GDPR
Last updated: June 2026
Nova Chat is designed with privacy by design. On this page, you can read how we comply with the General Data Protection Regulation (GDPR).
1. Roles under the GDPR
Nova Chat is responsible for website visitors and direct customers (account holders).
For guest chats via an organizational client, that organization is typically the data controller; Nova Chat acts as a processor. We offer a Data Processing Agreement (DPA) for business clients.
Privacy by design.
No guest accounts: visitors do not need to share a name or email.
Data minimization: only necessary technical data for session and abuse prevention.
Delete-on-close: chat messages are permanently deleted after closing.
Automatic cleanup of expired chats.
3. Processor register and sub-processors
We maintain an internal processing register. Sub-processors include, among others, hosting, Mollie (payments), email provider, and translation services.
Business customers receive an up-to-date list of sub-processors upon request.
4. Rights of data subjects
We support requests for access, rectification, deletion, restriction, objection, and data portability within the statutory time limits.
Guests should preferably direct requests to the organization with which they chatted; we assist our clients as processors.
5. Data breaches
In the event of a data breach, we follow our internal reporting procedure and inform those responsible and, where necessary, the Dutch Data Protection Authority and the data subjects in accordance with the GDPR.
6.DPIA
Organizations in healthcare, government, or other sensitive sectors sometimes conduct a Data Protection Impact Assessment (DPIA) themselves. We provide technical information upon request to support this.