Skip to content

Published policy

Data Handling SOP

Our operating standard for protecting customer documents while producing bounded, review-ready outputs.

Effective: 4 October 2026 · Last updated: 4 October 2026

1.Purpose and scope

This standard operating procedure governs how Novatra receives, accesses, processes, reviews, returns and deletes customer documents and related data for scoped projects.

It applies to Novatra personnel, approved contractors and approved systems. A signed proposal, data-processing agreement or written customer instruction may impose stricter controls; the stricter requirement takes priority.

2.Controls before intake

  • Confirm the business purpose, document types, fields, output format, approved users, processing tools, retention point and acceptance criteria in writing.
  • Use synthetic or redacted examples where practical during initial discovery.
  • Do not accept confidential documents through the public enquiry form. Establish an approved secure exchange method first.
  • Collect only the documents and fields necessary for the agreed work.

3.Classification and access

Customer documents, extracted values and credentials are treated as confidential. Access is limited to named people and systems with a project need. Shared credentials and use of customer data in personal accounts are prohibited.

Access is reviewed when responsibilities change and removed when no longer required. Administrative actions and material processing stages are recorded where the scoped system supports them.

4.Transfer and storage

  • Use the agreed encrypted transfer channel or access-controlled intake location.
  • Store active test documents only in approved access-controlled cloud locations; do not copy them to unmanaged devices or consumer file-sharing services.
  • Keep secrets and access credentials outside source files, documents and output spreadsheets.
  • Use encrypted network transport and the storage protections supplied by the approved platform.

5.Bounded processing and model use

Processing is restricted to the agreed extraction, transformation, validation and output tasks. Ambiguous or missing values are flagged rather than guessed. Novatra does not permit unsupervised direct writes to a customer’s production ERP unless separately designed, authorized and tested in writing.

Customer proprietary data is not used by Novatra to train public or commercial AI models. Where an approved AI-assisted tool is used, its role, data exposure and relevant provider terms are assessed for the project.

6.Human review, outputs and traceability

Outputs are drafts until an authorized customer reviewer accepts them. Exception fields remain visibly identified for human resolution. Where included in scope, output rows retain a source reference such as document, page, line or field location sufficient for review.

The customer remains responsible for commercial approval, accounting treatment and release into downstream systems unless a written agreement expressly assigns a task to Novatra.

7.Retention and secure deletion

The project record defines the acceptance event and deletion timetable. Unless another period is agreed, active test documents and working extracts are removed from active processing locations after written acceptance and completion of the agreed handover.

Deletion is recorded. Encrypted residual backups are not used for ordinary processing and expire through the provider’s backup cycle. Business correspondence, acceptance evidence, invoices and records needed for legal claims may be retained separately; website enquiries normally follow the 24-month period in the Privacy Policy.

8.Incident response

Anyone who suspects unauthorized access, disclosure, alteration or loss must stop unnecessary processing, preserve relevant evidence and notify the responsible Novatra contact immediately. Novatra will assess scope and risk, contain the event, document actions, and notify the customer and authorities when contract or law requires.

Security concerns can be reported to support@novatraindustries.com.

9.Completion checklist and accountability

  • Customer confirms acceptance or identifies exceptions against the agreed checklist.
  • Approved outputs and operating instructions are handed over through the agreed channel.
  • Temporary access is removed and active test data is deleted according to the project record.
  • Deletion, exceptions and any continuing support or retention obligation are documented.
  • Material deviations from this SOP require written approval and a recorded reason.

Defined Retention & Deletion

Active test documents are removed after acceptance and handover under the agreed project record.

No Model Training

Novatra does not use proprietary customer data to train public or commercial AI models.

Review Traceability

Scoped outputs retain source references where included in the agreed workflow.