Novable works with corporate innovation, R&D and venture teams inside large, regulated organisations. We treat the security of your briefs, your data and your decisions as a core part of the product, not an afterthought. This page explains how we protect your information, how we use AI, and how to reach us with a security or procurement question.
Data protection and privacy (GDPR)
Novable is operated by Novable SRL, a company registered in Belgium (Belgian Register of Legal Entities, BE0702877935), Chaussée de La Hulpe, 150, 1170 Brussels. As an EU company, our processing of personal data is governed by the EU General Data Protection Regulation (GDPR).
- We process personal data only to deliver the service and on documented instructions from our customers.
- A Data Processing Agreement (DPA) is available on request and can be signed as part of your contract.
- We maintain a register of sub-processors, available to customers on request.
- Your data stays yours. As stated in our Terms and Conditions, any title, right or interest in the Customer Data shall remain the ownership of the Customer.
- Privacy Policy. Check our privacy policy to discover how we process our customers and visitors data.
How we use AI at Novable
AI is central to what Novable does, so we are explicit about how we use it and what happens to your data.
- AI assists, people decide. Our DeepMatching engine surfaces candidates from activity-based data; senior Novable analysts then validate every shortlist. You never receive a raw, unchecked machine output. There is always a human in the loop.
- Your data is not training data. We do not use your confidential briefs, results or personal data to train public or third-party foundation models.
- Confidential by default. One customer's brief is never used to serve another.
- Data minimisation. Matching runs primarily on public, activity-based signals about companies, not on sensitive personal data.
- Vetted AI providers. Where we use third-party AI services, they operate under agreements that prohibit training on your data and meet our security and privacy requirements.
- Explainable and accountable. Because a person reviews every shortlist, we can explain why a candidate was included. AI accelerates the work; it does not make the final call.
Information security program
Our information security practices are aligned with the ISO/IEC 27001 framework. We operate a documented set of security policies covering access control, data handling, incident response, change management and vendor risk, and we review them regularly.
- Risk-based approach: we identify, assess and treat information security risks on an ongoing basis.
- Security by design: security and privacy are built into how we develop and operate the platform.
- Staff are bound by confidentiality obligations.
Infrastructure and hosting
- The platform is hosted on Amazon Web Services (AWS), in the European Union.
- Encryption in transit: all traffic is encrypted using TLS 1.2 or above.
- Encryption at rest: customer data is encrypted at rest.
- Infrastructure runs on AWS certified, enterprise-grade cloud, and is patched and monitored.
Access control
- Access to customer data is granted on a least-privilege, need-to-know basis and reviewed periodically.
- Employees are bound by confidentiality obligations, and access is removed promptly when no longer required.
Data handling and retention
- We process the briefs you submit, the results we deliver, account information, and public, activity-based company data used for matching.
- Customer data is retained for the duration of the engagement and deleted within 60 days of termination, subject to any legal retention obligations.
- We do not sell customer data.
Business continuity and backups
Customer data is backed up daily, and we maintain procedures to restore service in the event of disruption.
Vulnerability management and responsible disclosure
We monitor our systems and apply security updates on an ongoing basis. If you believe you have found a security vulnerability, please contact us at security@novable.com. We will acknowledge and investigate every good-faith report.
Talk to us
For a DPA, a security questionnaire, our sub-processor list, or any procurement or compliance question, contact security@novable.com or your Novable contact. We are used to working through enterprise supplier-assurance processes and respond promptly.