PIPEDA is the statute we are built around, but it is not the only one that applies. GDPR and the California regime give different rights on different timelines, and this section states which ones actually reach us.
9.1 GDPR — data subject rights
Where the GDPR applies, an individual has the rights below. Where Novel Systems is the processor — anything inside a tenant — a request is routed to the controlling customer and we assist rather than decide, which is stated in §1.1 and repeated here because it is the part that determines who must answer within the month.
Requests reach us at privacy@novelsystems.ca and are answered within one month, extensible by two further months for a complex request, with the reason for the extension given rather than asserted.
- Access — a copy of the personal data held, and the purposes, recipients, and retention period attached to it.
- Rectification of inaccurate data, and completion of incomplete data.
- Erasure, subject to the backup rolling-off window in §4.2, which is disclosed rather than treated as an exception nobody mentions.
- Restriction of processing while an accuracy or legitimate-interest objection is being resolved.
- Portability, in a structured machine-readable format — served by the same export described in §4.3, at no cost.
- Objection to processing carried out on the basis of legitimate interests.
- Withdrawal of consent, where consent is the basis, without affecting processing already carried out.
- Complaint to a supervisory authority, which we will not treat as a breach of any agreement.
9.2 GDPR — legal bases and transfers
Where we are the controller, the bases are: performance of a contract for account administration, billing, and support; legitimate interests for security monitoring, abuse detection, and product telemetry as described in §2.3; and legal obligation for tax and statutory record-keeping. We do not rely on consent for anything the platform needs in order to run, because consent that cannot be refused without losing the service is not consent.
Transfers out of the EEA are governed by the current Standard Contractual Clauses, included in the Data Processing Addendum and available before signature rather than after. Where an Article 27 representative is required for a tenant, it is appointed and named in that tenant's DPA before provisioning; no representative is named on this page because naming one we have not appointed would be worse than the omission.
9.3 CCPA and CPRA — California
Under the California Consumer Privacy Act as amended by the CPRA, a California resident has the rights below. Most personal information the platform holds is business-to-business workforce data for which our customer is the business and we are the service provider; requests about it are routed accordingly.
- Right to know the categories and specific pieces of personal information collected, the sources, the purposes, and the categories of third parties it is disclosed to. The categories are enumerated in §2 rather than summarised.
- Right to delete, subject to the same backup window in §4.2.
- Right to correct inaccurate personal information.
- Right to opt out of sale or sharing — see §9.4, which explains why there is nothing to opt out of.
- Right to limit the use and disclosure of sensitive personal information. Precise geolocation is the sensitive category the platform handles; it is used only to operate dispatch for the tenant that collected it and never for inferring characteristics about an individual.
- Right to non-discrimination for exercising any of the above. We do not operate financial incentive programmes tied to personal information, so there is no differential pricing to disclose.
9.4 No sale and no sharing
Novel Systems has not sold personal information, and has not shared it for cross-context behavioural advertising, in the preceding twelve months or at any point before that. Those two terms carry specific statutory definitions in California, and the statement above is made against those definitions rather than against the ordinary meaning of the word 'sell'.
We do not sell customer data or telemetry data in any form, to anyone, aggregated or otherwise. This is repeated from §3.2 because it is the single question a reviewer opens this section to answer, and making them cross-reference for it would be a strange choice.
It follows that there is no 'Do Not Sell or Share My Personal Information' mechanism to operate. A link that opts a person out of something that never happens is theatre, and we would rather explain the absence than build one.
In plain terms: Nothing is sold and nothing is shared for advertising, under the statutory meanings of both words. There is no opt-out link because there is nothing to opt out of.