Privacy Policy
Noviqent Business — covers the web dashboard (business.noviqent.co.uk) and the Noviqent Business mobile app (iOS and Android)
- Operator
- Noviqent Ltd
- Company number
- 17232197
- ICO registration
- ZC225920
- Last updated
- 20 August 2026
1. Who this policy covers, and who we are
This policy applies to anyone who uses Noviqent Business, whether through the web dashboard at business.noviqent.co.uk or the Noviqent Business app on iOS or Android. It covers staff accounts (the people who log in) and describes, at a high level, how organisation data (contacts, enquiries, properties and similar records) is handled on their behalf.
Noviqent Ltd (company no. 17232197, registered in England & Wales) builds and operates Noviqent Business. When you use the product as a staff member of a subscribing organisation, that organisation controls what business data goes into the system and who on their team can access it; Noviqent Ltd processes it on their instructions, as their data processor. For your own account details (login, password, the device you use to sign in), Noviqent Ltd is the data controller.
2. Information we collect
- Account details: name, email address, password (stored hashed, never in plain text), and which organisation(s) and role(s)/permission group(s) you belong to.
- Sign-in method: if you use "Sign in with Google", we receive the identity token Google provides (name, email, Google account ID) rather than a password.
- Business/CRM data entered into the system by you or colleagues at your organisation: enquiries, contacts, properties, viewings, deals/pipeline records, documents and similar records - this may include personal data about your organisation's own clients, applicants and enquirers, which your organisation is responsible for having a lawful basis to collect.
- Mileage and location data (mobile app only): if you use the mileage tracker, we collect GPS location while a trip is running, including while the app is backgrounded, so distance travelled can be calculated. Location is only collected between you tapping "Start trip" and "Stop trip" - the app does not track your location at any other time.
- Device push token (mobile app only, where notifications are enabled): a token used to deliver notifications to your device, not itself tied to your precise location.
- Connected mailbox data (optional): if you connect a Gmail, Microsoft 365 or IMAP mailbox for email sync, we access the mailbox data needed to match emails to CRM records, using the access you explicitly grant via that provider's own sign-in flow.
- Billing data: organisation-level subscription and payment status. Card and bank details themselves are handled directly by Stripe and GoCardless (see section 6) - we hold only references (e.g. a subscription status, a masked payment method summary), never full card or bank account numbers.
- Standard technical data: IP address, browser/device type, and access logs, for security and to keep the service running reliably.
3. How we use this information
To provide the service: authenticate you, show you the organisation data you're entitled to see, run the features you use (CRM records, mileage tracking, document generation, billing), and keep your account working across devices.
To keep the service secure: detect abuse, enforce permissions between organisations and between roles within an organisation, and maintain audit/security logs.
To communicate with you: service notifications (e.g. a new enquiry assigned to you), billing notices, and - if you use the mobile app and enable it - push notifications.
We do not sell personal data, and we do not use your account data or your organisation's business data to serve advertising.
4. Location data in the mobile app
The Noviqent Business app asks for location permission specifically for the mileage tracker. Foreground ("while using the app") permission is enough to track a trip you keep the app open for; "Always" permission is what lets tracking continue if your screen locks or you switch to another app mid-trip - both are entirely optional and only used while a trip you started is still running.
Location points collected during a trip are used to calculate distance travelled (for HMRC mileage-rate estimates) and are sent to your organisation's Noviqent Business account when the trip ends. They are not used for any other purpose, and are not collected outside an active trip.
5. Sharing and sub-processors
We share data with a limited number of service providers who help us run Noviqent Business, each only receiving what they need to perform their specific function:
- Stripe and GoCardless - process subscription payments (Stripe for an initial upfront period, GoCardless for ongoing Direct Debit) and, separately, an organisation's own connected Stripe account for payments it takes from its own clients. Card/bank details go directly to these providers, never through our own servers.
- Google - Sign-in with Google (authentication), reCAPTCHA (bot protection on forms), and, if you connect one, Gmail sync for the mailbox feature.
- Microsoft - if you connect an Office 365 mailbox for the mailbox feature.
- docsign.noviqent.co.uk - another Noviqent Ltd product, used for e-signing documents where that feature is used.
- Our hosting provider - runs the servers Noviqent Business operates on.
- A transactional email provider - sends account/notification emails on our behalf.
6. Retention
Account and business data is retained for as long as your organisation has an active Noviqent Business subscription, plus a limited period afterwards for legal, accounting and dispute-resolution purposes. Individual mileage trip records are kept as part of your organisation's business records under the same policy. If your organisation's subscription ends, we retain data only as long as reasonably necessary before deletion, unless a longer period is legally required.
7. International transfers
Our own infrastructure is hosted in the United Kingdom. Some of the third parties in section 5 (for example Google, Microsoft, Stripe, GoCardless) may process data outside the UK as part of their own global infrastructure; where that happens, we rely on the safeguards those providers offer (such as standard contractual clauses) for the transfer to be lawful.
8. Your rights
Depending on your role, you may have rights to access, correct, delete, restrict or export your personal data, and to object to certain processing. For your own staff account details, contact us directly (below). For data your organisation holds about its own clients/contacts, that organisation is normally the right first point of contact, since they control what's collected and why - we'll assist them with valid requests.
To request deletion of your own account and its associated data - from the web dashboard, the mobile app, or both - use this form.
You can also complain to the UK Information Commissioner's Office (ICO) if you're unhappy with how your personal data has been handled.
9. Children
Noviqent Business is a business tool for staff of subscribing organisations. It is not directed at, and is not intended to be used by, children.
10. Changes to this policy
We'll update this page if what we collect, why, or who we share it with changes materially - for example if a new integration or feature is added. The "Last updated" date above reflects the most recent revision.
11. Contact
Data protection contact: Noviqent Ltd, hello@noviqent.co.uk.