Noviq Logo Noviq
Legal Operations

Privacy Policy

Last Updated: August 7, 2026

1. Our Data Privacy Mandate

At Noviq Inc. ("Noviq", "we", "us", "our"), we build sovereign operating environments designed for government contractors ("GovCon"). We recognize that the data you process—including active federal solicitation responses, competitive pricing parameters, proprietary distributor network rates, and historical capture bid templates—constitutes core enterprise value. Our privacy practices are programmatically structured to respect and enforce total data ownership.

2. Zero AI Model Training Policy

Under no circumstances does Noviq train global natural language processing models, embeddings, or neural heuristics on customer workspace data. Any inputs you feed into our intelligence modules—such as Excel RFQ parsing lists, distributor quotes, compliance matrices, or competitor tracking histories—are executed strictly in isolated virtual machines. Model processing is handled via private, secure APIs with strict zero-retention parameters, ensuring no competitive telemetry leaks beyond your boundary.

3. Information We Collect and Process

We process information strictly to provision, secure, and maintain your workspace:

  • Account Authentication: Personal corporate identifiers retrieved via secure Google OAuth SSO integration (full names, professional corporate emails, and active tenant domain tags).
  • Operational Pipeline Data: Active opportunity records, solicitation numbers, subcontractor listings, TAA product validation indexes, and user-initiated bid pricing calculations.
  • Audit Telemetry: Log timestamps, login geolocation metrics, modification trail hashes, and API transaction metadata to facilitate federal regulatory auditability (e.g. NIST SP 800-171 standards).

4. Logical Database Segregation

All databases inside Noviq are logically segregated at the tenant-level using cryptographically isolated connection parameters. Your workspace content is never co-mingled or processed alongside adjacent corporate accounts. This protects against cross-tenant data bleed, unauthorized administrative overrides, and accidental exposure.

5. Encryption Standards

Noviq enforces AES-256 encryption-at-rest for all persistent relational database backends, static documents, and cache pools. All networking transactions, browser sessions, and proxy handshakes utilize Transport Layer Security (TLS 1.3) protocols natively, rendering all packet captures completely unreadable to interceptors.

6. International Data Governance

To accommodate DFARS, ITAR, and general federal procurement safeguards, Noviq operates its core infrastructure exclusively within secure data center zones physically located in the United States. No customer workspace data is stored, cached, or audited by personnel outside domestic parameters.

7. Data Rights and Deletion

Your data is entirely your property. Tenants can request complete workspace extraction or permanent database destruction at any point. Upon authorization, our engineering pipeline triggers an unrecoverable hard-wipe of all database instances, media buckets, and session caches within 48 hours.

8. Legal and Compliance Queries

For comprehensive security questionnaires, control matrices, or data processing agreements (DPAs) regarding your workspace, please contact our privacy compliance office at security@getnoviq.com.