Legal
Data processing addendum
This addendum (the “DPA”) sets out how Novix processes personal data on your behalf when you use the Service to diagnose and resolve support tickets. It forms part of our Terms of Service and applies whenever the data you route to Novix includes personal data protected by a data-protection law such as the GDPR or UK GDPR. Terms not defined here have the meaning given in the Terms or in the GDPR.
Roles: who controls what
For the ticket content and code context you connect, you are the controller and Novix is the processor. We process that personal data only to provide the Service and only on your documented instructions. Configuring your workspace and using the Service are your instructions; if a law requires us to process data on some other basis, we will tell you first unless the law forbids it.
The third parties that help us run the Service are subprocessors, listed at Subprocessors and services. They act on our instructions, and we stay responsible to you for what they do with your data.
For your own account data (your name, email, and workspace settings), Novix is the controller. How we handle that is covered by our Privacy Policy.
What we process, and why
Subject matter and purpose: processing the personal data in your support tickets and connected code context to classify, diagnose, draft fixes and replies, and keep an audit trail, for as long as you use the Service.
Categories of data subject: your end customers who contact support, and the members of your team who use Novix.
Categories of personal data: the contents of a ticket (messages, email addresses, and whatever the sender included), account identifiers for your team members, and the code and context pulled to diagnose a ticket. Please do not send special categories of data (health, biometric, and the like) through the Service.
Duration: the term of your use of the Service, plus the retention windows described in our Privacy Policy.
Subprocessors
You authorize us to use the subprocessors listed at Subprocessors and services. Each is bound by a written contract with data-protection terms no less protective than this DPA, and receives only the data it needs to do its job.
Our AI subprocessor is Anthropic, which processes ticket content and code context to return a diagnosis or draft. Under Anthropic’s commercial API terms, data you submit is not used to train its models, and Anthropic acts as our subprocessor under its own data processing terms, including Standard Contractual Clauses for international transfers.
We update the subprocessor list and its effective date before a new subprocessor starts handling your data, so you have time to object. If you have a reasonable data-protection objection to a new subprocessor, email privacy@getnovix.ai and we will work with you in good faith, up to and including letting you stop using the affected part of the Service.
International transfers
Novix and our subprocessors process data in the United States and other countries. Where we transfer personal data out of the EEA, the UK, or Switzerland to a country without an adequacy decision, we rely on the European Commission’s Standard Contractual Clauses (SCCs), with the UK addendum and the Swiss amendments as applicable, together with any additional safeguards the transfer requires.
Security
We keep technical and organizational measures appropriate to the risk. Today that includes: encryption in transit (TLS) for every connection; encryption at rest for the integration credentials you store; access scoped so a workspace only ever reaches its own data; an audit log of sensitive actions; and least-privilege access to production. Security is a moving target, and we will keep these measures current as the product grows.
Helping you answer data-subject requests
Because the content in Novix belongs to your end customers, a request from one of them (to access, correct, delete, port, restrict, or object to the processing of their data) should generally come through you as the controller. We will help you respond: taking account of the nature of the processing, we will give you the tools or the assistance you reasonably need to honor the request within the law’s deadline.
We will also promptly pass along any request we receive directly from a data subject, rather than answering it ourselves.
If there is a breach
If we become aware of a personal-data breach affecting data we process for you, we will notify you without undue delay, with the detail you need to meet your own notification obligations, and we will help you investigate and respond.
Deletion and return
You can delete a ticket or disconnect an integration at any time from the dashboard, which removes that data (and, for an integration, its stored credentials) right away. When you close your account or ask us to, we delete or return the personal data we process for you, subject only to what we must keep for legal reasons, on the timeline in our Privacy Policy. Our subprocessors delete their copies on their own documented schedules.
Demonstrating compliance
On reasonable request, we will make available the information you need to show that we are meeting this DPA, including a summary of our measures and our current subprocessor list. For anything beyond that (a questionnaire, a specific audit right, or your own paperwork), email us and we will work it out with you.
Getting a signed copy
This page states our standard data processing terms, and they apply to your use of the Service whether or not it is separately signed. If your organization needs a countersigned DPA for its records, or needs the SCCs executed as a standalone document, email privacy@getnovix.ai and we will send one over.
Contact
Questions about data processing?
Email privacy@getnovix.ai. See also our Subprocessors, Privacy Policy, and Terms of Service.