
Novara Human Capital Solutions
Privacy Policy
Effective as of May 1, 2024.
Who We Are
Novara Human Capital Solutions (“Novara”) is a North American HR Consulting firm that provides guidance and support to companies of all sizes. We are committed to understanding the unique needs, challenges, and long-term objectives of each client, offering a customized service that aligns with their vision. We believe in collaborative partnerships and aim to become a valued extension of our client’s teams, working together to reduce risk, drive goals and deliver on initiatives.
How We Care for Your Personal Information
Novara is dedicated to protecting your personal data. This privacy policy contains essential information about the personal data we collect, and how and why we collect, store, use, and share personal data. Novara designed and manages the site you are viewing.
This Privacy Policy applies to the collection and use of information of the websites and platforms where this policy is linked (“Sites”, “Website”, “Novara Applicant Sites”). None of the Sites publish content or collect data that is targeted at or relates to children under the age of 18.
The use of information collected through our Sites shall be limited to the purpose for which it was gathered, i.e., providing a service for which a Client has engaged Novara or Novara is gathering information for research purposes (hereinafter “Product Sites”), providing information to prospective Clients (hereinafter “Website”), or gathering information on applicants for career opportunities with Clients (hereinafter “Novara Applicant Sites”). For our “Product Sites”, Novara will abide by the laws that govern the applicable jurisdiction, solely to the extent that we process your data subject in the jurisdiction covered by each applicable law. For the “Website” and Novara Applicant Sites, Novara will be the controller of your data. The terms of which are detailed below.
a) “we”, “us” or “our” - refer to Novara Human Capital Solutions
b) “Client” - Client is an organization who has contracted Novara to perform services on their behalf. Client may also mean your employer.
c) “Our Data Protection Officer” - DataProtectionOfficer@novarahcs.com
d) “Personal Data” - Specific types of information relating to an identified or identifiable individual according to established information classifications
Personal Data We Collect
Categories of personal data we may collect about you as part of our product sites
· First Name and Last Name
· Email address
· Publicly available career information
· Data subject to request records
Categories of personal data we may collect about you as part of our applicant sites
· Employment application data
· Assessment results
· Employment history
· Professional accolades
Categories of personal data we may collect about you as part of our website
· First Name and Last Name
· Email address
Novara collects personal data drawn from inferences from the information identified above to create a profile about users who have opted-in to Novara-related products and/or services. These inferences include information about:
Consumer preferences
User characteristics
Behavior
How Your Personal Data Is Collected
Novara collects personal data directly from Novara’s Website, public sites, indirectly from your employer with your consent, or directly from you as an applicant. Novara may also collect information via automated monitoring of our websites and other technical systems and via communication systems such as email and instant messaging services.
Why and How We Use Your Personal Data
Purpose: To provide products and/or services to your employer
Reason: For the performance of our contract with your employer or to take steps at your employer’s request before entering a contract
Purpose: To verify identity
Reason: To comply with our legal and regulatory obligations
Purpose: Other processing necessary to comply with professional, legal, and regulatory obligations that might apply to our business, e.g., health and safety regulations.
Reason: To comply with our legal and regulatory obligations
Purpose: Gathering and providing information required by or relating to audits, inquiries, or investigations by regulatory bodies
Reason: To comply with our legal and regulatory obligations
Purpose: Ensuring business policies are adhered to, e.g., policies governing security and information use
Reason: For our legitimate interests or those of your employer, i.e., to make sure we are following our own internal procedures so we can deliver the best service to you
Purpose: Operational reasons, such as improving efficiency, training, and quality control
Reason: For our legitimate interests or those of your employer, i.e., to be as efficient as we can so we can deliver the best service for you at the best price
Purpose: Ensuring the confidentiality of commercially sensitive information
Reason: For our legitimate interests or those of your employer, i.e., to protect trade secrets and other commercially valuable information
To comply with our legal and regulatory obligations
Purpose: Statistical norming in relation to the services provided by Novara. (Data that is used for statistical norming is de-identified.)
Reason: For our legitimate interests or those of your employer to ensure fair and accurate data sets and measurement tools
Purpose: Statistical analysis to help us manage our business, e.g., in relation to delivery of services, product performance, or other efficiency measures (Data that is used for statistical norming is de-identified.)
Reason: For our legitimate interests or those of your employer, i.e., to be as efficient and relevant as we can so we can deliver the best service for you at the best price
Purpose: Preventing unauthorized access and alteration to systems
Reason: For our legitimate interests or those of your employer, i.e., to prevent and detect criminal activity that could be damaging for us and for you
Purpose: Updating and enhancing client’s records
Reason: For the performance of our contract with your employer or to take steps at your employer’s request before entering into a contract
To comply with our legal and regulatory obligations
For our legitimate interests or those of a third party, e.g., making sure that we can keep in touch with our clients/you about existing orders and new products
Purpose: Ensuring safe working practices, staff administration and assessments
Reason: To comply with our legal and regulatory obligations
For our legitimate interests or those of a third party, e.g., to make sure we are following our own internal procedures and working safely so we can deliver the best service to you
Purpose: Marketing our services to:
Existing and former clients
Third parties who have previously expressed an interest in our services;
Reason: For our legitimate interests or those of a third party, i.e., to promote our business to existing and former clients
Purpose: External audits and quality checks, e.g., accreditations, and the audit of our accounts
Reason: For our legitimate interests, i.e., to maintain our accreditations so we can demonstrate we operate at the highest standards applicable in our industry
To comply with our legal and regulatory obligations
To use the full functionality offered by the Sites, a user may be required to provide certain Personal data.
How We Use Anonymized Aggregate Data
Summaries of de-identified or anonymized and aggregated data analyses may be presented to public audiences (e.g., scientific conferences). A review of Novara’s general approaches and accumulated results with professional audiences ensures that Novara’s assessment methods remain up-to-date with best practices and professional, technical, and legal standards. While these summaries may be linked to general industries, the identities of client organizations and individuals remain confidential.
Summaries of aggregated data may also be used to create normative profiles (or “benchmarks”) for assessments. Normative profiles will not identify individuals or client organizations; however, the source data may link back to some or all the client organizations that are contained within the data set for defining the characteristics of the norm sample (such as platform, industry, etc.)
Circumstances Under Which We Share Personal Data
Novara will never sell your Personal Data.
We only allow our service providers to handle your personal data if we are satisfied, they take commercially reasonable and appropriate measures to protect your personal data. We also impose contractual obligations on service providers to confirm they can only use your personal data to provide services to us, to you, or to remain compliant with applicable laws and regulations of pertinent jurisdictions. We may also share personal data with external auditors about the audit of our accounts.
We may also need to share some personal data with other parties, such as potential buyers of some or all of our business during a restructuring. We will typically anonymize or de-identify information, but this may not always be possible. Recipients of your personal data will be bound by confidentiality obligations.
Novara will be responsible for the actions of any service providers to whom your Personal Data has been transferred in their performance of Services provided to you, your employer, or Novara.
Applicant Site
Novara routinely shares personal data with
· Our affiliates and licensees
· Other third parties we use to help us run our business, such as marketing agencies or website hosts
· Third parties approved by you
· Law enforcement agencies and regulatory bodies to comply with legal and regulatory obligations
Website
Novara routinely shares personal data with
· Other third parties we use to help us run our business, such as marketing agencies or website hosts
· Third parties approved by you
Third-party Use of Personal Data
Online Surveys
Novara’s third-party online survey provider collects and stores user information in a secure and private manner on behalf of Novara to manage online surveys. This provider allows Novara to create surveys and questionnaires for distribution to potential survey respondents.
Our third-party online survey service provider maintains respondent information that may include information about Novara survey recipients, and other demographics and data useful to Novara. Our third-party online survey provider uses the information they collect to improve the service they provide to Novara. No information is shared with other third parties.
Advertising
We engage a third-party ad network to either display advertising on our Sites or to manage our advertising on other sites. Our third-party partner may use technologies such as cookies to gather information about your activities on this Site and other sites to provide you advertising based upon your browsing activities and interests.
Promotional Communications
Novara may use your personal data to send you updates by mail, email, telephone, text message, or other instant message about our products and services, including exclusive offers, promotions, new products and/or suggested services.
Novara maintains a legitimate interest in processing your personal data for promotional purpose (see above “How and why we use your personal data”). This means we do not usually require your consent to send you promotional communications. However, where consent is needed, we will ask for this consent separately and clearly prior to the communication.
Novara will always treat your personal data with the utmost respect and never sell it to other organizations.
Novara may ask you to confirm or update your marketing preferences if you instruct us to provide further products or services in the future, or if there are changes in the law, regulation, or the structure of our business.
Testimonials
Novara may post client testimonials on our Sites, which may contain personal data. We do obtain the client's consent via email prior to posting the testimonial to post their name along with their testimonial. If you wish to have your personal data removed from this section of our site, please contact us at DataProtectionOfficer@novarahcs.com.
How Long We Keep Your Personal Data
We retain your personal data for as long as needed or permitted considering the purpose(s) for which it was obtained. The criteria used to determine our retention periods include:
The length of time we have an ongoing relationship with you or our client (your employer)
A period to respond to any questions, complaints, or claims made by you or on your behalf
Whether there is a legal obligation to which we are subject (for example, certain laws require us to keep records for a certain period before we can delete them)
Whether retention is advisable to fulfill a lawful request made by a regulatory body of an applicable jurisdiction
How We Keep Your Personal Data Secure
Novara is committed to protecting the security of your personal data. We use a variety of security technologies and procedures to help protect your personal data from unauthorized access, use, or disclosure. Novara complies with applicable data protection laws, including applicable security breach notification laws.
How to Exercise Your Rights or Contact Us
If you would like to exercise any of your rights as described in this Privacy Policy, please:
By email at: DataProtectionOfficer@novarahcs.com
Or by postal mail sent to:
Attn: Novara Data Protection Officer
Novara Human Capital Solutions
330 5th Avenue S.W. Suite 1800
Calgary, AB T2P 0L4
Changes to this Privacy Notice
Novara may change this privacy notice from time to time. When we do, we will post changes on the Sites and other places deemed appropriate, so our users are always aware of what information we collect, how we use it, and under what circumstances, if any, we share or disclose it.
Choice/Opt-out
Consent to the collection, use, and disclosure of Personal Information may be given in various ways. Consent may be expressed (e.g., orally, electronically, or on a form you may sign describing the intended uses and disclosures of Personal Information) or implied (e.g. when you provide information necessary for a service you or your employer has requested. In some circumstances, you are deemed to have given consent where notice has been provided to you about our intentions concerning your Personal Information and you have not withdrawn your consent.
Where permitted by applicable law, consent may be given by your authorized representative (such as a legal guardian, a person having a power of attorney, or a mandatary).
By providing us with Personal Information:
• You represent that you have read and understood this Privacy Policy,
• You consent to the collection, use, and disclosure of such Personal Information for the purposes (i) identified or described in this Privacy Policy, (ii) identified at the time you provide the Personal Information, or (iii) otherwise identified to you before you provide the Personal Information. Those who do not agree to this Privacy Policy may not use the Sites. Users also have the right to revoke prior consent at which time access to Sites and usage of Services would cease.