Governance & Compliance

Data Protection / Data Security Policy

Purpose:
NovaQuest is committed to responsibly collecting, storing, and using personal and organizational data. This policy ensures compliance with local and international data protection laws and safeguards the privacy of all individuals.

Key Commitments:

Lawful Data Use: Collect only data necessary for our projects and with proper consent.

Confidentiality & Security: Secure storage, controlled access, and encryption where needed.

Data Minimization: Limit the data collected and retained to what is strictly necessary.

Rights of Individuals: Participants can access, correct, or withdraw their personal data.

Training & Awareness: All staff receive data protection guidance relevant to their role.

Incident Response: Any breach or unauthorized access is reported and addressed promptly.

Next Review: Every 2 years or sooner if legal or operational changes occur.
Whistleblowing / Complaints Policy

Purpose:
NovaQuest encourages open reporting of misconduct, unethical behaviour, or violations of organizational policies. This policy ensures safe, confidential, and effective reporting while protecting reporters from retaliation.

Scope:
Staff, consultants, partners, and external stakeholders can report concerns.


Key Principles:

Confidentiality: Reports are handled discreetly.

Protection from Retaliation: Anyone reporting in good faith is safeguarded.

Responsiveness: All reports are acknowledged, investigated, and resolved promptly.

Accountability: Appropriate corrective measures are taken when violations are confirmed.

Reporting Channels:
admin@novaquestinsights.org
OR
Phone: 0780 603 207
OR
Direct reporting to supervisor, manager, or designated officer

Next Review: Every 2 years or as needed.