Privacy and Personal Data Protection Policy (GDPR)
I. General Information
SC MY NOVELA S.R.L., a commercial company registered with the Trade Register under no. J2017000468350, VAT number RO37094870, with its registered office in Timișoara, Strada Petre Cermena no. 1, Corp A1, Timiș County, Romania (“We”, “the Company”, or “the Data Controller”), is committed to protecting the confidentiality, integrity, and security of your personal data. This Privacy and Personal Data Protection Policy applies to the website novela.ro, as well as to the “Novela” application and related services made available by us. Through this document, we aim to provide transparency regarding the categories of personal data we collect, the purposes for which we process them, the legal bases on which we rely, the safeguards we apply, and the rights available to you under applicable data protection law, including Regulation (EU) 2016/679 (“GDPR”).
II. Scope
This policy explains how we collect, use, store, disclose, and protect the personal data of users, visitors, customers, and other individuals interacting with our services. It also describes your rights in relation to your personal data and how you may exercise them. We encourage you to read this policy carefully before using our services, creating an account, or signing in through third-party authentication providers such as Google.
III. Contact Information
If you have any questions, concerns, or requests regarding this policy or the way in which we process your personal data, you may contact us using the following details:
Company: SC MY NOVELA S.R.L.
Address: Strada Petre Cermena no. 1, Corp A1, Timișoara, Timiș County, Romania
Email: contact@novela.ro
IV. Categories of Personal Data We Collect
Depending on the way in which you interact with our services, we may collect and process the following categories of personal data:
Identification and contact data: such as first name, last name, email address, telephone number, username, billing or shipping details, and other information you voluntarily provide when registering an account, placing an order, contacting us, or interacting with our platform.
Account and profile data: such as account credentials, profile details, profile photo, saved preferences, account settings, and other information associated with your user account.
Technical and device data: such as IP address, browser type, browser language, operating system, device type, app version, log data, access timestamps, and similar technical information necessary for the operation, security, and improvement of our services.
Usage and interaction data: such as browsing behavior on our website or application, viewed pages, clicks, searches, wishlist or account activity, preferences, reading interests, product interactions, and other analytics or engagement data.
Communication data: such as messages sent through contact forms, support requests, email correspondence, survey responses, feedback, reviews, ratings, and other communications you send to us.
Transaction-related data: such as order details, payment status, invoicing details, delivery information, and other information necessary to process purchases and provide our services. We do not store full payment card details unless expressly stated otherwise by the payment provider under its own policies.
Cookies and similar technologies data: such as data collected through cookies, pixels, SDKs, and similar technologies used for essential functionality, analytics, security, performance, personalization, and, where permitted, marketing or advertising purposes.
Moderation data: if you report a review or a reply from our assistant, we record which content you reported, the reason you selected, the moment of the report and the fact that it came from your account, together with a copy of the reported text. If a review is hidden or restored following a report, we also record which administrator took the decision and when. This is what allows a report to be examined and a decision to be explained afterwards.
V. Data Collected When You Sign In with a Third-Party Provider
Signing in with Google
If you choose to create an account or sign in using your Google account, we may receive certain personal data from Google, depending on the permissions you grant and the scopes configured for our application. This may include:
Email address: used to create your account, authenticate you, allow a faster and easier login experience, prevent duplicate accounts, and communicate with you regarding your account or our services.
Profile photo: used to personalize your account and, where applicable, to display your avatar within your user profile or in areas of the platform where user identity is visually presented, such as account sections, reviews, ratings, or other user-generated content features.
Gender: where made available through the permissions granted by you, this information may be used to prefill certain profile fields and to support a more relevant and personalized on-platform experience, including content organization, account personalization, and product recommendation logic, where applicable.
Date of birth or age-related information: where made available through the permissions granted by you, this information may be used to determine whether your account should be treated as belonging to a user above or below the applicable age threshold for access to mature or age-restricted content. This helps us prevent the display of books or materials that may not be appropriate for minors, including certain titles containing explicit, violent, or otherwise mature themes. Where available, adult users may also be given account-level options regarding the visibility of such content.
We only access and use Google account data for the purposes described in this policy and in connection with the services provided through Novela. We do not sell personal data obtained through Google Sign-In to third parties.
Signing in with Facebook
If you choose to create an account or sign in using your Facebook account, we receive from Meta the data covered by the permissions you grant — typically your name, your email address and your account identifier with that provider. We use them to create and identify your account, to prevent duplicate accounts, and to communicate with you about your account. Deleting your Novela account does not delete your Facebook account; you may revoke our application's access at any time from the settings of that platform. The component that provides this sign-in is also able to collect an advertising identifier — see the dedicated section on advertising and measurement below.
VI. Data Collected in the Novela Mobile Application
The Novela application processes categories of data that do not arise on the website. We describe them separately so that you can see exactly what leaves your device and why.
Unique device identifier and device binding. When you sign in from the application, we generate an identifier for that installation and send it with each request. We use it to bind your session to the device, to enforce the limit on the number of devices that may access purchased content, to recognise a new device and ask you to confirm it, and to block a device where we detect abuse. If you delete your account, the devices linked to it are marked as blocked so that the account cannot simply be recreated on the same handset. Legal basis: performance of the contract and our legitimate interest in preventing fraud and unauthorised redistribution.
Reading licences and protected content. Books, e-books and audiobooks purchased through Novela are delivered in protected form. To make them readable on your device, the application generates a cryptographic key pair; the public part is sent to us and the private part never leaves your device. We store the licences issued to you, the devices they are bound to, and access logs for those licences. We use these records to deliver the content you paid for, to allow offline reading for a limited period, and to detect abnormal patterns of access. Legal basis: performance of the contract and legitimate interest in protecting the rights of authors and publishers.
Push notification token. If you allow notifications, the operating system issues a token that lets us send messages to that installation. We use it for messages relating to your orders, your account and the security of your account, and — only where you have agreed — for informational messages. You can withdraw the permission at any time from the operating system settings. Legal basis: performance of the contract for service and security messages; consent for the rest.
Location. When you choose delivery to a parcel locker, the application may ask for access to your location in order to show the lockers nearest to you on the map. Location is used at that moment, for that purpose, and only if you grant the permission; refusing it does not prevent you from choosing a locker manually. Legal basis: consent.
In-app purchases. Purchases of crystals are made through the app store, not directly by us. We receive from the store a purchase token and transaction details, which we verify with the store in order to credit your balance and to keep the accounting record of the transaction. We do not receive your card details. Legal basis: performance of the contract and legal obligation.
Device integrity signals. In order to protect purchased content, the application may determine whether the environment in which it runs shows signs of tampering and may request an attestation from the app store platform. The result is a verdict about the device, not information about you or about other applications. We use it to decide whether protected content may be delivered to that device. Legal basis: legitimate interest in preventing unauthorised access to protected content.
Reading activity. Reading progress, bookmarks and sample chapters you have opened are stored so that you can continue on any of your devices and so that we can recommend relevant titles. Legal basis: performance of the contract and legitimate interest.
VII. The Novela AI Assistant (Pixxel)
Novela offers an automated assistant, Pixxel, available on the website and as a tab in the mobile application. This section describes what happens to what you type into it.
What is processed. The messages you send to the assistant, the replies it generates, and the moment each was created. While you are signed in, a conversation is linked to your account so that you can find it again in your account area.
Why. To answer your questions about the catalogue, orders and the service, to operate and secure the feature, and to review reported responses. Legal basis: performance of the contract for the assistant itself, and legitimate interest in keeping the service functional, safe and free of abuse.
Who else sees it. To generate a reply, your message and the recent context of the conversation are transmitted to OpenAI, which acts as our processor and runs the language model. OpenAI processes this data on infrastructure located outside the European Economic Area, principally in the United States. That transfer is governed by a data processing agreement concluded with OpenAI, which incorporates the European Commission’s standard contractual clauses. Do not enter payment card details, passwords or other sensitive data into the assistant; it is not the channel for them.
How long. Conversations and their messages are currently retained for an indefinite period, in order to operate the assistant and analyse the quality of its answers. You are in control of your own history: in your account, under «Assistant conversations», you can remove any conversation from your account at any time. Removal detaches it from your account and it disappears from your list; the text itself is kept on our servers in anonymous form, no longer linked to you, until an administrator deletes it permanently. Deleting your account anonymises your conversations in the same way.
Reported responses. If you report a reply generated by the assistant, we keep a copy of the reported text together with your report, so that it can be reviewed. That copy is retained even if the conversation is subsequently removed or deleted — otherwise the evidence of a moderation case could be destroyed by the person who raised it.
The assistant can be wrong. Replies are generated automatically by a language model and may be inaccurate, incomplete or out of date. They do not constitute legal, medical or financial advice. Information that matters — prices, availability, order status, contractual terms — must be confirmed on the corresponding page of the site or from the documents you received.
VIII. Advertising, Measurement and Analytics
We do not display advertising inside Novela. We do, however, use measurement technologies, and one of them involves an advertising identifier. We prefer to state this plainly rather than leave it implicit.
Advertising identifier. The social sign-in component we integrate is able to read the advertising identifier assigned by your operating system and to report application events to its provider. This identifier is generated by the operating system, not by us; you can reset it or opt out of it at any time from your device settings, under the advertising or privacy section. Where this processing is used for marketing measurement, we rely on your consent.
Conversion measurement. Where we run marketing campaigns, we may transmit to the advertising platform events such as a completed purchase, together with identifiers that allow the platform to attribute that event to a campaign. Identifying data transmitted for this purpose is hashed before transmission wherever the platform supports it. Legal basis: consent.
Internal analytics. We record activity on the platform — such as browsing, interactions with products and purchases — in order to understand which sections are used, to operate, secure and improve the service, to personalise your recommendations and to produce aggregate, non-identifiable statistical reports for our publishing partners. While you are signed in, these events are linked to your account, so that features such as your library, your recommendations and your reading history work. For visitors who are not signed in, they are keyed instead to a pseudonymised value derived from the device with a secret salt, which does not identify you. When an account is deleted, its past events are re-keyed to an anonymous value and no longer point to any person. In every case, these events are not used to build advertising profiles and they are not sold to third parties. Legal basis: our legitimate interest in operating and improving the platform, and performance of the contract where the processing is necessary to provide a feature you asked for, such as personalised recommendations. You may object to this processing on grounds relating to your particular situation by writing to us through our Contact page, and you may delete your data and your account at any time.
You may withdraw consent for marketing measurement at any time; withdrawal does not affect the lawfulness of processing carried out before withdrawal, and it does not affect your ability to use the service.
IX. How We Collect Personal Data
We collect personal data through the following methods:
Directly from you: when you create an account, place an order, complete a form, subscribe to communications, contact us, leave a review, update your profile, or otherwise interact directly with our services.
Automatically: through cookies, server logs, SDKs, analytics tools, and similar technologies that collect technical and usage-related information when you browse or use our website or application.
From third-party authentication providers: such as Google, when you choose to register or sign in through such services and authorize the sharing of certain account data with us.
From service providers or partners: where necessary for payment processing, hosting, technical support, delivery, fraud prevention, legal compliance, or the provision of related services.
X. Purposes of Data Processing
We process your personal data for one or more of the following purposes:
Account creation and authentication: to create, manage, secure, and maintain your user account, including when you register or sign in through Google or other supported authentication methods.
Service provision and account management: to provide access to platform features, manage account settings, enable profile functionality, process orders, and deliver the services requested by you.
Personalization of the user experience: to display profile information, tailor certain content, improve account usability, and provide more relevant content, offers, or recommendations based on preferences, profile settings, and platform interactions, where applicable.
Age-appropriate content controls: to help determine whether certain categories of mature or age-sensitive content should be displayed or restricted based on the age-related information available to us.
Communication and support: to send transactional messages, service-related notifications, account confirmations, password reset messages, technical notices, support replies, and, where legally permitted or consented to, newsletters or promotional communications.
Analytics, improvement, and development: to understand how our website and application are used, diagnose issues, monitor performance, detect bugs, improve usability, and develop new tools, services, or features.
Security and fraud prevention: to protect our services, users, systems, and business operations against unauthorized access, abuse, fraud, malicious activity, and other security risks.
Legal and regulatory compliance: to comply with obligations under applicable law, including tax, accounting, consumer protection, and data protection requirements, and to respond to lawful requests from public authorities where required.
Establishment, exercise, or defense of legal claims: where necessary to protect our rights, property, operations, users, or legal position.
XI. Legal Bases for Processing
We process personal data only where we have an appropriate legal basis under Article 6 GDPR or, where applicable, other relevant provisions of data protection law. Depending on the context, processing may be based on:
Consent under Article 6(1)(a) GDPR, where you have expressly given your consent for specific processing activities, such as certain optional communications or permissions-based functions.
Performance of a contract under Article 6(1)(b) GDPR, where processing is necessary for the creation of your account, provision of our services, fulfillment of an order, authentication, support, or other steps taken at your request prior to entering into a contract.
Compliance with legal obligations under Article 6(1)(c) GDPR, where processing is necessary for us to comply with legal or regulatory duties.
Legitimate interests under Article 6(1)(f) GDPR, where processing is necessary for the operation, security, optimization, personalization, or improvement of our services, provided that such interests are not overridden by your fundamental rights and freedoms.
XII. Data Recipients and Disclosure
We do not disclose your personal data to third parties except where such disclosure is necessary, proportionate, and lawful. Depending on the service involved, recipients may include:
hosting, cloud infrastructure, and IT service providers;
payment processors and financial service providers;
courier, logistics, or fulfillment providers, where applicable;
analytics, performance, fraud-prevention, or security service providers;
professional advisers, such as lawyers, auditors, or consultants, where necessary;
public authorities, regulators, courts, or law enforcement bodies, where disclosure is required by law or necessary to protect legal rights.
Where personal data is shared with service providers acting on our behalf, we require them to process personal data in accordance with applicable law, appropriate confidentiality obligations, and adequate security standards. We do not sell your personal data, including personal data obtained through Google Sign-In, to third parties.
The service providers we rely on for these purposes currently include: our hosting and infrastructure provider; our content delivery and security provider; the payment processor that handles card transactions; the app store platform through which in-app purchases are made; the provider of our push notification infrastructure; the key management service that protects content encryption keys; the invoicing provider; the courier companies that deliver physical orders; and the social platforms through which you may choose to sign in. Each of them processes personal data on our behalf, under contract and only for the purpose for which it was engaged, or as an independent controller where the law characterises them as such.
XIII. International Data Transfers
As a general rule, your personal data is processed within the European Union or the European Economic Area. If, in specific cases, personal data is transferred to a country outside the European Union or the European Economic Area, such transfer will only take place where permitted by applicable law and subject to appropriate safeguards, such as an adequacy decision, standard contractual clauses, or other legally recognized protection mechanisms.
XIV. Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including for the provision of services, compliance with legal obligations, resolution of disputes, enforcement of agreements, and protection of our legitimate interests. Retention periods may vary depending on the type of data and the legal or operational context in which it is processed.
Data associated with your account, including information obtained through Google Sign-In, may be retained for as long as your account remains active or as otherwise necessary for the provision of our services. If you request deletion of your account or personal data, we will assess and process the request in accordance with applicable legal requirements, subject to any lawful retention obligations that may apply. Once the applicable retention period expires, the data will be securely deleted, anonymized, or irreversibly de-identified, so that you can no longer be identified from it.
As a guide, and subject to the criteria above: data required for accounting and tax purposes is kept for the period imposed by fiscal legislation; the record of in-app purchases is kept for seven years; account and profile data is kept for as long as the account is active and is removed when the account is deleted; technical and security logs are kept for a limited period, ordinarily not exceeding twelve months, unless a longer period is necessary to investigate an incident; and records relating to reading licences are kept for as long as the licence is valid and for a reasonable period thereafter for accounting and anti-fraud purposes.
XV. Security Measures
We implement appropriate technical and organizational measures designed to protect personal data against unauthorized or unlawful access, use, disclosure, alteration, loss, or destruction. Such measures may include, as appropriate, encryption in transit, secure communication protocols, access control mechanisms, role-based access restrictions, authentication procedures, internal confidentiality obligations, logging and monitoring measures, data minimization practices, and periodic reviews of our security posture.
Although we strive to apply a level of security appropriate to the risk, no method of transmission over the internet or method of electronic storage can be guaranteed to be completely secure. For this reason, while we take reasonable and appropriate steps to protect your data, we cannot guarantee absolute security.
XVI. Cookies and Similar Technologies
Our website and application may use cookies and similar technologies to ensure proper functionality, maintain security, remember preferences, analyze traffic, measure performance, and improve the overall user experience. Where required by law, non-essential cookies or similar technologies will only be used with your consent. For more information, please refer to any cookie notice or cookie management tools made available on our website or application.
In the mobile application there are no cookies in the browser sense. The equivalent role is played by software components integrated into the application — those that provide sign-in with a social account, those that deliver push notifications, those that process in-app purchases and those that record usage events. They may store identifiers locally on your device and may communicate with their providers. The pages of this website that are displayed inside the application are shown in a reduced mode that does not set analytics or marketing cookies.
XVII. Rights of Data Subjects
Under the GDPR and other applicable data protection laws, you may have the following rights, subject to the conditions and limitations provided by law:
Right of access: to obtain confirmation as to whether we process your personal data and, if so, to access that data and related information.
Right to rectification: to request correction of inaccurate personal data or completion of incomplete personal data.
Right to erasure: to request deletion of your personal data in the cases provided by law.
Right to restriction of processing: to request that we limit the processing of your personal data in certain situations.
Right to data portability: to receive the personal data you have provided to us in a structured, commonly used, and machine-readable format and, where technically feasible, to have it transmitted to another controller.
Right to object: to object, on grounds relating to your particular situation, to processing based on legitimate interests, subject to the conditions laid down by law.
Right to withdraw consent: where processing is based on consent, to withdraw that consent at any time without affecting the lawfulness of processing carried out before withdrawal.
Right to lodge a complaint: to submit a complaint to the competent data protection supervisory authority if you believe that your rights have been infringed.
To exercise any of these rights, please contact us using the details provided in Section III above. We may request reasonable information to verify your identity before responding to your request.
XVIII. Data Breach Procedure
In the event of a personal data breach, we will assess the nature and impact of the incident and take appropriate steps to contain, investigate, mitigate, and remedy the situation. Where required by applicable law, we will notify the competent supervisory authority and, where necessary, the affected data subjects, within the legally prescribed timeframe.
XIX. Children and Age-Sensitive Content
Our services may include books or materials that are not suitable for minors. For this reason, we may use age-related information made available to us, including information obtained through Google Sign-In where the user has granted such permission, in order to apply age-sensitive visibility or access controls. If a user is determined to be under the applicable age threshold, certain content categories may be hidden, restricted, or otherwise not made available through the platform.
Users who are above the applicable age threshold may, where such functionality exists, have the ability to manage certain mature-content visibility preferences in their account settings. We encourage parents or legal guardians to supervise minors when using online services.
XX. Changes to This Policy
We may update or modify this Privacy and Personal Data Protection Policy from time to time in order to reflect changes in legal requirements, technical standards, business operations, platform functionality, or data processing practices. Any updated version will be published on this page and will become effective as of the date of publication, unless otherwise stated. We encourage you to review this page periodically to remain informed about how we process and protect your personal data.
XXI. Acknowledgement
By accessing or using the website novela.ro, the “Novela” application, or related services, you acknowledge that your personal data may be processed in accordance with this Privacy and Personal Data Protection Policy. Your continued use of our services after any updates to this policy constitutes your acknowledgement of the revised version, to the extent permitted by applicable law.
Thank you for your trust and continued cooperation!