NOVAKOS PRIVACY POLICY
Version: 4.0 Effective Date: 2026-09-10 Last Updated: 2026-09-10
This Privacy Policy explains how Michael Novak O/A NovakOS, carrying on business as “NovakOS” (“NovakOS,” “we,” “us,” or “our”) collects, uses, discloses, stores, protects, retains, and otherwise handles personal information through NovakOS.
This Policy applies to the NovakOS website, web application, native/mobile applications, customer support, subscription and payment functions, communications systems, connected mailbox and accounting integrations, field-service functions, optional employee location and rewards/performance tools, and other NovakOS functionality.
Privacy Officer: Michael Novak, Privacy Officer Privacy / Support / Security Email: [support@novakos.org](mailto:support@novakos.org) Mailing Address: 2524 Hastings Road, Chemainus, BC, V0R 1K5 Website: https://novakos.org
This Policy is a transparency statement. A request that a user acknowledge this Policy is not, by itself, blanket consent to every possible collection, use, disclosure, monitoring activity, payment, or marketing communication. Separate notice, authorization, or consent is used where applicable law or the circumstances require it.
1. PRIVACY ROLES
NovakOS may handle personal information in different capacities depending on the information and relationship.
For information concerning NovakOS account administration, direct subscription billing, direct communications with NovakOS, product security, fraud prevention, legal compliance, product operations, and NovakOS support, NovakOS may determine the purposes for which information is handled and may be responsible for those purposes under applicable law.
Where a subscribing business enters or generates personal information concerning its customers, employees, contractors, technicians, property owners, tenants, or other individuals for the business’s own field-service, employment, accounting, communications, or commercial purposes, that subscribing business ordinarily determines those purposes and NovakOS processes the information to provide the Services and follow lawful instructions.
If you are an employee, contractor, or customer of a business using NovakOS, that business may therefore be the appropriate first contact about why it collected your information, how it uses it, and whether a particular record should be corrected, retained, or disclosed. NovakOS may assist the business within NovakOS’s role.
Applicable Canadian privacy law can vary by province, sector, and interprovincial or international activity. This Policy does not assert that one privacy statute applies to every record or transaction.
2. ACCOUNTABILITY
NovakOS maintains a privacy-management program appropriate to the Services.
Our Privacy Officer is responsible for overseeing NovakOS privacy practices and receiving privacy inquiries and complaints.
Where a Customer controls Customer Data, NovakOS will reasonably assist Customer in carrying out applicable privacy obligations within NovakOS’s role and capabilities.
3. INFORMATION WE MAY COLLECT
The categories collected depend on the Services actually enabled and used. The presence of a possible category below does not mean NovakOS collects that category from every user.
NovakOS seeks to avoid collecting information that is not reasonably necessary for an identified product, security, support, contractual, or legal purpose. Customers are also expected to minimize unnecessary sensitive information in free-text fields, uploads, photographs, and integrations.
4. ACCOUNT INFORMATION
We may process:
- name; email address; telephone number; profile image; authentication identifiers; sign-in provider; role; employer or company; account status; preferences; legal acceptance records.
Where Google, Apple, or another identity provider is used, the provider may authenticate the user without supplying NovakOS with that provider account’s password.
5. COMPANY INFORMATION
We may process:
- company name; trade/business information; company address; billing address; province; postal code; business telephone number; billing email; Subscription plan; account configuration; connected domains; payment-account status; personnel and permission information.
Business information may constitute personal information where it identifies an individual, including a sole proprietor.
6. END CUSTOMER INFORMATION
Businesses using NovakOS may submit information about their customers, including:
- names; telephone numbers; email addresses; billing addresses; service addresses; properties; communication preferences; jobs; appointments; equipment; service history; notes; estimates; quotes; invoices; payments; forms; signatures; communications; photographs; videos; * files.
7. EMPLOYEE, CONTRACTOR, AND PERFORMANCE INFORMATION
Depending on Customer configuration, NovakOS may process:
- names, work contact information, job roles, permissions, assignments, schedules, and job history;
- clock-in/out, break, attendance, time-entry, paid-leave, rate, wage-related, payroll-snapshot, adjustment, and timesheet information;
- optional work-related location information and tracking-policy acknowledgement records;
- sales, booking, job, dispatch, pricebook-item, performance, and opportunity metrics;
- optional NOS Points / Responsible Rewards information, including points, levels, leaderboard visibility, achievement records, configured reward types, reward eligibility, fulfillment status, and payroll-bonus workflow information; and
- inventory or material-use records associated with jobs, technicians, vehicles, warehouses, or equipment where the Customer uses those functions.
These records are provided to the Customer as business-management information. NovakOS does not independently hire, fire, discipline, promote, classify, or compensate a Customer’s worker.
8. LOCATION INFORMATION
Where a Customer enables location functionality, the current company location policy permits collection, the affected user has completed any NovakOS acknowledgement required by the product, and required device permissions are granted, NovakOS may process precise or approximate work-related location information.
Location information may include coordinates, timestamps, accuracy, speed, heading, altitude, device/platform metadata, policy version, associated time-entry or job context, whether a point was queued offline, and tracking state.
Depending on configuration, NovakOS may collect periodic or continuous points during an applicable active work/clock state and discrete event-location snapshots associated with work actions such as dispatch, arrival, clock, job, or other operational events. A snapshot taken as part of a clock-in or clock-out action can occur at the boundary of an active clock state.
NovakOS location functionality is intended for legitimate field-service and employment-management purposes and is not intended to facilitate covert off-duty surveillance, stalking, harassment, discrimination, or unrelated monitoring.
9. PHOTOGRAPHS, VIDEOS, AND MEDIA
NovakOS may process media that a user captures or selects, including:
- job photographs; equipment photographs; property photographs; videos; image attachments; signatures; files.
Where a feature requires audio capture, a device may request microphone access.
NovakOS does not intentionally access more of a user’s photo library than is required for the functionality the user invokes where system-level limited-selection functionality is available.
10. SUBSCRIPTION BILLING INFORMATION
For Customer’s NovakOS Subscription, we may process information including:
- billing email; Stripe customer identifier; Subscription identifier; Subscription plan; Subscription status; invoice information; charge amounts; payment-method type; card brand; last four digits; expiry information; * processor transaction identifiers.
Full payment-card numbers and CVVs are intended to be handled directly by Stripe or the applicable payment provider rather than NovakOS.
11. END-CUSTOMER PAYMENT INFORMATION
Where Customer uses supported payment functionality, NovakOS may process:
- Stripe Connected Account identifiers; Checkout Session identifiers; PaymentIntent identifiers; payment status; payment amount; platform fees; refund records; dispute records; payment-method identifiers; limited card metadata; payment consent records.
Full card credentials are handled by the applicable payment provider.
12. COMMUNICATION INFORMATION
Where a Customer uses email, connected mailbox, SMS, telephone-number, notification, or related communication functionality, NovakOS may process sender and recipient identifiers, email addresses, telephone numbers, message text, message subject, attachments, templates, timestamps, provider identifiers, delivery status, bounce status, complaint status, unsubscribe requests, STOP records, consent records, suppression records, and technical or audit information needed to send, troubleshoot, secure, and reconcile the communication.
Where the Customer connects its own mailbox, additional provider-specific information is described below.
12A. CONNECTED ACCOUNTING, MAILBOX, AND BUSINESS-INTEGRATION INFORMATION
Where Customer enables a supported integration, NovakOS may process and synchronize the information reasonably necessary for that connection.
QuickBooks Online / Intuit. Depending on enabled functions, this may include provider company and OAuth connection identifiers, protected authorization credentials, customers, invoices, payments, refunds or credits, products and services, tax codes or mappings, chart-of-accounts mappings, expenses, bills, vendors, attachments, provider record identifiers, synchronization state, read-only mirror data, errors, and audit information.
Connected business email. NovakOS may use Nylas or another communications provider to connect supported Google Workspace/Gmail, Microsoft 365/Outlook, iCloud, Yahoo, IMAP/SMTP, or other accounts. NovakOS may process the connected account identity, grant or connection identifier, provider, account email, sender/recipient information, message subject/body, attachments, delivery or send metadata, and connection state to the extent reasonably necessary for the enabled feature.
For the current Google Workspace/Gmail connection, NovakOS is designed to request identity information and the Gmail send permission needed to send user-authorized outbound company email rather than a general Gmail inbox-reading scope. For Microsoft accounts, the provider authorization flow may technically request permissions such as Mail.ReadWrite and Mail.Send because of provider/Nylas requirements even though NovakOS’s current connected-email product is designed as an outbound sending feature rather than a general-purpose inbox reader. Nylas, Google, Microsoft, or another provider may process information under its own infrastructure and terms.
NovakOS does not require Customer to connect an optional third-party integration to use unrelated functionality unless the relevant product flow expressly says the integration is required.
12B. INVENTORY, EQUIPMENT, DEMAND, AND OPPORTUNITY INFORMATION
Where inventory or opportunity functions are enabled, NovakOS may process inventory locations, vehicle assignments, serialized-unit identifiers, equipment and pricebook relationships, counts, transfers, returns, reservations, quote demand, accepted-quote reservations, job material usage, consumption, reconciliation issues, historical demand, sales measures, customer/item filters, and other operational analytics.
Some of this information may be linked to identifiable Authorized Users or End Customers when needed to show who performed an action, which job used an item, or how a business metric was calculated.
13. DEVICE, TECHNICAL, SECURITY, AND OFFLINE INFORMATION
We may process browser type, operating system, device type, application version, platform, IP address, session and authentication information, timestamps, connection information, diagnostic and error data, push-notification tokens, correlation identifiers, security events, audit events, webhook or integration diagnostics, and similar technical information.
Where offline functionality is used, a protected working copy of selected Customer Data and unsynchronized changes may be stored locally on a device or browser until synchronization, cleanup, sign-out, or other product controls remove or replace it.
14. SUPPORT INFORMATION
When someone contacts NovakOS, we may retain:
- correspondence; issue descriptions; support history; account details relevant to support; actions taken; identity-verification information where required; security or incident-related information.
15. SOURCES OF INFORMATION
NovakOS may receive personal information directly from an individual; from Customer owners, administrators, employees, contractors, or technicians; from End Customers; from uploaded files and user devices; and from Customer-authorized or operational Third-Party Services.
Depending on enabled features, those services may include Supabase, Stripe, Twilio, Resend or current email-delivery infrastructure, Nylas, Google, Microsoft, Intuit/QuickBooks Online, Apple, Firebase/Google push infrastructure, mapping providers, application marketplaces, Lovable-related deployment or gateway services, Cloudflare or network infrastructure, and successor or replacement providers.
A provider is a source only to the extent the applicable feature is configured and used.
16. PURPOSES OF COLLECTION AND PROCESSING
We may use personal information, as applicable, to create and authenticate accounts; administer Customers and permissions; manage customer/property/equipment records; schedule and dispatch work; manage jobs; create quotes and invoices; facilitate and reconcile payments; support saved methods and recurring plans; manage time, leave, payroll-related summaries and exports; provide optional work-location functions; operate NOS Points/Responsible Rewards and performance tools selected by Customer; manage inventory and demand/opportunity indicators; provide maps and routing; send communications and notifications; connect business mailboxes and accounting systems; synchronize supported records; support mobile/offline workflows; provide imports/exports and privacy-request aids; respond to support; prevent fraud and abuse; secure systems; investigate incidents; troubleshoot; enforce agreements; maintain legal and audit records; comply with law; and improve reliability and functionality using appropriate aggregate or de-identified information.
NovakOS does not use a broad product permission as a licence to repurpose identifiable Customer Data for unrelated behavioural advertising or general-purpose AI model training.
17. CONSENT AND OTHER LEGAL AUTHORITY
Where consent is required by applicable law, NovakOS or the relevant Customer should obtain meaningful consent appropriate to the circumstances.
Depending on the jurisdiction and activity, personal information may also be processed based on another authority permitted by applicable law.
Customer is responsible for determining the lawful authority applicable to Customer’s own collection and use of Customer Data.
18. EMPLOYEE PERSONAL INFORMATION
Customers using NovakOS for employee-management purposes are responsible for complying with applicable employment, labour, human-rights, surveillance, workplace, and privacy requirements.
Depending on the jurisdiction, an employer may be permitted to collect, use, or disclose certain employee personal information without consent for reasonable employment-management purposes, but may still have mandatory notice and purpose-limitation obligations. The existence of a NovakOS feature is not a determination that the employer’s proposed purpose is reasonable or lawful.
Customer must provide legally required notices, consultation, consent, policy access, and contact information before using employee-information functionality. NovakOS may provide acknowledgement records to help document presentation of a policy, but those records do not replace a legal requirement that applies independently to the employer.
19. EMPLOYEE LOCATION TRACKING
Where location functionality is enabled, Customer may use work-related location information for purposes it has lawfully identified, which may include dispatch, attendance or time verification, travel verification, assignment management, arrival status, operational review, or another reasonable work purpose.
Customer is responsible for determining whether each purpose is reasonable and lawful and for limiting access to people who have a legitimate business need. Customer must not use NovakOS location information for unlawful covert monitoring, stalking, harassment, discrimination, or unrelated off-duty surveillance.
Location information can be inaccurate. Customer should not make a material adverse employment decision solely from a single point, stale live-map pin, or unverified GPS record.
20. CONTINUOUS TRACKING AND EVENT SNAPSHOTS
NovakOS’s continuous/background employee-location feature is designed to require an enabled company policy, an applicable current policy acknowledgement, appropriate device permission, and an active work/clock state before continuous points are accepted. Continuous tracking is designed to pause or stop when the relevant work state ends or when policy/permission controls no longer authorize it.
Separately, if Customer enables event capture, NovakOS may capture a discrete location snapshot when a user performs a supported work action. Because a work action may itself begin or end a clock state, an event snapshot is not necessarily the same as continuous background tracking.
Paid vacation, sick, statutory-holiday, or other leave records are not intended to create an active employee clock session or continuous background GPS tracking.
21. LOCATION RETENTION AND LEGAL HOLDS
Under NovakOS’s current standard design, raw operational location history is configured for a short retention period selected within supported limits and ordinarily no more than approximately 28 days. Live-map location is intended to be transient rather than a permanent employment file.
Ordinary expiry may be suspended for particular information when reasonably necessary for a lawful litigation hold, threatened claim, investigation, security incident, employment-record preservation obligation, regulatory inquiry, or another legal requirement. A legal hold may therefore cause relevant location information to remain longer than the ordinary operational window.
If a Customer uses location information to make a decision that directly affects an individual, the Customer may have an independent legal obligation to preserve the information for longer than NovakOS’s ordinary location window. The Customer must preserve or export the relied-upon information and contact NovakOS promptly if a hold on NovakOS-controlled records is required. NovakOS’s ordinary 28-day maximum is not a representation that 28 days is legally sufficient for every employment decision.
22. LOCATION ACCURACY
Location information may be inaccurate or unavailable.
Factors include:
- device settings; GPS reception; network connectivity; operating-system controls; background restrictions; battery management; permission choices.
Location information is not intended for emergency response.
23. CAMERA PERMISSION
Where supported, NovakOS may request camera permission when a user chooses functionality requiring the camera.
Camera access may be used to capture job-site, equipment, form, or other work-related media.
24. PHOTO-LIBRARY ACCESS
NovakOS may allow a user to select photographs or videos from the device.
Where supported, NovakOS uses system selection functionality intended to limit access to media the user chooses.
25. MICROPHONE
Where a feature requires capture of media with audio, the operating system may request microphone permission.
NovakOS does not intend to continuously record microphone input in the background.
26. LOCATION PERMISSIONS
NovakOS may request:
- foreground location; * background/Always location
where required by an enabled field-service feature.
Users can deny or revoke permissions using operating-system settings, although functionality requiring that permission may no longer operate.
27. PUSH NOTIFICATIONS
NovakOS may request notification permission to provide:
- job updates; schedule information; account notices; * other operational notifications.
Push delivery depends on device and third-party infrastructure.
28. OFFLINE INFORMATION
NovakOS may temporarily store information locally on a device to support offline field work.
Local information may include unsynchronized changes.
Unsynchronized information may be lost if the application or browser data is cleared before synchronization.
NovakOS may clear local user-scoped application data during sign-out as part of account-security controls.
29. COOKIES, LOCAL STORAGE, AND ADVERTISING
NovakOS may use cookies, browser storage, device storage, or similar technology for authentication, security, session continuity, interface preferences, offline operation, required notices, performance, and other technical functionality.
NovakOS does not currently sell Customer application data or use identifiable Customer Data for third-party cross-site behavioural advertising profiles. If that practice materially changes, NovakOS will update this Policy and obtain consent or other authorization where legally required before the materially different use.
30. PAYMENT PROCESSORS
Stripe processes payment-card information for supported NovakOS payment functionality.
Stripe operates under its own terms and privacy practices.
NovakOS receives only the payment-related information reasonably required to provide and reconcile the applicable functionality.
31. SAVED PAYMENT METHODS
Where Customer uses stored-payment functionality, NovakOS may maintain records documenting authorization or consent.
Customer remains responsible for ensuring it has lawful authority to use an End Customer’s saved payment method.
32. COMMERCIAL ELECTRONIC MESSAGES
Customer may use NovakOS to send emails and text messages.
Customer is responsible for complying with applicable electronic-messaging laws.
Where legally required, Customer must have an appropriate basis for sending the communication and satisfy applicable:
- sender-identification; contact-information; unsubscribe; * consent requirements.
33. UNSUBSCRIBE AND SUPPRESSION RECORDS
NovakOS may maintain:
- email suppression lists; SMS suppression lists; STOP requests; complaints; hard-bounce information; * unsubscribe records.
These records may be retained after other information is deleted where reasonably necessary to ensure the individual is not accidentally contacted again.
34. SERVICE PROVIDERS AND SUBPROCESSORS
NovakOS uses service providers to operate the Services. Which providers receive information depends on the functions a Customer actually uses. Material current or contemplated provider categories include:
Supabase — authentication, database, application infrastructure, and file/object storage services used by the deployment. Stripe — NovakOS Subscription billing and supported Stripe Connect payment functionality. Twilio — SMS, messaging infrastructure, telephone numbers, and related communications functionality where enabled. Resend and/or current transactional-email infrastructure — NovakOS transactional or branded email delivery where used. Nylas — Customer-authorized connected business mailbox/OAuth connectivity and outbound mail functions where enabled. Google Workspace / Gmail — Customer-authorized connected mailbox sending and Google identity functionality where enabled. Microsoft 365 / Outlook — Customer-authorized connected mailbox functionality where enabled. Intuit QuickBooks Online — Customer-authorized accounting connectivity and synchronization where enabled. Google Maps Platform or supported mapping providers — maps, places, addresses, geocoding, routing, and related geographic functionality. Firebase Cloud Messaging / Google and Apple Push Notification Service — push-notification delivery where enabled. Apple and Google Play / Google — application distribution and platform functionality. Lovable-related platform, gateway, hosting, or connector services — deployment or integration infrastructure where present in the active NovakOS architecture. Cloudflare or other network/edge infrastructure — network delivery, security, DNS, or edge functionality where configured.
A provider listed here may not process every Customer’s information, and a provider or feature that is only configured or under development is not necessarily live in production.
35. SUBPROCESSOR CHANGES
NovakOS may add, replace, or remove service providers as reasonably necessary for security, reliability, legal compliance, product functionality, cost, or provider availability.
Where a change materially affects NovakOS’s processing of Customer personal information, NovakOS will update relevant public disclosures and provide any additional notice or contractual process required by applicable law or a separately signed agreement.
Customers with a specific regulatory or procurement need may contact NovakOS for reasonably available information about current material subprocessors before enabling a sensitive integration.
36. CROSS-BORDER AND OUT-OF-PROVINCE PROCESSING
Some service providers may process, route, or support personal information outside Customer’s province or outside Canada. Information stored or processed in another jurisdiction may be subject to that jurisdiction’s laws and lawful access by courts, law-enforcement bodies, regulators, or governmental authorities.
NovakOS uses contractual, technical, provider, and organizational safeguards appropriate to NovakOS’s role and the information involved. Disclosure of a provider’s location does not itself mean that a statutory privacy-impact assessment or transfer assessment has been completed for the Customer’s own purposes.
Where Québec or another applicable law requires a business to conduct a privacy impact assessment or enter a written agreement before communicating or entrusting personal information outside the jurisdiction, the Customer remains responsible for the assessment applicable to the Customer’s own use of NovakOS as the organization deciding those purposes. NovakOS will provide reasonably available information about material providers and safeguards upon reasonable request where appropriate, and remains separately responsible for assessments or contractual measures legally required of NovakOS for NovakOS’s own processing.
36A. GOOGLE API USER DATA
Where Customer authorizes Google API access, NovakOS uses Google user data only for the user-facing and security/connection purposes disclosed for the applicable integration. NovakOS’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
For the current Gmail-connected sending workflow, NovakOS is designed to request the minimum Google identity and Gmail send access needed for that workflow rather than broad inbox-reading access. NovakOS does not use Google API user data for targeted advertising, sale as a data-broker product, or general-purpose AI-model training.
Google may independently process authorization, account, security, and service information under Google’s terms and privacy practices.
37. NO SALE OF PERSONAL INFORMATION
NovakOS does not sell Customer Data or personal information submitted to NovakOS as a data-broker product.
NovakOS does not acquire ownership of Customer Data by processing it.
38. AI, AUTOMATION, AND GENERAL-PURPOSE MODEL TRAINING
NovakOS does not currently use identifiable Customer Data to train a general-purpose artificial-intelligence model.
NovakOS may use rules, calculations, search, automation, reconciliation, fraud/security systems, and aggregate or appropriately de-identified information to provide, secure, measure, troubleshoot, and improve the Services.
If NovakOS proposes a materially different use that would send identifiable Customer Data to an external generative-AI service or use it to train a general-purpose model, NovakOS will update relevant disclosures and obtain Customer authorization or individual consent where required before enabling that materially different processing.
39. DE-IDENTIFIED INFORMATION
NovakOS may create and use aggregate or de-identified information for:
- security; service reliability; analytics; capacity planning; product improvement.
NovakOS will not treat information as de-identified where re-identification remains reasonably likely merely because names have been removed.
40. SECURITY SAFEGUARDS
NovakOS uses administrative, technical, and organizational safeguards that are intended to be reasonable for the nature and sensitivity of the information and the foreseeable risks.
Depending on the system, safeguards may include authentication, authorization, tenant-scoped access controls, encrypted transport, provider-managed encryption or storage protections, protected credentials, webhook authentication, role-based access, audit logging, access logging, security monitoring, backups or recovery processes, payment tokenization, rate limiting, and incident-response procedures.
Security controls are layered and risk-based. No information system can guarantee absolute security, permanent availability, zero data loss, or that every vulnerability or unauthorized act will be prevented.
41. ACCOUNT SECURITY
Customers and Authorized Users share responsibility for security within their control.
Users should:
- use strong credentials; protect devices; avoid credential sharing; promptly report suspicious activity; sign out of devices they no longer control.
42. NOVAKOS SUPPORT AND ADMINISTRATIVE ACCESS
NovakOS personnel or authorized service providers may access Customer Data only where reasonably necessary for authorized support, security, incident response, troubleshooting, service administration, fraud prevention, legal compliance, or another legitimate operational purpose compatible with this Policy.
Administrative and sensitive access should be limited according to role and may be audit logged. Customers should not send passwords, full payment-card numbers, CVVs, or unrelated highly sensitive personal information to support.
43. SECURITY AND PRIVACY INCIDENTS
NovakOS maintains procedures for investigating suspected security and privacy incidents.
Where applicable law requires NovakOS to report or notify an affected individual, Customer, regulator, or authority, NovakOS will take the legally required steps. Where Customer has a separate obligation concerning Customer-controlled data, NovakOS will provide reasonable information available to NovakOS, subject to security, confidentiality, privilege, proportionality, and legal restrictions.
NovakOS may retain a record of a security breach or incident for at least any minimum period required by applicable law and for longer where reasonably necessary for investigation, security, insurance, legal claims, or regulatory compliance. Retention of an incident record does not mean all underlying Customer Data is kept for the same period.
44. RETENTION PRINCIPLES
NovakOS retains personal information only for as long as reasonably necessary for identified purposes, Customer instructions, service operation, legal requirements, security, fraud prevention, accounting, tax, contractual obligations, dispute resolution, or legitimate legal claims.
Different categories have different retention periods. A product screen may show an ordinary operational target or configured limit, but legal holds, provider-side records, backup rotation, fraud/security needs, and statutory obligations can lawfully require a different period.
Where personal information is no longer reasonably required and no legal or business purpose justifies retention, NovakOS seeks to delete or de-identify it in accordance with applicable law and operational processes.
45. LOCATION DATA RETENTION
Raw operational location history is ordinarily configured for a short period and currently supports a maximum ordinary window of approximately 28 days. A Customer may configure a shorter supported period.
Relevant location records may be preserved beyond ordinary expiry if a lawful hold, threatened claim, investigation, security incident, regulatory matter, or statutory record-preservation obligation applies. Live-location rows are intended to be cleared when continuous tracking is no longer authorized and are not intended as a permanent historical archive.
46. COMMUNICATION RECORD RETENTION
NovakOS may target approximately one year for ordinary application-level message, send, delivery, and operational communication records, but actual retention can vary by record type, provider-side retention, account configuration, synchronization state, complaint/suppression needs, security, legal requirements, or lawful hold.
Suppression, unsubscribe, complaint, bounce, and consent evidence may be retained longer where reasonably necessary to honour preferences, prevent accidental re-contact, establish compliance, investigate abuse, or defend a claim.
A connected mailbox provider may retain messages or provider logs independently under the provider’s own settings and terms even after NovakOS disconnects the integration.
47. AUDIT AND SECURITY RECORDS
NovakOS may target approximately two years for ordinary application-level access, administrative, security, and audit records where that period is appropriate, but some records may be retained for a shorter or longer period depending on sensitivity, operational need, provider-side retention, legal obligations, investigation, fraud prevention, contractual history, or claims.
Legal acceptance records and records necessary to prove a contractual, consent, suppression, or security history may be retained longer than an ordinary application audit log.
48. FINANCIAL, TAX, PAYMENT, AND ACCOUNTING RECORDS
Financial, invoice, payment, refund, dispute, subscription, tax, and accounting records may be retained for approximately seven years where NovakOS determines that period is reasonably appropriate to cover common Canadian business recordkeeping, audit, payment, and claim needs. The exact legal minimum or maximum is not the same for every record or jurisdiction.
For example, Canadian tax law commonly requires many books and records to be retained for at least six years, with longer periods in specified circumstances. NovakOS may therefore retain a relevant record longer where a return was filed late, an objection or appeal is outstanding, a government demand applies, a chargeback or claim remains open, or another legal requirement exists.
A seven-year product retention practice is not a representation that every financial record is legally required to be kept for exactly seven years.
49. SECURITY-INCIDENT AND BREACH RECORDS
Security-incident and breach records may be retained for at least the legally required minimum and longer where reasonably necessary for security, insurance, investigation, litigation, regulator review, or compliance.
Where PIPEDA’s federal breach-record rule applies, the applicable breach record must be maintained for at least 24 months after NovakOS determines the breach occurred. Other laws or legitimate needs may justify a longer period.
50. CUSTOMER BUSINESS RECORDS
Active records such as:
- customers; jobs; equipment; quotes; forms; invoices; photographs; videos; files
may remain while Customer retains them in an active account unless another specific retention rule applies.
51. COMPANY DELETION
When an authorized company owner initiates deletion, access may be revoked or restricted and the company may remain recoverable for an ordinary recovery period currently designed to be approximately 30 days. After that period, active Customer Data is scheduled for deletion or de-identification subject to legal retention, security, fraud, provider-side retention, suppression, audit, payment, tax, contractual-history, backup, and lawful-hold requirements.
Customer should export required information before requesting deletion and should not use company deletion as a method to destroy information subject to a legal, tax, employment, payment, or litigation-preservation obligation.
52. BACKUP RETENTION
Deletion from active systems may not immediately erase every copy from encrypted backups.
Backup copies may remain until backup expiration or rotation.
Backup copies are not intended for ordinary processing after deletion.
53. LEGAL HOLDS
NovakOS may suspend ordinary deletion where information must reasonably be preserved because of:
- litigation; threatened litigation; tax audit; payment dispute; chargeback; fraud investigation; security incident; regulatory inquiry; lawful preservation obligation.
54. RECORDS THAT MAY REMAIN AFTER DELETION
Certain payment, invoice, refund, dispute, tax, accounting, security, suppression, legal-acceptance, incident, or other records may remain after active Customer Data is otherwise deleted where retention is required or permitted for a legitimate legal or business purpose.
Where reasonably possible and appropriate, personal information may be minimized, segregated, or masked while preserving the transaction or evidentiary record that still must be retained.
55. CONSENT RECORDS
NovakOS may retain records demonstrating:
- recurring-payment authorization; saved-payment authorization; marketing consent; SMS consent; unsubscribe; STOP; privacy or location acknowledgements.
Such records may remain where reasonably necessary to establish compliance.
56. LEGAL ACCEPTANCE RECORDS
NovakOS may retain information showing acceptance of applicable legal documents.
This may include:
- user ID; company ID; document name; document version; exact acceptance language; timestamp; IP address; user agent; device/platform; * correlation identifier.
These records may be retained as evidence of contractual history and compliance.
57. ACCESS REQUESTS
Subject to applicable law, exceptions, and reasonable identity verification, individuals may request access to personal information for which NovakOS is legally responsible.
Where a NovakOS Customer controls the underlying Customer Data, NovakOS may refer the request to that Customer and reasonably assist the Customer. An in-product JSON or customer export is a convenience tool and is not necessarily a complete legal access response; responsive information may also require a search of attachments, communications, audit records, provider records, derived records, or other systems, together with appropriate third-party redaction and legal review.
58. CORRECTION
Individuals may request correction of inaccurate personal information where applicable.
Where Customer controls the underlying information, Customer may be responsible for determining whether a correction is appropriate.
59. DELETION REQUESTS
Individuals may request deletion where applicable law provides that right or where deletion is otherwise available.
Deletion is not absolute and may be refused, delayed, or limited where retention is required or permitted for legal obligations, financial/tax records, payment disputes, fraud prevention, security, suppression records, incident records, employment-decision preservation, legal claims, regulator requirements, contractual history, backup rotation, or another lawful purpose.
Where Customer controls the information, Customer is responsible for determining whether the request should be granted and NovakOS may assist within its role.
60. WITHDRAWAL OF CONSENT
Where processing depends on consent, an individual may withdraw consent subject to:
- legal restrictions; reasonable notice; contractual requirements; * information that must lawfully be retained.
Withdrawal does not invalidate processing that was lawful before the withdrawal.
Certain NovakOS functionality may become unavailable if a required permission or consent is withdrawn.
61. LOCATION PERMISSION WITHDRAWAL
A user may change device-location permission through operating-system settings.
Where background location permission is withdrawn, applicable background-tracking functionality may stop operating.
Customer remains responsible for any employment-related consequence or alternative process.
61A. PRESERVATION WHEN INFORMATION AFFECTS AN INDIVIDUAL
A Customer may have an independent legal obligation to preserve personal information it actually uses to make a decision that directly affects an individual, even where NovakOS’s ordinary product retention period is shorter.
Customers should not rely on automatic expiry of location, audit, communication, or performance data after using that information for a disciplinary, termination, compensation, promotion, denial-of-service, dispute, or other material decision. The Customer should preserve the relied-upon record for the legally required period and contact NovakOS promptly if preservation of NovakOS-controlled data is needed.
62. COMMUNICATION OPT-OUT
Marketing recipients may use applicable unsubscribe or STOP mechanisms.
NovakOS may continue to send communications that are legally permitted or necessary for:
- account security; requested transactions; service administration; * contractual obligations;
where an unsubscribe does not legally apply to those communications.
63. DATA EXPORT
Authorized Customer personnel may use NovakOS export functionality to retrieve Customer Data in supported formats.
Once downloaded, exported data is controlled and secured by Customer.
64. IDENTITY VERIFICATION
NovakOS may verify identity and authority before responding to a sensitive privacy request.
Verification will be proportionate to the sensitivity and risk of the information involved.
65. AUTHORIZED REPRESENTATIVES
Where permitted, an individual may make a privacy request through an authorized representative.
NovakOS may require reasonable proof of that authorization.
66. PRIVACY COMPLAINTS
Privacy questions or complaints may be submitted to:
Michael Novak, Privacy Officer — NovakOS [support@novakos.org](mailto:support@novakos.org) 2524 Hastings Road, Chemainus, BC, V0R 1K5
NovakOS will investigate complaints appropriate to NovakOS’s role and respond in accordance with applicable legal obligations.
67. REGULATORY RIGHTS
Depending on the circumstances and applicable law, an individual may have the right to complain to the appropriate Canadian or provincial privacy regulator.
Nothing in this Policy is intended to prevent an individual from exercising a legally protected regulatory right.
68. CHILDREN AND MINORS
NovakOS is commercial business software and is not directed or marketed to children as account holders. Company accounts must be created and commercial terms accepted by a person with legal capacity and the required business authority.
Customers may provide field services to households or may lawfully employ or contract with younger persons. If Customer processes information concerning a minor, Customer is responsible for any additional consent, capacity, employment, safeguarding, marketing, or privacy requirements that apply.
Customer should avoid entering unnecessary sensitive information about children into free-text fields, photographs, or attachments.
69. QUÉBEC
Where NovakOS or a Customer is subject to Québec private-sector privacy law, each remains responsible for obligations applicable to its role. These may include privacy governance, confidentiality-incident response, privacy impact assessments for qualifying systems or cross-border processing, written transfer/outsourcing agreements, transparency, individual rights, and safeguards.
Before a Québec enterprise communicates personal information outside Québec or entrusts a person outside Québec to collect, use, communicate, or keep it on the enterprise’s behalf, Québec law may require a privacy impact assessment and a written agreement reflecting that assessment. A Customer should not treat this Privacy Policy alone as completion of that assessment.
Customers should contact NovakOS before enabling an integration if they require specific provider-location, contractual, or security information for a mandatory assessment.
70. AUTOMATED CALCULATIONS, METRICS, AND DECISION SUPPORT
NovakOS may use automated software rules for billing, permission enforcement, tax and payroll-related calculations, dispatch, inventory reservations, demand or opportunity indicators, NOS Points/reward calculations, fraud prevention, payment reconciliation, synchronization, security, and notifications.
These automated functions assist people and organizations but are not intended to independently make a final legal, employment, disciplinary, credit, insurance, safety, medical, or professional decision for Customer.
Customer is responsible for human review of material decisions, accuracy of inputs, and correction of errors. Where applicable law imposes special transparency or human-review obligations for a decision based exclusively on automated processing of personal information, Customer must determine whether its own use triggers those obligations and configure its process accordingly.
71. EMPLOYMENT, REWARD, AND PERFORMANCE DECISIONS
NovakOS does not independently hire, fire, discipline, promote, classify, schedule, compensate, or determine an award for Customer’s workers.
Customer may choose to view time, location, sales, booking, job, NOS Points, leaderboard, reward, inventory, or other performance-related information. Customer remains responsible for the fairness, accuracy, lawfulness, notice, preservation, and human review of any employment or compensation decision it makes using that information.
NovakOS discourages using sales or reward tools to promote unnecessary, deceptive, unsafe, exploitative, or professionally improper sales.
72. BUSINESS TRANSACTIONS
If NovakOS undergoes:
- merger; financing; acquisition; restructuring; sale of assets;
information may be disclosed to appropriate transaction participants subject to confidentiality, security, and applicable privacy requirements.
73. LEGAL DISCLOSURES
NovakOS may disclose information where required or permitted by applicable law, including in response to:
- court orders; warrants; lawful governmental demands; regulatory requirements; legal proceedings.
Where legally permitted and appropriate, NovakOS may notify affected Customers or seek to narrow an overbroad request.
74. FRAUD AND SECURITY
NovakOS may use or disclose information where reasonably necessary and legally permitted to:
- identify fraud; investigate unauthorized access; secure accounts; defend legal rights; protect persons; * prevent abuse.
75. CHANGES TO THIS PRIVACY POLICY
NovakOS may update this Privacy Policy as the Services, providers, laws, security practices, or privacy practices evolve.
The current Policy will display its version and effective date. Material changes will be communicated through reasonable means appropriate to the change.
Where applicable law requires new consent, a specific notice, or another legal formality for a materially different collection, use, disclosure, monitoring activity, or transfer, NovakOS will not rely solely on a new Privacy Policy version or continued use to eliminate that requirement.
76. PRIVACY POLICY ACKNOWLEDGEMENT
Where NovakOS asks a user to acknowledge this Policy, acknowledgement means the user confirms that the Policy has been presented for review. It is not intended to create blanket consent for every possible collection, use, disclosure, transfer, location activity, marketing message, payment, or employment use.
Separate consent, authorization, notice, or other legal authority may be required for particular activities, including location, connected mailboxes, marketing, recurring payments, saved payment methods, device permissions, employee monitoring, or a materially new purpose.
NovakOS may retain the Policy version, acknowledgement statement, user/company identifiers, timestamp, IP address, user agent, platform/app version, and correlation identifiers as evidence that the disclosure was presented.
77. CUSTOMER PRIVACY RESPONSIBILITIES
A Customer using NovakOS remains responsible for its own privacy practices and for the lawfulness of the Customer-controlled purposes for which it collects, uses, discloses, monitors, exports, synchronizes, or retains Customer Data.
Customer should maintain a privacy policy and employee/workplace notices appropriate to its business where required, limit access according to need, avoid unnecessary sensitive information, honour valid rights and opt-outs, preserve records when law requires, and explain to End Customers and workers how Customer uses information through NovakOS.
NovakOS settings and templates are tools and do not replace Customer’s own privacy impact assessment, legal advice, consent analysis, employment notice, or regulatory obligations.
78. CONTACT US
Privacy questions, complaints, access/correction requests for information for which NovakOS is responsible, or requests for provider/security information relevant to a Customer privacy assessment may be directed to:
Michael Novak, Privacy Officer — NovakOS Legal Entity: Michael Novak O/A NovakOS, carrying on business as NovakOS Email: [support@novakos.org](mailto:support@novakos.org) Mail: 2524 Hastings Road, Chemainus, BC, V0R 1K5
General support and security reports may also be sent to [support@novakos.org](mailto:support@novakos.org).
END OF PRIVACY POLICY