Noetis — Privacy Policy
Version 2.0 · Effective date: to be announced upon release · Last updated: to be announced upon release
This Privacy Policy describes how Final Frame trading as Noetis processes Personal Data.
1. Who we are
Final Frame Trading as: Noetis KvK: 92376193 Defensie-eiland 110 3441 VL Woerden Netherlands
Privacy contact: chris@noetis.nl
2. Our roles
Legal roles depend on the actual processing.
Noetis acts as Controller for Personal Data concerning its own customers, account users, prospects and business operations.
Noetis generally acts as Processor where it processes Personal Data concerning Visitors of a Customer Property on Customer's behalf.
The Customer operating the relevant website generally determines why Visitor Intelligence, analytics, experimentation or Personalisation is used and is responsible for its own privacy notice and lawful basis.
The DPA governs Noetis's processor activities.
3. Account and business data
As Controller, Noetis may process:
- name;
- email;
- organisation;
- role;
- account information;
- hashed authentication information;
- billing information;
- VAT information;
- payment status;
- IP and device information;
- Service usage;
- security logs;
- support communications;
- integration information;
- marketing preferences;
- transactional communication data.
Payment-card information is generally processed directly by the applicable payment provider rather than stored in full by Noetis.
4. Purposes and lawful bases
Noetis may process Controller data to:
Provide and administer the Service — performance of contract.
Manage billing and accounts — contract and legal obligations.
Protect the Platform and prevent abuse — legitimate interests in security and fraud prevention.
Provide support — contract and legitimate interests.
Maintain and improve Noetis — legitimate interests, subject to appropriate safeguards.
Send required Service communications — contract or legitimate interests.
Marketing — consent or another lawful basis where applicable.
Comply with law and establish or defend claims — legal obligation and/or legitimate interests.
5. When Noetis powers another website
If you visit a website using Noetis, Noetis may process information on behalf of that website operator.
Depending on that operator's configuration and your consent or privacy choices, this may include:
- pages visited;
- clicks;
- scroll depth;
- section visibility;
- time spent;
- navigation behaviour;
- interaction events;
- IP/device/browser information;
- pseudonymous session or Visitor Identifiers;
- repeat-visit information;
- experiment assignments;
- Personalisation information.
6. Visitor Intelligence and profiling
Where lawfully enabled by the website operator, Noetis may associate behavioural information across visits using a pseudonymous Visitor Identifier.
The Service may use those signals to infer or update:
- interests;
- preferences;
- engagement;
- behavioural segments;
- commercial-intent signals;
- persona hypotheses;
- other probabilistic characteristics.
These are inferences, not necessarily verified facts about you.
The relevant website operator determines the purposes for which this functionality is used.
7. Personalisation
Where enabled, Visitor Data may be used to determine which eligible website experience is displayed.
For example, the website may emphasise different:
- wording;
- calls to action;
- sections;
- cases;
- content;
- layout variants.
Noetis may record whether a treatment was selected, rendered, viewed or interacted with so that the website operator can measure performance.
8. Sensitive profiling
Noetis Visitor Intelligence is not designed to infer or personalise based on special categories of Personal Data such as racial or ethnic origin, political opinions, religion, health or sexual orientation, whether directly or through deliberate indirect proxies.
Customers are contractually prohibited from using the Service for prohibited sensitive profiling.
9. Significant automated decisions
Noetis does not design Visitor Intelligence for decisions based solely on automated processing that produce legal or similarly significant effects concerning Visitors.
Customers are contractually restricted from using the Service for such purposes without specific approval and appropriate legal safeguards.
10. Cookies and similar technologies
Noetis uses cookies and similar technologies on its own Sites as described in the Cookie & Similar Technologies Policy.
On Customer Properties, Noetis may operate similar technologies on the Customer's behalf.
The website operator is responsible for obtaining consent where required.
Consent-dependent persistent recognition and profiling should only be activated following a supported affirmative consent signal; an unknown, missing, malformed, rejected or withdrawn consent state does not count as consent.
11. AI
Noetis uses AI systems to provide functionality including content generation, recommendations, experimentation, Personalisation and autonomous optimisation, as described in the AI & Autonomous Systems Policy.
Relevant information may be transmitted to AI providers acting as subprocessors where required to provide the feature.
Noetis does not intentionally use Customer Data to train public or shared third-party foundation models.
12. Recipients
Noetis uses service providers for infrastructure and operation, which may include providers of:
- cloud hosting;
- databases;
- authentication;
- AI inference;
- payments;
- transactional email;
- analytics/search integrations;
- monitoring and security.
The current processor/subprocessor information is maintained in the applicable legal documentation.
13. International transfers
Where Personal Data is transferred outside the EEA, Noetis uses an applicable Chapter V GDPR mechanism, which may include:
- adequacy decisions;
- the EU-US Data Privacy Framework where valid and applicable;
- Standard Contractual Clauses;
- supplementary measures where appropriate.
Information concerning applicable safeguards is available on request.
14. Retention
Noetis retains Personal Data only as long as reasonably necessary for the relevant purpose and legal obligations.
Different retention periods apply to different data classes, including:
- account information;
- tax/billing records;
- security logs;
- raw behavioural events;
- session data and Visitor Identifiers;
- Visitor Profiles and Derived Data;
- experiment assignments and outcomes;
- Personalisation Records;
- consent-related information;
- session recordings;
- AI request metadata, stored prompts and AI Outputs;
- deletion/suppression records;
- backups.
For Customer-controlled Visitor Data, retention is governed by Customer configuration, the DPA and Noetis's applicable retention architecture. Operational retention periods are maintained in the applicable product and compliance documentation once technically verified.
Noetis may de-identify information where continued identifiable retention is unnecessary.
15. Security
Noetis maintains technical and organisational safeguards appropriate to the risk.
Additional information is available in the Security & Compliance Addendum.
No internet or software system can be guaranteed to be completely secure.
16. Your rights
Subject to GDPR requirements and exceptions, individuals may have rights to:
- access;
- rectification;
- erasure;
- restriction;
- portability;
- object;
- withdraw consent;
- lodge a complaint.
Where Noetis acts as Controller, requests may be submitted to chris@noetis.nl.
Where Noetis processes Visitor Data as Processor, the relevant website operator is generally responsible for the request. Noetis will assist that operator as required by the DPA.
17. Consent withdrawal
Where processing is based on consent, consent may be withdrawn.
Withdrawal does not affect the lawfulness of processing before withdrawal.
Where a supported withdrawal is communicated to Noetis for consent-dependent Visitor Intelligence, further use of the relevant Visitor Identifier for that purpose will cease in accordance with the Customer's configuration and the DPA: consent-dependent cross-session recognition, profile enrichment, consent-dependent inference and consent-dependent Personalisation for that identifier stop, background processes do not silently reactivate the withdrawn processing, historical behavioural data is not used to silently reconstruct the withdrawn profile, and a return visit does not by itself reactivate the withdrawn purpose. Where consent is legally required, a new valid affirmative consent is required before that processing may resume.
18. Children
Noetis's business Service is not directed to children.
Customers are responsible for ensuring that their use of Noetis in relation to children complies with applicable law.
Noetis may restrict Visitor Intelligence functionality where use involving children presents unacceptable legal or privacy risk.
19. Complaints
Individuals may complain to their competent supervisory authority.
In the Netherlands this is the Autoriteit Persoonsgegevens.
20. Changes
Noetis may update this Policy as its Service or applicable law evolves.
Material changes will be communicated where required.
Privacy contact: chris@noetis.nl