Legal
GDPR Compliance
Last updated 31 July 2026
This page summarises how Novrex approaches its obligations under the GDPR and equivalent regimes.
1. Roles
For customer account data Novrex acts as a controller. For data our customers process using the platform, Novrex acts as a processor on the customer's documented instructions.
2. Lawful basis
We rely on contract performance, legitimate interests, and consent as applicable to the processing in question.
3. Data subject rights
We support access, rectification, erasure, portability, restriction, and objection requests, and assist customers in responding to requests they receive.
4. International transfers
Where personal data leaves the EEA we rely on an appropriate transfer mechanism, such as Standard Contractual Clauses.
5. Sub-processors
A current list of sub-processors is available on request. Customers are notified of material changes.
Contact
Questions about this document? Email novrex2026@gmail.com or use our contact page.