Legal
Privacy Notice
How Everest Nova handles client, product, project, payment-status, and website information.
Effective 2026-07-14
This notice applies to the Everest Nova website, portal, and dossier preparation service operated by Everest Links Pte Ltd, located at #07-27 Midview City, 18 Sin Ming Lane, Singapore 573960.
Information we collect
Account and organization information, including your name, work email, company, authentication details, and recorded acceptance of the current Terms and Privacy Notice.
Project and dossier information, including intended use, proposed classification, target market, product and manufacturer details, messages, uploaded files, deliverables, and related regulatory material.
Order information, including the package, price, currency, payment status, and payment-provider references. Everest Nova does not store raw payment-card numbers.
If you allow analytics, website usage information may include a pseudonymous visitor identifier, page path, referrer, browser user agent, and interaction events.
Our role and why we use information
For account, website, sales, billing, and direct service-administration information, Everest Links Pte Ltd generally determines the purposes and means of processing. For dossier material processed only on a business client's documented instructions, the client may be the controller or responsible organization and Everest Nova may act as its processor or service provider. A data processing addendum is available where the parties' roles or applicable law require one.
We process information to take steps requested before a contract, perform the service contract, comply with legal obligations, protect legitimate interests in security, fraud prevention, support, accounting, service improvement, and legal claims, and—where required—based on consent. The applicable basis depends on the information, relationship, and jurisdiction.
With analytics permission, we use website and product events to understand demand, diagnose the purchase journey, improve the service, and measure configured marketing campaigns. Essential portal functions do not require analytics permission.
Service providers and access
The application uses service providers for managed authentication, database and private file storage, payment processing, operational email, and the current AI-assisted readiness workflow. The Subprocessors page identifies the current providers and functions.
The current AI gap review sends structured project context and the uploaded file inventory, including file names and document categories. It does not send the contents of uploaded files to OpenAI in this workflow.
Configured Google Analytics or Google Ads tags load only after you select Allow analytics. A client account can access projects it owns. Authorized Everest Nova administrators can access projects and files where needed to provide and secure the service. Information may also be disclosed for professional advice, a corporate transaction, legal compliance, or protection of rights and safety. Everest Nova does not sell raw dossier files or patient data.
International transfers
Everest Nova is based in Singapore, clients and manufacturers may be located worldwide, and service providers may process information in other countries. Where required, Everest Nova uses contractual and organizational safeguards intended to provide comparable protection for cross-border transfers and assesses provider terms and the nature of the information.
Clients remain responsible for confirming that they have a lawful basis and any required notices, consents, approvals, contracts, or transfer safeguards before uploading information from another country. Contact us to request the current data processing addendum or transfer information relevant to an enterprise engagement.
Sensitive and patient information
Do not upload patient, clinical-trial subject, or other directly identifiable health information. De-identify document contents and file names before upload.
The service is designed for medical-product regulatory documentation, not patient care or the storage of identifiable patient or clinical-trial subject records. If sensitive information is accidentally submitted, stop using the affected file, notify the privacy contact promptly, and request secure review or deletion.
Retention, rights, and complaints
Information is retained while needed for the project and for legitimate contractual, security, accounting, dispute-resolution, and legal purposes. The current service uses manual retention review; automated deletion schedules are not yet enabled.
Depending on applicable law, you may request access, correction, a copy, deletion review, restriction, objection, portability, or withdrawal of consent and may complain to the relevant privacy regulator. We may verify identity and authority before acting. A request can be limited where continued processing is required or permitted, including for another person's rights, security, accounting, legal claims, or legal obligations.
You can change analytics permission through Analytics settings in the footer. Everest Nova will notify relevant authorities and affected persons of a qualifying personal-data breach where required by applicable law.
Updates and contact
We may update this notice to reflect service, provider, or legal changes. Material changes are dated and, where appropriate, presented in the portal or sent to the account contact before they apply to a later purchase.
The privacy contact for Everest Nova is security@everestnova.ai. You can use it to request the data processing addendum, exercise privacy rights, raise a concern, or report an accidental sensitive-data upload. General service questions can be sent to support@everestnova.ai.
See the Subprocessors page and the Data lifecycle page for the current operational status.