27001 certification covering the relevant information-security management system and the claim has been approved for publication, NOVATRADE does not claim ISO/IEC 27001 certification on this website.
45. PCI DSS
NOVATRADE does not claim PCI DSS certification merely because customers can pay for NOVATRADE services.
Where payment credentials are processed by a payment service provider, that provider may operate within its own PCI DSS responsibilities.
NOVATRADE's own PCI DSS obligations, if any, depend on its actual payment architecture and cardholder-data environment.
46. GDPR
NOVATRADE processes personal data subject to the GDPR where the GDPR applies.
GDPR is a legal framework, not a general product certification.
NOVATRADE therefore does not display a "GDPR Certified" claim merely because it is subject to or seeks to comply with the GDPR.
47. Regulated Data
Customers considering use of the Service for data subject to special regulatory or industry requirements should evaluate the Service and applicable contractual terms before using it for that purpose.
Examples may include sectors involving:
- protected health information;
- financial-sector regulatory data;
- government-classified information;
- highly sensitive identity information;
- other specially regulated data.
A general SaaS subscription does not automatically establish compliance with a customer's sector-specific requirements.
48. Responsible Security Reporting
If you believe you have identified a security issue affecting NOVATRADE systems, please contact [email protected].
Use a subject line such as: Security Report
Please provide enough information for NOVATRADE to understand and investigate the issue.
Where possible, include:
- affected URL or functionality;
- description of the issue;
- steps required to reproduce it;
- potential impact;
- relevant timestamps;
- non-destructive supporting evidence.
Do not include unnecessary personal data or sensitive third-party information.
49. Responsible Testing
Do not attempt security testing that:
- accesses another customer's data;
- alters or deletes production data;
- disrupts service availability;
- introduces malware;
- performs denial-of-service activity;
- involves social engineering;
- accesses systems beyond what is necessary to demonstrate the reported issue.
NOVATRADE does not authorize unrestricted penetration testing of production systems merely because this Security page provides a security-reporting contact.
Organizations requiring formal security testing arrangements should contact NOVATRADE to discuss appropriate authorization.
Zobacz też: Polityka dopuszczalnego korzystania
50. Security Incidents Affecting Customers
Where a material security incident affects a customer, communication will be handled according to:
- the nature of the incident;
- applicable law;
- the Data Processing Agreement;
- the applicable customer agreement;
- relevant contractual notification obligations.
NOVATRADE will not knowingly conceal a notification required by applicable law or a binding contractual obligation.
51. Continuous Improvement
Security risks, technology, infrastructure, and attack techniques change over time.
NOVATRADE may therefore update:
- technical controls;
- operational processes;
- architecture;
- monitoring;
- authentication;
- provider relationships;
- security procedures
as appropriate.
Security improvements may be made without updating this page where the change does not materially affect the accuracy of the public description.
52. Security Information and Contractual Commitments
This page provides a general public overview of NOVATRADE's security approach.
It does not independently create:
- a Service Level Agreement;
- a guaranteed uptime commitment;
- a guaranteed recovery objective;
- a guaranteed backup schedule;
- a fixed vulnerability-remediation SLA;
- a fixed incident-notification period;
- a certification.
Specific contractual security commitments may be contained in:
- the applicable Service Agreement;
- Order Form;
- Data Processing Agreement;
- Service Level Agreement;
- other signed documentation.
53. Contact
Questions about security or data protection may be directed to:
NOVATRADE SOLUTIONS Sp. z o.o., Hoża 86 lok. 410, 00-682 Warszawa, Poland
Email: [email protected]
Phone: +48 22 273 95 89
For a suspected security vulnerability, use the email subject: Security Report
- [email protected]
- TELEFON
- +48 22 273 95 89