Skip to content
Skip to main content
Novel Systems home
Legal

Privacy Policy

What personal information the platform holds, why it holds it, how long it keeps it, and who else can touch it. Most of it is workforce data — technician names, device identifiers, and location traces captured while a job is open — which is a more sensitive category than customer contact records and is treated that way.

Effective
June 1, 2026
Version
Version 2.1
Length
9 sections · 23 clauses

Read this before you rely on anything below

These documents describe the terms on which Novel Systems operates the platform. They are published so that a buyer can evaluate the commitments before a call, not as a substitute for the agreement you sign. Where an executed order form, master service agreement, or data processing addendum differs from anything below, the executed document governs.

A signed Data Processing Addendum supersedes this policy for the tenant that signed it. Where a customer's DPA is silent, this policy fills the gap.

1 · Scope and roles

Who is the controller, who is the processor, and which of the two you are dealing with depends on whose data is in question.

1.1 Controller and processor

Novel Systems is the controller for information collected about visitors to this website and about the individuals who administer a customer account — the people we bill, support, and email.

For everything inside a tenant — customers, quotes, jobs, technicians, location traces, photographs, and signatures — the customer is the controller and Novel Systems is the processor. We hold that data on instruction and do not decide what it is used for.

In plain terms: Your business data is yours. We are the custodian, not the owner, and we act on your instruction.

1.2 Relationship to Novel Blinds Inc.

Novel Systems is an operating division of Novel Blinds Inc., registered in Toronto, Ontario, Canada. The parent entity is the legal person behind the contract, and personnel data for our own employees is administered under the parent's HR policies rather than this one.

Novel Blinds Inc. is also a customer of the platform. That tenant is isolated on the same terms as every other tenant, with no elevated read path, and no data from a customer tenant is visible to the parent's operating business.

2 · What we collect

Enumerated rather than described, because 'information you provide to us' is a phrase that tells a reader nothing.

2.1 Account and billing information

Collected directly from you when an account is opened and when it is administered thereafter.

  • Name, work email address, telephone number, and role for each user in the tenant.
  • Business name, service area, and the registered address on your order form.
  • Billing contact, payment instrument tokens held by the payment processor, and invoice history. Full card numbers never reach our infrastructure.
  • Authentication metadata: identity provider, SSO assertion attributes, sign-in timestamps, and originating IP.

2.2 Field and device data

The mobile technician application collects operational data while a job is open. This is the most sensitive category the platform handles and the section worth reading in full.

  • Location traces from the assigned device, captured only between job acceptance and job completion. Retained for 90 days by default and configurable per tenant down to 24 hours.
  • Device identifiers, operating system version, application version, battery state, and connectivity state — used for sync diagnosis and for knowing whether an offline device is offline or has stopped.
  • Photographs, measurements, signatures, and free-text notes captured against a job by a technician.
  • Timestamps for arrival, start, completion, and each status transition.

In plain terms: Location tracking is bounded to an open job. It is not continuous, it is not collected outside a job window, and the retention window is yours to shorten.

2.3 Product telemetry

Error reports, performance traces, and feature usage counts. Payloads are scrubbed of personal information at the tenant boundary before they leave it, and stack traces are stripped of variable contents rather than shipped whole.

Telemetry is not used to build a profile of an individual user, and it is not sold, shared, or made available to another tenant in any form, aggregated or otherwise.

2.4 This website

Requests to this site are logged with a truncated IP address, a user agent string, and the requested path, retained for 30 days for abuse and availability diagnosis.

Forms on this site are processed to answer the enquiry they were submitted for. Where a form states that it is a preview and transmits nothing — as the careers application does — that statement is accurate and nothing is stored.

3 · Why we hold it

Purpose limitation stated as purposes, with the negatives spelled out.

3.1 Permitted purposes

Personal information is processed to deliver the platform, to support and secure it, to bill for it, and to meet a legal obligation. Nothing else.

  • Operating the service the tenant subscribed to, including quoting, dispatch, invoicing, and integration synchronisation.
  • Supporting the tenant, which occasionally requires break-glass access to production under the controls described in §6.
  • Detecting and investigating abuse, fraud, and security incidents.
  • Billing, tax compliance, and statutory record-keeping.

3.2 What we do not do

Stated as prohibitions so they are testable rather than aspirational.

  • We do not sell personal information, and we do not disclose it for consideration of any kind.
  • We do not use tenant data to train models made available to any other tenant, and we do not use it to train general-purpose models.
  • We do not serve advertising, and we do not operate advertising or cross-site tracking pixels on the application.
  • We do not use field location data for individual performance evaluation on our own initiative. What a customer does with its own workforce data is a matter for the customer and its employment obligations.

4 · Retention and deletion

Every window has a number. A retention policy without numbers is a statement of intent.

4.1 Retention windows

Defaults, all of which can be shortened by tenant configuration.

  • Field location traces: 90 days, configurable to 24 hours.
  • Audit log entries: 24 months, append-only and not editable by any role including ours.
  • Operational records — quotes, jobs, invoices — for the life of the tenant, because they are the customer's business records rather than ours to expire.
  • Encrypted backup snapshots: 35 days, rolling.
  • Website request logs: 30 days.

4.2 Deletion

A deletion instruction is executed across primary storage within 30 days. Encrypted backups are not selectively edited — doing so would compromise their integrity — so deleted records persist in backup for up to 35 days until the snapshot rolls off, and are not restored into production by any routine.

On termination, tenant data remains exportable for 60 days before deletion begins. That window is not conditional on the account being in good standing; withholding a customer's own operating data as leverage in a billing dispute is not a practice we are willing to have.

In plain terms: Deleted means deleted within 30 days, plus up to 35 days for backups to roll off. Nobody restores your deleted data back into service.

4.3 Export

Every record a tenant owns is exportable in CSV and JSON at any time from the administrative interface, without a support ticket, a professional services engagement, or a fee. The export includes relationships, not only flat tables, so it is usable as a migration source rather than as a compliance gesture.

5 · Subprocessors

Every third party that can process tenant data, what it does, and where it runs.

5.1 Categories in use

The current named list, with the control mapping and the executed agreements, is provided to customers and prospects under NDA. The categories are public here because a category list is enough to tell a reviewer whether there is a problem.

  • Cloud infrastructure and managed databases — Canada (ca-central-1), primary and replica. Processes all tenant data at rest and in transit.
  • Payment processing for subscription billing — processes billing contact details and card data. Never receives job, customer, or workforce records.
  • Transactional email and SMS delivery for dispatch notifications — receives message content and recipient number only.
  • Error and performance telemetry — receives scrubbed diagnostic payloads, with personal information removed before the payload leaves the tenant boundary.

5.2 Adding or changing a subprocessor

Customers subscribed to subprocessor notifications receive 30 days written notice before a new subprocessor begins processing tenant data. A customer with a reasonable objection on data protection grounds may raise it during that window, and if it cannot be resolved, may terminate the affected service without penalty for the remainder of the term.

No subprocessor is added without a data processing agreement at least as protective as the commitments in this policy, and none is granted access beyond the category described above.

6 · Security and access

How the data is protected and, more usefully, who can reach it and under what conditions.

6.1 Controls

Encryption in transit with TLS 1.2 or better, and at rest with AES-256. Tenant isolation is enforced at the query layer rather than by application convention, so a missing filter is a failed query rather than a cross-tenant read.

SOC 2 Type II is in progress and is not represented as achieved anywhere on this site or in any document we issue. The control set is implemented and being observed over an audit window; the report is the thing we do not have yet.

6.2 Staff access to production

Routine operation of the platform requires no access to tenant records. Access for a support investigation is break-glass: time-bounded, individually attributed, written to the append-only audit log the tenant can read, and expired automatically rather than revoked manually.

Break-glass access is limited to Canadian-resident personnel. That is a residency commitment about people, not only about servers, and it is the one most residency claims quietly omit.

6.3 Breach notification

Where a breach of security safeguards creates a real risk of significant harm, affected tenants are notified within 72 hours of confirmation, together with the Office of the Privacy Commissioner of Canada where PIPEDA requires it.

Notification states what was accessed, when, by what means, and what has been done — not a paragraph about how seriously we take security.

7 · Data residency

Where the data physically is, including the parts most residency statements leave out.

7.1 Canadian residency

For tenants on the Canadian residency configuration, the primary region, the read replica, the automated failover target, and the encrypted backups are all inside Canada. The replica is in a separate availability zone in the same region, not a United States secondary.

Support access, as noted in §6.2, is likewise Canada-based. Residency that covers the storage but not the people who can read it is residency in name.

7.2 Cross-border transfer

Canadian residency is avoidable end to end for a tenant that selects it — there is no configuration in which a Canadian-resident tenant's records transit a foreign region in the normal course.

Tenants outside Canada may be provisioned in another region by agreement. Where that happens it is stated in the order form rather than left as an inference.

8 · PIPEDA statement

How the platform maps to Canada's Personal Information Protection and Electronic Documents Act, and who answers when a request arrives.

8.1 Mapping to the ten principles

Consent, purpose limitation, and retention are configured per tenant rather than assumed globally, because a dispatch business in Ontario and a distributor with a national workforce do not have the same obligations and should not be forced into the same defaults.

  • Accountability — a named Privacy Officer is accountable for compliance and is reachable directly.
  • Identifying purposes and consent — the purposes in §3 are the complete set; a new purpose requires a policy change with notice, not a broader reading of this one.
  • Limiting collection, use, and retention — enumerated in §2 and §4 with numbers attached.
  • Accuracy and individual access — §8.2.
  • Safeguards and openness — §6, plus the published control posture on the security page.
  • Challenging compliance — §8.3.

8.2 Access and correction requests

Where Novel Systems is the controller, an individual may request access to, or correction of, their personal information. The Privacy Officer responds within 30 days, which is the statutory ceiling rather than a service target we are proud of.

Where Novel Systems is the processor — which is the case for anything inside a tenant — a request is routed to the controlling customer, and we assist that customer in responding. Requests reach us at privacy@novelsystems.ca.

8.3 Challenging compliance

A complaint about our handling of personal information should go to the Privacy Officer at privacy@novelsystems.ca and will be investigated and answered in writing.

An individual dissatisfied with the outcome may complain to the Office of the Privacy Commissioner of Canada. We will not treat that as a breach of any agreement, and saying so here removes any doubt about it.

9 · Contact and changes

How to reach a person, and how you find out when this document changes.

9.1 Contact

Privacy Officer, Novel Systems, a division of Novel Blinds Inc. — privacy@novelsystems.ca.

Both entities are service-area businesses with no walk-in premises, so written notice by post should be addressed to the registered address stated on your order form. Service-area business · no walk-in office.

9.2 Changes to this policy

A material change is notified to account administrators in advance and the effective date on this page moves. Immaterial corrections — a typo, a clarified sentence that does not change the obligation — are made without notice.

Prior versions are retained and provided on request. A policy whose history cannot be produced is a policy that can be quietly rewritten.

Questions, or a redline

Questions about these documents go to privacy@novelsystems.ca for privacy matters and sales@novelsystems.ca for commercial terms. Security disclosures go to security@novelsystems.ca.

Procurement teams are welcome to send this document to counsel before speaking to anyone here. That is why it is published rather than gated behind a form.