Privacy Notice
Last updated 30 August 2026
Who provides this service
Noviqent Ltd ("Noviqent", "we", "us") operates Noviqent DevOps at devops.noviqent.co.uk. For your account, billing, and audit-log data, Noviqent is the data controller. For the ticket, source code, and runbook data your organisation connects, your organisation is normally the data controller and Noviqent processes it on your behalf, as described below.
Information we process
- Account data — name, email address, hashed password, and your organisation membership and role.
- Audit log data — an append-only record of actions taken in your organisation, including credential and membership changes.
- Connector credentials — the Jira, GitHub, GitLab, and Confluence API tokens your organisation supplies, and the API key for whichever AI provider your organisation has chosen. These are encrypted at rest and are never returned by our API or displayed back to you. Alternatively, your organisation may keep a credential in its own Noviqent Vault space and reference it by name instead — in that case we never store the credential at all, only the name of the secret we resolve at the moment it's needed.
- Ticket data — the webhook payloads Jira sends us (only the ticket key is trusted from them — the ticket is re-fetched through your own credentials), and the context we gather in response: source code from your GitHub or GitLab repository, runbook pages from your Confluence, and summaries of related tickets from your Jira project. Any of these can incidentally contain personal data — a code comment naming an engineer, a ticket reporter's name — so we treat all of it as potentially personal data rather than assuming it isn't.
- Fix attempts — the root-cause explanation, confidence rating, and the file changes proposed for each ticket, plus the resulting pull request URL and CI result.
How we use it
To operate your account, receive Jira's webhook, gather context from the tools you have connected, generate a fix and open it as a draft pull request, poll that pull request's own CI result, comment the outcome back onto the ticket, and maintain the audit log.
Where your data is processed
Noviqent DevOps runs on Noviqent's own infrastructure. Ticket payloads and the context gathered in response to them are processed and stored there.
One step sends data outside that boundary, and you choose where it goes. To produce a fix, the gathered context for a ticket — which can include source code, runbook pages, and related ticket summaries — is sent to the AI provider your organisation has configured. Your organisation selects that provider and supplies its own API key; exactly one is active at a time, and if none is configured, nothing is sent and the reasoning step does not run.
Depending on that choice, the recipient is Anthropic PBC (Claude), OpenAI L.L.C. (GPT), Google LLC (Gemini), or xAI Corp. (Grok), and that company acts as our sub-processor for the reasoning step and for that step only. Alternatively, your organisation can point Noviqent DevOps at an OpenAI-compatible endpoint you host yourself, in your own network or cloud account — in which case the context does not reach any AI vendor and there is no AI sub-processor for this step at all. Whichever applies, no provider receives your account credentials or your connector credentials. See our sub-processor register for exactly what the active provider receives.
Jira, GitHub, GitLab, and Confluence are not sub-processors of ours. They are your own systems, which you authorise us to connect *to*. Data flows from them to us, not from us to them, with two exceptions you explicitly configure: we open a draft pull or merge request in your repository, and we post one comment back onto the Jira ticket that triggered the fix attempt. In both cases the destination is your own tenant, under your own control.
Retention
Account and audit-log data is retained for as long as your organisation's account is active. Ticket fix requests, their gathered context, and their results are retained until you delete them or close your account. Deleting your organisation removes associated data, other than what we're required to keep for legal or accounting purposes.
Sharing and sub-processors
We don't sell your data. See our sub-processor register for the current list of third parties who process data on our behalf and exactly what each one receives.
International transfers
Where a sub-processor operates outside the UK or EEA, we rely on an appropriate transfer mechanism, such as the UK's International Data Transfer Addendum, before any transfer takes place.
Your rights
Depending on your role, you or your organisation as data controller may have rights to access, correct, delete, restrict, or port the personal data we hold, and to object to certain processing. Requests relating to your organisation's data should go through your organisation admin where Noviqent is acting as processor. You can also complain to the UK Information Commissioner's Office at ico.org.uk. Noviqent Ltd is registered with the ICO under registration number ZC225920.
Contact
Noviqent Ltd, company no. 17232197, registered in England & Wales. Data protection queries: compliance@noviqent.co.uk.
Changes to this notice
We'll update this page when what we process, or why, materially changes.