Legal information
Personal data protection
This page is a courtesy translation. In the event of any discrepancy in interpretation, the French version prevails.
Data controller
NOVAELAR GROUP, a société par actions simplifiée registered with the Paris Trade Register under number 999 831 514, with its registered office at 60 rue François Ier, 75008 Paris, France, is the controller of the personal data processing described below.
Any question relating to this processing may be sent to contact@novaelar.com or by post to the registered office.
Data collected
We collect only the data necessary for the purposes set out below:
- Contact data — name, email address, subject and content of the message sent through the contact form, together with the details exchanged during our communications.
- Relationship data — information on your estate, objectives, investment horizon and risk profile gathered during the audit, once a contractual relationship is contemplated or entered into.
- Regulatory identification data — identity document, proof of address and information on the source of funds, where anti-money-laundering and counter-terrorist-financing rules require it.
- Technical data — IP address and connection logs, generated automatically when the site is visited and necessary for its security.
No special category data within the meaning of Article 9 GDPR is collected. The site carries out no automated profiling producing legal effects.
Purposes and legal bases
- Answering enquiries
- Handling messages received through the contact form. Legal basis: pre-contractual steps taken at your request, and legitimate interest in responding to enquiries received.
- Managing the relationship
- Audit, construction and monitoring of the mandate, correspondence and reporting. Legal basis: performance of the contract.
- Meeting our obligations
- Client identification, retention of supporting documents, accounting and regulatory obligations. Legal basis: legal obligation.
- Securing the site
- Technical logging, prevention of abuse. Legal basis: legitimate interest.
Retention periods
- Enquiries not leading to a relationship — three years from the last contact.
- Contractual relationship data — for the duration of the relationship, then five years from its end under statutory retention obligations.
- Regulatory identification documents — five years from the end of the business relationship, in accordance with the French Monetary and Financial Code.
- Technical logs — twelve months at most.
Recipients
Your data is accessible only to authorised staff within NOVAELAR GROUP. It may be shared with our technical providers acting as processors — website hosting, email delivery — as well as with our professional advisers bound by confidentiality, and with administrative or judicial authorities where the law so requires.
Your data is never sold, rented or transferred for commercial purposes, to anyone, under any circumstances.
To be completed: chosen host, form-handling provider, and any transfer outside the European Union together with the applicable safeguard.
Your rights
You have the right of access, rectification, erasure, restriction of processing, objection and data portability, as well as the right to give instructions concerning the fate of your data after your death.
These rights are exercised at contact@novaelar.com. You will receive a reply within one month. Proof of identity may be requested in the event of reasonable doubt as to the identity of the applicant.
Certain data cannot be erased before the expiry of the statutory retention periods binding upon us.
If, after contacting us, you consider that your rights are not being respected, you may lodge a complaint with the French data protection authority — CNIL, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07 — or online at cnil.fr.
Cookies and trackers
This site sets no advertising cookies and no audience-measurement trackers requiring your consent. Only cookies strictly necessary for its operation and security are used, where applicable, which are exempt from consent under CNIL guidance.
To be revised if an analytics tool or third-party service is added: a consent banner would then become mandatory.
Security
We implement appropriate technical and organisational measures to protect your data against destruction, loss, alteration, unauthorised disclosure or access: encryption of communications, restriction of access to authorised staff only, and logging of consultations.
Last updated: September 2026.