Legal

Privacy policy

Last updated: 4 October 2026

This policy explains what personal data NovaHire ("we", "us") collects, why, and what your rights are. We keep it short and collect as little as we can.

1. Who is responsible

NovaHire Studio is an AI & web automation studio based in the Netherlands and is the data controller for the data described here. For any privacy question or request, email [email protected].

2. What we collect and why

DataPurposeLegal basis (GDPR art. 6)
Name, email, business name, website and your message (contact form or email)To reply to you, make your free sample and send a quoteSteps at your request before a contract (6(1)(b))
Project materials you share (texts, photos, footage, reviews, account access you grant)To deliver the service you orderedPerformance of a contract (6(1)(b))
Invoice and payment details (name, business, address if you provide it, amounts)Invoicing and bookkeepingLegal obligation (6(1)(c))
Publicly listed business contact details (e.g. an info@ address on a company website)A short, relevant business-to-business message about our services, with an easy opt-outLegitimate interest (6(1)(f))
Basic technical logs kept by our hosting provider (IP address, browser, time of request)Security and keeping the site runningLegitimate interest (6(1)(f))

We don't sell your data, we don't use it for automated decision-making, and we don't add you to newsletters without asking.

3. Business-to-business messages

We may occasionally email businesses at a contact address they have published, with a specific, relevant offer. Each message says who we are and how to opt out. If you reply "no" or ask us to stop, we add your address to a do-not-contact list straight away and won't email you again. We keep only the minimum needed to respect that request.

4. Cookies and analytics

This website doesn't use tracking or advertising cookies, so there's no cookie banner. If we add privacy-friendly, cookieless visitor statistics in the future, we'll update this page.

5. Who we share data with

We use a small number of service providers ("processors") who handle data on our behalf, under their own data-processing terms:

AI receptionist / voice agents: when we set up a voice agent for a client, it runs in the client's own voice-platform account. For callers' data the client is the controller and we only access it to configure and maintain the agent on the client's instructions. The agent tells callers they are speaking to an AI assistant.

Some of these providers may process data outside the European Economic Area, for example in the United States. Where that happens, transfers rely on safeguards recognised under the GDPR, such as the EU–US Data Privacy Framework or the European Commission's Standard Contractual Clauses.

6. How long we keep data

7. Security

We use reputable providers, strong passwords and two-factor authentication. We ask for the least access needed to deliver a project, and you can remove our access at any time. Please never send passwords by email. We'll suggest a safer way, such as adding us as a user or manager.

8. Your rights

Under the GDPR you have the right to access, correct or delete your personal data, to restrict or object to its processing (including any direct marketing, at any time), and to data portability. To use any of these rights, email [email protected]. We'll reply within one month.

You also have the right to complain to a data protection authority. In the Netherlands, that's the Autoriteit Persoonsgegevens. You can also contact the authority in your own country.

9. Changes

If we change this policy, we'll update the date at the top of this page.