Privacy Notice

Last updated 21 August 2026

Who provides this service

Noviqent Ltd ("Noviqent", "we", "us") operates the Cloud & Kubernetes Performance & Compliance platform at compliance.noviqent.co.uk. For your account, billing, and audit-log data, Noviqent is the data controller. For the cloud resource configuration, cost, and security data your organisation connects for scanning, your organisation is normally the data controller and Noviqent processes it on your behalf, as described below.

Information we process

  • Account data — name, email address, hashed password (or your Google account identifier, if you sign in with Google), and your organisation membership and role.
  • Audit log data — an append-only record of actions taken in your organisation, kept for accountability.
  • Cloud and Kubernetes data — depending on the connection tier your organisation chooses (see below), this can include resource configuration, cost and usage data, and the security findings generated from the AWS, Azure, GCP, or Kubernetes environments you connect.

How we use it

To operate your account, run the scans your organisation requests, evaluate findings against the compliance frameworks you've opted into, generate cost and reliability recommendations, maintain the audit log, and protect the service from abuse, including reCAPTCHA scoring at registration.

Where your data is processed

This platform offers three connection tiers, and which one your organisation chooses determines what, if anything, reaches Noviqent's infrastructure:

  • Direct connection (Tier 1) — scanning runs on Noviqent's backend, using a narrowly-scoped, read-only role into your cloud account. The full raw configuration of every scanned resource is processed and stored here, alongside the cost data, findings, and recommendations computed from it.
  • In-account collector (Tier 2) — scanning runs inside your own account or cluster, on your schedule. Only findings and recommendations are sent to Noviqent, never the underlying raw configuration, unless your organisation explicitly opts in otherwise.
  • Fully self-hosted (Tier 3) — the entire platform runs on your own infrastructure. Nothing reaches Noviqent at all.

Retention

Account and audit-log data is retained for as long as your organisation's account is active. Scan results and findings are retained according to your organisation's configuration. Deleting your organisation removes associated data, other than what we're required to keep for legal or accounting purposes.

Sharing and sub-processors

We don't sell your data. A small number of third parties support running this service — see our sub-processor register for the current list and exactly what each one receives.

International transfers

Where a sub-processor operates outside the UK or EEA, we rely on an appropriate transfer mechanism, such as the UK's International Data Transfer Addendum, before any transfer takes place.

Your rights

Depending on your role, you or your organisation as data controller may have rights to access, correct, delete, restrict, or port the personal data we hold, and to object to certain processing. Requests relating to your organisation's data should go through your organisation admin where Noviqent is acting as processor. You can also complain to the UK Information Commissioner's Office at ico.org.uk. Noviqent Ltd is registered with the ICO under registration number ZC225920.

Contact

Noviqent Ltd, company no. 17232197, registered in England & Wales. Data protection queries: hello@noviqent.co.uk.

Changes to this notice

We'll update this page when what we process, or why, materially changes.