No cookies
This site sets no cookies. It writes nothing to local storage or session storage and issues no device identifier. There is no cookie banner because there is nothing to consent to, and no legitimate interest to weigh.
Privacy notice
Almost nothing. No cookies, no analytics, no tracking. Beyond the routine server logs every website generates — described below — the only personal data we receive through this site is what you choose to put in the enquiry form or in an email.
This notice sets out what then happens to it: who holds it, why we are allowed to, how long we keep it, who else sees it, and what you can require of us. It is written to be read.
Last updated 29 September 2026. It applies to novus-point.com (and novus-point.co.uk, which redirects to it) and to the correspondence that reaches us through it.
Verifiable in this page's source
Who holds it
One company decides what happens to the personal data described here, and that company is answerable for it.
Novus Point Limited is registered in England and Wales, company no. 08146241. Our registered office is 124 City Road, London EC1V 2NX. We work from London and Dubai. For anything in this notice, write to enquiries@novus-point.co.uk.
This website, and the correspondence that reaches us through it. If we are engaged to act for you, the personal data we handle in the course of that engagement is governed by the terms we agree with you at the time — including whether we act as controller or as your processor for it. This notice does not displace those terms.
We are not a public authority, we do not monitor people at scale and we do not process special category data as our core activity, so UK GDPR Article 37 does not require us to appoint one, and we have not appointed one for appearances. Data protection questions are answered at principal level, at the address above.
The site itself
This is a static site. There is nothing on it that watches you.
An advisory firm that writes about data governance should be able to state plainly what its own website does, and should not mind being checked. Everything below can be confirmed from the page source and from the response headers this site sends.
This site sets no cookies. It writes nothing to local storage or session storage and issues no device identifier. There is no cookie banner because there is nothing to consent to, and no legitimate interest to weigh.
There is no analytics package, no tag manager, no advertising or social pixel, no session recorder and no third-party script of any kind. We do not count your visit, and we do not build a profile of you.
There is exactly one form on this site — the enquiry form at /contact, which asks for your name, email address and, if there is one, your company. It submits only to this domain: the content security policy sets form-action to self, so a page here could not send your data anywhere else even if it were altered. Every other contact link on this site is a mailto link that opens your own email client, or our LinkedIn page.
The typefaces, the logo and the icons are self-hosted. Loading a page here makes no request to Google Fonts, to a content delivery network or to any other third party, so no other company learns that you visited, or from where.
This site is hosted by Vercel. As an ordinary incident of serving a web page, Vercel's systems record technical request data: your IP address, the user agent string your browser sends, the page requested, the time of the request and the response status. Every web server on the internet does this — it is how a page is delivered and how a host defends itself against abuse.
Our lawful basis is legitimate interests, UK GDPR Article 6(1)(f): delivering this site reliably and keeping it secure. We do not use that log data for analytics, marketing or profiling, we do not combine it with anything else, and we make no attempt to identify you from it. It is generated and retained by Vercel as our hosting processor and expires automatically on Vercel's rolling platform schedule; we take no copy and keep none ourselves. The small function that delivers the enquiry form also glances at your IP address to slow down automated abuse; it holds it briefly in the function's own memory and writes it nowhere.
If you contact us
Nothing is sent to us until you press send.
The enquiry form at /contact asks for four things — first name, last name, email address and, optionally, a company name — and delivers them to enquiries@novus-point.co.uk as a single email over our own mail service. It exists so that reaching us does not depend on your machine having a working mail client. Every other contact link on this site is a mailto link to the same address, or our LinkedIn page.
What you have to give us. Nothing, until you decide to write. If you use the form, three of its four fields are required — your name and your email address — because what you are asking for is a conversation, and we need a way to answer. We do not ask for a telephone number: the diagnostic is arranged by email, and if a call turns out to be the better way to hold it, we agree that with you at the time. None of it is demanded by any law or contract: the only consequence of not providing it is the obvious one, that we cannot come back to you. And by email you decide entirely what we get — you can send us less than you think we want.
From the form: the four fields above, and nothing else — the form has no message box, no identifier of any kind, and one hidden field: a decoy that only spam robots fill in. If it is filled, nothing is sent. A person never sees it, and it never carries your data. From email: whatever your message contains. In practice that is your name and email address, your job title and employer if you mention them, and what you tell us about your organisation, your systems or the problem you are trying to solve. We also receive the ordinary metadata that travels with any email: the sending address, the time, and the routing headers.
Please do not send special category data — health, biometric, trade union, religious or similar — or anyone else's personal data, in an opening email. An unsolicited message is not a controlled channel. If something sensitive has to move, say so first and we will agree a route for it.
Legitimate interests. UK GDPR Article 6(1)(f). Running an advisory firm means reading, answering and keeping a record of the enquiries sent to it. You would expect a reply; holding your message in order to write one is what you asked for, and it does not override your interests or rights.
Steps prior to a contract. UK GDPR Article 6(1)(b). Where your enquiry concerns a possible engagement, we process what you send in order to take steps at your request before entering into a contract — holding the diagnostic conversation, scoping the work, quoting it and agreeing terms.
To answer you. To hold the thirty-minute diagnostic if you want one, to prepare a written position or a proposal, and to keep a record of what was asked and what we said. That is the list. We do not sell personal data, we do not share it for anyone's marketing, and we do not add you to a mailing list you did not ask to join.
Correspondence that does not lead to an engagement is deleted within 12 months of the last message. Where an engagement follows, the records are kept for the duration of that engagement and for six years afterwards — the period in which a claim could still be brought and in which we may need to evidence what was advised. We delete sooner if you ask and there is no reason left to hold it.
Who else is involved
Nobody else touches it, and none of them may use it for their own purposes.
Our email is provided by Google Workspace. Google stores and transmits our messages, including yours, as our processor under a data processing agreement, and is not permitted to use their content for its own purposes.
Vercel hosts this website, runs the small function that handles the enquiry form, and generates the server log data described above, as our processor.
When you submit the enquiry form, the message carrying your details travels from that function to our mailbox through Resend, an email delivery service, as our processor under a data processing agreement. Resend handles the message only long enough to deliver it and keeps a delivery log; it is not permitted to use the content for its own purposes. Email you send us directly, rather than through the form, never touches Resend.
All three providers are capable of storing or processing data outside the UK. Where that happens, the transfer is made under the safeguards UK law requires: the adequacy regulations made under section 17A of the Data Protection Act 2018 where the destination is covered by them, or the Information Commissioner's International Data Transfer Addendum to the European Commission's standard contractual clauses where it is not. If you want to know which safeguard covers a particular transfer, or to see a copy of it, write to us and we will show you. We work from London and Dubai, so a message you send us may be read by us in either place. When that happens in Dubai it is still Novus Point Limited reading it — the same company, under the same obligations to you. No separate company there receives your data.
We would disclose personal data where we are required to by law, by a court or by a regulator, or where it is necessary to establish, exercise or defend a legal claim. Where an engagement needs specialist legal, security or data expertise, we bring that expertise in under our own direction and responsibility — and we tell you before your information reaches anyone outside the firm.
This site is served over HTTPS with strict transport security, a content security policy that permits no third-party code, and no scripts beyond our own. Email is a less controlled medium: it crosses the public internet, and no one can guarantee a message in transit. Treat a first email accordingly.
Some pages link outward — to LinkedIn, to Companies House, to EUR-Lex. Following a link takes you to someone else's site, where their privacy notice applies and ours does not. We have no control over what they do.
Your rights
Exercising these rights costs you nothing, and we answer within one month.
You do not need to cite an article, fill in a form or explain yourself. Write and say what you want. If a request is genuinely complex we may take up to two further months, in which case we will tell you why inside the first month. We would charge a fee, or decline, only for a request that is manifestly unfounded or excessive — and we would say so, and why.
Rights under the UK GDPR
We make no decision about you by automated means, and we do not profile you. Article 22 does not arise. Where we use AI tools in our own work, a person decides, and that person is accountable for the decision.
Email enquiries@novus-point.co.uk and say what you want. We may ask you to confirm who you are before we release information about you, which is a protection for you rather than an obstacle.
Tell us, and we will look at it again. You also have the right to complain to the Information Commissioner's Office, the UK's data protection regulator, at ico.org.uk, or by post to Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF. Raising it with us first is not a precondition, and complaining to the ICO does not stop you raising it with us as well.
Nothing above changes, but two things are worth saying plainly. Where we have offered our services to you in the EU, the EU GDPR may apply to what you send us alongside the UK version; the two are materially the same, and this notice is written to honour both. And you can complain to the data protection authority where you live or work, not only to the ICO — raising it with one does not shut the door on the other.
Our representative in the EU under Article 27 of the EU GDPR is Prighter EU Rep GmbH, Schellinggasse 3/10, 1010 Vienna, Austria. You — or a data protection authority — can reach them through prighter.com/q/16315401859, quoting ID-16315401859. Writing to them is the same as writing to us: it changes nothing about who is responsible for your data, which remains Novus Point Limited.
If what we do changes, this notice changes with it and the date at the top of the page changes too. The current version is always the one published here. Where a change materially affects something you have already sent us, we will tell you rather than leave you to notice.
The text and design of this site belong to Novus Point Limited. The typefaces — Source Serif 4, Lato and Montserrat — are used under the SIL Open Font License; their licence texts sit alongside the font files at /assets/fonts/. Where we set out the EU AI Act, we compile from Regulation (EU) 2024/1689 and Regulation (EU) 2026/1744 as published in the Official Journal of the European Union — which alone is authentic. The legislation itself belongs to everyone; our reading of it belongs to us. Quote this site with attribution and we will not mind.