novela.ro

Privacy Policy


Privacy and Personal Data Protection Policy (GDPR)


I. General Information

SC MY NOVELA S.R.L., a commercial company registered with the Trade Register under no. J2017000468350, VAT number RO37094870, with its registered office in Timișoara, Strada Petre Cermena no. 1, Corp A1, Timiș County, Romania (“We”, “the Company”, or “the Data Controller”), is committed to protecting the confidentiality, integrity, and security of your personal data. This Privacy and Personal Data Protection Policy applies to the website novela.ro, as well as to the “Novela” application and related services made available by us. Through this document, we aim to provide transparency regarding the categories of personal data we collect, the purposes for which we process them, the legal bases on which we rely, the safeguards we apply, and the rights available to you under applicable data protection law, including Regulation (EU) 2016/679 (“GDPR”).

II. Scope

This policy explains how we collect, use, store, disclose, and protect the personal data of users, visitors, customers, and other individuals interacting with our services. It also describes your rights in relation to your personal data and how you may exercise them. We encourage you to read this policy carefully before using our services, creating an account, or signing in through third-party authentication providers such as Google.

III. Contact Information

If you have any questions, concerns, or requests regarding this policy or the way in which we process your personal data, you may contact us using the following details:

IV. Categories of Personal Data We Collect

Depending on the way in which you interact with our services, we may collect and process the following categories of personal data:

V. Data Collected When You Sign In with a Third-Party Provider

Signing in with Google

If you choose to create an account or sign in using your Google account, we may receive certain personal data from Google, depending on the permissions you grant and the scopes configured for our application. This may include:

We only access and use Google account data for the purposes described in this policy and in connection with the services provided through Novela. We do not sell personal data obtained through Google Sign-In to third parties.

Signing in with Facebook

If you choose to create an account or sign in using your Facebook account, we receive from Meta the data covered by the permissions you grant — typically your name, your email address and your account identifier with that provider. We use them to create and identify your account, to prevent duplicate accounts, and to communicate with you about your account. Deleting your Novela account does not delete your Facebook account; you may revoke our application's access at any time from the settings of that platform. The component that provides this sign-in is also able to collect an advertising identifier — see the dedicated section on advertising and measurement below.

VI. Data Collected in the Novela Mobile Application

The Novela application processes categories of data that do not arise on the website. We describe them separately so that you can see exactly what leaves your device and why.

VII. The Novela AI Assistant (Pixxel)

Novela offers an automated assistant, Pixxel, available on the website and as a tab in the mobile application. This section describes what happens to what you type into it.

VIII. Advertising, Measurement and Analytics

We do not display advertising inside Novela. We do, however, use measurement technologies, and one of them involves an advertising identifier. We prefer to state this plainly rather than leave it implicit.

You may withdraw consent for marketing measurement at any time; withdrawal does not affect the lawfulness of processing carried out before withdrawal, and it does not affect your ability to use the service.

IX. How We Collect Personal Data

We collect personal data through the following methods:

X. Purposes of Data Processing

We process your personal data for one or more of the following purposes:

XI. Legal Bases for Processing

We process personal data only where we have an appropriate legal basis under Article 6 GDPR or, where applicable, other relevant provisions of data protection law. Depending on the context, processing may be based on:

XII. Data Recipients and Disclosure

We do not disclose your personal data to third parties except where such disclosure is necessary, proportionate, and lawful. Depending on the service involved, recipients may include:

Where personal data is shared with service providers acting on our behalf, we require them to process personal data in accordance with applicable law, appropriate confidentiality obligations, and adequate security standards. We do not sell your personal data, including personal data obtained through Google Sign-In, to third parties.

The service providers we rely on for these purposes currently include: our hosting and infrastructure provider; our content delivery and security provider; the payment processor that handles card transactions; the app store platform through which in-app purchases are made; the provider of our push notification infrastructure; the key management service that protects content encryption keys; the invoicing provider; the courier companies that deliver physical orders; and the social platforms through which you may choose to sign in. Each of them processes personal data on our behalf, under contract and only for the purpose for which it was engaged, or as an independent controller where the law characterises them as such.

XIII. International Data Transfers

As a general rule, your personal data is processed within the European Union or the European Economic Area. If, in specific cases, personal data is transferred to a country outside the European Union or the European Economic Area, such transfer will only take place where permitted by applicable law and subject to appropriate safeguards, such as an adequacy decision, standard contractual clauses, or other legally recognized protection mechanisms.

XIV. Data Retention

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including for the provision of services, compliance with legal obligations, resolution of disputes, enforcement of agreements, and protection of our legitimate interests. Retention periods may vary depending on the type of data and the legal or operational context in which it is processed.

Data associated with your account, including information obtained through Google Sign-In, may be retained for as long as your account remains active or as otherwise necessary for the provision of our services. If you request deletion of your account or personal data, we will assess and process the request in accordance with applicable legal requirements, subject to any lawful retention obligations that may apply. Once the applicable retention period expires, the data will be securely deleted, anonymized, or irreversibly de-identified, so that you can no longer be identified from it.

As a guide, and subject to the criteria above: data required for accounting and tax purposes is kept for the period imposed by fiscal legislation; the record of in-app purchases is kept for seven years; account and profile data is kept for as long as the account is active and is removed when the account is deleted; technical and security logs are kept for a limited period, ordinarily not exceeding twelve months, unless a longer period is necessary to investigate an incident; and records relating to reading licences are kept for as long as the licence is valid and for a reasonable period thereafter for accounting and anti-fraud purposes.

XV. Security Measures

We implement appropriate technical and organizational measures designed to protect personal data against unauthorized or unlawful access, use, disclosure, alteration, loss, or destruction. Such measures may include, as appropriate, encryption in transit, secure communication protocols, access control mechanisms, role-based access restrictions, authentication procedures, internal confidentiality obligations, logging and monitoring measures, data minimization practices, and periodic reviews of our security posture.

Although we strive to apply a level of security appropriate to the risk, no method of transmission over the internet or method of electronic storage can be guaranteed to be completely secure. For this reason, while we take reasonable and appropriate steps to protect your data, we cannot guarantee absolute security.

XVI. Cookies and Similar Technologies

Our website and application may use cookies and similar technologies to ensure proper functionality, maintain security, remember preferences, analyze traffic, measure performance, and improve the overall user experience. Where required by law, non-essential cookies or similar technologies will only be used with your consent. For more information, please refer to any cookie notice or cookie management tools made available on our website or application.

In the mobile application there are no cookies in the browser sense. The equivalent role is played by software components integrated into the application — those that provide sign-in with a social account, those that deliver push notifications, those that process in-app purchases and those that record usage events. They may store identifiers locally on your device and may communicate with their providers. The pages of this website that are displayed inside the application are shown in a reduced mode that does not set analytics or marketing cookies.

XVII. Rights of Data Subjects

Under the GDPR and other applicable data protection laws, you may have the following rights, subject to the conditions and limitations provided by law:

To exercise any of these rights, please contact us using the details provided in Section III above. We may request reasonable information to verify your identity before responding to your request.

XVIII. Data Breach Procedure

In the event of a personal data breach, we will assess the nature and impact of the incident and take appropriate steps to contain, investigate, mitigate, and remedy the situation. Where required by applicable law, we will notify the competent supervisory authority and, where necessary, the affected data subjects, within the legally prescribed timeframe.

XIX. Children and Age-Sensitive Content

Our services may include books or materials that are not suitable for minors. For this reason, we may use age-related information made available to us, including information obtained through Google Sign-In where the user has granted such permission, in order to apply age-sensitive visibility or access controls. If a user is determined to be under the applicable age threshold, certain content categories may be hidden, restricted, or otherwise not made available through the platform.

Users who are above the applicable age threshold may, where such functionality exists, have the ability to manage certain mature-content visibility preferences in their account settings. We encourage parents or legal guardians to supervise minors when using online services.

XX. Changes to This Policy

We may update or modify this Privacy and Personal Data Protection Policy from time to time in order to reflect changes in legal requirements, technical standards, business operations, platform functionality, or data processing practices. Any updated version will be published on this page and will become effective as of the date of publication, unless otherwise stated. We encourage you to review this page periodically to remain informed about how we process and protect your personal data.

XXI. Acknowledgement

By accessing or using the website novela.ro, the “Novela” application, or related services, you acknowledge that your personal data may be processed in accordance with this Privacy and Personal Data Protection Policy. Your continued use of our services after any updates to this policy constitutes your acknowledgement of the revised version, to the extent permitted by applicable law.


Thank you for your trust and continued cooperation!