Privacy Notice
NOVA POST IT S.R.L. (“we”, “us”, “our”, “Company”, “Nova Post“) attach great importance to the security and privacy of your personal data. This Privacy Notice (the "Notice", the “Policy”, the “Privacy Policy”) explains our practices in relation to the processing of personal data of individuals.
This Privacy Policy describes which personal data is collected by the Nova Post App, how it is stored, processed, and used.
About Us
- NOVA POST IT S.R.L.Address
Milan, street Augusto Anfossi 2, 20135
Contact email
If you have a question related to this Privacy Policy, our processing activities, or your data subject rights under the GDPR and other applicable laws, you can contact us directly using the following details: dpo@novapost.com
Data Collection
We collect the following types of personal data through the App:
- A.Contact data: full name, phone number, email address.
- B.Address data: country, city/town/village, pick-up point, home address in case of home delivery to the client, Shipment ID.
- C.Customer support data: private person (first name, last name, TIN, phone number), type of claim (lost cargo, damaged cargo, delayed cargo, other), situation description, compensation amount request, other necessary information provided by client.
- D.Billing data: first name, last name,USREOU code (if necessary), name of organisation.
Purpose of processing
- Data Type
- A.Contact data
- B.Address data
- C.Geolocation data
- D.Customer support data
- E.Billing data
- Reasons for Processing
To provide delivery services.
To provide delivery services.
To identify the closest branch to the merchant.
To handle customer support requests related to issues like lost, damaged, or delayed cargo.
To provide delivery services and to maintain bookkeeping.
- Legal Basis
Performance of a contract (Art. 6(1)(b))
Performance of a contract (Art. 6(1)(b))
Consent of a data subject (Art. 6(1)(a))
Legitimate interest (Art. 6(1)(f))
Performance of a contract (Art. 6(1)(b)) and Legal obligation (Art. 6(1)(c))
Data Security, Integrity, and Retention
We keep your personal data as long as it is needed to fulfil the purposes described in this Policy, unless a law requires us to retain it for a longer period.
If laws such as the GDPR compel us to keep certain information, we may not be able to delete or anonymize it immediately. You can request deletion of your account and all personal data at any time by clicking “Delete account” in Settings or by contacting us through another available channel.
We have implemented appropriate organizational, technical, administrative, and physical safeguards to protect your personal data from unauthorized access, disclosure, use, or alteration, and we regularly review and update our security practices to keep pace with new technologies and methods.
Data Sharing and Disclosure
In principle, we do not share your personal data with anyone but the suppliers and/or partners who help us process your personal data. Anyone who has access to your personal data will always be bound by strict legal or contractual obligations to keep your personal data safe and confidential. This means your personal data can access:
- You;
- Nova Post employees and/or contractors;
- Seller you are buying from;
- National governmental or judicial authorities insofar we are required to send them your personal data.
Shopify: As a Shopify app developer, we interact with Shopify's API and platform. Our use of information received from Shopify APIs will adhere to the Shopify API Terms of Service, including the Shopify API Data Protection Terms.
International data transfers
We may need to transfer your personal data to countries outside the EU and EEA that do not meet the requirements of Article 45 of GDPR on the adequacy of data protection. In such cases, we will transfer your personal data to third countries under Article 46 of GDPR with the appropriate safeguards, including Standard Contractual Clauses (SCC).
Your Rights Under the GDPR
You have the following rights in relation to the processing of your personal data, which we are committed to respecting:
- Right of Access: You have the right to request access to the personal data we hold about you. This includes obtaining confirmation as to whether or not your personal data is being processed, and if so, receiving a copy of the data in an understandable format along with information about how and why we are processing it.
- Right to Rectification: If any of the personal data we hold about you is inaccurate or incomplete, you have the right to request its correction or completion. We will promptly make the necessary changes to ensure your information is up-to-date.
- Right to Erasure (Right to be Forgotten): You have the right to request the deletion of your personal data when it is no longer necessary for the purposes for which it was collected if you withdraw your consent, or if you object to the processing and we have no legitimate overriding interest to continue processing. You can also request erasure if your data is being processed unlawfully or if it must be erased to comply with a legal obligation.
- Right to Data Portability: You have the right to receive the personal data you have provided to us in a structured, commonly used, and machine-readable format. You can also request that we transfer this data to another controller where it is technically feasible.
- Right to Object: You have the right to object to the processing of your personal data at any time, especially in cases where the processing is based on our legitimate interests, including profiling. If you object, we will stop processing your data unless we can demonstrate compelling legitimate grounds for the processing that override your rights and interests or if the processing is necessary for legal claims.
- Right to Restrict Processing: You can request that we limit the processing of your personal data in specific situations, such as when you contest the accuracy of the data, if the processing is unlawful but you prefer restriction over deletion, or if you need the data to be preserved for legal claims despite us no longer needing it for processing purposes.
- Right to Withdraw Consent: If we are processing your personal data based on your consent, you have the right to withdraw that consent at any time. Once consent is withdrawn, we will stop processing your personal data for the purposes you initially agreed to, unless we have another legal basis for continuing the processing.
To exercise any of these rights, please contact us at dpo@novapost.com
Please note that whenever you wish to exercise a right, we will ask you for proof of identity. We would like to avoid an unauthorized person obtaining your personal information while pretending to be you. This would result in a data breach.
Data Protection Authority under the GDPR
We kindly invite you to share your concerns with us in the first place regarding any issue related to your personal data processing. You may use the following channels to address your inquiries: dpo@novapost.com
In some cases, you have the right to lodge a complaint with a data protection authority about our use of your personal data. We are an Italian company, so you can contact the Italian Data Protection Authority (“Garante Privacy” or “Garante”). You can find all information from Garante following this LINK.
Moreover, if you would like to find contact details of other EU data protection authorities, you can find a full list through this link.



