Privacy Policy
Novitio Platform
Effective date: September 2026
Last updated: September 2026
Introduction
This Privacy Policy explains how Novitio ApS (“Novitio”, “we”, “us” or “our”) collects, uses, stores and protects personal data in connection with the Novitio platform, our website and our professional business relationships.
Novitio operates a professional B2B trading infrastructure for used and surplus IT equipment. The platform is designed for professional organisations, including ITAD companies, brokers, resellers and other professional participants in the IT lifecycle ecosystem.
As a B2B platform, Novitio processes a limited amount of personal data. The personal data processed primarily relates to professional contact persons, company administrators and individual users representing organisations using the platform.
Novitio applies the following principles when processing personal data:
- Data minimisation
- Purpose limitation
- Controlled access
- Secure processing
- Limited retention
- Transparency and accountability
Novitio does not, as part of its standard B2B operating model, intentionally collect personal data that is not necessary for the professional relationship.
This Privacy Policy should be read together with Novitio’s Terms of Service and, where applicable, relevant contractual agreements and Data Processing Agreements (“DPA”).
1. Data Controller
For personal data processed for Novitio’s own purposes, the data controller is:
Novitio ApS
VAT No.: DK41309296
Østre Allé 102
9000 Aalborg
Denmark
Email: info@novitio.com
Website: www.novitio.com
Questions regarding this Privacy Policy or Novitio’s processing of personal data may be directed to:
2. Data Controller and Data Processor Roles
Novitio generally acts as an independent data controller in relation to personal data required to:
- Establish and administer user accounts
- Manage company profiles
- Operate and secure the Novitio platform
- Conduct onboarding and company verification
- Communicate with customers and partners
- Administer contractual relationships
- Provide customer support
- Maintain security, audit and transaction records
- Meet legal and regulatory obligations
In certain customer-specific or white-label arrangements, Novitio may process personal data on behalf of another organisation.
In such circumstances, the respective roles and responsibilities of the parties are defined contractually and, where required, through a separate Data Processing Agreement.
Where Novitio acts as a data processor, personal data is processed only in accordance with documented instructions from the relevant data controller and applicable data protection legislation.
3. Personal Data We Process
Novitio follows the principle of data minimisation and processes only personal data reasonably necessary for operating the platform and managing professional business relationships.
3.1 Company Profile and Administrator Information
Company profiles may contain:
- Company name
- VAT/registration number
- Company/user classification
- Business address
- Postal code
- City
- Country
- Name of company administrator or primary contact person
- Business email address
- Business telephone or mobile number
Company information such as company name, VAT number and business address does not normally constitute personal data in itself. However, it may become personal data where it identifies or relates to an identifiable natural person.
3.2 Individual Platform User Information
For individual users associated with a participating company, Novitio may process:
- Name
- Associated company
- Company role or professional title
- Business email address
- Business telephone or mobile number
- User permissions and access rights
- Preferred platform currency
- Account and authentication information
Permissions are assigned according to the user’s role and determine which parts of the Novitio platform the individual user can access.
3.3 Commercial Preferences
For users with buyer permissions, Novitio may process professional purchasing preferences, including:
- Product categories
- Product subcategories
- Brands of commercial interest
These preferences are used to provide relevant platform functionality, notifications and commercial opportunities.
They relate to the user’s professional role and are not intended to create consumer profiles.
3.4 Contractual Information
Where Novitio enters into agreements with customers, partners or suppliers, contractual documentation may include:
- Name
- Professional title
- Business contact information
- Signature
- Company represented
- Contract-related correspondence
Contracts may be executed using electronic signature providers such as Penneo or DocuSign, or through another signing solution agreed with the relevant business partner.
Novitio may download and retain a PDF copy of the executed agreement within its controlled document environment.
3.5 Platform Activity and Transaction Records
To maintain security, traceability and platform integrity, Novitio may record user activity associated with professional transactions.
This may include:
- User login and authentication events
- Time-stamped bid submissions
- Listing-related actions
- Order confirmations
- Purchase Order and Sales Order references
- Certificate generation events
- Permission and administrative actions
- Transaction-related user activity
- Destination declarations and other transaction records
Logging is used to support:
- Platform security
- Transaction traceability
- Dispute resolution
- Compliance verification
- Internal audit readiness
- Protection of ecosystem integrity
Novitio’s existing platform governance is based on structured transaction logging and role-based accountability.
4. Information We Do Not Normally Collect
Novitio is a professional B2B platform.
As part of its standard platform operations, Novitio does not require or intentionally collect:
- Danish CPR numbers or equivalent national identification numbers
- Private residential addresses
- Private email addresses
- Private telephone numbers unrelated to the business relationship
- Payment card information
- Special categories of personal data, such as health information, political opinions, religious beliefs, biometric information or information concerning a person’s private life
Users and participating companies should therefore avoid submitting personal information that is not necessary for the professional transaction or business relationship.
Novitio does not process end-consumer personal data as part of its standard B2B transaction model. This is consistent with the data-minimisation principle already established in Novitio’s Data & Security Overview.
5. How We Collect Personal Data
Personal data may be collected when:
- A company registers with Novitio
- A user account is created
- A company administrator creates or manages users
- A person communicates directly with Novitio
- A company enters into a contractual relationship with Novitio
- A user participates in transactions through the platform
- Novitio conducts onboarding or verification activities
- A person requests support, information or a demonstration
- A professional contact engages with Novitio’s sales or customer relationship activities
Information may be provided directly by the individual, by the company the individual represents, or generated through use of the platform.
6. Purposes of Processing
Novitio processes personal data for legitimate and defined business purposes, including:
- Creating and maintaining company and user accounts
- Authenticating users and controlling platform access
- Managing user roles and permissions
- Conducting onboarding and company verification
- Operating listings, bidding, orders and other platform functions
- Providing relevant notifications and platform communication
- Providing customer support
- Maintaining transaction traceability
- Maintaining security and preventing misuse
- Managing contractual relationships
- Managing customer and partner relationships
- Maintaining documentation and audit trails
- Resolving disputes
- Complying with legal, accounting and regulatory obligations
- Improving and developing the Novitio platform and related services
Personal data is not processed for purposes incompatible with the reason for which it was originally collected unless another lawful basis applies.
7. Legal Basis for Processing
Novitio processes personal data only where a lawful basis exists under applicable data protection legislation, including the General Data Protection Regulation (“GDPR”).
Depending on the specific processing activity, Novitio may rely on:
Contractual necessity
Where processing is necessary to enter into or perform a contract with the data subject.
Legal obligations
Where processing is necessary for Novitio to comply with applicable legal, accounting, tax, documentation or regulatory obligations.
Legitimate interests
Novitio may process professional contact and platform data where necessary for legitimate business interests, including:
- Operating a secure B2B trading platform
- Managing professional customer and partner relationships
- Protecting platform integrity
- Preventing misuse
- Maintaining transaction documentation
- Improving platform functionality
- Communicating with existing or prospective professional business contacts
Novitio assesses such processing against the rights and interests of the individuals concerned.
Consent
Where processing is based specifically on consent, consent may be withdrawn at any time.
The GDPR recognises contractual necessity, legal obligations and legitimate interests as separate lawful bases for processing; consent is therefore not required for every processing activity.
8. CRM and Business Communication
Novitio currently uses HubSpot for certain customer relationship management activities.
Information stored within the CRM environment is generally limited to professional business information that is also used within Novitio’s ordinary sales, onboarding and platform processes, such as:
- Name
- Company
- Professional role
- Business email
- Business telephone number
- Relevant business communication and relationship information
Novitio may change or replace its CRM systems as its internal infrastructure develops.
Any replacement system will be subject to Novitio’s data protection, access control and security requirements.
9. Email and Platform Communications
Novitio uses professional email and communication infrastructure to communicate with platform users, customers and partners.
Microsoft 365 is used for corporate email and collaboration.
SendGrid is used for certain system-generated and platform-related email communications.
Such communications may include:
- Account-related messages
- Platform notifications
- Transaction-related messages
- Security notifications
- Operational information
- Relevant service communications
Where electronic communications constitute direct marketing, Novitio will comply with applicable requirements governing such communications.
10. Hosting and IT Infrastructure
The Novitio platform is hosted using Microsoft Azure cloud infrastructure.
Novitio’s hosting environment is designed to provide:
- Secure cloud infrastructure
- Infrastructure redundancy
- Network-level protection
- Regular automated backups
- Operational resilience
- Disaster recovery safeguards
The Novitio platform operates within an EU/EEA hosting environment unless otherwise contractually specified.
Microsoft 365, including SharePoint, is used for corporate email, collaboration and controlled document storage.
Executed contracts and related corporate documentation may be stored as PDF documents within Novitio’s SharePoint environment.
Access to sensitive contractual documentation is restricted to authorised personnel based on business need.
11. Service Providers and Sub-Processors
Novitio relies on selected third-party service providers to operate its business and technical infrastructure.
These currently include services within areas such as:
- Microsoft Azure – cloud infrastructure and platform hosting
- Microsoft 365 and SharePoint – email, collaboration and document storage
- HubSpot – customer relationship management
- SendGrid – system and email delivery
- Penneo – electronic contract signing
- DocuSign – electronic contract signing where applicable
Novitio selects service providers based on relevant considerations including:
- Security standards
- Data protection requirements
- Regulatory compliance
- Operational reliability
Third-party providers may process personal data only to the extent necessary for providing their respective services and subject to applicable contractual and data protection requirements.
Where Novitio acts as a processor for a customer, applicable sub-processor requirements are governed by the relevant Data Processing Agreement.
12. International Data Transfers
Novitio aims to process and store platform data within the EU/EEA where applicable.
Some technology providers used by Novitio are international organisations and may process certain data outside the EU/EEA as part of their service infrastructure.
Where personal data is transferred outside the EU/EEA, Novitio requires an appropriate legal transfer mechanism in accordance with applicable data protection legislation.
This may include:
- An adequacy decision adopted by the European Commission
- Standard Contractual Clauses
- Other legally recognised safeguards
Novitio does not transfer personal data internationally without an applicable legal basis or safeguard where one is required.
13. Data Retention
Novitio retains personal data only for as long as necessary for the purpose for which the information was collected.
As a general principle, ordinary professional contact and CRM information associated with an inactive business relationship will be reviewed for deletion after 24 months of inactivity, unless there remains a legitimate business purpose or a legal, contractual, accounting, documentation or compliance requirement for continued retention.
Different retention periods may therefore apply to different categories of information.
Transaction-related information may be retained for longer where necessary for:
- Accounting requirements
- Contractual documentation
- Compliance records
- Audit trails
- Dispute resolution
- Legal claims
- Regulatory requirements
Contractual documentation may similarly be retained for the period required to document the commercial relationship and comply with applicable legal obligations.
When personal data is no longer required for a legitimate or legally required purpose, it will be deleted or anonymised where appropriate.
This approach follows Novitio’s existing retention framework, under which transactional data is retained for compliance, documentation and audit purposes but not beyond legitimate business or regulatory necessity.
14. Data Security
Novitio applies technical and organisational safeguards designed to protect personal and transactional data.
These include, where applicable:
- Encryption in transit using TLS
- Secure HTTPS communication
- Encrypted API communication
- Individual user authentication
- Role-based access control
- Company-level access separation
- Administrative access restrictions
- Principle of least privilege
- Structured system logging
- Automated backups
- Infrastructure redundancy
- Disaster recovery safeguards
- Multi-factor authentication for relevant corporate systems
Access to personal data is limited according to role and operational necessity.
Company Administrators are responsible for managing user access within their own organisation, while Novitio maintains the underlying permission and access-control infrastructure.
Further information regarding Novitio’s technical and organisational security framework is available in the Novitio Data & Security Overview, including information on hosting, encryption, access control, audit logging, backup, operational continuity and sub-processors.
15. White-Label Solutions
Novitio provides white-label solutions in which Novitio technology and infrastructure may be operated under or integrated into a customer’s own commercial environment.
The processing of personal data within such arrangements depends on the specific setup.
Depending on the circumstances:
- The customer may act as data controller
- Novitio may act as data processor
- The parties may independently act as data controllers for different processing activities
Where Novitio processes personal data on behalf of a white-label customer, the processing relationship will be governed by the relevant contractual documentation and, where required, a Data Processing Agreement.
The specific contractual arrangement takes precedence regarding processor instructions, security requirements, sub-processors, deletion and return of data and other processor obligations.
16. Data Subject Rights
Individuals whose personal data is processed by Novitio have rights under applicable data protection legislation.
Depending on the circumstances, these may include the right to:
- Receive information about the processing
- Request access to personal data
- Request correction of inaccurate personal data
- Request deletion of personal data
- Request restriction of processing
- Object to certain processing
- Receive personal data in a portable format where applicable
- Withdraw consent where processing is based on consent
- Object to processing for direct marketing purposes
These rights are subject to the conditions and limitations established by applicable data protection legislation.
Requests relating to personal data may be submitted to:
Novitio may request appropriate information to verify the identity of the person making the request before disclosing or changing personal data.
17. Complaints
If you have concerns regarding Novitio’s processing of your personal data, we encourage you to contact Novitio first:
You also have the right to lodge a complaint with the competent supervisory authority.
In Denmark, the supervisory authority is:
Datatilsynet
Carl Jacobsens Vej 35
2500 Valby
Denmark
Telephone: +45 33 19 32 00
Email: dt@datatilsynet.dk
18. Changes to This Privacy Policy
Novitio may update this Privacy Policy when necessary to reflect:
- Changes to the Novitio platform
- Changes to processing activities
- Changes to service providers
- Changes to applicable legal or regulatory requirements
- Changes to Novitio’s organisational structure
The latest version will be made available through Novitio’s website and/or platform.
Material changes may also be communicated directly to affected customers or users where appropriate.
19. Contact
For questions regarding this Privacy Policy, personal data or data protection within the Novitio platform, please contact:
Novitio ApS
Østre Allé 102
9000 Aalborg
Denmark
VAT No.: DK41309296
Email: info@novitio.com
Website: www.novitio.com
Summary
Novitio operates a professional B2B platform based on data minimisation, controlled access and structured governance.
Personal data processed by Novitio is primarily limited to professional contact information and information necessary to operate user accounts, contractual relationships and secure platform transactions.
Novitio does not intentionally collect unnecessary private or sensitive personal information as part of its standard operating model.
Personal data is processed only for defined business or legal purposes, protected through technical and organisational safeguards, and retained only for as long as necessary.
Structured digital trading requires structured data protection.
Questions About Privacy or Personal Data?
If you have any questions regarding this Privacy Policy, the processing of personal data, or your rights under applicable data protection legislation, please contact us.
Contact Novitio:
info@novitio.com
Our team will assist with privacy-related enquiries and requests concerning personal data.