Privacy Policy
Last updated: October 7, 2026
NovaReps is a voice AI platform operated by Bluecarbon Technologies Inc., a Canadian company based in Toronto, Ontario ("NovaReps", "we", "us", "our"). This Privacy Policy explains what personal information we collect, why we collect it, who we share it with, how long we keep it, and the rights you have over it.
It covers our website at novareps.ai, the NovaReps dashboard and applications, the website voice widget, our free tools and chat assistant, and the calls and text messages that run through the platform (together, the "Services").
If you do not agree with this Privacy Policy, please do not use the Services.
1. Who this policy applies to and the role we play
NovaReps handles personal information in two different roles. Which one applies decides who answers your request.
When we decide why and how information is used (controller, or the accountable organization under Canadian law). This applies to:
- Visitors to our website and users of our free tools and chat assistant
- People who fill in a form, book a call or contact our sales or support team
- Account owners, team members, agency and reseller users, and partner program members
- Billing and payment contacts
When we process information for a Customer (processor or service provider). Our customers ("Customers") are businesses, agencies and resellers that build voice agents on NovaReps. They decide who is called, what the agent says, whether calls are recorded and how long records are kept. For the callers, call recipients, website visitors and contacts their agents speak with ("End Users"), the Customer is the controller and we act on the Customer's instructions under our Terms of Service.
Where an agency resells NovaReps to its own clients, the agency and its client are responsible for the End Users, and we process that information for them.
If you are an End User who spoke with an agent built on NovaReps, the business that ran that agent is responsible for your information. Please contact that business first. If you contact us, we will pass your request to the Customer where we can identify it and help them respond.
2. Information we collect
2.1 Information you give us on the website
- Forms. Name, email address, phone number, business name, business type, team size, call volume, the message you write, and your consent choices. We also record the page the form was sent from and your IP address.
- Chat assistant. The messages you type, your email address if you give it, the page you were on, your IP address and a session identifier. The chat assistant is automated and runs on an AI language model.
- Free tools and calculators. The numbers you enter are used in your browser to produce an estimate. If a tool asks for your email to send a result, we keep that email and the result.
- Newsletter and updates. Your email address and your subscription status.
- Partner program applications. Contact details, business details and the information needed to pay commissions.
2.2 Account and billing information
- Identity and login. Name, email address, a hashed password, login records, multi factor or passkey credentials, and profile details received from Google if you sign in with Google (name, email address and verified email status).
- Organization. Company name, business details, team members and their roles, white label settings such as your domain, logo and colours.
- Billing. Plan, subscription status, invoices, usage and payment history. Card details are collected and stored by our payment processor, Stripe. We receive a token and limited card details such as the brand and last four digits. We do not store full card numbers.
- Provider credentials. If you bring your own keys or your own carrier account, we store those credentials encrypted and use them only to run your agents.
- Support and communications. Emails, messages and call notes when you contact us.
2.3 Customer Data processed through the platform
When a Customer runs agents on NovaReps, we process the following for that Customer:
- Voice and call data. Live call audio, caller and recipient phone numbers, call direction, time, duration, status, routing and transfer events, and voicemail detection results.
- Recordings, transcripts and summaries. Where the Customer turns recording on, an audio recording of the call. A text transcript and an AI generated summary of the call.
- Text messages. The content and delivery details of SMS sent or received, such as missed call text back, appointment reminders and replies.
- Scheduling data. Appointment times, attendee names, email addresses, phone numbers and booking details read from or written to a connected Google or Microsoft calendar.
- Outbound campaign data. Contact lists uploaded by the Customer (names, phone numbers and any other fields the Customer includes), call outcomes, answers to qualifying questions, callback requests, Do Not Call entries and the Customer's own record that it has consent to call.
- Caller memory. Where the Customer enables it, a short profile of a returning caller so the agent can recognise context from earlier calls.
- Knowledge content. Documents the Customer uploads and web pages the Customer asks us to read so the agent can answer questions.
- Website voice widget data. Microphone audio after the visitor starts a conversation, the page the widget is on, and any visitor context the Customer chooses to pass in.
- Integration data. Webhook payloads sent to the Customer's systems and, on Enterprise, data exchanged with the Customer's own API tools and MCP connections.
Customers decide what their agents ask for. We ask Customers not to collect payment card numbers, health information, government identifiers or other sensitive information through an agent unless they have agreed that use with us in writing.
2.4 Information collected automatically
- IP address, approximate location derived from it (country or region), browser type, device type, operating system and language
- Pages viewed, links clicked, referring page, and time and date of visits
- Dashboard activity, feature usage, error logs and performance data
- Security data such as failed logins, bot checks and records of who accessed personal information inside the platform
2.5 Information from other sources
- Sign in providers such as Google, when you choose to use them
- Calendar providers you connect
- Telephone carriers, which give us call status and number information
- Payment processors, which tell us whether a payment succeeded
- Partners and affiliates who refer you to us
2.6 Voice data and biometrics
We process voice audio to transcribe speech and to respond to it. We do not create voiceprints, and we do not use voice recordings to identify or authenticate a person.
3. How we use information and our legal bases
We use personal information only for the purposes below. Where the GDPR or UK GDPR applies, the legal basis is shown for each purpose. In Canada we rely on your consent, which may be express or implied depending on the situation and the sensitivity of the information, or on an exception allowed by law.
- To provide the Services. Create and run accounts, connect calls, transcribe and respond to speech, book appointments, send text messages, run campaigns and deliver webhooks. Legal basis: performance of a contract, and for End Users our Customer's instructions.
- To bill and collect payment. Charge subscriptions, measure usage, send invoices and prevent payment fraud. Legal basis: performance of a contract and legal obligation.
- To answer you. Reply to forms, chat messages, demo requests and support questions. Legal basis: steps taken at your request before a contract, and legitimate interests.
- To send marketing. Product news, guides and offers by email, and calls or texts where you ticked the consent box. Legal basis: consent, which you can withdraw at any time.
- To keep the Services secure. Detect abuse, spam, fraud and unlawful calling, check for bots, investigate incidents and enforce our Terms. Legal basis: legitimate interests and legal obligation.
- To measure and improve the Services. Understand which pages and features are used, fix errors and plan capacity. Legal basis: legitimate interests, and consent where the law requires it for analytics cookies.
- To meet legal duties. Keep tax and accounting records, answer lawful requests and defend legal claims. Legal basis: legal obligation and legitimate interests.
We do not use personal information for purposes that are incompatible with the ones above without telling you and, where required, asking for your consent.
4. Artificial intelligence and automated processing
NovaReps agents use speech to text, language models and text to speech to hold a conversation, classify a request, book an appointment, transfer a call or trigger a workflow. These actions happen automatically and usually without a person reviewing them at the time.
- No model training by us. We do not use Customer call recordings, transcripts or contact data to train or fine tune AI models, ours or anyone else's.
- AI providers. Audio and text are sent to the AI providers listed in section 6 so they can return a transcript, a response or a voice. On platform managed keys we use their business or API services. Where a Customer uses its own keys, that provider handles the data under the Customer's own agreement with it.
- No decisions with legal effect. We do not use automated processing to make decisions about you that have legal or similarly significant effects. Customers must not use the Services to make such decisions about End Users without a person involved. If you believe an automated action affected you, you can ask the responsible business, or us, for a person to review it.
- Accuracy. AI output can be wrong or incomplete. Customers are responsible for testing their agents and reviewing results.
- Website chat assistant. Messages you send to the chat assistant on our site are sent to a language model provider to generate a reply. Please do not enter sensitive information in the chat.
5. Calendar access and Google user data
When you authorise it, the Services access connected calendars, including Google Calendar and Microsoft Outlook or Microsoft 365. Access is limited to reading availability and creating, changing or cancelling the appointments needed for scheduling. Calendar data is not used for advertising.
You can revoke calendar access at any time in your account settings or with the calendar provider.
NovaReps.ai's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google Workspace data to develop, improve or train generalized AI or machine learning models. We do not transfer Google user data to others except as needed to provide the scheduling feature you asked for, to comply with the law, or as part of a merger or sale with notice to you.
6. Who we share information with
We do not sell personal information. We do not share it for cross context behavioural advertising. We share it only as described here.
6.1 Service providers
These providers process information for us so the Services can run. Each one processes it under its own service terms and data protection terms.
- Telephone and SMS carriers: Twilio and Telnyx. Call audio, phone numbers, text message content and call details.
- Speech to text: Deepgram. Live call audio for transcription.
- Language models: OpenAI, Anthropic, Google (Gemini), xAI (Grok) and DeepSeek, depending on the model the Customer selects for an agent. Conversation text, instructions and knowledge content.
- Text to speech: ElevenLabs, Cartesia, Deepgram and Twilio, depending on the voice the Customer selects. The text the agent is about to speak.
- Calendars and sign in: Google and Microsoft. Appointment details and, for sign in, profile details.
- Payments: Stripe. Billing contact, payment method and subscription details.
- File storage and hosting: Amazon Web Services and our cloud hosting providers. Recordings, uploaded files, databases and backups.
- Network security and bot protection: Cloudflare, including Cloudflare Turnstile on forms, login and the voice widget. IP address and browser signals.
- Email delivery and newsletters: our transactional email provider and MailerLite. Name, email address and message content.
- Website analytics: Google Tag Manager and Google Analytics, and other measurement tools loaded through Google Tag Manager, which may include Microsoft Clarity. Device data, pages viewed and interactions.
- Website chat assistant: OpenAI or DeepSeek. The messages you type into the chat.
- Location lookup for forms: ipapi.co, used to guess your country so phone number fields are formatted correctly. It receives your IP address.
- Internal team tools: messaging and alerting tools such as Discord and Slack, where our team receives a notice when a form is submitted or a system alert fires.
The model, voice and carrier used on a call depend on how the Customer set up the agent. We update this list when we add or replace a provider.
6.2 Bring your own keys and carrier
If a Customer connects its own AI provider keys or its own Twilio or Telnyx account, call data goes to that provider under the Customer's own agreement with it. That provider is the Customer's provider, not our service provider, for that data.
6.3 Customers, agencies and resellers
Call records, transcripts, recordings and contact data are available to the Customer that runs the agent. Where an agency manages a client account, the agency can see that client's data as the client allows.
6.4 Integrations a Customer turns on
When a Customer sets up a webhook, calendar, API tool or MCP connection, we send data to the destination the Customer chose. The Customer is responsible for that destination.
6.5 Legal, safety and business transfers
We may disclose information where the law, a court order or a valid request from a public authority requires it, or where it is needed to investigate fraud, protect the safety of any person, or establish and defend legal claims. If we are involved in a merger, financing, acquisition or sale of assets, information may be transferred as part of that transaction under confidentiality, and the new owner must continue to honour this policy or notify you of changes.
6.6 With your consent
We share information in other ways only when you ask us to or agree to it.
7. Cookies and similar technologies
We use cookies, local storage and similar technologies.
- Strictly necessary. A security token that protects forms from forged requests, a session cookie for logged in areas, and bot protection checks. The site does not work properly without these.
- Functional. Local storage entries that remember your cookie choice, your chat session, whether you dismissed a popup, whether you already subscribed, and a country guess used to format phone number fields.
- Analytics and measurement. Google Tag Manager, Google Analytics and tools loaded through them, which may set cookies and collect your IP address, device details and how you use the site.
Fonts on our website are served from our own servers, so loading a page does not send a request to a font provider.
Your choices. By using our website you agree to the cookies described here. You can block or delete cookies in your browser settings, or use the Google Analytics opt out add on. Where our website shows a cookie banner or a "Cookie settings" link in the footer, you can use it to decline analytics cookies. We do not sell personal information or share it for cross context behavioural advertising, so there is no sale or sharing to opt out of. If you block strictly necessary cookies, forms and login may stop working.
8. Call recording, consent and outbound calling
The Customer running an agent decides whether calls are recorded and transcribed, who is called and what the agent says. The Customer is responsible for:
- Telling callers that a call may be recorded or transcribed, and getting consent where the law requires it
- Telling people they are speaking with an AI agent where the law requires it
- Having the consent needed to call or text a person, and honouring Do Not Call lists and opt out requests
- Following the telemarketing, anti spam and call recording laws that apply to it and to the people it contacts
NovaReps provides controls that help, such as calling hour windows, an internal Do Not Call list, daily caps, cooldowns and opt out handling. These controls support compliance. They do not replace the Customer's own legal duties, and we do not check a Customer's call lists or consent records.
If you received an unwanted call or text from an agent built on NovaReps, you can ask the agent to stop calling you, reply STOP to a text message, or contact us at the address in section 16 with the number that called you and the time of the call. We may pass it to the Customer and review it under our acceptable use rules. The Customer, and not NovaReps, placed the call and is responsible for it.
9. How long we keep information
We keep personal information only as long as needed for the purpose it was collected for, and then delete or anonymise it. The periods below are our current defaults. They can vary by plan and Customer settings and may change.
- Call recordings. For the retention period of the Customer's plan, which is 30 days by default, unless the Customer deletes them sooner. Recordings past that period are deleted by a scheduled process.
- Transcripts, summaries and call records. For as long as the Customer's account is active, unless the Customer deletes them sooner.
- Outbound contacts and leads on the platform. 365 days by default from when they were added, unless an active campaign still needs them or the Customer deletes them sooner.
- Caller memory profiles. 12 months by default after the caller's last contact.
- Account data. For the life of the account. When an account owner asks for deletion, the account is closed at once and the data is permanently deleted after a 30 day grace period.
- Billing and tax records. For the period required by Canadian tax and accounting law, generally six to seven years.
- Website form submissions and chat conversations. Until we no longer need them to deal with your enquiry or our relationship with you, or until you ask us to delete them.
- Marketing contacts. Until you unsubscribe. We then keep a minimal record so we do not contact you again.
- Security and access logs. For a limited period needed to investigate incidents.
- Backups. Deleted data may remain in encrypted backups for a short period until those backups are overwritten.
We may keep information longer where the law requires it or where it is needed for a legal claim.
10. How we protect information
We use administrative, technical and physical safeguards that are appropriate to the sensitivity of the information, including:
- Encryption in transit using TLS
- Encryption at rest for provider keys, calendar tokens and carrier credentials
- Passwords stored as hashes, with multi factor and passkey sign in available
- Separate login systems for our staff and for Customers
- Data scoped to each account so one Customer cannot see another Customer's calls or contacts
- A separate carrier subaccount for each tenant where the plan supports it
- A record of who accessed personal information inside the platform
- Access to production systems limited to people who need it
No system is completely secure, and we cannot guarantee the security of information. You send information to us at your own risk. You are responsible for keeping your password and devices safe and for telling us quickly if you think your account has been compromised.
Breach notification. If a breach of security safeguards involving personal information under our control creates a real risk of significant harm, we will notify affected individuals and regulators where and as the law requires. Where we process information for a Customer, we notify that Customer, and the Customer is responsible for notifying its own End Users and regulators.
11. Where information is processed
We are based in Canada. We and our service providers process and store information in Canada, the United States and other countries where those providers operate. We do not offer a guarantee that data stays in a particular country or region.
When information is in another country, it is subject to the laws of that country, and courts, law enforcement and national security authorities there may be able to access it.
For personal information from the European Economic Area, the United Kingdom and Switzerland: Canada is recognised as providing adequate protection for information subject to the Personal Information Protection and Electronic Documents Act. For transfers to other countries, where the law requires a transfer mechanism we rely on the mechanisms our providers make available, such as standard contractual clauses.
Residents of Quebec: your information may be communicated outside Quebec as described in this section.
12. Your rights and choices
You can exercise your rights by emailing us at the address in section 16. Account owners can also export their data and delete their account from the Data and Privacy page in the dashboard. We do not charge for a reasonable request and we will not treat you differently for making one.
We need to confirm your identity before acting on a request. We answer within the time the law that applies to you allows. We may refuse a request where the law permits, for example where it is unfounded, repetitive or would affect another person's rights.
12.1 Everyone
- Unsubscribe from marketing emails using the link in any email
- Reply STOP to a text message to stop texts
- Ask an agent, or us, not to call you again
- Change cookie settings in your browser
12.2 Canada
Under the Personal Information Protection and Electronic Documents Act and provincial laws that are substantially similar, you may:
- Ask whether we hold personal information about you and get access to it
- Ask us to correct information that is inaccurate or incomplete
- Withdraw consent, subject to legal or contractual limits and reasonable notice. We will tell you what withdrawing means for your use of the Services
- Challenge our compliance by contacting our Privacy Officer
Residents of Quebec also have the right to ask for information to be de-indexed or to stop being disseminated in certain cases, to receive computerised information in a structured, commonly used format, and to be told when a decision is based only on automated processing and to have it reviewed by a person.
If you are not satisfied with our answer, you may complain to the Office of the Privacy Commissioner of Canada, the Commission d'accès à l'information du Québec, or the privacy commissioner of your province.
12.3 European Economic Area, United Kingdom and Switzerland
Under the GDPR and UK GDPR you have the right to:
- Access your personal data and receive a copy
- Have inaccurate data corrected
- Have your data erased in certain cases
- Restrict or object to processing, including processing based on legitimate interests and direct marketing
- Receive your data in a portable format
- Withdraw consent at any time, without affecting processing that took place before
- Not be subject to a decision based only on automated processing that has legal or similarly significant effects
You may lodge a complaint with the data protection authority where you live or work.
12.4 California and other United States states
If the California Consumer Privacy Act or a similar state privacy law applies to us, residents of those states have the right to:
- Know the categories and specific pieces of personal information we collected, the sources, the purposes and who we disclosed it to
- Delete personal information we collected from them
- Correct inaccurate personal information
- Opt out of the sale or sharing of personal information and of targeted advertising. We do not sell personal information and do not share it for cross context behavioural advertising
- Limit the use of sensitive personal information. We do not use sensitive personal information to infer characteristics about a person
- Not be discriminated against for exercising these rights
- Use an authorised agent, who must show written permission from you
- Appeal a refusal by replying to our decision. We will answer the appeal in writing
In the last 12 months we collected these categories: identifiers (name, email, phone number, IP address), commercial information (plans and purchases), internet activity (pages viewed and interactions), approximate location, audio information (call recordings where enabled), professional information (business name and role) and account login details. We disclosed them to the service providers in section 6 for the business purposes in section 3.
Where we process information as a service provider for a Customer, please send your request to that Customer.
13. Marketing communications
We send marketing email only where we have your consent or another basis allowed by Canada's Anti Spam Legislation and similar laws. Every marketing email identifies us and includes a working unsubscribe link. We act on an unsubscribe request within 10 business days.
We call or text you for marketing only if you ticked the consent box on a form. That consent is not a condition of buying anything. You can withdraw it at any time.
We will still send service messages about your account, such as invoices, security notices and changes to the Services.
14. Children
The Services are for businesses and are not directed at children. You must be at least 18, or the age of majority where you live, to open an account. We do not knowingly collect personal information from children under 16. If you believe a child has given us personal information, contact us and we will delete it.
Customers must not use NovaReps to knowingly target or collect information from children.
15. Other sites, customer responsibilities and changes
Other sites and services. Our website links to sites we do not run, and Customers connect NovaReps to their own tools. This policy does not cover those sites and tools. Please read their privacy policies.
Customer responsibilities. Customers must have their own privacy notice, have a lawful basis for the information they collect through their agents, give End Users the notices the law requires, and set recording, retention and integration settings to match their legal duties. NovaReps is a technology platform and does not give legal advice.
Changes to this policy. We may update this Privacy Policy as the Services or the law change. We will post the new version here with a new "Last updated" date. If a change is material, we will give account owners notice by email or in the dashboard before it takes effect. Where the law requires consent for a change, we will ask for it.
16. Contact us and our Privacy Officer
Bluecarbon Technologies Inc. is responsible for personal information under its control and has appointed a Privacy Officer who is accountable for our compliance with this policy and with privacy law.
Bluecarbon Technologies Inc. Attention: Privacy Officer Toronto, Ontario, Canada Email: [email protected] with the subject line "Privacy request"
Please include your name, the email or phone number your request relates to, and what you would like us to do. Do not send sensitive information by email.