Privacy Policy
At Novva Creative, we hold your personal data, artwork, and customer trust to the highest privacy and encryption standards.
PRIVACY POLICY
Last updated: 22 September 2026
1. Personal Data Controller
This Privacy Policy describes how personal data is collected, used, stored, and protected when using novvacreative.mk.
The controller of your personal data is:
- Full registered legal name: Друштво за печатење услуги и трговија НОВАКРЕАТИВ ДООЕЛ Струга
- Short legal name: НОВАКРЕАТИВ ДООЕЛ Струга
- Legal form: ДООЕЛ — single-member limited liability company
- Registered office: ул. Ристо Крле бр. 9, Струга, Republic of North Macedonia
- Email for privacy and data protection inquiries: novakreativ@gmail.com
- Telephone: +389 75 889 596
- Website: https://novvacreative.mk
In this Policy, the controller is referred to as "the Controller", "we", "us", or "Novva Creative".
2. Who This Policy Applies To
This Policy applies to:
- visitors to novvacreative.mk;
- registered users who create an account;
- customers who submit orders for personalized or standard products;
- persons who contact us for customer service, defect claims, or inquiries;
- individuals whose names, shipping details, or contact information are provided for delivery.
3. Categories of Personal Data We Process
3.1 Account and Identity Data
- Email address;
- Google account display name and avatar (if signing in via Google Firebase Auth);
- Phone number and phone verification status (verified via SMS code);
- User identifier (UID) and timestamp of account creation/last login;
- User role permissions (customer, authorized print staff, or owner).
3.2 Order and Delivery Data
- Recipient's full name;
- Delivery telephone number;
- Delivery address: street name, building/house number, apartment, city, and 4-digit postal code;
- Ordered products, sizes, quantities, fabric colors, canvas dimensions, and accessories;
- Total order price, shipping fee, chosen payment method (cash on delivery or bank transfer), and payment status;
- Unique order number (e.g., NV-YYYYMMDD-XXXXX) and order timestamp;
- Delivery notes or customer instructions;
- Customer communications, defect claims, and resolution history.
3.3 Uploaded Designs, Images, and Mockup Files
- Photographs, artworks, illustrations, graphics, typography, or custom texts uploaded by the user;
- Custom positioning, scaling, rotation, and dimensions;
- Generated print-ready files and digital mockup previews;
- Technical metadata associated with uploaded files (file format, dimensions, resolution).
Important note: Uploaded artwork may contain images of you or other individuals. We do not apply facial recognition or biometric identification technologies to your images. Please refrain from uploading sensitive personal data, national identity documents, or biometric data unless strictly agreed upon in advance.
3.4 Technical and Security Data
- IP address;
- Date, time, and duration of requests;
- Device category, browser type, and operating system;
- API endpoint requests and diagnostic logs;
- reCAPTCHA security signals and bot detection scores;
- Error reports and abuse prevention telemetry.
3.5 Local Storage and Technical Cookies
We store necessary operational state directly in your browser's local storage:
- Shopping cart items and configuration;
- Interface language preference;
- Dark/light visual mode preference;
- Authentication session token.
4. Purposes and Legal Bases for Processing
We process personal data in accordance with the Law on Personal Data Protection of the Republic of North Macedonia under the following legal bases:
4.1 Performance of a Contract and Pre-Contractual Steps
- Creating and managing your user account;
- Verifying your phone number via SMS to protect against fraudulent orders;
- Processing, verifying, manufacturing, packaging, and delivering your personalized orders;
- Facilitating customer support, order updates, and defect inquiries;
- Enabling the "My Designs" library for re-orders and personal editing.
4.2 Compliance with Legal Obligations
- Fulfilling statutory accounting, book-keeping, and tax obligations under Macedonian fiscal laws;
- Handling and documenting statutory consumer defect complaints under the Law on Consumer Protection;
- Responding to legitimate requests from public supervisory authorities or law enforcement agencies.
4.3 Legitimate Interests
- Protecting the website, backend infrastructure, and customers against spam, automated abuse, and fraud via Google reCAPTCHA;
- Maintaining system stability, error logging, and technical troubleshooting;
- Defending legal claims or asserting statutory rights before competent judicial or administrative bodies.
4.4 Consent
- We will only send direct marketing communications if you have provided voluntary, unambiguous consent. You may withdraw consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
- We do not publish or display your custom designs in advertising, marketing, or public portfolios without your explicit prior written consent.
5. Authorized Staff and Service Providers
Personal data is accessed exclusively on a strict need-to-know basis:
- Authorized Production & Print Staff: Access is restricted to the customer name, delivery address, phone number, and print design files necessary to produce, inspect, pack, and ship orders.
- Technical Maintenance & Software Engineering: The website developer and infrastructure maintenance providers have access strictly when necessary for hosting, security incident response, technical troubleshooting, and system administration, operating under strict contractual confidentiality instructions.
- Individual employees and maintenance providers are not independent data controllers or sellers.
6. Recipients of Personal Data
We never sell, rent, or trade personal data to third parties. We disclose personal data only to the following necessary recipients:
- Google Firebase and Google Cloud: Infrastructure provider for user authentication, cloud database (Firestore), media storage, backend server hosting (Cloud Run), and security;
- Google reCAPTCHA: Service provider for automated bot and fraud prevention;
- Contracted Courier Services: Standard delivery couriers in North Macedonia receive the recipient's name, address, phone number, and cash on delivery amount solely to perform physical delivery;
- Banking Institutions: When payment is completed via bank transfer, transaction records are processed through licensed banks;
- External Professional Advisors: Certified accountants, auditors, and legal counsel when required for regulatory compliance or defense of legal claims;
- Competent Public Authorities: State Market Inspectorate, Personal Data Protection Agency, tax authorities, or courts where mandated by law.
7. Google, Firebase, Cloud Run, and International Transfers
The website relies on Google Cloud and Firebase infrastructure to ensure security, high availability, and performance.
- Only the production Cloud Run backend is confirmed in the
europe-west1region in Belgium. - We do not claim that all Firebase data stays in Belgium. Firebase services (including Firestore, Authentication, Firebase Storage, and reCAPTCHA) operate across Google's distributed global infrastructure and Content Delivery Network (CDN).
- For this reason, we do not represent that all data is stored exclusively in any single country.
- Where international processing or cross-border data transfers occur, Standard Contractual Clauses (SCCs) apply where applicable, alongside technical encryption, access controls, and data processing agreements under Google Cloud and Firebase Data Processing Terms.
For further details regarding Google's data handling practices:
- Google Privacy Policy: https://policies.google.com/privacy
- Google Terms of Service: https://policies.google.com/terms
- Firebase Data Processing Terms: https://firebase.google.com/terms/data-processing-terms
- Google Cloud Data Processing Addendum: https://cloud.google.com/terms/data-processing-addendum
8. Data Retention Periods
Personal data is retained only as long as necessary to achieve the specific purposes outlined in this Policy, or as required by applicable statutory recordkeeping laws:
- User Account Data: Retained for as long as your account remains active. Upon a verified request for account deletion, personal profile data is purged or anonymized within thirty (30) days, except for historical order records required by law.
- Order, Invoicing, and Transaction Records: Retained for the statutory retention periods prescribed by applicable Macedonian accounting, tax, and consumer-protection legislation.
- Uploaded Designs and Print Files: Retained for as long as required to manufacture, deliver, and support your order, as well as to facilitate re-ordering via "My Designs". Uploaded artwork is deleted within thirty (30) days upon verified customer request, unless necessary for an active order, pending defect claim, or legal duty.
- Security, reCAPTCHA, and Access Logs: Retained for ninety (90) days for diagnostic and security auditing, unless a longer retention is necessitated by an active security incident or law enforcement inquiry.
- System Backups: Data purged from live systems is completely overwritten in encrypted backups within regular backup cycles, not exceeding sixty (60) days.
9. Technical and Organizational Security Measures
We implement comprehensive technical and administrative security controls:
- End-to-end TLS/HTTPS encryption for all data in transit;
- Role-based access control (RBAC) enforced via verified cryptographic custom claims;
- Firestore database security rules preventing unauthorized reads, writes, and role escalations;
- Server-side order verification, schema validation, and price recalculation;
- Phone verification via one-time SMS passwords to prevent forged submissions;
- Automated bot mitigation via Google reCAPTCHA Enterprise.
10. Cookies and Local Storage
We only employ strictly necessary technologies:
- Session and Authentication: Maintaining logged-in status securely;
- Local Storage: Preserving your shopping cart, preferred language, and color theme;
- reCAPTCHA: Identifying malicious bot traffic.
We do not use third-party tracking cookies, advertising pixels (e.g., Meta Pixel), or invasive commercial profiling scripts. If analytics or advertising tools are introduced in the future, this Policy will be updated and explicit consent will be gathered where required by law.
11. Your Statutory Rights as a Data Subject
Under the Law on Personal Data Protection of the Republic of North Macedonia, you have the following rights:
- Right of Access: The right to obtain confirmation as to whether your personal data is being processed and to receive a copy thereof;
- Right to Rectification: The right to obtain rectification of inaccurate or incomplete personal data;
- Right to Erasure ("Right to be Forgotten"): The right to request the deletion of your personal data where statutory grounds apply;
- Right to Restriction of Processing: The right to request the restriction of processing under legally defined circumstances;
- Right to Data Portability: The right to receive your personal data in a structured, commonly used, and machine-readable format;
- Right to Object: The right to object at any time to processing based on legitimate interests;
- Right to Withdraw Consent: Where processing is based on consent, you may withdraw it at any time without penalty.
To exercise any of these rights, contact us at: novakreativ@gmail.com. We will respond to your request without undue delay and at the latest within one (1) month of receipt. In complex cases, this period may be extended by up to two (2) further months in accordance with statutory rules.
12. Automated Decision-Making and Profiling
We do not make automated decisions that produce legal effects concerning you or similarly significantly affect you. Automated risk scoring by reCAPTCHA is used solely for the technical defense against abusive bots and denial-of-service attacks. If you encounter difficulty completing an order due to a security check, you may contact our customer support for manual assistance.
13. Third-Party Data in Custom Prints
If you upload images or text containing personal data of third parties (e.g., photos of family members, friends, or colleagues), you confirm and represent that you have obtained lawful authorization or consent to upload and reproduce such materials.
14. Children's Privacy
Our services and products are not targeted at children under the age of 18. Orders involving minors must be placed or authorized by a parent or legal guardian.
15. Changes to This Privacy Policy
We may periodically update this Policy to reflect operational, legal, or technological developments. The updated version will be published on novvacreative.mk with a revised "Last updated" date.
16. Contact and Supervisory Authority
For inquiries, requests, or complaints regarding personal data protection, contact:
Друштво за печатење услуги и трговија НОВАКРЕАТИВ ДООЕЛ Струга
- Short legal name: НОВАКРЕАТИВ ДООЕЛ Струга
- Registered office: ул. Ристо Крле бр. 9, Струга, Republic of North Macedonia
- Email: novakreativ@gmail.com
- Telephone: +389 75 889 596
- Website: https://novvacreative.mk
You also have the right to lodge a complaint with the national supervisory authority:
Агенција за заштита на личните податоци (АЗЛП)
- Address: бул. Гоце Делчев бр. 18, 1000 Скопје, Република Северна Македонија
- Email: info@privacy.mk
- Website: https://azlp.mk
Data Security & Trust
Have questions regarding data protection or wish to exercise your statutory rights? Reach out directly to our Data Protection team at novakreativ@gmail.com.