GDPR

Last updated: June 2026

Nova Chat is designed with privacy by design. On this page, you can read how we comply with the General Data Protection Regulation (GDPR).

1. Roles under the GDPR

Nova Chat is responsible for website visitors and direct customers (account holders).

For guest chats via an organizational client, that organization is typically the data controller; Nova Chat acts as a processor. We offer a Data Processing Agreement (DPA) for business clients.

Privacy by design.

No guest accounts: visitors do not need to share a name or email.

Data minimization: only necessary technical data for session and abuse prevention.

Delete-on-close: chat messages are permanently deleted after closing.

Automatic cleanup of expired chats.

3. Processor register and sub-processors

We maintain an internal processing register. Sub-processors include, among others, hosting, Mollie (payments), email provider, and translation services.

Business customers receive an up-to-date list of sub-processors upon request.

4. Rights of data subjects

We support requests for access, rectification, deletion, restriction, objection, and data portability within the statutory time limits.

Guests should preferably direct requests to the organization with which they chatted; we assist our clients as processors.

5. Data breaches

In the event of a data breach, we follow our internal reporting procedure and inform those responsible and, where necessary, the Dutch Data Protection Authority and the data subjects in accordance with the GDPR.

6.DPIA

Organizations in healthcare, government, or other sensitive sectors sometimes conduct a Data Protection Impact Assessment (DPIA) themselves. We provide technical information upon request to support this.

← Back to the landing page