licence and privacy agreements

This Privacy Policy explains how [LEGAL ENTITY NAME] ("Novus," "we," "us," or "our") handles information when an authorized user accesses the Novus Proposal Agent (the "App") or connects Microsoft 365 or QuickBooks Online. The App is currently designed for internal Novus use, not for general public enrollment.

1. Information we handle

QuickBooks Online information

  1. company and connection identifiers, including the QuickBooks realm/company ID;

  2. customer records used for exact matching or approved creation, including display name, company name, active status, email address, phone number, billing address, and QuickBooks customer ID;

  3. product/service names and stable item IDs used on Estimates;

  4. Estimate data, including document number, customer reference, service descriptions, quantities, rates, amounts, total, email status, Estimate ID, and synchronization token; and

  5. OAuth access and refresh tokens, expiration data, and connection-environment metadata.

Proposal and Microsoft 365 information

  1. proposal-request emails, sender and recipient information, message identifiers, subject lines, message bodies, timestamps, and attachments;

  2. client and project information, such as names, company, email, phone, project name, address/location, area, scope, schedule, exclusions, and proposal status;

  3. pricing workbooks, pricing inputs and outputs, service fees, proposal totals, and related SharePoint files and lifecycle records; and

  4. internal review messages, approval evidence, revision hashes, conversation identifiers, and workflow state.

Technical and audit information

We may handle correlation IDs, operation names, timestamps, stable external record IDs, workflow version, runtime mode, error and retry information, and security events. The implementation is designed not to place OAuth tokens, passwords, full email bodies, or unnecessary attachment content in technical audit logs.

2. Sources of information

We obtain information from authorized users; connected Microsoft 365 and QuickBooks Online accounts; emails, attachments, SharePoint files and workbooks; and records generated by the App, such as revision hashes, approval evidence, deterministic request IDs, and audit events.

3. How we use information

  1. authenticate and maintain authorized connections;

  2. identify and archive proposal requests and supporting files;

  3. prepare project scopes, calculate and review proposal pricing, and maintain proposal workflow state;

  4. find an unambiguous active QuickBooks customer or, when the approved workflow allows, create and verify a customer from validated information;

  5. create, read back, verify, and reconcile an unsent QuickBooks Estimate after current-revision approval;

  6. prevent duplicate customers, files, proposal records, and Estimates;

  7. secure, troubleshoot, audit, and improve the App; and

  8. comply with law and enforce applicable agreements.

We do not use connected-company information for advertising, sell it, or share one QuickBooks customer's data with another customer. The current App does not process QuickBooks Payments or automatically send Estimates to clients.

4. OAuth permissions

The intended Intuit OAuth permission is `com.intuit.quickbooks.accounting`, which provides access to the QuickBooks Online Accounting API. The App does not intend to request the QuickBooks Payments scope. The repository does not implement Intuit OpenID profile scopes. Before publication, Novus will verify that the Developer Portal and live authorization request match this statement.

5. How we disclose information

We disclose information only as reasonably necessary to operate the workflow, including to:

  1. Intuit/QuickBooks Online, to authenticate and perform the authorized customer and Estimate operations;

  2. Microsoft, to use Outlook, SharePoint, and Excel functionality;

  3. [CONFIRM HOSTING, MONITORING, AI, AND OTHER SERVICE PROVIDERS], acting under appropriate contractual and security obligations;

  4. professional advisers and auditors who need the information to provide services; and

  5. government authorities or other parties when required by law or reasonably necessary to protect rights, safety, accounts, or systems.

If the App's operator is involved in a merger, acquisition, financing, reorganization, or sale of assets, information may be transferred subject to applicable law and appropriate protections.

6. Storage, retention, and deletion

The current implementation stores durable proposal business records and archived source material in Novus's Microsoft 365/SharePoint environment. It may also store local, access-restricted workflow state, audit files, and OAuth token caches. The repository excludes these local files and secrets from Git. Hosted secret storage in Azure Key Vault is planned but is not yet implemented in the reviewed repository.

Retention confirmation required. The repository does not define or enforce a production retention schedule or automated deletion workflow. Before publication, Novus must adopt the following periods and operational process: QuickBooks OAuth tokens: delete/revoke within [X DAYS] after disconnect; local runtime/audit files: [X DAYS]; proposal emails, attachments, workbooks, Estimates, and SharePoint lifecycle records: [X YEARS OR BUSINESS RETENTION RULE]; backups: [X DAYS].

 

Subject to legal and business-record obligations, Novus will delete or de-identify information when it is no longer needed for the purposes described above. Disconnecting QuickBooks prevents new access only after the connection tokens are revoked; it does not by itself delete source emails, SharePoint records, workbooks, or QuickBooks records already created.

7. Security

The reviewed implementation uses HTTPS APIs, separate Microsoft and Intuit OAuth connections, environment and realm checks, restricted runtime modes, deterministic approval and idempotency controls, gitignored token/state files, and access-restricted local file writes where supported. It avoids putting credentials in application commands or durable proposal state. No security measure is perfect, and the current local token stores must be replaced or formally approved before hosted production use.

8. Your choices and requests

An authorized account administrator may disconnect QuickBooks Online using [DISCONNECT METHOD/URL] and may request access, correction, deletion, or export of information by contacting [PRIVACY EMAIL]. Requests may be limited by identity verification, legal obligations, and the need to preserve legitimate business records. Novus will respond within the time required by applicable law.

9. International and state privacy rights

The App is intended for [CONFIRM OPERATING COUNTRY/REGION AND ACCEPTED CONNECTION COUNTRIES]. Depending on location and applicable law, individuals may have rights to access, correct, delete, restrict, object to, or obtain a copy of personal information, and to appeal certain decisions. Contact us to exercise a right. We will not discriminate for exercising applicable privacy rights.

10. Children

The App is a business tool and is not directed to children. We do not knowingly collect personal information from children through the App.

11. Changes to this Policy

We may update this Privacy Policy. We will post the revised version, change the effective date, and provide additional notice when required by law or when a material change affects authorized users.

12. Contact

Novus Consulting
Attn: Privacy
13100 Wortham Center Drive, Ste. 3114

Houston, TX 77065
Email: agent@novusgroupconsulting.com
Website: www.novusprograms.com

These Terms of Use ("Terms") are an agreement between [LEGAL ENTITY NAME] ("Novus," "we," "us," or "our") and the person or organization authorized to use the Novus Proposal Agent (the "App"). By accessing the App or connecting a QuickBooks Online company, you agree to these Terms. If you use the App for an organization, you represent that you may bind that organization.

1. The App

The App is an internal, assisted proposal-intake and estimating workflow. When enabled and authorized, it may read approved business information from Microsoft 365 and QuickBooks Online, prepare proposal and pricing records, resolve or create a QuickBooks customer under the configured workflow, and create an unsent QuickBooks Online Estimate after approval of the current proposal revision.

The App does not currently send an Estimate to a customer, process payments, create invoices, provide tax or accounting advice, or replace final human review. QuickBooks production use is not enabled in the current repository build; production activation is a separate administrative and security decision.

2. Eligibility and authorized use

You may use the App only if you are an authorized Novus user, are at least 18 years old, and have authority to connect and use the relevant Microsoft 365 and QuickBooks Online accounts and data. Access is not offered to the public unless Novus expressly changes that policy in writing.

3. Limited license

Subject to these Terms, Novus grants you a limited, revocable, non-exclusive, non-transferable, non-sublicensable license to use the App for Novus business purposes. Novus and its licensors retain all rights not expressly granted.

4. Connected services and permissions

The App relies on third-party services, including Microsoft 365 and QuickBooks Online. Those services are governed by their own terms and privacy practices. You authorize the App to access connected-account data only for the workflow described in these Terms and the Privacy Policy.

For QuickBooks Online, the intended OAuth permission is the QuickBooks Online Accounting scope. That scope can technically permit access to accounting data beyond the narrow operations used by the App. The App's current code limits its QuickBooks behavior to customer lookup/creation and unsent Estimate lookup/creation/readback in the configured company.

5. Human approval and accuracy

You are responsible for reviewing all extracted project information, customer information, scopes, pricing, exclusions, and Estimate details. An approval authorizes only the action stated in the approval request for the matching proposal number, revision, and content hash. Approval to create an unsent Estimate is not approval to send it to a customer.

The App may produce incomplete or incorrect results from incomplete messages, attachments, workbooks, account records, or other source data. You must correct errors before relying on or delivering any output.

6. Your responsibilities

You agree to:

  1. provide only information you are authorized to process and keep connected-account permissions current;

  2. protect your account credentials and promptly report suspected unauthorized access;

  3. verify customer identity, contact information, scope, pricing, taxes, and commercial terms before client delivery;

  4. use the App in compliance with applicable law, professional obligations, and third-party terms; and

  5. maintain appropriate QuickBooks and Microsoft 365 records, backups, and internal approvals.

7. Prohibited conduct

You may not use the App to access a company or mailbox without authority; bypass approval or security controls; send spam or deceptive communications; introduce malicious code; probe or disrupt the App or connected services; reverse engineer the App except where law prohibits that restriction; resell or sublicense the App; or use the App for unlawful, fraudulent, or infringing activity.

8. Privacy and data

Our collection, use, storage, disclosure, retention, and deletion of information are described in the Novus Proposal Agent Privacy Policy. You are responsible for providing any notices and obtaining any permissions required from clients, prospects, employees, or other individuals whose information you submit or connect.

9. Ownership and feedback

As between you and Novus, you retain rights in data you are authorized to provide. Novus owns the App, its software, workflow design, documentation, and branding. If you provide feedback, you grant Novus a perpetual, worldwide, royalty-free right to use it without obligation to you.

10. Availability and changes

The App is under active development and may change, be suspended, or be discontinued. Connected services may change their APIs, permissions, or availability. Novus does not promise uninterrupted or error-free operation and may restrict access to protect data, accounts, or systems.

11. Disclaimers

TO THE MAXIMUM EXTENT PERMITTED BY LAW, THE APP IS PROVIDED "AS IS" AND "AS AVAILABLE." NOVUS DISCLAIMS ALL EXPRESS, IMPLIED, AND STATUTORY WARRANTIES, INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, NON-INFRINGEMENT, ACCURACY, AND RESULTS. THE APP IS NOT ACCOUNTING, TAX, LEGAL, ENGINEERING, OR OTHER PROFESSIONAL ADVICE.

12. Limitation of liability

TO THE MAXIMUM EXTENT PERMITTED BY LAW, NOVUS AND ITS AFFILIATES, OFFICERS, EMPLOYEES, AND LICENSORS WILL NOT BE LIABLE FOR INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, OR PUNITIVE DAMAGES, OR FOR LOST PROFITS, REVENUE, DATA, GOODWILL, OR BUSINESS INTERRUPTION. NOVUS'S TOTAL LIABILITY ARISING OUT OF THE APP OR THESE TERMS WILL NOT EXCEED [CONFIRM LIABILITY CAP]. Some jurisdictions do not allow certain limitations, so they may not apply to you.

13. Suspension, termination, and disconnect

You may stop using the App and disconnect QuickBooks Online at any time using [DISCONNECT METHOD/URL]. Novus may suspend or terminate access for security, legal, operational, or policy reasons. Disconnecting stops new QuickBooks API access after tokens are revoked, but it does not automatically delete records that Novus must retain for legitimate business or legal purposes. Deletion is addressed in the Privacy Policy.

14. Governing law and disputes

These Terms are governed by the laws of [STATE], without regard to conflict-of-law rules. The state and federal courts located in [COUNTY, STATE] will have exclusive jurisdiction, unless applicable law requires otherwise.

15. Changes to these Terms

We may update these Terms. We will post the updated version and revise the effective date. If a change materially affects authorized users, we will provide reasonable notice through the App, email, or another appropriate channel.

16. Contact

Novus Consulting
Attn: Privacy
13100 Wortham Center Drive, Ste. 3114

Houston, TX 77065
Email: agent@novusgroupconsulting.com
Website: www.novusprograms.com

QuickBooks and Intuit are trademarks of Intuit Inc. The App is independently operated by Novus and is not sponsored or endorsed by Intuit.