Privacy Policy
Last updated: 9 August 2026
Current website configuration:
This website has no contact form and does not use cookies, analytics or tracking technologies. Limited technical information, such as IP address, request time and browser information, may be processed automatically by our hosting infrastructure where necessary to deliver and secure the website. All fonts used on this site are hosted on our own server; no connection is made to any third-party font service.
1. Who we are
Noverys Ltd ("Noverys", "we", "us") is the controller of the personal data described in this policy. We are a private limited company registered in England and Wales under company number 16686328.
Our registered office is Unit 7, Initial Business Centre, Wilson Business Park, Manchester, England, M40 8WN.
This policy explains how we handle personal data when you contact us about our cyber security audit, compliance and information-systems risk consultancy services. Privacy enquiries may be sent to info@noverys.co.uk or to our registered office.
2. Personal data we process
The website has no contact form. It displays only info@noverys.co.uk for contact. If you choose to email us, we may process your name, email address, business contact details, organisation, the content of your message, service interests, correspondence and other information you choose to provide.
If a business relationship is established, we may also process business contact, engagement, contract, service-delivery, billing, security and compliance records obtained from you, your organisation, contracts and service activity.
Please do not send passwords, payment-card data, special-category personal data, client secrets or other unnecessary sensitive information through a general enquiry.
3. How and why we use personal data
We use personal data to:
- receive, assess and respond to enquiries and communicate with business contacts;
- take steps requested before entering into a contract;
- provide agreed services and administer contracts, accounts and business records;
- meet legal and regulatory duties; and
- establish, exercise or defend legal claims.
Our lawful bases are legitimate interests in managing enquiries and business relationships, steps requested before a contract, performance of a contract where applicable, and compliance with legal obligations. Where we rely on legitimate interests, we consider necessity, proportionality and the rights and reasonable expectations of affected people.
We do not use personal data for automated decision-making producing legal or similarly significant effects.
4. Website technical data and cookies
We do not use cookies, analytics or tracking technologies. Limited technical information, such as IP address, request time and browser information, may be processed automatically by our hosting infrastructure where necessary to deliver and secure the website. This processing is carried out by our hosting provider as part of ordinary web server operation (for example, connection logs and security protection) and is not used by Noverys for analytics, profiling or marketing purposes.
All fonts used on this website are self-hosted on our own server (noverys.co.uk). No connection is made to Google Fonts or any other third-party font service, and no font-related data is shared with, or requested from, any external provider.
The website does not set or use cookies or similar browser-storage technologies. If this changes, we will update this policy and, where required, provide clear information and obtain valid consent before non-essential technology is used.
5. Sharing personal data
We disclose personal data only where necessary and proportionate. Recipients may include authorised Noverys Directors, providers supporting business email, professional advisers, competent authorities where legally required, and parties needed to establish, exercise or defend legal claims.
Providers are subject to appropriate contractual and confidentiality controls where required. We do not sell personal data.
External websites linked from our site have their own privacy practices. Please review their notices before providing information.
6. International transfers
A business email provider or its infrastructure may process correspondence outside the UK. Before introducing or materially changing a provider, we assess data location and transfer arrangements. Where UK data-protection law restricts a transfer, we use an applicable adequacy regulation, recognised contractual safeguard or another lawful mechanism, together with supplementary measures where appropriate.
You may contact us for information relevant to a particular transfer.
7. Retention
We keep personal data only for as long as needed for the purpose collected, legal and contractual duties, security, dispute handling and the establishment or defence of claims.
- Routine business email and unsuccessful enquiries are reviewed and deleted when no longer needed and within 12 months.
- Client contracts, final deliverables and acceptance or closure evidence are normally retained for six years after engagement closure unless another applicable requirement specifies otherwise.
A legal hold, active dispute, investigation or other applicable requirement may require longer retention.
8. Security
We use proportionate organisational and technical safeguards, including controlled access, confidentiality requirements, secure configuration, monitoring, backup and incident management. Internet transmission cannot be guaranteed completely secure.
If you believe information sent to or held by Noverys may be at risk, contact us promptly at info@noverys.co.uk.
9. Your rights
Depending on the circumstances, UK data-protection law may give you rights to request access, correction, erasure, restriction, objection or portability, and to withdraw consent where processing relies on consent. Rights may be limited by law and may not apply in every case.
To make a request, contact info@noverys.co.uk. We may ask for proportionate information to verify identity and scope and normally respond within one month, subject to any lawful extension.
10. Data-protection complaints
You may make a data-protection complaint to info@noverys.co.uk. We acknowledge a complaint within 30 days, take appropriate steps to investigate without undue delay, keep you informed where appropriate and tell you the outcome.
You may also complain to the UK Information Commissioner's Office through ico.org.uk. Your right to contact the ICO is not affected by contacting us first.
11. Changes to this policy
We review this policy at least annually and after a material change to the website, processing, provider or applicable law. The current version will be published on noverys.co.uk.