Privacy Policy
Data-light.Client-boundary first.
NovaOps helps owner-led businesses fix painful workflows with AI. This policy explains what information we collect, how we use it, and how we try to limit unnecessary data custody.
Last updated: July 6, 2026
1. Who we are
NovaOps helps owner-led businesses find painful workflows, fix the right workflow first with AI, and build the systems, training, and structure that make improvements repeatable.
Contact: kevin@getnovaops.com
2. Information we may collect
Depending on how you interact with NovaOps, we may collect:
- Contact information, such as your name, email address, phone number, company, and role.
- Information you provide through the AI Fit Interview, contact forms, emails, calls, or working sessions.
- Business and workflow information, such as current tools, process steps, workflow pain points, examples, notes, documents, transcripts, and implementation context.
- Client-provided materials needed to evaluate, design, build, support, or improve an agreed workflow.
- Basic website or technical information, such as browser/device information, IP address, pages visited, referral source, and similar usage data if collected by our website, hosting, analytics, form, interview, or security tools.
- Billing and payment-related information handled by third-party payment providers when applicable.
3. How we use information
We use information to:
- Respond to inquiries and evaluate whether NovaOps is a good fit.
- Run the AI Fit Interview and related intake or discovery processes.
- Understand workflow pain, recommend next steps, and prepare proposals or scopes of work.
- Design, build, test, support, and improve approved workflows and AI operations systems.
- Prepare project notes, value baselines, usage/value reports, training materials, and handoff materials.
- Operate, protect, troubleshoot, and improve NovaOps services and business systems.
- Invoice, collect payment, maintain business records, and comply with applicable obligations.
4. Our data-light operating principle
NovaOps is designed to be data-light by default. When client information is needed, we prefer client-owned systems, client-owned data stores, client-owned AI/API accounts, approved client-controlled workspaces, or other approved third-party tools wherever practical.
The default model is simple: the client owns the data; NovaOps owns or licenses the workflow engine, workflow pattern, prompts, configuration, reusable methods, and support layer unless a separate written agreement says otherwise.
NovaOps does not sell personal information. NovaOps does not design workflows around reusing raw client data for unrelated clients.
5. Sensitive data and credentials
Do not send passwords, API keys, private keys, recovery codes, secret values, session tokens, payment credentials, production environment values, or direct access credentials through normal email, forms, Google Docs, Google Sheets, AI chats, or project notes.
If sensitive access is required, we will use or recommend a safer access path, such as native tool invitations, least-privilege temporary access, approved password manager or secure vault sharing, client-side setup, time-limited access, and access removal or rotation after the work is complete.
6. AI tools and human review
NovaOps may use approved AI tools to help analyze information, draft materials, summarize workflows, generate implementation plans, build workflow logic, or support agreed services.
AI-generated outputs that affect external communication, customer/client communication, financial matters, legal/compliance matters, business decisions, or judgment-heavy work should be reviewed by a human before use.
NovaOps may use generalized lessons, non-confidential patterns, and reusable methods from its work to improve future services, but we do not intentionally disclose or reuse confidential client information, raw client data, or client-identifying information for unrelated clients.
7. Third-party tools and service providers
NovaOps may use third-party tools for hosting, forms, interviews, AI/model access, email, analytics, payments, document creation, automation, project management, data storage, security, or related business operations.
We share information with these providers only as reasonably needed to operate the website, run intake/interview workflows, communicate with you, provide services, process payments, secure systems, or support the agreed work.
Client-specific software subscriptions, paid tools, AI/API usage, hosting, storage, secure vaults, or third-party platform costs may be separate from NovaOps implementation fees unless expressly included in a written agreement.
8. Data retention
We keep information only as long as reasonably needed for the purposes described in this policy, the applicable client agreement, business records, legal/accounting obligations, security needs, and ongoing support.
Where practical, we will remove, return, export, or delete client information that is no longer needed, especially when it creates unnecessary risk.
9. Security
NovaOps uses reasonable administrative, technical, and operational safeguards appropriate for a small business and for the sensitivity of the information involved. No website, tool, AI system, or transmission method can be guaranteed perfectly secure.
NovaOps is not acting as your managed service provider, cybersecurity provider, legal advisor, compliance advisor, accountant, system-of-record owner, or data custodian unless a separate written agreement says so.
10. Sensitive or regulated workflows
Workflows involving financial, medical, HR, legal, security, credential, customer, employee, regulated, or otherwise sensitive information may require a separate data-boundary review before implementation. NovaOps may decline, defer, narrow, or separately scope higher-risk workflows.
11. Your choices
You can contact NovaOps to request access, correction, deletion, or export of information you have provided, subject to reasonable business, security, legal, accounting, and contractual limits.
You can also choose not to provide certain information, though that may limit our ability to evaluate fit, prepare a proposal, or deliver services.
12. Children
NovaOps is intended for business use and is not directed to children.
13. Changes to this policy
We may update this policy as NovaOps, its tools, or its services change. The updated version will be posted on this page with a new effective date.
14. Contact
Questions about this policy can be sent to kevin@getnovaops.com.