Trust
This page explains how Novella approaches security, privacy, and reliability for our website and customer feedback platform.
This page provides an overview of Novella’s trust posture. For legal details, refer to our Privacy Policy and Terms & Conditions.
1. Security practices
We apply practical, industry-standard safeguards to protect data against unauthorized access, alteration, or loss. Measures include:
- Encrypted data transmission (HTTPS / TLS)
- Access controls and role-based permissions
- Secure hosting and infrastructure hardening
- Monitoring and logging of key application events
- Regular updates and dependency maintenance
Important: No system can be guaranteed to be 100% secure. We focus on proportional controls aligned with the sensitivity of the data processed in Novella.
2. Privacy & data protection
Novella is designed to support GDPR-aligned feedback programs. Depending on context, Novella acts as either:
- Controller for website visitors and Novella account users
- Processor for feedback collected on behalf of customers
Details on personal data processing, legal bases, retention and rights are provided in our Privacy Policy.
3. Compliance & governance
We work to support responsible handling of data across the platform. This includes:
- Use of subprocessors where needed (bound by appropriate agreements)
- Data minimization: customers control what they collect in surveys
- Retention controls aligned with subscription plans and configuration
- Clear separation between customer account data and respondent feedback data
4. Reliability
Novella is built to be dependable for operational teams. We aim for predictable performance through:
- Lean architecture with minimal moving parts
- Monitoring and alerting for critical services
- Controlled releases and rollbacks where appropriate
5. Responsible use
Customers are responsible for using Novella lawfully and ethically, including:
- Providing clear notices to respondents
- Ensuring a valid legal basis for collecting feedback
- Avoiding collection of sensitive personal data unless legally permitted and necessary
6. Contact
Questions about trust, security, or privacy?