Data Processing Addendum

Effective 14 August 2026 · Version 3.0

This addendum applies whenever you use NovaBuild to process personal data for which you are the controller. It is incorporated into the Terms of Service automatically and needs no separate signature, although we will countersign a copy on request for procurement.

Plain language summary

  • You are the controller of the personal data in your projects, and NovaBuild is your processor.
  • We process only on your instruction, keep it confidential, and apply the security measures in Annex 2.
  • Subprocessors are listed publicly and we give notice before adding one, with a right to object.
  • Transfers out of the EEA and the United Kingdom rely on the Standard Contractual Clauses and the UK Addendum.
  • We notify you of a personal data breach without undue delay and help with data subject requests.

The summary is for orientation only. The numbered sections below are the operative text.

1. Incorporation and order of precedence

This addendum forms part of the agreement between you and NovaBuild. Where it conflicts with the Terms of Service on the processing of personal data, this addendum prevails. Where the Standard Contractual Clauses conflict with this addendum, the clauses prevail.

2. Definitions

Data protection law
All applicable law on the processing of personal data, including the EU General Data Protection Regulation, the UK GDPR and Data Protection Act 2018, the Swiss FADP, the Australian Privacy Act, and United States state privacy laws.
Controller, processor, data subject, personal data, processing
As defined in the GDPR, and equivalent terms such as business and service provider in United States state law.
Customer personal data
Personal data contained in your content or generated output that NovaBuild processes on your behalf.
Subprocessor
A third party engaged by NovaBuild to process customer personal data.
SCCs
The Standard Contractual Clauses approved by the European Commission on 4 June 2021.
UK Addendum
The International Data Transfer Addendum issued by the UK Information Commissioner.

3. Roles of the parties

For customer personal data you are the controller and we are the processor. Where you are yourself a processor for another controller, we are a subprocessor and this addendum applies as if you were the controller.

Separately, NovaBuild is an independent controller for account administration, billing, metering, security and abuse prevention, and product analytics about platform use. That processing is described in the Privacy Policy and is outside this addendum.

4. Scope of processing and your instructions

We process customer personal data only to provide the service, to follow your documented instructions, and to comply with law. Your use of the platform, including the prompts you write, the autonomy mode you select, the integrations you connect and the visibility you set, constitutes your instruction.

  • We do not sell customer personal data, and we do not use it for our own purposes.
  • We do not use customer personal data to train foundation models.
  • If we believe an instruction breaches data protection law, we tell you and may pause that processing.
  • If law compels us to process beyond your instruction, we inform you unless prohibited.

Do not put special category data in projects

The platform is not designed for health records, biometric identifiers, full payment card numbers, criminal record data or government identity numbers. Processing that data through prompts or project files is outside the intended use and remains your risk.

5. Our processor obligations

  • Process only on your instruction and for the purposes in Annex 1.
  • Ensure personnel with access are bound by confidentiality and trained on data handling.
  • Implement and maintain the measures in Annex 2, and not materially reduce them.
  • Engage subprocessors only under section 8, with equivalent written obligations.
  • Assist you with data subject requests, impact assessments and regulator engagement.
  • Notify you of a personal data breach without undue delay.
  • Delete or return customer personal data at the end of the service, subject to section 14.
  • Make available the information needed to demonstrate compliance, as set out in section 13.

6. Confidentiality and personnel

Access to customer personal data is limited to personnel who need it to operate or support the service. Access is role based, individually attributed, logged, reviewed periodically and revoked promptly on role change or departure. Staff are subject to confidentiality obligations that survive their engagement, and to background screening where local law allows.

7. Security measures

We maintain appropriate technical and organisational measures having regard to the state of the art, the cost of implementation, and the risk to data subjects. The current measures are set out in Annex 2 and described further on the Security page. We may update measures over time provided the overall level of protection is not reduced.

8. Subprocessors

You give general authorisation for the subprocessors listed in Annex 3 and on the Subprocessors page. Before adding or replacing a subprocessor that processes customer personal data, we publish the change and notify workspace owners at least 30 days in advance where feasible.

  • You may object on reasonable data protection grounds within the notice period by emailing privacy@novabuild.dev.
  • If we cannot offer a workaround, you may terminate the affected part of the service and receive a pro rata refund of prepaid fees for the unused period.
  • We impose data protection terms on each subprocessor that are no less protective than this addendum, and we remain responsible for their performance.

9. International transfers

Customer personal data may be processed in the United States, the European Economic Area and other countries where our subprocessors operate. Where we transfer personal data from the EEA, the United Kingdom or Switzerland to a country without an adequacy decision, the SCCs apply and are incorporated by reference, completed as set out in Annex 4, together with the UK Addendum for United Kingdom transfers.

We apply supplementary measures including encryption in transit and at rest, access control, data minimisation in what is sent to model providers, and a documented process for handling government access requests, under which we assess validity, challenge overbroad requests and notify you where lawful.

10. Assistance with data subject rights

The platform lets you find, export, correct and delete project data yourself, which is normally the fastest route. If a data subject contacts us directly about your data, we refer them to you and do not respond substantively. On request we provide reasonable assistance with access, rectification, erasure, restriction, portability and objection, at no charge for a proportionate volume of requests.

11. Personal data breach

  • We notify you without undue delay, and in any event within 48 hours of confirming a breach affecting customer personal data.
  • The notice describes the nature of the breach, the categories and approximate volume of data and data subjects affected, the likely consequences, and the measures taken or proposed.
  • Where full detail is not yet available, we provide information in phases as the investigation progresses.
  • We do not notify your data subjects or regulators on your behalf unless you instruct us in writing.
  • We keep a record of breaches and provide a post incident summary on request.

12. Data protection impact assessments

On request we provide the information reasonably needed for your impact assessment or prior consultation with a supervisory authority, including the processing details in Annex 1, the measures in Annex 2, subprocessor locations and transfer mechanisms.

13. Audits, reports and information rights

We satisfy audit obligations primarily by providing documentation: this addendum, the Security page, dependency and vulnerability scan summaries, subprocessor lists, and answers to a reasonable security questionnaire once per twelve months.

Where data protection law entitles you to an on site or deeper audit, you may request one no more than once per twelve months, with at least 30 days notice, at your cost, subject to confidentiality, scoped to systems processing your data, and conducted so as not to disrupt other tenants. An independent auditor must not be a competitor of NovaBuild.

14. Return, deletion and retention

EventWhat happensTiming
You delete a projectFiles, chat history and agent logs removed from live systemsImmediate
You delete a workspaceAll customer personal data in that workspace removed from live systemsSame day
Service endsExport window, then deletion of remaining customer personal data30 days, or immediately on written instruction
BackupsEncrypted backup copies expire automaticallyUp to 35 days
Legal holdRetained only where law requires, isolated and not processed for other purposesAs required by law

On request we confirm deletion in writing. Aggregated, de identified operational metrics that cannot be attributed to a person may be retained.

15. Liability under this addendum

Each party's liability under this addendum is subject to the limitations and exclusions in the Terms of Service. Nothing in this addendum limits a data subject's rights under data protection law, or either party's liability to a supervisory authority.

16. Term and survival

This addendum applies for as long as we process customer personal data for you. Obligations of confidentiality, security, breach notification and deletion survive termination until deletion is complete.

17. Annex 1: processing details

Subject matter and duration

Provision of the NovaBuild AI application builder, for the duration of the agreement plus the retention periods in section 14.

Nature and purpose

Hosting and storage of project content, transmission of prompts and file context to model providers, execution of code in isolated sandboxes, generation of previews, building and publishing deployments, sending transactional email, metering and billing, and providing support.

Categories of data subjects

  • Your personnel who hold accounts or workspace membership
  • Your end users, where their data appears in prompts, files, seed data or a connected database
  • Third parties whose details you include in project content

Categories of personal data

  • Identity and contact details such as name, email and avatar
  • Authentication metadata and session records
  • Content data inside prompts, files, migrations and generated output
  • Technical data such as IP address, user agent and timestamps
  • Usage and metering records tied to a member

Special category data

None intended. The platform is not configured for special category data, and you must not submit it.

Frequency of transfer

Continuous, for the duration of the service.

18. Annex 2: technical and organisational measures

AreaMeasure
EncryptionTLS 1.2 or higher in transit, encryption at rest for databases, object storage and backups, application level encryption for stored credentials
Access controlUnique accounts, strong authentication for staff, role based least privilege, quarterly access review, prompt revocation
Tenant isolationRow level security on every tenant table, authorisation through server side helper functions, per project sandbox containers
Secret handlingCredentials readable only inside server side execution, never returned to a browser, masked to the last four characters in the interface
Logging and monitoringTamper resistant audit log of privileged actions, error and performance monitoring, alerting on anomalous usage
ResilienceManaged database with point in time recovery, automated encrypted backups, documented restore procedure
Change managementVersion control, peer review, automated typecheck and build gates, staged rollout, rollback capability
Vulnerability managementDependency scanning, prompt patching of critical issues, periodic security review of the platform surface
Incident responseDocumented severities, on call escalation, containment and forensics steps, customer notification workflow, post incident review
Data minimisationOnly the file context needed for a task is sent to a model provider, and sandbox contents are cleared when a machine stops
PersonnelConfidentiality undertakings, security and privacy training, screening where lawful
DeletionDocumented deletion paths from the interface, automatic expiry of backups, written confirmation on request

19. Annex 3: approved subprocessors

The authoritative, always current list is on the Subprocessors page, which includes the purpose, processing location and transfer mechanism for each entry. Categories are: model providers, sandbox and compute, database and storage, hosting and content delivery, transactional email, payment processing, and error and product analytics.

20. Annex 4: transfer clauses module mapping

ItemCompletion
ModuleModule Two, controller to processor. Module Three, processor to processor, where you act as a processor for another controller
Clause 7 dockingIncluded, so additional parties may accede
Clause 9 subprocessorsOption 2, general written authorisation, with 30 days notice
Clause 11 redressOptional independent dispute resolution not selected
Clause 17 governing lawThe law of Ireland, unless another EEA member state law is required
Clause 18 forumThe courts of Ireland, without prejudice to a data subject's own forum rights
Annex I and IICompleted by Annex 1 and Annex 2 of this addendum
UK Addendum tablesCompleted by this addendum, with the ICO Addendum version B1.0 applying to United Kingdom transfers
Swiss transfersThe SCCs apply with references read to include the Swiss FADP and the Federal Data Protection and Information Commissioner

To request a countersigned copy of this addendum with the SCCs completed for your entity, email legal@novabuild.dev with your legal name, address and signatory.

This document is published by the NovaBuild team as general information about the service. It is not legal advice, and it is not a certification or an independent audit of NovaBuild or of any third party. If anything here is unclear, or you need a countersigned copy for procurement, email legal@novabuild.dev.