NovaQAAI AGENT
LEGAL & PRIVACY COMPLIANCE

Privacy Policy & Terms of Service

Last updated: August 24, 2026 • Effective immediately for all NovaQA cloud and on-premise users.

1. Zero-Retention Financial Data Policy

NovaQA does not store, log, or process raw credit card numbers, CVVs, or bank credentials on any of our infrastructure. All payment processing is conducted directly through Paymob Unified Checkout under PCI-DSS Level 1 compliance with timing-safe HMAC SHA-512 cryptographic verification.

2. Multi-Tenant Data Isolation

Customer test artifacts, DOM snapshots, network HAR recordings, video captures, and source code telemetry are strictly isolated using organization-scoped foreign keys and cryptographically verified role-based access control (RBAC). Data belonging to one organization is never accessible by another tenant.

3. AI Diagnostic Data Handling

Failure logs and stack traces transmitted to our AI failure analysis engine are sanitized to remove accidental authorization headers, secret API keys, and session cookies before LLM evaluation. Customer proprietary code is never used to train generalized foundation models without explicit consent.

4. Service Level & Data Retention

Data retention is enforced dynamically according to each tenant's plan tier (7 days for Community, up to 365 days or Unlimited for Enterprise). Automated pruning tasks remove expired sandbox logs to preserve storage quotas and user privacy.