Privacy, terms, security and support for Novulis products
One place for the policies that apply to Build Studio and GovXRM, whether you use Novulis-hosted SaaS or run the product in your own Microsoft cloud environment.
Privacy Policy
How information is handled across Novulis-hosted SaaS and customer-hosted deployments.
Novulis Corporation ("Novulis," "we," "us," or "our") respects the privacy, security, and data-sovereignty requirements of organizations using our software products.
This Product Privacy Policy applies to the Novulis products listed below and explains how information is handled across Novulis-hosted SaaS and customer-hosted deployment models.
01Products Covered
This policy applies to:
- Build Studio - an enterprise application modernization and software delivery platform.
- GovXRM - a relationship and operations platform for government organizations.
This policy applies to product use. Novulis may maintain a separate corporate or website privacy policy for visitors to novulis.com, marketing activities, recruiting, and other corporate processing activities.
02Deployment Models
Novulis products may be offered using one or both of the following deployment models.
Novulis-Hosted SaaS
The product is hosted and operated by Novulis using Microsoft cloud infrastructure. Novulis manages the service environment required to provide the subscribed product.
Customer-Hosted on Microsoft Cloud
The product is deployed into an environment controlled by the customer. Depending on the product and customer architecture, this may include the customer's Microsoft Azure subscription and other customer-controlled Microsoft cloud resources.
For customer-hosted deployments, the customer controls its environment, users, identities, permissions, networking, resource configuration, data retention, and access policies.
03Information the Products May Process
The information processed depends on the product, modules selected by the customer, deployment model, configuration, and the information the customer chooses to provide.
Build Studio
Build Studio may process information such as:
- Source code and software artifacts
- Application and architecture documentation
- Business and technical requirements
- Policies, procedures, and regulatory documents
- Meeting notes and transcripts
- Business rules
- User stories and acceptance criteria
- Test plans, test cases, and automated testing artifacts
- Application metadata
- Other project information selected by the customer
GovXRM
Depending on the modules configured by the customer, GovXRM may process information related to:
- Residents and constituents
- Businesses and organizations
- Properties
- Cases and service requests
- Applications, forms, and submissions
- Permits and approvals
- Grants and grant activities
- Partners and vendors
- Contracts and related records
- Policies, audits, and compliance activities
- Communications and interactions
- Documents and attachments
- Program and operational information
- Other information selected by the customer
Customers determine what information is entered into or connected to Novulis products and are responsible for ensuring that they have the appropriate authority and lawful basis to process that information.
04Account and Technical Information
Depending on the deployment model, Novulis products may process limited account and technical information required to provide, secure, support, or administer the product, including:
- User name
- Business email address
- Organization name
- User or tenant identifiers
- Roles and permissions
- Authentication and authorization events
- Application logs
- Error and diagnostic information
- Security events
- Performance and availability information
Where Microsoft Entra ID or another customer-selected identity provider is used, authentication credentials are managed by the applicable identity provider rather than by Novulis.
05Novulis-Hosted SaaS Data Handling
When Build Studio or GovXRM is delivered as a Novulis-hosted SaaS service, Customer Content may be processed within the Microsoft cloud environment used by Novulis to provide the subscribed service.
Novulis may process Customer Content as necessary to:
- Provide the product and its configured functionality
- Authenticate and authorize users
- Perform customer-requested workflows and processing
- Generate product outputs requested by authorized users
- Maintain service availability, reliability, and security
- Diagnose and resolve product issues
- Provide technical support
- Maintain and improve product functionality
- Meet contractual, regulatory, and legal obligations
Novulis does not sell Customer Content.
Novulis does not use Customer Content for behavioral advertising.
Novulis does not use Customer Content submitted to Build Studio or GovXRM to train Novulis-owned general-purpose artificial intelligence models.
06Customer-Hosted Data Handling
When Build Studio or GovXRM is deployed into a customer-controlled environment, Customer Content remains within the customer's environment as part of normal product operation.
Novulis does not transfer, copy, store, or process Customer Content outside the customer-controlled environment as part of the normal operation of a customer-hosted deployment.
For Build Studio, a customer-hosted deployment may include Azure Kubernetes Service (AKS) or other Azure compute resources, databases, Azure AI Foundry resources, storage, networking, Microsoft Entra ID, Playwright or testing resources, monitoring, and other Azure services required by the customer's selected architecture.
For GovXRM, a customer-hosted deployment may use customer-controlled Microsoft cloud resources appropriate to the selected GovXRM modules and architecture.
A customer-hosted deployment does not require Customer Content to be transferred to a Novulis-hosted application backend, database, storage service, AI environment, or control plane for normal product operation.
07Limited Customer-Hosted Deployment Information Maintained by Novulis
For customer-hosted deployments of Build Studio and GovXRM, Novulis may maintain limited information needed to identify and support the customer deployment, including:
- Customer or organization name
- Microsoft Azure Subscription ID associated with the deployment, where applicable
Novulis may use this limited information to:
- Identify authorized customer deployments
- Maintain licensing and product-entitlement records
- Maintain deployment records
- Coordinate product updates and upgrades
- Communicate availability of new releases
- Provide product support
- Coordinate future Build Studio or GovXRM maintenance activities
An Azure Subscription ID is an identifier. Possession of the Subscription ID alone does not provide Novulis with access to the customer's Azure resources or Customer Content.
08Artificial Intelligence Processing
Certain product capabilities may use Microsoft Azure AI services, including Azure AI Foundry, or other AI services configured for the applicable deployment.
For Novulis-hosted SaaS, applicable AI processing is performed through the Microsoft cloud resources used by Novulis to provide the service.
For customer-hosted deployments, applicable AI resources are configured within or associated with the customer's controlled environment. Customer Content is not required to be transferred to a Novulis-hosted AI environment for normal operation.
Novulis does not use Customer Content from Build Studio or GovXRM to train Novulis-owned general-purpose AI models.
Use of Microsoft cloud and AI services is also subject to the applicable Microsoft terms governing the customer's or Novulis's use of those services.
09Customer-Hosted Support Access
Novulis does not require routine or permanent administrative access to Customer Content for a customer-hosted deployment to operate.
If a customer requests technical assistance that requires Novulis personnel to access customer-controlled resources, access must be authorized by the customer and may be limited by the customer to specific resources, permissions, and time periods.
Any information made available to Novulis for support will be used only as necessary to provide the requested support, investigate technical or security issues, or satisfy applicable contractual or legal obligations.
10Security
Novulis maintains administrative, technical, and organizational measures designed to protect information processed through Novulis-hosted services.
Depending on the product and deployment model, available security controls may include:
- Microsoft Entra ID integration
- Role-based access control
- Encryption in transit
- Encryption at rest where supported by the applicable Microsoft service
- Network security controls
- Secrets and credential management
- Logging and monitoring
- Security updates and product fixes
- Backup and recovery controls
- Administrative access restrictions
For customer-hosted deployments, the customer is responsible for configuring and operating its cloud environment in accordance with its own security, compliance, and governance requirements.
No information system can provide absolute security.
11Data Residency
For Novulis-hosted SaaS, Customer Content is processed in the Microsoft cloud environment selected by Novulis for the applicable service, subject to the applicable customer agreement and service configuration.
For customer-hosted deployments, the customer selects and controls the regions, resources, and data-location configuration used for its deployment.
Customers with specific data-residency, sovereignty, regulatory, or security requirements should confirm the applicable architecture and contractual requirements before deployment.
12Data Retention and Deletion
For Novulis-hosted SaaS, Customer Content is retained in accordance with the applicable customer agreement, service configuration, operational requirements, and legal obligations.
For customer-hosted deployments, the customer controls retention and deletion of Customer Content in its environment, including applicable databases, storage, logs, documents, generated artifacts, backups, and other resources.
Novulis does not maintain a separate operational copy of Customer Content from customer-hosted deployments as part of normal product operation.
Novulis may retain limited customer and deployment metadata, such as organization name and Azure Subscription ID, where needed for licensing, entitlement, support, product administration, update coordination, contractual obligations, or legal requirements.
13Service Providers
Novulis may use technology and service providers necessary to provide and support Novulis-hosted services. Microsoft is a principal cloud technology provider used in connection with Novulis products.
Service providers are permitted to process information only as necessary to provide the applicable services and subject to applicable contractual and confidentiality obligations.
For customer-hosted deployments, third-party and Microsoft services configured by the customer are governed by the customer's agreements with those providers.
14Information Sharing
Novulis does not sell Customer Content and does not disclose Customer Content to third parties for their independent marketing purposes.
Novulis may disclose information when:
- Directed or authorized by the customer
- Necessary to provide a customer-requested service
- Required by applicable law, regulation, court order, or lawful government request
- Reasonably necessary to protect the security or integrity of Novulis products, customers, users, or systems
- Required in connection with a corporate transaction, subject to applicable confidentiality and legal requirements
15Cookies and Similar Technologies
Novulis products may use cookies or similar technologies that are necessary for authentication, session management, security, user preferences, and application functionality.
Novulis products do not use Customer Content for behavioral advertising.
16Individual Privacy Rights
Depending on applicable law, individuals may have rights concerning their personal information, including rights to request access, correction, deletion, restriction, objection, portability, or information about processing.
Where Novulis processes personal information on behalf of an organizational customer, individuals should generally direct requests to that organization. Novulis will assist customers with applicable privacy obligations where required by contract or law.
17Children's Privacy
Build Studio and GovXRM are enterprise and government software products intended for organizational and professional use. They are not designed or marketed as consumer services for children.
18Customer Responsibilities
Customers are responsible for determining what information they process using Novulis products and for configuring their environments and product use in accordance with applicable privacy, security, records-management, contractual, and regulatory requirements.
For customer-hosted deployments, customers are also responsible for their cloud subscription, identities, access controls, networking, security configuration, backup policies, data retention, regional configuration, and integrations.
19Changes to This Policy
Novulis may update this Product Privacy Policy to reflect changes to our products, deployment models, practices, technology, or legal requirements. The current version will be published on this page with an updated effective date.
Terms of Use & EULA
General product-use terms for authorized use of Build Studio and GovXRM.
These Novulis Product Terms of Use and End User License Agreement ("Product Terms") apply to authorized use of Build Studio and GovXRM software and services provided by Novulis Corporation ("Novulis").
These Product Terms are intended to provide general product-use terms. A customer's order form, subscription agreement, private offer, statement of work, Microsoft Marketplace legal agreement, or other written agreement with Novulis may contain additional or different terms.
01Order of Precedence
If the customer has entered into a separate written agreement with Novulis governing the applicable product, that agreement controls to the extent of any conflict with these Product Terms.
If a product is acquired through Microsoft Marketplace and Novulis has selected the Microsoft Standard Contract for Microsoft Marketplace, the Microsoft Standard Contract and any applicable Novulis amendments or private-offer terms govern that Marketplace transaction to the extent specified in the purchase flow.
If Novulis elects to use its own custom legal terms for a Marketplace offer instead of the Microsoft Standard Contract, the legal terms presented and accepted in the applicable Marketplace purchase flow govern that offer.
These Product Terms do not replace a Microsoft Marketplace legal contract where another contract is expressly presented and accepted as part of the Marketplace transaction.
When these Product Terms are presented and accepted as Novulis's custom terms in a Microsoft Marketplace purchase, they govern the product license. Any accepted customer-specific terms in the private offer also apply to that transaction.
These Product Terms do not alter the customer's separate agreements with Microsoft for Marketplace purchases or Microsoft cloud services.
02Products Covered
These Product Terms apply to:
- Build Studio
- GovXRM
They apply to both Novulis-hosted SaaS and customer-hosted deployments unless an applicable order or agreement states otherwise.
03License and Right to Use
Subject to payment of applicable fees and compliance with the governing agreement, Novulis grants the customer a limited, non-exclusive, non-transferable right to access and use the applicable product during the subscription or license term for the customer's internal business or governmental purposes.
The scope of use may be limited by the applicable order, private offer, plan, subscription, environment, organization, user population, capacity, or other entitlement identified in the governing agreement.
No ownership interest in Novulis software or intellectual property is transferred to the customer.
04SaaS Use
For a Novulis-hosted SaaS deployment, Novulis provides access to the applicable product as a hosted service. Build Studio SaaS is hosted in Novulis's Azure subscription, with a separate Build Studio environment for each customer.
The applicable order identifies the agreed deployment location and cloud environment, subject to supported configurations and service availability.
The customer may permit authorized users to access the service in accordance with the purchased subscription and the customer's internal policies.
The customer is responsible for:
- Authorized-user administration
- Appropriate use of credentials and identity systems
- The accuracy and legality of Customer Content submitted to the service
- Compliance with applicable laws, regulations, and organizational policies governing the customer's use of the service
05Customer-Hosted Use
For a customer-hosted deployment, Novulis provides the applicable software, deployment artifacts, entitlement, updates, or other materials described in the governing agreement for deployment into a customer-controlled environment.
For Build Studio, the customer may choose deployment into a new Azure environment or installation into an existing customer Azure Kubernetes Service (AKS) cluster, subject to the supported deployment requirements. The applicable order or deployment documentation identifies the required supporting resources and customer prerequisites.
The customer is responsible for operating and administering its environment, including applicable cloud subscriptions, infrastructure, identities, networking, security configuration, backups, monitoring, and third-party or Microsoft cloud services unless the governing agreement states otherwise.
Novulis does not receive ownership of customer cloud resources or Customer Content by virtue of the deployment.
06Authorized Users
The customer is responsible for ensuring that only authorized users access the products and that users comply with these Product Terms and the governing agreement.
The customer is responsible for maintaining appropriate identity, authentication, and access-control practices for its users.
07Acceptable Use and Restrictions
Except to the extent expressly permitted by applicable law or the governing agreement, the customer will not:
- Sell, sublicense, lease, rent, distribute, or commercially provide the product to a third party as a standalone product
- Copy or reproduce the product except as necessary for an authorized customer-hosted deployment, backup, or disaster-recovery purpose
- Reverse engineer, decompile, or disassemble the product
- Remove or obscure proprietary notices
- Circumvent license, entitlement, security, or access-control mechanisms
- Use the product to violate applicable law or the rights of another person or organization
- Introduce malicious code or intentionally disrupt the product or related systems
- Attempt unauthorized access to Novulis-hosted systems or another customer's environment
Nothing in this section restricts rights that cannot lawfully be restricted under applicable law.
08Customer Content
As between Novulis and the customer, the customer retains its rights in data, documents, source code, records, content, and other information provided to or processed through the products ("Customer Content").
The customer grants Novulis only the rights necessary to process Customer Content to provide the applicable Novulis-hosted service, support the customer, comply with customer instructions, or perform obligations under the governing agreement.
For customer-hosted deployments, Customer Content remains within the customer-controlled environment as described in the Novulis Product Privacy Policy, except where the customer expressly provides information to Novulis for support or another authorized purpose.
09Privacy
Use of Build Studio and GovXRM is subject to the Novulis Product Privacy Policy, available at:
The Product Privacy Policy explains the different data-handling models for Novulis-hosted SaaS and customer-hosted deployments.
10Artificial Intelligence Features
Certain product features may use artificial intelligence or machine-learning services, including Microsoft Azure AI services, depending on product configuration and deployment.
AI-generated output may be probabilistic and may not always be complete, accurate, or appropriate for every use. Customers are responsible for reviewing outputs before relying on them for legal, regulatory, security, financial, operational, or other material decisions.
Customers are responsible for determining whether their content is appropriate for processing through configured AI features and for configuring applicable customer-hosted AI resources in accordance with their requirements.
Novulis does not claim ownership of Customer Content merely because it is processed by an AI-enabled feature.
11Microsoft and Third-Party Services
Novulis products may depend on, integrate with, or be deployed using Microsoft Azure, Microsoft cloud services, or other third-party services.
Use of those services may be subject to separate terms between the customer and the applicable provider. Unless the governing agreement expressly states otherwise, the customer is responsible for licenses, subscriptions, consumption charges, and configuration of third-party services procured directly by the customer.
Novulis is not responsible for changes made independently by third-party providers to services outside Novulis's control, but Novulis may provide product updates or compatibility guidance under the applicable support arrangement.
12Support and Updates
Support, maintenance, update rights, service levels, and response commitments are governed by the applicable subscription, support plan, Marketplace offer, private offer, order form, or service agreement.
General Novulis product-support information is available at:
Novulis may provide product updates, defect fixes, security-related fixes, compatibility updates, and new versions. The manner and timing of deployment may differ between SaaS and customer-hosted environments.
For customer-hosted environments, deployment of an update may require customer action or customer authorization.
13Security
Security responsibilities are shared according to the selected deployment model.
A summary of Novulis product-security practices and customer responsibilities is available at:
The customer remains responsible for its own users, endpoints, identities, cloud subscriptions, network configuration, and customer-controlled infrastructure unless the governing agreement expressly assigns a responsibility to Novulis.
14Ownership and Intellectual Property
Novulis and its licensors retain all right, title, and interest in and to the products, software, documentation, product designs, trademarks, and related intellectual property, including improvements and derivative works created by Novulis.
No rights are granted except those expressly stated in the governing agreement or these Product Terms.
15Feedback
If a customer voluntarily provides product suggestions, ideas, or feedback, Novulis may use that feedback to improve its products without restriction or payment, provided that Novulis does not acquire ownership of the customer's confidential information or Customer Content through this feedback provision.
16Fees, Taxes, and Cloud Consumption
Product fees and billing terms are established in the applicable order, subscription, Marketplace transaction, private offer, or other governing agreement.
For Build Studio purchases through Microsoft Marketplace, the applicable private offer specifies the annual software license fee, payable upfront through Microsoft, and any add-on package charges. Customer-specific prices are established in the accepted private offer.
For Build Studio SaaS, the applicable private offer or order specifies the included allowance for hosting and AI usage. Customers may purchase add-on packages providing fixed amounts of extra AI processing and hosting or storage capacity, with payment collected through Microsoft Marketplace. The applicable offer or order must specify the package quantities, usage units, validity period, price, and payment schedule.
For customer-hosted deployments, cloud infrastructure and consumption charges associated with the customer's environment are the customer's responsibility unless expressly included in the governing agreement.
Taxes are handled in accordance with the applicable transaction and governing agreement.
17Suspension
Novulis may suspend access to a Novulis-hosted service when reasonably necessary to address a material security threat, prevent unlawful or unauthorized use, comply with law, or address a material breach of the governing agreement, subject to any applicable contractual notice requirements.
For customer-hosted deployments, Novulis may suspend or terminate entitlement to future updates, support, or licensed use as permitted by the governing agreement, but Novulis does not obtain independent administrative control over customer resources solely through these Product Terms.
18Term and Termination
The subscription or license term is specified in the applicable governing agreement.
Upon expiration or termination, the customer's right to use the product ends except to the extent that the governing agreement provides continuing or perpetual rights.
For customer-hosted deployments, the customer remains responsible for removing or disabling software where required by the governing agreement and for managing its own Customer Content and cloud resources.
19Confidentiality
Confidentiality obligations are governed by the applicable agreement between Novulis and the customer. These Product Terms do not reduce confidentiality protections contained in a separately executed agreement.
20Warranties, Disclaimers, Liability, and Indemnification
Any warranties, disclaimers, limitations of liability, indemnification obligations, remedies, service credits, or similar risk-allocation terms are governed by the applicable written agreement, Microsoft Marketplace legal contract, private offer, or order governing the transaction.
Where no separate written provision applies, rights and remedies are determined by applicable law.
21Government and Regulated Customers
Customers are responsible for determining whether the applicable product configuration, deployment model, and Microsoft cloud environment meet their regulatory, procurement, records-management, accessibility, security, and data-residency requirements.
Novulis may provide product documentation or respond to customer security and compliance reviews under the applicable sales or support process.
22Export and Sanctions Compliance
Customers must use Novulis products in compliance with applicable export-control, sanctions, and trade laws.
23Changes to These Product Terms
Novulis may update these Product Terms from time to time. Changes will be posted with a revised effective date.
For an active paid subscription, changes that materially alter contractual rights will apply only to the extent permitted by the governing agreement and applicable law.
Security Overview
The product-security model and shared responsibilities for each deployment type.
Novulis Corporation designs Build Studio and GovXRM for enterprise and public-sector environments where security, data control, and deployment flexibility are important.
This page describes the product-security model for Novulis-hosted SaaS and customer-hosted deployments. Specific contractual commitments, service levels, security controls, and compliance requirements may be documented separately for an individual customer or deployment.
01Products Covered
This security overview applies to:
- Build Studio
- GovXRM
Both products may be provided as a Novulis-hosted SaaS service or deployed into a customer-controlled Microsoft cloud environment, depending on the applicable product plan and customer agreement.
02Shared Responsibility Model
Security responsibilities depend on the selected deployment model.
Novulis-Hosted SaaS
Novulis operates the application environment used to provide the SaaS service and is responsible for the security of the Novulis-managed application and service configuration within the scope of the applicable agreement.
Customers remain responsible for matters such as authorized-user administration, appropriate identity configuration, lawful and appropriate Customer Content, endpoint security, and customer-side integrations.
Customer-Hosted
For customer-hosted deployments, the application and supporting resources operate within a customer-controlled environment.
The customer controls and is responsible for its cloud subscription or tenant, identities, permissions, network configuration, security policies, resource configuration, monitoring, backup policies, data retention, and other customer-controlled infrastructure.
Novulis is responsible for the Novulis software and for product updates, fixes, or support provided under the applicable subscription or support agreement.
03Customer-Hosted Data Boundary
For customer-hosted deployments, Customer Content remains within the customer-controlled environment as part of normal product operation.
Novulis does not require Customer Content to be transferred to a Novulis-hosted application backend, database, storage service, AI environment, or control plane for normal operation.
Novulis may retain limited deployment metadata, including customer or organization name and an applicable Microsoft Azure Subscription ID, for entitlement, licensing, support, deployment identification, and update coordination.
An Azure Subscription ID by itself does not provide Novulis access to customer resources or Customer Content.
04Build Studio Customer-Hosted Architecture
A Build Studio customer-hosted deployment may use customer-controlled Microsoft Azure resources such as:
- Azure Kubernetes Service (AKS) or other Azure compute resources
- Application containers
- Databases
- Azure AI Foundry resources
- Storage
- Networking
- Microsoft Entra ID
- Playwright or testing resources
- Monitoring and logging services
- Other Azure resources required by the selected architecture
The customer controls these resources and determines how its environment is configured.
05GovXRM Customer-Hosted Architecture
GovXRM customer-hosted deployments operate within customer-controlled Microsoft cloud resources appropriate to the selected GovXRM modules and architecture.
Customers control the applicable tenant or subscription configuration, identities, access policies, data, integrations, and regional deployment choices.
06Identity and Access Management
Depending on product configuration, Novulis products may integrate with Microsoft Entra ID or other customer-approved identity providers.
Security capabilities may include:
- Centralized identity management
- Role-based access control
- Customer-controlled user provisioning
- Least-privilege access configuration
- Customer-controlled authentication policies
For customer-hosted deployments, customers control access to their environment and may restrict or revoke support access.
07Administrative Access
Novulis does not require permanent administrative access to customer-hosted environments for normal product operation.
If a customer requests support that requires Novulis access, the customer may authorize access according to its own security and change-management procedures. Customer-authorized access may be time limited, scoped to specific resources, logged, monitored, and revoked by the customer.
For Novulis-hosted SaaS, administrative access to service environments is limited to authorized operational and support purposes.
08Encryption
Novulis products are designed to use encrypted network communications for supported product connections.
Data-at-rest protection depends on the Microsoft cloud services and configuration used by the applicable deployment. For customer-hosted environments, the customer controls the configuration of encryption, keys, storage, databases, networking, and related cloud-security features unless otherwise agreed.
09Network Security
Customer-hosted customers control their network architecture and may use Microsoft Azure security capabilities appropriate to their environment, including private networking, firewalls, private endpoints, network security controls, and customer-defined routing policies where supported by the selected architecture.
For SaaS, Novulis manages the network configuration of the Novulis-hosted application environment.
10Application Logging and Monitoring
Novulis products may generate application, diagnostic, security, and operational logs necessary to operate and troubleshoot the product.
For customer-hosted deployments, logs remain within customer-controlled resources unless the customer chooses to provide specific information to Novulis for support.
For SaaS, Novulis may use operational logs to maintain availability, investigate incidents, troubleshoot defects, and protect the service.
11Artificial Intelligence Security and Data Handling
Build Studio may use Microsoft Azure AI services, including Azure AI Foundry, when configured for applicable product capabilities. GovXRM may also use AI-enabled capabilities where included in the selected deployment.
For customer-hosted deployments, applicable AI resources are configured within or associated with the customer-controlled Microsoft cloud environment. Customer Content is not required to be transferred to a Novulis-hosted AI environment for normal operation.
For Novulis-hosted SaaS, AI processing occurs through the cloud resources used by Novulis to provide the subscribed service.
Novulis does not use Customer Content to train Novulis-owned general-purpose AI models.
12Product Updates and Security Fixes
Novulis may release product updates, compatibility updates, defect fixes, and security-related fixes for Build Studio and GovXRM.
For SaaS, Novulis manages deployment of updates to the Novulis-hosted service in accordance with the applicable service process.
For customer-hosted deployments, Novulis may notify customers of applicable updates and provide deployment artifacts, instructions, or support. Deployment timing remains subject to the customer's change-management process unless another process is established in the applicable agreement.
13Vulnerability and Security Issue Handling
Customers should report suspected product vulnerabilities or security issues through the applicable Novulis product-support channel and should avoid including sensitive Customer Content in an initial report unless necessary and authorized.
Novulis may request additional technical information to reproduce, assess, and remediate a reported product-security issue.
For Build Studio, reports may be submitted to:
buildstudioPG@novulis.com
GovXRM customers may use the security or support contact identified in their agreement with Novulis.
14Backup, Recovery, and Availability
For customer-hosted deployments, customers control backup, recovery, redundancy, disaster-recovery, and availability configurations for their own cloud resources unless the applicable agreement states otherwise.
For SaaS, backup, recovery, and availability practices are managed as part of the Novulis-hosted service and may be further described in the applicable customer agreement or service documentation.
15Customer Responsibilities
Customers are responsible for securing the components under their control, including:
- User accounts and identities
- Endpoint devices
- Customer-managed credentials and secrets
- Cloud subscriptions and tenants
- Network and firewall configuration
- Customer-managed integrations
- Data classification and retention
- Backup and recovery configuration for customer-hosted deployments
- Compliance with customer-specific security policies and regulatory requirements
16Compliance and Certifications
This page does not claim a certification, audit report, regulatory authorization, or compliance designation unless Novulis separately identifies that certification or authorization in writing.
Customers with specific compliance requirements should confirm those requirements with Novulis during the procurement or security-review process and validate that the selected Microsoft cloud environment and product configuration satisfy their requirements.
17Privacy
For information about product data handling, see the Novulis Product Privacy Policy:
18Support
For support information, see:
Support
How to get help, what to include in a request, and what support covers.
Novulis Corporation provides product support for Build Studio and GovXRM according to the customer's subscription, support plan, Marketplace offer, private offer, order form, or other applicable agreement.
This page provides the general support model for both Novulis-hosted SaaS and customer-hosted deployments.
01Products Covered
This support page applies to:
- Build Studio
- GovXRM
Support entitlements, service levels, hours, response targets, and included services may vary by customer agreement or purchased support plan.
02Build Studio Support
Build Studio customers may contact Novulis at:
Build Studio Support
buildstudiosupport@novulis.com
For product-engineering questions:
Build Studio Product Group
buildstudioPG@novulis.com
Novulis may request customer, subscription, deployment, version, diagnostic, or other technical information necessary to investigate the issue.
03GovXRM Support
GovXRM customers should use the Novulis product-support contact identified in their subscription, order form, private offer, support plan, or service agreement.
This page may be used as the public support URL for GovXRM Marketplace listings, while the applicable customer agreement identifies the operational support contact and service-level commitments for that customer.
04Support for Novulis-Hosted SaaS
For Novulis-hosted SaaS, Novulis support may assist with issues involving:
- Product availability
- Authentication and product access
- Product defects
- Product configuration
- Product functionality
- Supported integrations
- Product updates
- Security-related product issues
- Service incidents
Customers remain responsible for their own users, endpoints, customer-managed identity policies, and external systems unless the applicable agreement states otherwise.
05Support for Customer-Hosted Deployments
For customer-hosted Build Studio or GovXRM deployments, Novulis support may assist with:
- Product installation and deployment questions
- Product configuration
- Product defects
- Upgrade and update guidance
- Compatibility issues
- Product troubleshooting
- Supported integrations
- Security-related product fixes
- Deployment-artifact questions
The customer manages its own Microsoft cloud environment unless the governing agreement specifically includes managed services.
Novulis does not require permanent administrative access to customer-hosted environments.
If troubleshooting requires access to customer-controlled resources, the customer must authorize that access. The customer may scope, monitor, time-limit, and revoke support access in accordance with its security policies.
06Information to Include in a Support Request
To help Novulis investigate efficiently, customers should provide information that is appropriate and authorized for the issue, such as:
- Product name: Build Studio or GovXRM
- Customer or organization name
- Product version or release, if known
- Deployment model: SaaS or customer-hosted
- A clear description of the issue
- Business impact
- Date and approximate time the issue occurred
- Relevant error messages
- Steps to reproduce the issue, if available
- Relevant diagnostic or log information that the customer is authorized to share
Customers should avoid sending passwords, private keys, secrets, access tokens, or unnecessary sensitive Customer Content through email.
07Support Prioritization
Novulis may prioritize support requests based on business impact, product availability, security risk, number of affected users, and the applicable customer's support agreement.
Specific severity definitions, response targets, resolution targets, escalation procedures, service credits, or 24x7 commitments apply only when stated in the customer's governing support agreement or Marketplace offer.
08Product Updates
Novulis may provide:
- Product updates
- Security-related updates
- Defect fixes
- Compatibility updates
- Upgrade guidance
- New product releases
For SaaS, Novulis manages updates to the Novulis-hosted environment.
For customer-hosted deployments, Novulis may use limited deployment information such as customer or organization name and an applicable Azure Subscription ID to identify affected deployments and coordinate updates. The customer remains in control of deployment timing and its change-management process unless otherwise agreed.
09Customer-Hosted Data Handling During Support
Customer Content remains within the customer-controlled environment during normal operation.
If a customer voluntarily provides logs, screenshots, configuration information, or other technical data to Novulis for troubleshooting, Novulis will use that information only as necessary to investigate and support the customer, subject to the applicable agreement and Novulis Product Privacy Policy.
Novulis does not require customers to provide broad or permanent access to Customer Content for routine product support.
10Security Issues
Suspected vulnerabilities or security issues should be identified clearly as a security matter when contacting Novulis.
For Build Studio security or product-engineering issues, customers may contact:
buildstudioPG@novulis.com
GovXRM customers may use the security or support contact identified in their Novulis agreement.
Do not include passwords, secret keys, access tokens, or exploit data containing unnecessary sensitive information in an initial email.
11Items Generally Outside Product Support
Unless included in the customer's agreement, product support does not automatically include responsibility for:
- Administration of the customer's Azure subscription or Microsoft tenant
- Customer endpoint management
- Customer network administration
- Customer identity administration
- Operation of unrelated third-party products
- Custom software not supplied by Novulis
- Customer-developed integrations outside the documented Novulis product interface
- Cloud consumption charges
- General consulting or implementation services not included in the purchased support plan
Novulis may offer separately scoped services where appropriate.
12Microsoft Marketplace Customers
Customers that acquire a Novulis product through Microsoft Marketplace may use the support information presented in the applicable Marketplace listing and this page.
Marketplace purchase terms, support entitlements, and any private-offer commitments remain subject to the applicable Marketplace transaction and governing agreement.
13Privacy and Security Resources
14Mailing Address
Novulis Corporation
1925, Isaac Newton Square, Suite 110
Reston, Virginia 20190
Contact
Novulis Corporation
Build Studio Support
Product help, configuration and troubleshooting.
buildstudiosupport@novulis.comAbout Build StudioBuild Studio Product Group
Product-engineering questions and security reports.
buildstudioPG@novulis.comMailing Address
Novulis Corporation
1925, Isaac Newton Square, Suite 110
Reston, Virginia 20190
