Privacy Policy

Last updated: March 2026

1. Introduction

NOVO.IM (UK) LIMITED, a company registered in England and Wales (company number 15046888), the operator of the RepeatPosts platform ("Company", "we", "us", or "our"), is the data controller responsible for your personal data. We are committed to protecting your privacy in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you use the RepeatPosts platform ("Service"). By using the Service, you acknowledge that you have read and understood this policy.

2. Information We Collect

Information You Provide

  • Account information: Name, email address, and password when you register.
  • Profile data: Additional details you choose to add to your profile.
  • Content: Brand assets, logos, images, templates, and other content you upload to the Service.
  • Payment information: Billing details processed securely by our payment provider, Stripe. We do not store your full credit card number.
  • Communications: Information you provide when contacting our support team or submitting feedback.

Information Collected Automatically

  • Usage data: Pages visited, features used, time spent, and actions taken within the Service.
  • Device information: Browser type, operating system, screen resolution, and device identifiers.
  • Log data: IP address, access times, and referring URLs.
  • Cookies and similar technologies: See our Cookie Policy for full details.

3. Lawful Basis for Processing

Under the UK GDPR, we process your personal data on the following lawful bases:

  • Contract: Processing necessary to perform our contract with you, including providing the Service, managing your account, and processing payments.
  • Legitimate interests: Processing necessary for our legitimate interests, including improving the Service, analysing usage patterns, ensuring security, and preventing fraud. We balance these interests against your rights and freedoms.
  • Legal obligation: Processing necessary to comply with our legal obligations, such as tax, accounting, and regulatory requirements.
  • Consent: Where we rely on your consent (for example, for analytics cookies), you may withdraw that consent at any time.

4. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve the Service
  • Process your transactions and manage your subscription
  • Send you important notifications about your account, such as billing confirmations and security alerts
  • Respond to your support requests and communications
  • Analyse usage patterns to improve features and user experience
  • Detect, prevent, and address technical issues and security threats
  • Comply with legal obligations

We will not use your personal data for purposes materially different from those described here without informing you and, where required, obtaining your consent.

5. How We Share Your Information

We do not sell your personal data. We may share your information in the following circumstances:

  • Service providers: We use trusted third-party services to operate the platform, including cloud hosting (AWS), payment processing (Stripe), email delivery (SendGrid), and security services (Google reCAPTCHA). These providers only access your data as needed to perform services on our behalf and are contractually obligated to protect it.
  • Team members: If you are part of a team, other team members can see shared templates, creations, and brand kits within that team. Your profile name and email may be visible to team members.
  • Legal requirements: We may disclose your information if required by law, regulation, legal process, or governmental request.
  • Business transfers: In the event of a merger, acquisition, or sale of assets, your data may be transferred as part of the transaction. We will notify you of any such change.

6. Data Storage and Security

Your data is stored on secure cloud infrastructure. We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These measures include:

  • Encryption of data in transit (TLS/SSL) and at rest
  • Regular security assessments and updates
  • Access controls limiting who can access your data
  • Secure password hashing

While we take reasonable measures to protect your data, no method of transmission or storage is 100% secure. We cannot guarantee absolute security.

7. International Data Transfers

Your data may be processed and stored in countries outside the United Kingdom, including the United States (for cloud hosting and third-party services). Where data is transferred outside the UK, we ensure appropriate safeguards are in place, including:

  • Transfers to countries with UK adequacy decisions
  • Standard contractual clauses approved by the Secretary of State
  • Other appropriate safeguards as required under the UK GDPR

You may request further details of the safeguards in place by contacting us.

8. Data Retention

We retain your personal data for as long as your account is active or as needed to provide the Service. If you delete your account, we will delete or anonymise your personal data within 30 days, except where we are required to retain it for legal, accounting, or reporting purposes (for example, financial records may be retained for up to 7 years to comply with HMRC requirements). Generated images and uploaded content will be permanently deleted within 30 days of account termination.

9. Your Rights

Under the UK GDPR, you have the following rights regarding your personal data:

  • Right of access: Request a copy of the personal data we hold about you.
  • Right to rectification: Request that we correct inaccurate or incomplete data.
  • Right to erasure: Request that we delete your personal data, subject to legal retention requirements.
  • Right to data portability: Request a copy of your data in a structured, commonly used, machine-readable format.
  • Right to restriction: Request that we restrict the processing of your data in certain circumstances.
  • Right to object: Object to processing based on legitimate interests or for direct marketing purposes.
  • Right to withdraw consent: Where processing is based on consent, withdraw your consent at any time without affecting the lawfulness of prior processing.

To exercise any of these rights, please contact us at [email protected]. We will respond to your request within one month. In complex cases, we may extend this by up to two further months, in which case we will inform you of the extension and the reasons for it.

You will not normally be charged a fee for exercising your rights. However, we may charge a reasonable fee if your request is clearly unfounded or excessive, or we may refuse to comply with your request in such circumstances.

10. Right to Complain

If you are not satisfied with how we handle your personal data or your privacy rights, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority for data protection:

We would appreciate the opportunity to address your concerns before you approach the ICO, so please contact us first.

11. Children's Privacy

The Service is not intended for use by anyone under the age of 18. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child under 18, we will take steps to delete that information promptly.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on the Service and updating the "Last updated" date. For significant changes, we may also notify you via email. Your continued use of the Service after any changes constitutes your acknowledgement of the updated policy.

13. Governing Law

This Privacy Policy is governed by and construed in accordance with the laws of England and Wales.

14. Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact our data controller:

See also our Cookie Policy and Terms of Service.