What to add to your privacy policy when using novella

This article outlines the privacy policy disclosures you should consider when using Novella to survey your customers and website visitors. It's written for teams running NPS, CSAT, or CES surveys through hosted survey pages, the embeddable widget, or email surveys.

This is general guidance, not legal advice. Your specific obligations depend on your business, your markets, and how you configure Novella. Talk to your legal counsel or DPO before finalizing your policy.

1. Identify Novella as a processor

Under GDPR, you (the business collecting feedback) are the data controller. Novella acts as your data processor. Your privacy policy should name Novella (or describe it as a customer feedback platform provider) in the section listing the processors or service providers who handle personal data on your behalf.

If you maintain a subprocessor list or a "who we share data with" section, include:

  • Novella — customer feedback and survey platform
  • Purpose: collecting and analyzing customer feedback (NPS, CSAT, CES surveys)
  • Location of processing: EU (Frankfurt, Germany)

2. Describe what data is collected through surveys

Depending on how you've configured your surveys, Novella may collect:

  • Survey responses (ratings, free-text comments)
  • Respondent identifiers you pass in (name, email address, customer ID)
  • Metadata such as timestamp, survey type, and which product or touchpoint triggered the survey
  • For the embeddable widget: browser and device information, IP address, and session-level data needed to display and track the widget
  • For email surveys: email open and click data

Your policy should describe these categories in plain language so visitors and customers understand what's collected when they respond to a survey or interact with the widget on your site.

Common legal bases for customer feedback surveys include:

  • Legitimate interest — for standard NPS, CSAT, or CES surveys sent to existing customers as part of an ongoing relationship
  • Consent — if you're surveying website visitors who aren't yet customers, or if local rules in a specific market require opt-in

If you rely on legitimate interest, be prepared to explain the balancing test you've done (this doesn't need to be in the public policy, but you should have it documented internally).

4. Disclose the widget's use of cookies or local storage

If you're using Novella's embeddable widget on your website, it may use cookies or browser storage to avoid showing the same survey repeatedly to the same visitor and to track response state. This needs a mention in your cookie policy or cookie banner, not just your privacy policy, including:

  • What the cookie does
  • How long it persists
  • Whether it's used for anything beyond survey display logic (e.g. linking to session recordings, if you've connected Novella to a tool like Microsoft Clarity)

5. Cover international data transfers, if relevant

Novella's infrastructure runs in the EU (Hetzner, Frankfurt), and its analytics layer (Tinybird) is also EU-hosted (Frankfurt). If all your processing stays within Novella's EU infrastructure, your transfer disclosures are simpler. If you use integrations that send survey data to non-EU tools (certain CRMs, BI platforms, or your own downstream systems), disclose those transfers and the safeguard used (e.g. Standard Contractual Clauses).

6. Set and disclose a retention period

Decide how long you keep survey responses and respondent data, and state it. Common approaches:

  • Keep individual responses for a fixed period (e.g. 24 months) and then anonymize or delete
  • Keep aggregated/anonymized trend data indefinitely, delete identifiable data on a schedule

Your policy should reflect whatever retention setting you actually use, not a generic placeholder.

7. Explain data subject rights

Include the standard GDPR rights section if you don't already have one: access, rectification, erasure, restriction, portability, and objection. Make clear how a respondent can ask you to delete their feedback data, since these requests come to you as the controller, not to Novella directly. You're responsible for relaying deletion or access requests to Novella if needed.

8. Mention the Data Processing Agreement

If you've signed a Data Processing Agreement (DPA) with Novella, you can reference that your processor relationships are governed by DPAs consistent with Article 28 GDPR. You don't need to publish the DPA itself, just note that one is in place.

Checklist

  • [ ] Novella listed as a processor/subprocessor
  • [ ] Categories of survey data described
  • [ ] Legal basis stated (legitimate interest and/or consent)
  • [ ] Widget cookies disclosed in cookie policy
  • [ ] International transfer disclosures updated if using non-EU integrations
  • [ ] Retention period set and stated
  • [ ] Data subject rights section present and accurate
  • [ ] DPA referenced if signed

Questions

If you need documentation to support your privacy policy update, our sales or support team can provide our subprocessor list, DPA, and security overview on request.