Privacy Policy
Last updated: [DATE — e.g. 30 July 2026]
NovaTech Solutions ("we", "us", "our") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains what data we collect when you visit this website, why we collect it, and what rights you have. It is written to comply with the EU General Data Protection Regulation (GDPR), the UK GDPR, and the California Consumer Privacy Act (CCPA/CPRA), as applicable.
1. Data Controller
The data controller responsible for this website is:
NovaTech Solutions [replace with full legal entity name]
123 Innovation Drive, Suite 400, Example City, Country
Email: contact@example.com
[If you are required to appoint an EU representative under GDPR Art. 27 or a Data Protection Officer under Art. 37, add their contact details here.]
2. What Data We Collect and Why
2.1 Server log data (when you visit the site)
When you access this website, our hosting provider automatically processes technical data necessary to deliver the website, including your IP address, date and time of the request, browser type and version, operating system, and the pages accessed.
- Purpose: delivering the website securely, detecting abuse, and troubleshooting.
- Legal basis: legitimate interest (GDPR Art. 6(1)(f)) in operating a secure website.
- Retention: log data is retained by the hosting provider for a limited period (typically up to 30 days) and then deleted, unless required for security investigation.
2.2 Contact form data (when you send us a message)
If you use the contact form, we collect your name, email address, company name (optional), and the content of your message.
- Purpose: responding to your inquiry and any follow-up communication.
- Legal basis: your consent (GDPR Art. 6(1)(a)), given via the checkbox before submission; and, where your inquiry relates to a contract, GDPR Art. 6(1)(b).
- Processor: form submissions are transmitted and processed via Formspree, Inc. (USA), acting as our data processor, and then forwarded to our email inbox. Formspree's privacy policy: formspree.io/legal/privacy-policy. Transfers to the USA are safeguarded by Standard Contractual Clauses and/or the EU–US Data Privacy Framework, as applicable.
- Retention: we keep inquiry data only as long as needed to handle your request, and no longer than 24 months after the last communication, unless a legal obligation requires longer storage.
2.3 Email correspondence
If you email us directly at contact@example.com, we process the data you provide in the email for the purpose of handling your request (GDPR Art. 6(1)(b) or (f)).
2.4 Cookies and local storage
This website does not use advertising or tracking cookies. We use a single first-party local storage entry to remember your cookie consent choice. Optional third-party content (such as embedded external videos) is loaded only after you explicitly agree. For details, see our Cookie Policy.
2.5 Embedded videos
The product video on our homepage is hosted on our own servers; playing it does not transmit data to third parties. If we embed externally hosted videos (e.g. YouTube), they are blocked by default and loaded only after you click "Load video" and thereby consent to data transfer to the third-party provider (GDPR Art. 6(1)(a)).
3. Who We Share Data With
We do not sell your personal data. We share data only with:
- our website hosting provider [name the provider, e.g. Vercel Inc. / Netlify Inc. / Cloudflare Inc.], as processor for server log data;
- Formspree, Inc., as processor for contact form submissions;
- public authorities, where required by law.
4. International Data Transfers
Our website is hosted on infrastructure that may be located outside your country, including the United States. Where personal data is transferred outside the EU/EEA or UK, we rely on adequacy decisions, the EU–US Data Privacy Framework, or Standard Contractual Clauses (GDPR Art. 46) to safeguard the transfer.
5. How Long We Keep Data
We keep personal data only as long as necessary for the purposes described above or as required by applicable law, after which it is deleted or anonymized.
6. Your Rights
Subject to applicable law (including GDPR Arts. 15–21), you have the right to:
- access the personal data we hold about you;
- request rectification of inaccurate data;
- request erasure ("right to be forgotten");
- request restriction of processing;
- data portability;
- object to processing based on legitimate interest;
- withdraw consent at any time, without affecting prior processing;
- lodge a complaint with a supervisory authority (in the EU, your local Data Protection Authority).
To exercise any of these rights, contact us at contact@example.com. We will respond within one month (GDPR) or the timeframe required by your local law.
7. California Residents (CCPA/CPRA)
We do not sell or share personal information as defined by the CCPA/CPRA, and we do not use it for cross-context behavioral advertising. California residents have the right to know, delete, and correct personal information, and the right to non-discrimination for exercising these rights. Requests can be made via the contact details above.
8. Children's Privacy
This website is intended for business audiences and is not directed at children under 16. We do not knowingly collect personal data from children.
9. Data Security
We use appropriate technical and organizational measures to protect your data, including HTTPS/TLS encryption for all traffic to this website.
10. Changes to This Policy
We may update this Privacy Policy from time to time. The current version is always available on this page with the "Last updated" date shown above.