Legal
Privacy Policy
Last updated:
This Privacy Policy explains how Novita collects, uses, stores, and protects your personal information when you use our platform and services.
1. Who We Are
Novita is a social welfare platform dedicated to supporting individuals and families through recovery, mental health care, cyber safety awareness, and rehabilitation services. Our platform is operated as a non-commercial educational and welfare project. When we refer to "Novita", "we", "our", or "us" in this policy, we mean the Novita platform and its administrators.
You can contact us regarding privacy matters at: our contact page.
2. Information We Collect
We collect personal information in the following ways:
2.1 Information You Provide Directly
- Account registration: full name, email address, password, date of birth, phone number, address.
- Profile: profile image, school/college name, personal details.
- Service inquiries: subject, messages, and attachments you send when requesting expert support.
- Support tickets: descriptions of issues, category, priority, and related messages.
- Admission requests: full name, email, phone, age, primary concern, preferred admission date.
- Expert applications: professional title, bio, specialization, years of experience, and service interests.
- Contact messages: name, email, subject, and message content.
- Blog posts & community content: text, images, categories you author or interact with.
- Recovery data: check-in logs, mood scores, goals, milestones, and appointment records.
2.2 Information Collected Automatically
- Session identifiers and authentication tokens stored in browser cookies.
- Pages visited, features used, and navigation patterns (not shared with third parties).
- Device type, browser type, and operating system (for compatibility and debugging only).
3. How We Use Your Information
We use the personal information we collect for the following purposes:
- Provide platform services: create and manage your account, process service inquiries, and respond to support requests.
- Recovery support: display your recovery dashboard, milestone tracking, and appointment management.
- Expert matching: connect client requests to qualified experts based on service type.
- Admission management: process rehab admission requests and deliver admin updates to applicants and guardians.
- Communication: respond to contact form submissions and provide system notifications.
- Safety and moderation: review content for compliance with our community standards.
- Platform improvement: analyse usage patterns to improve features and fix issues.
- Legal compliance: comply with applicable laws and protect against abuse.
We do not sell your personal data, run advertising on your data, or share it with marketing third parties.
4. Sensitive Health Information
Novita handles sensitive health and recovery data, including mental health status, substance use history, and rehabilitation records. We treat this information with the highest level of care:
- Only authorised staff and assigned experts can access health-related records.
- Recovery check-in data and therapy notes are private and not publicly visible.
- Admission requests are visible only to the submitting user and platform administrators.
- Admin update notes sent to applicants are for the applicant/guardian only.
5. How We Share Information
We only share your personal information in the following circumstances:
- With assigned experts: when you submit a service inquiry, the assigned expert may see your name, contact details, and inquiry content.
- With platform administrators: staff can access all platform data for moderation, support, and operational purposes.
- Legal obligations: if required by law or a lawful authority request, we may disclose relevant data.
- Emergency safety: if we reasonably believe disclosure is necessary to prevent harm to you or others.
We do not share data with external analytics companies, social networks, or advertising platforms.
6. Data Retention
We retain your personal data for as long as your account is active or as needed to provide services. Specific retention periods:
- Account data: retained until you request deletion of your account.
- Recovery records: retained for the duration of your active account.
- Contact messages & support tickets: retained for up to 3 years for audit and safety purposes.
- Admission request records: retained for up to 5 years in line with health service record-keeping practices.
- Expert applications: retained for 2 years from date of submission.
You may request deletion of your account and associated data at any time via the contact page.
7. Security
We take reasonable technical and organisational measures to protect your data:
- All passwords are hashed using Django's PBKDF2 algorithm — we never store plain-text passwords.
- Session tokens and CSRF protection are enforced on all forms.
- Access to admin functions is restricted to verified staff accounts.
- Uploaded files (attachments, images) are stored in non-public directories.
Despite these measures, no online platform can guarantee absolute security. Please use a strong, unique password and keep your login credentials private.
8. Cookies
Novita uses only essential session cookies required for authentication and CSRF protection. We do not use advertising, tracking, or analytics cookies. No third-party cookies are set by our platform.
9. Your Rights
You have the following rights regarding your personal data:
- Access: request a copy of the data we hold about you.
- Correction: request correction of inaccurate or incomplete data.
- Deletion: request deletion of your account and personal data (subject to legal retention obligations).
- Restriction: request that we limit processing of your data in certain circumstances.
- Objection: object to specific uses of your data.
To exercise any of these rights, contact us. We will respond within 30 days.
10. Children's Privacy
Our platform is not intended for children under 13 years of age. We do not knowingly collect personal data from children under 13. If you are a parent or guardian and believe your child has submitted data, please contact us and we will delete it promptly.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When changes are material, we will update the "Last updated" date at the top of this page. We encourage you to review this policy periodically. Continued use of the platform after changes constitutes acceptance of the updated policy.
12. Contact Us
If you have any questions about this Privacy Policy or how we handle your data, please contact us via our contact page or submit a support ticket.