Privacy Notice
Last updated 25 August 2026
Who provides this service
Noviqent Ltd ("Noviqent", "we", "us") operates Incident Copilot at incident-response-ai.noviqent.co.uk. For your account, billing, and audit-log data, Noviqent is the data controller. For the alert, observability, source code, and ticket data your organisation connects, your organisation is normally the data controller and Noviqent processes it on your behalf, as described below.
Information we process
- Account data — name, email address, hashed password, and your organisation membership and role.
- Audit log data — an append-only record of actions taken in your organisation, including who approved which proposed fix and when.
- Connector credentials — the Grafana service-account token, GitHub personal access token, and Jira API token your organisation supplies, and the API key for whichever AI provider your organisation has chosen. These are encrypted at rest and are never returned by our API or displayed back to you.
- Incident data — the alert payloads your systems send us, and the context we gather in response to them: metrics and log lines from your Grafana, source code from your GitHub repository, and summaries of related tickets from your Jira. Any of these can incidentally contain personal data — a log line with a user identifier in it, a code comment naming an engineer, a ticket reporter's name — so we treat all of it as potentially personal data rather than assuming it isn't.
- Analyses — the root-cause hypothesis, confidence rating, and proposed fix generated for each incident.
How we use it
To operate your account, receive your alerts, gather context from the tools you have connected, generate a root-cause hypothesis and proposed fix, package that as a ticket and (for code fixes) a draft pull request, and maintain the audit log.
Where your data is processed
Incident Copilot runs on Noviqent's own infrastructure. Alert payloads and the context gathered in response to them are processed and stored there.
One step sends data outside that boundary, and you choose where it goes. To produce a root-cause hypothesis, the gathered context for an incident — which can include metric values, log lines, source code, and related ticket summaries — is sent to the AI provider your organisation has configured. Your organisation selects that provider and supplies its own API key; exactly one is active at a time, and if none is configured, nothing is sent and the reasoning step does not run.
Depending on that choice, the recipient is Anthropic PBC (Claude), OpenAI L.L.C. (GPT), or Google LLC (Gemini), and that company acts as our sub-processor for the reasoning step and for that step only. Alternatively, your organisation can point Incident Copilot at an OpenAI-compatible endpoint you host yourself, in your own network or cloud account — in which case the context does not reach any AI vendor and there is no AI sub-processor for this step at all. Whichever applies, no provider receives your account credentials or your connector credentials. See our sub-processor register for exactly what the active provider receives.
Grafana, GitHub, and Jira are not sub-processors of ours. They are your own systems, which you authorise us to connect *to*. Data flows from them to us, not from us to them, with two exceptions you explicitly configure: we open a draft pull request in your GitHub repository, and we create a ticket in your Jira project. In both cases the destination is your own tenant, under your own control.
Retention
Account and audit-log data is retained for as long as your organisation's account is active. Incidents, their gathered context, and their analyses are retained until you delete them or close your account. Deleting your organisation removes associated data, other than what we're required to keep for legal or accounting purposes.
Sharing and sub-processors
We don't sell your data. See our sub-processor register for the current list of third parties who process data on our behalf and exactly what each one receives.
International transfers
Where a sub-processor operates outside the UK or EEA, we rely on an appropriate transfer mechanism, such as the UK's International Data Transfer Addendum, before any transfer takes place.
Your rights
Depending on your role, you or your organisation as data controller may have rights to access, correct, delete, restrict, or port the personal data we hold, and to object to certain processing. Requests relating to your organisation's data should go through your organisation admin where Noviqent is acting as processor. You can also complain to the UK Information Commissioner's Office at ico.org.uk. Noviqent Ltd is registered with the ICO under registration number ZC225920.
Contact
Noviqent Ltd, company no. 17232197, registered in England & Wales. Data protection queries: compliance@noviqent.co.uk.
Changes to this notice
We'll update this page when what we process, or why, materially changes.