Get a Quote
Home Solutions Technology About Us Contact Get a Quote

Privacy Policy

Last Updated: January 2026

At NovaFlow, we are committed to protecting your personal data and respecting your privacy. This policy outlines how we collect, use, and safeguard your information when you use our smart mobility solutions and website.

1. Introduction and Data Controller

NovaFlow acts as the Data Controller for your personal information. We are dedicated to ensuring that your privacy is protected in accordance with the General Data Protection Regulation (GDPR) and other applicable data protection laws.

We use your personal data solely to provide and improve our urban mobility services. By using our website or services, you acknowledge that you have read and understood this Privacy Policy.

Contact Details for Data Privacy Matters:
Email: [email protected]
Address: 42 Quay Street, Galway, H91 R2X3, Ireland

2. Data We Collect

We collect various types of information to provide, maintain, and improve our services. This includes:

Personal Identification Information

  • Name, job title, and company name.
  • Contact details including email address and phone number.
  • Billing and payment information (processed securely via third-party payment processors).

Technical Data

  • IP address and browser type.
  • Device information and operating system.
  • Pages visited and time spent on our website.

Mobility and Analytics Data

  • Fleet tracking data and vehicle telemetry.
  • Route optimization logs and traffic analysis data.
  • Usage patterns regarding our software interfaces.

3. How We Use Your Data

We only use your personal data when the law allows us to. Most commonly, we will use your personal data in the following circumstances:

  • To Deliver Services: Managing your account, providing customer support, and deploying smart mobility solutions.
  • To Communicate: Sending you technical updates, security alerts, and support messages.
  • For Marketing: With your consent, sending you newsletters and promotional materials about our services.
  • For Legal Compliance: To comply with legal obligations, such as record-keeping and reporting.

4. Legal Basis for Processing

Under GDPR, we must have a lawful basis for processing personal data. Our lawful bases are:

  • Contract: Processing necessary to perform our contract with you (e.g., providing software licenses).
  • Legitimate Interest: Processing necessary for our legitimate business interests, such as fraud prevention and network security.
  • Consent: When you explicitly consent to us processing your data for specific purposes, such as marketing emails.
  • Legal Obligation: Processing to comply with our legal and regulatory obligations.

5. Data Sharing and Third Parties

We do not sell your personal data. We may share your data with trusted third parties only in the following circumstances:

  • Service Providers: Third parties who perform services on our behalf, such as cloud hosting providers, data analytics firms, and payment processors.
  • Business Transfers: If we are involved in a merger, acquisition, or sale of assets, your data may be transferred.
  • Legal Requirements: If we are required to disclose your data to comply with a legal obligation or protect our rights.

All third parties are strictly bound by confidentiality obligations and data protection agreements.

6. Data Security and Retention

We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These include encryption, access controls, and regular security audits.

We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including for the satisfaction of any legal, accounting, or reporting requirements.

Retention Periods

  • Account Data: Retained for the duration of your contract and 7 years after termination for legal and accounting purposes.
  • Marketing Data: Retained until you withdraw your consent.
  • System Logs: Retained for 12 months for security analysis.

7. Your Rights and GDPR

Under the GDPR, you have specific rights regarding your personal data. You have the right to:

  • Access: Request a copy of the personal data we hold about you.
  • Rectification: Request correction of any inaccurate or incomplete data.
  • Erasure: Request the deletion of your personal data (the "right to be forgotten").
  • Restriction: Request that we restrict the processing of your personal data.
  • Portability: Request the transfer of your data to another organization.
  • Objection: Object to the processing of your personal data.

To exercise these rights, please contact our Data Protection Officer via email at [email protected]. We will respond to your request within one month.

8. International Data Transfers

Your data is primarily processed within the European Economic Area (EEA). If we transfer your data outside the EEA, we ensure that adequate safeguards are in place to protect your data, such as the use of Standard Contractual Clauses (SCCs) approved by the European Commission.

9. Updates to This Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date. You are advised to review this Privacy Policy periodically for any changes.

10. Contact Information

If you have any questions about this Privacy Policy or our data practices, please contact us:

Company: NovaFlow
Address: 42 Quay Street, Galway, H91 R2X3, Ireland
Email: [email protected]
Phone: +353 21 991 6987