This Privacy Policy explains how NovaMind AI collects, uses, stores, shares, and protects your personal data when you visit our website and use our services.
NovaMind AI ("we", "us", "our") is committed to protecting and respecting your privacy. This Privacy Policy applies to the website operated by NovaMind AI, located at 180 John Street, Suite 302, Toronto, ON M5T 1X5, Canada. If you have any questions about this policy or how we handle your data, you may contact us at [email protected] or by calling +1 (416) 835-2749.
This policy covers all data collected through our website, including through cookies, tracking pixels, forms, and other technologies. We encourage you to read this document carefully so that you understand how your information is processed and what choices are available to you.
Our cookie consent banner appears upon your first visit to this website and offers three options: "Accept All", "Reject Non-Essential", and "Manage Preferences". Marketing and analytics cookies are not activated until you explicitly accept them. Your choice is stored in your browser's localStorage for 12 months. The banner can be dismissed without accepting cookies, in which case only essential cookies remain active. The banner links directly to this Privacy Policy for your reference.
By clicking "Accept All Cookies", you consent to the storing of cookies on your device for analytics and advertising purposes, including personalized advertising delivered by Google and Meta. You may withdraw consent at any time through the cookie preferences panel without affecting the lawfulness of processing that occurred before withdrawal.
Users in the European Economic Area and the United Kingdom receive this consent notice in compliance with the General Data Protection Regulation (GDPR) and UK GDPR. Marketing and analytics cookies are activated solely after explicit, informed, freely given consent under GDPR Article 6(1)(a). Consent is recorded with a timestamp and may be audited upon request.
You may withdraw consent at any time by clicking "Manage cookie preferences" in the website footer, or by clearing cookies via your browser settings. Withdrawal does not affect processing that occurred while consent was valid.
We share certain data with advertising partners for campaign delivery and measurement. Recipients and the data categories shared include:
Cookie identifiers, conversion events, anonymized behavioral data, remarketing lists. Governed by Google's Privacy Policy: https://policies.google.com/privacy
Pixel events, conversion data, custom audiences. Governed by Meta's Data Policy: https://www.facebook.com/privacy/policy
We do not sell personal data. All transfers to Google and Meta operate under Standard Contractual Clauses where applicable. Data is processed for ad targeting and campaign measurement only and is not resold to unaffiliated third parties.
Google and Meta may use this data across their own platforms in accordance with their respective policies. We encourage users to review those policies directly.
When you submit a contact form, request a quote, or register interest in our services, we collect the information you provide. This typically includes: full name, email address, phone number, and your message or area of interest.
Legal basis: Consent (GDPR Art. 6.1.a) and, where a service relationship exists, performance of a contract (GDPR Art. 6.1.b).
Retention: Form submission data is retained for up to 2 years from the date of submission, unless a longer period is required by applicable law.
You may request deletion of your data at any time by contacting us at [email protected].
A link to this Privacy Policy appears adjacent to every submission button on this site. Submitting a form constitutes acknowledgment of this policy.
This website uses the following Google services:
Collects anonymized usage data, device info, and behavioral signals. IP anonymization is enabled. Data retention is set to 14 months. Users may opt out via the Google Analytics Opt-out Browser Add-on: https://tools.google.com/dlpage/gaoptout
Records when a user completes a defined action (form submission, call, purchase) after clicking one of our ads. This data is used solely for measuring ad campaign performance.
Allows us to show ads to previous visitors across Google's network. Remarketing lists are not created from sensitive data categories (health, finance, religion, sexual orientation).
Deploys tracking tags on our behalf. No personal data is collected by GTM itself; it acts as a container for the tags listed above.
Google's advertising products are governed by: https://policies.google.com/technologies/ads
This website uses the Meta Pixel to measure the effectiveness of our advertising on Facebook and Instagram. The pixel may record:
We do not use the Meta Pixel to collect sensitive personal data, nor to target users based on health status, financial situation, religion, political views, sexual orientation, or any other special-category attribute prohibited under Meta's advertising policies.
Meta acts as an independent data controller for data collected via its Pixel and processed within its own platform. Refer to Meta's Data Policy: https://www.facebook.com/privacy/policy
To manage your ad preferences on Meta platforms, visit: https://www.facebook.com/adpreferences/
This website does not promote, sell, or facilitate access to prohibited product or service categories including but not limited to: weapons, controlled substances, counterfeit goods, gambling services (unlicensed), adult content, or services that make misleading health or financial claims. All advertising conducted through Google Ads and Meta Ads complies with the respective platform policies in full.
The content of this website accurately represents the products and services advertised. No bait-and-switch practices are employed. The experience delivered to users arriving from paid advertisements is identical to the experience for all other visitors. Cloaking, automatic redirects, and content variation by traffic source are not used on this website.
This website is not directed at individuals under the age of 16. We do not knowingly collect personal data from minors. If we discover that data has been collected from a person under 16 without verifiable parental consent, we will delete it promptly. Contact us at [email protected] if you believe we have received data from a minor.
Personal data collected through this website may be transferred to and processed in countries outside the European Economic Area, including the United States, where Google LLC and Meta Platforms, Inc. are based.
These transfers are conducted under Standard Contractual Clauses (SCCs) approved by the European Commission, which provide appropriate safeguards for personal data. A copy of the applicable SCCs can be requested by contacting us directly at [email protected].
If you are located in the EEA or UK, you have the following rights:
Request a copy of data we hold about you.
Correct inaccurate or incomplete data.
Request deletion ("right to be forgotten").
Limit how we process your data.
Receive your data in a structured, machine-readable format.
Object to processing based on legitimate interest.
Revoke consent at any time without penalty.
To exercise any right, email us at [email protected]. We will respond within 30 days. You also have the right to lodge a complaint with your local supervisory authority:
We collect the following categories of data when you visit our website or interact with our services:
For each type of data processing, the legal basis under the GDPR is as follows:
| Data Type | Legal Basis |
|---|---|
| Contact form data | Consent (Art. 6.1.a) and contract performance (Art. 6.1.b) |
| Analytics data | Consent (Art. 6.1.a) |
| Marketing / remarketing data | Consent (Art. 6.1.a) |
| Security and fraud prevention | Legitimate interest (Art. 6.1.f) |
We retain data for specific periods based on category and purpose. Once the retention period has elapsed, data is securely deleted or anonymized.
| Data Category | Retention Period |
|---|---|
| Contact form submissions | 2 years |
| Analytics data (GA4) | 14 months |
| Marketing cookies (Google Ads) | Up to 540 days |
| Email communications | Duration of relationship + 1 year |
| Server logs | 90 days |
| Cookie consent records | 3 years (audit requirement) |