Skip to content
Skip to main content
Novel Systems home
Legal

Privacy Policy

What personal information the platform holds, why it holds it, how long it keeps it, and who else can touch it. Most of it is workforce data — technician names, device identifiers, and location traces captured while a job is open — which is a more sensitive category than customer contact records and is treated that way.

Effective
July 1, 2026
Version
Version 2.2
Length
10 sections · 27 clauses

Read this before you rely on anything below

These documents describe the terms on which Novel Systems operates the platform. They are published so that a buyer can evaluate the commitments before a call, not as a substitute for the agreement you sign. Where an executed order form, master service agreement, or data processing addendum differs from anything below, the executed document governs.

A signed Data Processing Addendum supersedes this policy for the tenant that signed it. Where a customer's DPA is silent, this policy fills the gap.

1 · Scope and roles

Who is the controller, who is the processor, and which of the two you are dealing with depends on whose data is in question.

1.1 Controller and processor

Novel Systems is the controller for information collected about visitors to this website and about the individuals who administer a customer account — the people we bill, support, and email.

For everything inside a tenant — customers, quotes, jobs, technicians, location traces, photographs, and signatures — the customer is the controller and Novel Systems is the processor. We hold that data on instruction and do not decide what it is used for.

In plain terms: Your business data is yours. We are the custodian, not the owner, and we act on your instruction.

1.2 Relationship to Novel Blinds Inc.

Novel Systems is an operating division of Novel Blinds Inc., registered in Toronto, Ontario, Canada. The parent entity is the legal person behind the contract, and personnel data for our own employees is administered under the parent's HR policies rather than this one.

Novel Blinds Inc. is also a customer of the platform. That tenant is isolated on the same terms as every other tenant, with no elevated read path, and no data from a customer tenant is visible to the parent's operating business.

2 · What we collect

Enumerated rather than described, because 'information you provide to us' is a phrase that tells a reader nothing.

2.1 Account and billing information

Collected directly from you when an account is opened and when it is administered thereafter.

  • Name, work email address, telephone number, and role for each user in the tenant.
  • Business name, service area, and the registered address on your order form.
  • Billing contact, payment instrument tokens held by the payment processor, and invoice history. Full card numbers never reach our infrastructure.
  • Authentication metadata: identity provider, SSO assertion attributes, sign-in timestamps, and originating IP.

2.2 Field and device data

The mobile technician application collects operational data while a job is open. This is the most sensitive category the platform handles and the section worth reading in full.

  • Location traces from the assigned device, captured only between job acceptance and job completion. Retained for 90 days by default and configurable per tenant down to 24 hours.
  • Device identifiers, operating system version, application version, battery state, and connectivity state — used for sync diagnosis and for knowing whether an offline device is offline or has stopped.
  • Photographs, measurements, signatures, and free-text notes captured against a job by a technician.
  • Timestamps for arrival, start, completion, and each status transition.

In plain terms: Location tracking is bounded to an open job. It is not continuous, it is not collected outside a job window, and the retention window is yours to shorten.

2.3 Product telemetry

Error reports, performance traces, and feature usage counts. Payloads are scrubbed of personal information at the tenant boundary before they leave it, and stack traces are stripped of variable contents rather than shipped whole.

Telemetry is not used to build a profile of an individual user, and it is not sold, shared, or made available to another tenant in any form, aggregated or otherwise.

2.4 This website

Requests to this site are logged with a truncated IP address, a user agent string, and the requested path, retained for 30 days for abuse and availability diagnosis.

Forms on this site are processed to answer the enquiry they were submitted for. Where a form states that it is a preview and transmits nothing — as the careers application does — that statement is accurate and nothing is stored.

3 · Why we hold it

Purpose limitation stated as purposes, with the negatives spelled out.

3.1 Permitted purposes

Personal information is processed to deliver the platform, to support and secure it, to bill for it, and to meet a legal obligation. Nothing else.

  • Operating the service the tenant subscribed to, including quoting, dispatch, invoicing, and integration synchronisation.
  • Supporting the tenant, which occasionally requires break-glass access to production under the controls described in §6.
  • Detecting and investigating abuse, fraud, and security incidents.
  • Billing, tax compliance, and statutory record-keeping.

3.2 What we do not do

Stated as prohibitions so they are testable rather than aspirational.

  • We do not sell personal information, and we do not disclose it for consideration of any kind.
  • We do not use tenant data to train models made available to any other tenant, and we do not use it to train general-purpose models.
  • We do not serve advertising, and we do not operate advertising or cross-site tracking pixels on the application.
  • We do not use field location data for individual performance evaluation on our own initiative. What a customer does with its own workforce data is a matter for the customer and its employment obligations.

4 · Retention and deletion

Every window has a number. A retention policy without numbers is a statement of intent.

4.1 Retention windows

Defaults, all of which can be shortened by tenant configuration.

  • Field location traces: 90 days, configurable to 24 hours.
  • Audit log entries: 24 months, append-only and not editable by any role including ours.
  • Operational records — quotes, jobs, invoices — for the life of the tenant, because they are the customer's business records rather than ours to expire.
  • Encrypted backup snapshots: 35 days, rolling.
  • Website request logs: 30 days.

4.2 Deletion

A deletion instruction is executed across primary storage within 30 days. Encrypted backups are not selectively edited — doing so would compromise their integrity — so deleted records persist in backup for up to 35 days until the snapshot rolls off, and are not restored into production by any routine.

On termination, tenant data remains exportable for 60 days before deletion begins. That window is not conditional on the account being in good standing; withholding a customer's own operating data as leverage in a billing dispute is not a practice we are willing to have.

In plain terms: Deleted means deleted within 30 days, plus up to 35 days for backups to roll off. Nobody restores your deleted data back into service.

4.3 Export

Every record a tenant owns is exportable in CSV and JSON at any time from the administrative interface, without a support ticket, a professional services engagement, or a fee. The export includes relationships, not only flat tables, so it is usable as a migration source rather than as a compliance gesture.

5 · Subprocessors

Every third party that can process tenant data, what it does, and where it runs.

5.1 Named subprocessors

Named rather than described. A category list tells a reviewer whether there is a class of problem; a named list is what they need in order to run their own vendor assessment, and withholding it only defers the question to a questionnaire later.

The control mapping and the executed data processing agreements remain available to customers and prospects under NDA. The table below is the complete list of entities that process tenant data — a party not named here does not receive it.

This list was last validated against the production account inventory in Q3 2026, and is revalidated quarterly. The date is published because a subprocessor list without one is a claim about the past that a reader cannot date: the useful question is not whether the list was ever accurate but when it was last checked against what is actually deployed.

  • Cloud infrastructure and managed databases — Canada (ca-central-1), across availability zones. Processes all tenant data at rest and in transit.
  • Payment processing for subscription billing — processes billing contact details and card data. Never receives job, customer, or workforce records.
  • Transactional email for intake acknowledgements and dispatch notifications — receives recipient address and message content only.
  • SMS delivery for dispatch notifications, in tenants that have enabled it — receives the recipient number, the technician's name and arrival window, and the site address.
Subprocessors that process tenant data, with purpose, data reached, and processing region
SubprocessorPurposeData reachedRegion
Amazon Web Services Canada, Inc.Cloud infrastructure underlying the managed database tier.All tenant data at rest.Canada · ca-central-1
SupabaseManaged Postgres and object storage, running in the AWS region above.All tenant data at rest and in transit.Canada · ca-central-1
VercelApplication hosting, edge routing, and TLS termination.Request metadata in transit. No tenant data at rest.Global edge · Canadian origin
ResendTransactional email — intake acknowledgements and dispatch notifications.Recipient address and message content only.United States
Twilio Inc.SMS dispatch notifications, and only in tenants that have enabled them. A tenant that leaves SMS off sends nothing here.Recipient mobile number, the technician's name and arrival window, and the site address as it appears in the message body.United States
StripeSubscription billing and payment processing.Billing contact details and card data. Never job, customer, or workforce records.United States

5.2 Adding or changing a subprocessor

Customers subscribed to subprocessor notifications receive 30 days written notice before a new subprocessor begins processing tenant data. A customer with a reasonable objection on data protection grounds may raise it during that window, and if it cannot be resolved, may terminate the affected service without penalty for the remainder of the term.

No subprocessor is added without a data processing agreement at least as protective as the commitments in this policy, and none is granted access beyond the category described above.

6 · Security and access

How the data is protected and, more usefully, who can reach it and under what conditions.

6.1 Controls

Encryption in transit with TLS 1.2 or better, and at rest with AES-256. Tenant isolation is enforced at the query layer rather than by application convention, so a missing filter is a failed query rather than a cross-tenant read.

SOC 2 Type II is in progress and is not represented as achieved anywhere on this site or in any document we issue. The control set is implemented and being observed over an audit window; the report is the thing we do not have yet.

6.2 Staff access to production

Routine operation of the platform requires no access to tenant records. Access for a support investigation is break-glass: time-bounded, individually attributed, written to the append-only audit log the tenant can read, and expired automatically rather than revoked manually.

Break-glass access is limited to Canadian-resident personnel. That is a residency commitment about people, not only about servers, and it is the one most residency claims quietly omit.

6.3 Breach notification

Where a breach of security safeguards creates a real risk of significant harm, affected tenants are notified within 72 hours of confirmation, together with the Office of the Privacy Commissioner of Canada where PIPEDA requires it.

Notification states what was accessed, when, by what means, and what has been done — not a paragraph about how seriously we take security.

7 · Data residency

Where the data physically is, including the parts most residency statements leave out.

7.1 Canadian residency

For tenants on the Canadian residency configuration, the primary region, the read replica, the automated failover target, and the encrypted backups are all inside Canada. The replica is in a separate availability zone in the same region, not a United States secondary.

Support access, as noted in §6.2, is likewise Canada-based. Residency that covers the storage but not the people who can read it is residency in name.

7.2 Cross-border transfer

Canadian residency is avoidable end to end for a tenant that selects it — there is no configuration in which a Canadian-resident tenant's records transit a foreign region in the normal course.

Tenants outside Canada may be provisioned in another region by agreement. Where that happens it is stated in the order form rather than left as an inference.

8 · PIPEDA statement

How the platform maps to Canada's Personal Information Protection and Electronic Documents Act, and who answers when a request arrives.

8.1 Mapping to the ten principles

Consent, purpose limitation, and retention are configured per tenant rather than assumed globally, because a dispatch business in Ontario and a distributor with a national workforce do not have the same obligations and should not be forced into the same defaults.

  • Accountability — a named Privacy Officer is accountable for compliance and is reachable directly.
  • Identifying purposes and consent — the purposes in §3 are the complete set; a new purpose requires a policy change with notice, not a broader reading of this one.
  • Limiting collection, use, and retention — enumerated in §2 and §4 with numbers attached.
  • Accuracy and individual access — §8.2.
  • Safeguards and openness — §6, plus the published control posture on the security page.
  • Challenging compliance — §8.3.

8.2 Access and correction requests

Where Novel Systems is the controller, an individual may request access to, or correction of, their personal information. The Privacy Officer responds within 30 days, which is the statutory ceiling rather than a service target we are proud of.

Where Novel Systems is the processor — which is the case for anything inside a tenant — a request is routed to the controlling customer, and we assist that customer in responding. Requests reach us at privacy@novelsystems.ca.

8.3 Challenging compliance

A complaint about our handling of personal information should go to the Privacy Officer at privacy@novelsystems.ca and will be investigated and answered in writing.

An individual dissatisfied with the outcome may complain to the Office of the Privacy Commissioner of Canada. We will not treat that as a breach of any agreement, and saying so here removes any doubt about it.

9 · Rights outside Canada

PIPEDA is the statute we are built around, but it is not the only one that applies. GDPR and the California regime give different rights on different timelines, and this section states which ones actually reach us.

9.1 GDPR — data subject rights

Where the GDPR applies, an individual has the rights below. Where Novel Systems is the processor — anything inside a tenant — a request is routed to the controlling customer and we assist rather than decide, which is stated in §1.1 and repeated here because it is the part that determines who must answer within the month.

Requests reach us at privacy@novelsystems.ca and are answered within one month, extensible by two further months for a complex request, with the reason for the extension given rather than asserted.

  • Access — a copy of the personal data held, and the purposes, recipients, and retention period attached to it.
  • Rectification of inaccurate data, and completion of incomplete data.
  • Erasure, subject to the backup rolling-off window in §4.2, which is disclosed rather than treated as an exception nobody mentions.
  • Restriction of processing while an accuracy or legitimate-interest objection is being resolved.
  • Portability, in a structured machine-readable format — served by the same export described in §4.3, at no cost.
  • Objection to processing carried out on the basis of legitimate interests.
  • Withdrawal of consent, where consent is the basis, without affecting processing already carried out.
  • Complaint to a supervisory authority, which we will not treat as a breach of any agreement.

9.2 GDPR — legal bases and transfers

Where we are the controller, the bases are: performance of a contract for account administration, billing, and support; legitimate interests for security monitoring, abuse detection, and product telemetry as described in §2.3; and legal obligation for tax and statutory record-keeping. We do not rely on consent for anything the platform needs in order to run, because consent that cannot be refused without losing the service is not consent.

Transfers out of the EEA are governed by the current Standard Contractual Clauses, included in the Data Processing Addendum and available before signature rather than after. Where an Article 27 representative is required for a tenant, it is appointed and named in that tenant's DPA before provisioning; no representative is named on this page because naming one we have not appointed would be worse than the omission.

9.3 CCPA and CPRA — California

Under the California Consumer Privacy Act as amended by the CPRA, a California resident has the rights below. Most personal information the platform holds is business-to-business workforce data for which our customer is the business and we are the service provider; requests about it are routed accordingly.

  • Right to know the categories and specific pieces of personal information collected, the sources, the purposes, and the categories of third parties it is disclosed to. The categories are enumerated in §2 rather than summarised.
  • Right to delete, subject to the same backup window in §4.2.
  • Right to correct inaccurate personal information.
  • Right to opt out of sale or sharing — see §9.4, which explains why there is nothing to opt out of.
  • Right to limit the use and disclosure of sensitive personal information. Precise geolocation is the sensitive category the platform handles; it is used only to operate dispatch for the tenant that collected it and never for inferring characteristics about an individual.
  • Right to non-discrimination for exercising any of the above. We do not operate financial incentive programmes tied to personal information, so there is no differential pricing to disclose.

9.4 No sale and no sharing

Novel Systems has not sold personal information, and has not shared it for cross-context behavioural advertising, in the preceding twelve months or at any point before that. Those two terms carry specific statutory definitions in California, and the statement above is made against those definitions rather than against the ordinary meaning of the word 'sell'.

We do not sell customer data or telemetry data in any form, to anyone, aggregated or otherwise. This is repeated from §3.2 because it is the single question a reviewer opens this section to answer, and making them cross-reference for it would be a strange choice.

It follows that there is no 'Do Not Sell or Share My Personal Information' mechanism to operate. A link that opts a person out of something that never happens is theatre, and we would rather explain the absence than build one.

In plain terms: Nothing is sold and nothing is shared for advertising, under the statutory meanings of both words. There is no opt-out link because there is nothing to opt out of.

10 · Contact and changes

How to reach a person, and how you find out when this document changes.

10.1 Contact

Privacy Officer, Novel Systems, a division of Novel Blinds Inc. — privacy@novelsystems.ca.

Neither entity maintains walk-in premises, so written notice by post should be addressed to the registered address stated on your order form.

10.2 Changes to this policy

A material change is notified to account administrators in advance and the effective date on this page moves. Immaterial corrections — a typo, a clarified sentence that does not change the obligation — are made without notice.

Prior versions are retained and provided on request. A policy whose history cannot be produced is a policy that can be quietly rewritten.

Questions, or a redline

Questions about these documents go to privacy@novelsystems.ca for privacy matters and sales@novelsystems.ca for commercial terms. Security disclosures go to security@novelsystems.ca.

Procurement teams are welcome to send this document to counsel before speaking to anyone here. That is why it is published rather than gated behind a form.