Privacy policy
Last updated: 8 October 2026 · Version 1.2
This policy explains what personal data Novagenta LLC collects through this website and in the course of providing services, why, on what legal basis, and what rights you have. We keep it short because we collect very little.
1. Controller
The controller responsible for processing described here is:
Novagenta LLC, a Wyoming limited liability company
Registered office: 30 N Gould St, Ste R, Sheridan, WY 82801, USA
Correspondence address: European Union (full postal address available on request)
Email: hello@novagenta.com
Novagenta LLC has no establishment in the United States beyond its statutory registered agent; its management is located in the European Union. Because the company offers services to persons in the EU and is managed from the EU, the General Data Protection Regulation (GDPR) applies to the processing described here. We have not appointed a data protection officer, as we are not required to; privacy requests are handled directly by the company at hello@novagenta.com.
2. What we collect and why
| Activity | Data | Purpose | Legal basis (GDPR Art. 6(1)) |
|---|---|---|---|
| Contact form and email | Name, company, email address, country, chosen topic, message content, time of submission | Answering your enquiry and preparing a quote | (a) your consent given via the form checkbox, for storing the enquiry; (b) steps prior to a contract at your request; (f) legitimate interest in responding to business enquiries |
| Booking a call (Cal.com) | Name, email, chosen time, optional notes | Scheduling and holding the call | (b) steps prior to a contract |
| Client engagements | Contact details of client staff, contract and invoicing data, project files you provide | Performing the contract, invoicing, accounting | (b) contract; (c) legal obligations (accounting, tax) |
| Website hosting | IP address, user agent, requested URL, timestamp (server logs held by the hosting provider, Cloudflare) | Serving the site securely, preventing abuse | (f) legitimate interest in operating a secure website |
We do not run advertising, profiling or automated decision-making about you. We do not sell personal data.
3. Cookies and tracking
This website sets no cookies and uses no analytics or tracking scripts. The only client-side storage is a single localStorage entry (nv-theme) that remembers whether you chose the light or dark theme. It contains no identifier, is never transmitted to us, and is only written if you press the theme button. You can remove it at any time by clearing your browser's site data. No consent banner is shown because none is required for this.
Fonts are hosted on this website itself. Your browser does not contact any third-party font service when you visit.
4. Processors and recipients
We use a small number of service providers who process data on our behalf under GDPR Article 28 contracts:
- Formspree, Inc. (USA) — receives and forwards contact form submissions to our mailbox. Formspree acts as our processor; transfers to the US are covered by the EU–US Data Privacy Framework and/or standard contractual clauses in Formspree's data processing addendum.
- Cal.com, Inc. (USA) — call scheduling, only if you follow the booking link and book a call. Cal.com's own privacy notice applies on its site; data it processes for us is covered by its data processing agreement with standard contractual clauses.
- Cloudflare, Inc. (USA, with EU data centres) — website hosting and content delivery (Cloudflare Pages), including the short-lived server logs described in section 2. Cloudflare is certified under the EU–US Data Privacy Framework and provides standard contractual clauses in its data processing addendum.
- Email and document hosting — our business mailbox and file storage are hosted in EU data centres. [EMAIL / STORAGE PROVIDER, REGION]
- AI model providers — used only inside client engagements, under business terms with no training on submitted content and, where available, zero data retention. EU-region endpoints are used where a client requires it. Named providers are listed in the engagement's data processing agreement.
- Accountant and banks — invoicing and payment data as required by law and for performing the contract.
We disclose personal data to authorities only where legally required.
5. International transfers
Your data is stored in the EU by default. Where a processor is located outside the European Economic Area (see section 4), we rely on an adequacy decision of the European Commission where one exists (including the EU–US Data Privacy Framework for certified US companies) and otherwise on the European Commission's standard contractual clauses (SCCs), supplemented where needed by additional safeguards such as encryption in transit and at rest. You can request a copy of the relevant safeguards at the address above.
6. Retention
- Enquiries that do not lead to an engagement: deleted 12 months after the last message.
- Form submissions held at Formspree: deleted from the Formspree dashboard within 30 days of forwarding.
- Contract, invoice and accounting records: kept for the statutory period, currently up to 7 years under applicable US federal and EU member-state accounting rules, then deleted.
- Project files supplied for translation or automation work: deleted or returned 90 days after project close unless a longer period is agreed in writing (for example to maintain a translation memory for you).
- Server logs: held by the hosting provider for a short rolling period, typically under 30 days.
7. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you and receive a copy (Art. 15);
- have inaccurate data corrected (Art. 16);
- have your data erased where there is no longer a legal reason to keep it (Art. 17);
- restrict processing in certain circumstances (Art. 18);
- receive data you provided in a portable format (Art. 20);
- object to processing based on legitimate interests (Art. 21);
- withdraw consent at any time where processing is based on consent, without affecting processing before withdrawal.
To exercise any of these rights, email hello@novagenta.com. We answer within one month. You also have the right to lodge a complaint with a supervisory authority, in particular in the EU member state of your residence or place of work.
8. Security
The website is served over HTTPS only. Business systems use multi-factor authentication, encrypted storage and least-privilege access. Only authorised staff and, where needed for a specific project, individually bound subcontractors (translators or developers under confidentiality obligations) have access to client data.
9. Children
Our services are for businesses and are not directed at children. We do not knowingly collect data from anyone under 16.
10. Changes
We will update this policy when our processing changes. The version and date at the top tell you which version applies. Material changes affecting existing clients are communicated by email.