Summary
This summary provides key points from our Privacy Policy.
Who is the data controller?
Novus Strategy & Consulting Ltd (Company No. 12184516), based at Kemp House, 128 City Road, London EC1V 2NX. Our Data Protection Lead is Claire Van der Zant, CEO. You can contact us at privacy@www.novus-strategy.com.
What personal data do we collect?
We collect data you provide through our contact form (name, work email, organisation, role, and message), and data collected automatically when you browse the site (such as IP address, pages visited, and session duration) subject to your cookie preferences.
Do we process sensitive personal data?
No. We do not collect or process special category data such as health information, ethnicity, or political opinions.
What legal bases do we rely on?
We rely on your consent for analytics and advertising cookies, and on legitimate interests for processing enquiry form data and aggregated marketing reporting.
Do we use cookies?
Yes. We use strictly necessary cookies to keep the site functioning, and — with your consent — analytics and advertising cookies via Google Analytics, Google Ads, LinkedIn, and Meta. All non-essential cookies are controlled through our consent banner and can be managed or withdrawn at any time.
Do we share your data with third parties?
We work with a small number of trusted processors including HubSpot, Google, LinkedIn, Meta, Supermetrics, Microsoft, SiteGround, and Complianz. They act only on our instructions and are bound by appropriate data protection agreements.
Is data transferred outside the UK?
Some processors are based in the United States. All transfers are covered by appropriate safeguards, including the EU-US Data Privacy Framework and Standard Contractual Clauses.
How do we keep your data safe?
We use TLS encryption, multi-factor authentication, least-privilege access controls, and Zero Trust Architecture principles. We are working towards Cyber Essentials Plus certification.
How long do we keep your data?
Enquiry data is reviewed and deleted if no engagement progresses within 12 months. Analytics data follows Google’s standard 14-month retention. Advertising data is held per platform settings.
Do we carry out automated decision-making?
No. We do not make any automated decisions about individuals via this website.
What are your rights?
Under UK GDPR you have eight rights, including the right to access, correct, or delete your data, and the right to object to processing. All requests should be sent to privacy@www.novus-strategy.com and will be responded to within one calendar month.
How do you exercise your rights?
Email us at privacy@www.novus-strategy.com. If you are not satisfied with our response, you may complain to the Information Commissioner’s Office at ico.org.uk or on 0303 123 1113.
Who We Are
This Privacy Policy explains how Novus Strategy & Consulting Ltd collects, uses, and protects personal data through our website at www.www.novus-strategy.com.
Novus Strategy & Consulting Ltd is the data controller for the personal data described in this policy.
| Detail | Information |
| Company name | Novus Strategy & Consulting Ltd |
| Company number | 12184516 |
| Registered address | Kemp House, 128 City Road, London EC1V 2NX |
| Data Protection Lead | Claire Van der Zant, CEO |
| Privacy enquiries | privacy@www.novus-strategy.com |
| Website | www.www.novus-strategy.com |
What This Website Does
Our website is a business-to-business (B2B) marketing and thought leadership platform that:
- Showcases our three service lines (Strategy, Design, Deliver) and our proprietary Horizontal Digital Integration (HDI) framework
- Publishes intelligence content, including bulletins and insights articles
- Promotes Novus hosted events and immersion tours
- Hosts a contact and enquiry form, powered by HubSpot
- Links externally to LinkedIn
The website does not sell products, process payments, require visitor login, or provide log-in access to platforms.
What Personal Data We Collect And Why
The table below sets out the categories of personal data we collect through this website, where it comes from, why we collect it, and the legal basis we rely on under UK GDPR.
UK GDPR requires us to have a lawful basis for processing personal data. The two bases we rely on are:
- Consent: you have actively agreed to the processing, for example by accepting cookies.
- Legitimate interests: we have a genuine business reason to process the data that does not override your rights and interests.
| Data collected | Source | Purpose | Lawful basis |
| First name, last name, work email, organisation, role, area of interest, and free-text message | HubSpot contact form | Respond to enquiries; route to the correct team member; record in our CRM | Legitimate interests |
| IP address, browser and device type, pages visited, session duration, referral source | Google Analytics and Google Tag Manager | Understand how the site is used; measure content performance; improve the website | Consent |
| Ad interaction and conversion data (clicks, impressions, conversions) | Google Ads, LinkedIn, Meta | Measure advertising effectiveness; retargeting | Consent |
| Professional profile data (job title, company, LinkedIn activity) | LinkedIn Insight Tag | Audience analytics; campaign attribution | Consent |
| Aggregated marketing performance data | Supermetrics (pulling from Google Analytics, Google Ads, LinkedIn, Meta, and HubSpot) | Consolidated marketing reporting; no new data is collected, this aggregates data already covered by consent | Legitimate interests |
Cookies And Tracking
Our website uses cookies and similar technologies, deployed via Google Tag Manager. A cookie is a small text file placed on your device when you visit a website. We use cookies to help the site work correctly and to understand how visitors use it.
Google Tag Manager itself does not set cookies or collect personal data directly, it manages the deployment of other tags and scripts.
We use four categories of cookies:
| Category | What they do | Consent required? |
| Strictly necessary | Enable core site functionality such as session security and form submission. Without these, the website cannot operate properly. | No |
| Analytics | Google Analytics (including GA4). Measures pages visited, session duration, and traffic source. Data is sent to Google servers in the United States under the EU-US Data Privacy Framework and UK adequacy mechanisms. | Yes |
| Advertising and conversion tracking | Google Ads (conversion tracking and remarketing), LinkedIn Insight Tag (conversion tracking and audience matching), and Meta Pixel (conversion tracking and Custom Audiences). All involve transfers to US-based servers under appropriate safeguards. | Yes |
| Functional / preference | Remembers your preferences to improve your experience on return visits. | Yes |
Managing your cookie preferences
All non-essential cookies are managed through a cookie consent banner, powered by Complianz (a WordPress consent management plugin). No analytics or advertising cookies are set until you have actively consented.
You can review or withdraw your consent at any time by clicking the ‘Cookie Preferences’ link in the footer of any page on our website. You can also manage or delete cookies through your browser settings; your browser’s help function will tell you how.
For general guidance on cookies and how to manage them, visit www.allaboutcookies.org.
Third-Party Processors
We use several trusted third-party suppliers to operate our website and marketing activities. Each acts as a data processor on our behalf, meaning they process data only on our instructions. The table below lists our key processors, their role, where data is held, and the safeguard that covers any international transfer.
| Processor | Role | Data location | Transfer safeguard |
| HubSpot | CRM; contact form processing | United States | EU-US Data Privacy Framework; Standard Contractual Clauses; HubSpot is UK GDPR compliant |
| Google (Analytics, Ads, Tag Manager) | Analytics; advertising measurement; tag deployment | United States | EU-US Data Privacy Framework; UK adequacy mechanisms |
| Advertising; Insight Tag analytics | United States | EU-US Data Privacy Framework; Standard Contractual Clauses | |
| Meta | Advertising; Meta Pixel conversion tracking | United States | EU-US Data Privacy Framework; Standard Contractual Clauses |
| Supermetrics | Marketing data aggregation and reporting | EU / EEA | EU-based processing; Standard Contractual Clauses where applicable |
| Microsoft 365 | Internal email; document management | United Kingdom | UK data residency configured |
| SiteGround / WordPress | Website hosting | European Union | Standard Contractual Clauses |
| Complianz | Cookie consent management; consent record logging | EU (Netherlands) | EU-based; processes consent records only — no behavioural data collected |
Where you interact with LinkedIn or Meta through external links or embedded content, those interactions are also subject to those platforms’ own privacy policies. We recommend you review them independently.
International Data Transfers
Several of our processors are based in the United States. Whenever personal data is transferred outside the UK, we ensure an appropriate safeguard is in place. The safeguards we rely on include:
- The EU-US Data Privacy Framework (and its UK equivalent): a recognised adequacy mechanism for transfers to certified US organisations.
- Standard Contractual Clauses (SCCs): contractual commitments approved by the UK Information Commissioner’s Office (ICO) that bind processors to equivalent data protection standards.
Where data is processed within the EU or EEA, no additional transfer mechanism is required as these territories are covered by UK adequacy regulations.
How We Keep Your Data Secure
We take the security of personal data seriously. Our measures include:
- TLS 1.2+ encryption for all data transmitted to and from the website
- Microsoft 365 with UK data residency for internal email and document management
- Multi-factor authentication and least-privilege access controls across our systems
- Zero Trust Architecture principles applied to our internal infrastructure
- Working towards Cyber Essentials Plus certification
In the event of a personal data breach that is likely to result in a risk to individuals’ rights and freedoms, we will notify the ICO within 72 hours as required by law and will inform affected individuals where required.
How Long We Keep Your Data
| Data type | Retention period |
| Enquiry and contact data (HubSpot) | Retained for as long as needed to manage the enquiry and any resulting client relationship. Reviewed and deleted if no engagement progresses within 12 months. |
| Analytics data (Google Analytics) | Per Google’s standard retention settings (default 14 months). Data is anonymised or aggregated where possible. |
| Advertising data (Google Ads, LinkedIn, Meta) | Per each platform’s standard retention settings. Novus does not independently store this data beyond what is visible in platform dashboards. |
| Supermetrics reporting data | Aggregated and anonymised; retained for internal reporting purposes. |
Automated Decision-Making
Novus does not carry out any automated decision-making or profiling, including decisions made solely by computer that produce legal effects or similarly significant impacts, via this website.
Your Rights Under UK GDPR
As a data subject, you have the following rights in relation to your personal data. To exercise any of these rights, please contact us at privacy@www.novus-strategy.com. We will respond within one calendar month of receiving your request.
| Right | What it means |
| Right to be informed | To receive clear, transparent information about how we use your data, which is the purpose of this Privacy Policy. |
| Right of access | To request a copy of the personal data we hold about you (known as a Subject Access Request). |
| Right to rectification | To ask us to correct personal data that is inaccurate or incomplete. |
| Right to erasure | To ask us to delete your personal data in certain circumstances (also known as the ‘right to be forgotten’). |
| Right to restrict processing | To ask us to pause the processing of your personal data in certain circumstances, for example while a dispute is resolved. |
| Right to data portability | To receive your personal data in a structured, commonly used, machine-readable format, and to transfer it to another organisation. |
| Right to object | To object to the processing of your personal data where we rely on legitimate interests as our lawful basis. We will stop processing unless we can demonstrate compelling legitimate grounds that override your rights. |
| Rights related to automated decision-making | To not be subject to decisions made solely by automated processing that produce legal or similarly significant effects. As noted above, Novus does not conduct this type of processing via this website. |
How to Complain
If you are not satisfied with how we have handled your data or responded to a request, you have the right to lodge a complaint with the UK supervisory authority:
Information Commissioner’s Office (ICO)
- Website: ico.org.uk
- Telephone: 0303 123 1113
We would, however, always appreciate the opportunity to address your concerns directly before you contact the ICO. Please reach out to us first at privacy@www.novus-strategy.com.
Changes To This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our data practices or legal obligations. When we do, we will update the version number and ‘Last updated’ date at the top of this page. We recommend checking this page periodically for updates.
This policy does not form part of any contract and does not create legal rights or obligations beyond those required by applicable data protection law.
Contact Us
If you have any questions about this Privacy Policy or how we handle your personal data, please contact us:
| Contact method | Details |
| privacy@www.novus-strategy.com | |
| Post | Data Protection Lead, Novus Strategy & Consulting Ltd, Kemp House, 128 City Road, London EC1V 2NX |
| Website | www.www.novus-strategy.com |