SECURITY AND COMPLIANCE

    How we handle your data and your calls

    Novara Tech is run by a founder with a masters in cybersecurity. These decisions are made before the first call is answered, not after an incident.

    Data residency

    Client application data, contact records and call logs are stored in Australia. Some language and speech processing is performed by providers located in the United States, under their standard data processing terms. We state this plainly rather than claiming end-to-end Australian processing: audio transcription and response generation transit US-located infrastructure, while the systems of record remain in Australia.

    Hosting regions: our application database and file storage run on Supabase in ap-southeast-2 (Sydney). Workflow execution runs on Oracle Cloud Infrastructure in ap-sydney-1 (Sydney). Language and speech processing is performed in the United States under standard data processing terms.

    Call recording and consent

    Every agent opens by identifying itself as an AI and advising that the call may be recorded. This wording is configured per client at deployment, and a caller who declines recording is still assisted - the agent continues the conversation without retaining audio, or hands the call through to a person where the client has one available.

    Australian recording law differs by state. Consent requirements in Victoria, New South Wales, Queensland and other jurisdictions are not identical, and the recording configuration for each deployment is set according to the state the client operates in.

    The exact consent wording is configured per client to match the recording law of the state the client operates in, and is confirmed with the client before the agent goes live. A caller who declines to be recorded is transferred to a person where the client has one available, or is offered a callback, and no audio is retained for that call.

    Retention and deletion

    Call audio, transcripts and call metadata each carry a default retention period, enforced by the platform rather than by convention. Retention rules are set per tenant at deployment and can be shortened at the client's request.

    A client may request deletion of their data, or of records relating to a specific caller, at any time by emailing us directly. Deletion requests are actioned from the live systems and confirmed in writing once complete.

    Default retention periods:

    • Call audio: 90 days.
    • Transcripts: 12 months.
    • Call metadata and logs: 24 months.
    • Contact form submissions: 24 months.

    These are defaults. A client can ask for shorter periods on any category at deployment, and demo call logs on this website are purged automatically after 30 days.

    Access control

    Access to client data is restricted to the operator of the platform. Authentication is multi-factor, credentials are held in a managed secrets store rather than in code, and administrative access to the data layer is logged.

    The principle is least privilege, stated plainly: no account, service key or integration holds more access than the specific task it performs requires, and access that is no longer required is revoked rather than left in place.

    Subprocessors

    The following subprocessors may process client data in the course of delivering the service. This list is maintained as our stack changes, and clients are given advance notice of material changes.

    ProviderPurposeData processedRegion
    OpenAILanguage modelTranscript textUS
    ElevenLabsSpeech synthesisResponse textUS
    CrazytelAustralian telephony carriageNumbers, call metadataAU
    TwilioLegacy telephony carriageNumbers, call metadataUS
    SupabaseApplication data and logsContact details, call logsAU
    Oracle CloudWorkflow executionVaries by client integrationAU

    Systems we integrate with at a client's direction, such as their booking system, CRM or e-commerce platform, remain under that client's own control and are not subprocessors of Novara Tech.

    Australian Privacy Principles

    The handling described on this page maps to the Australian Privacy Principles under the Privacy Act 1988: collection is limited to what the service requires (APP 3), use and disclosure are limited to delivering the service (APP 6), reasonable security measures are in place (APP 11), and individuals may request access to or correction of their information (APPs 12 and 13).

    The full privacy policy, including how to exercise those rights, is at /privacy-policy.

    Incident response

    If a breach occurs, affected systems are isolated first and the scope is established from access and call logs. Where the breach is likely to result in serious harm, we notify affected individuals and the Office of the Australian Information Commissioner as required under the Notifiable Data Breaches scheme, within the timeframes that scheme sets.

    Clients whose data is affected are notified directly, with a plain account of what happened, what was affected, and what has been done about it.

    Responsible disclosure

    If you believe you have found a vulnerability in our systems, report it to mohammad@novaratech.cloud. Reports are acknowledged and investigated, and we ask that you give us reasonable time to resolve the issue before any public disclosure.

    Reports are acknowledged within two business days, and we will tell you what we found and when it was fixed. General security and compliance questions can go to sales@novaratech.cloud.

    Security questionnaires

    Vendor security assessments and questionnaires are welcomed. Send them directly to mohammad@novaratech.cloud.