ENTERPRISE TRUST & COMPLIANCE
Privacy Policy & Data Security
Last Updated: September 14, 2026 · Effective Immediately
01
Zero Model Training Guarantee
NOVA Technologies Inc. (“NOVA”, “we”, “us”, or “our”) enforces a legally binding, contractual Zero Model Training Guarantee for all customers. Your proprietary company documents, code repositories, pull request summaries, customer conversations, and executive briefs are never used to train, retrain, fine-tune, or calibrate any foundation artificial intelligence models.
All interactions with upstream foundation model APIs (including Anthropic Claude, OpenAI Enterprise, and AWS Bedrock) operate under strict enterprise Zero Data Retention (ZDR) commercial agreements. Payloads sent for model inference are processed entirely in-memory and are purged immediately upon completion of the token stream.
02
Data Encryption at Rest & in Transit
All vector embeddings, customer metadata, and audit logs are encrypted at rest using industry-standard AES-256 encryption. In transit, all network traffic is encrypted using TLS 1.3 with automated certificate rotation and strict HSTS policy enforcement.
Enterprise customers retain the option to bring and manage their own encryption keys via AWS KMS, GCP Cloud KMS, or Azure Key Vault (Customer-Managed Encryption Keys / CMEK). Under CMEK, NOVA engineers have zero ability to decrypt customer embeddings without customer authorization.
03
Tenant Isolation & Private VPC Deployment
NOVA operates with strict logical multi-tenant database isolation. Each customer workspace has dedicated cryptographic tenant keys enforcing row-level security (RLS) across all vector stores and relational databases.
For customers in regulated sectors (Fintech, Healthcare, Defense), NOVA provides dedicated single-tenant worker clusters deployed directly inside private cloud virtual private clouds (AWS VPC, GCP VPC, Azure VNet) with dedicated egress IPs and zero public Internet ingress.
04
Regulatory Compliance (SOC 2, GDPR, HIPAA)
NOVA undergoes annual independent third-party audits to maintain SOC 2 Type II certification covering the Security, Availability, and Confidentiality trust service principles. Our SOC 2 Type II audit report and continuous monitoring dashboard are available to enterprise customers under NDA.
We are fully compliant with the European Union General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA). Enterprise customers may execute our standard Data Processing Addendum (DPA) incorporating EU Standard Contractual Clauses (SCCs). Healthcare customers can sign a HIPAA Business Associate Agreement (BAA), and PHI is processed only inside dedicated, audit-logged tenant environments.
05
Data Retention, Export & Permanent Deletion
Workspace administrators maintain full ownership of all uploaded documents, connector mappings, and agent telemetry. You may request a complete JSON/raw export or trigger a cryptographic hard delete of all customer vector embeddings at any time. Permanent deletion completes across all replica volumes within 7 calendar days.
06
Data Protection Officer & Security Contact
For legal inquiries, DPA requests, or vulnerability disclosures, contact our legal and security compliance team directly:
NOVA Technologies Inc. — Data Protection Office
Email: privacy@nova.ai
Security Hotline: security@nova.ai
Address: 500 Howard Street, Suite 400, San Francisco, CA 94105, United States
