Last updated: 16 April 2026

Data Processing Agreement.

This Data Processing Agreement (“DPA”) is incorporated into and forms part of the Terms of Service between Norma AI Ltd. (“Processor”) and you, the customer (“Controller”). It governs the processing of personal data by Norma on your behalf, as required by GDPR Article 28.

Note: This DPA is automatically in effect for all Norma customers. If your organisation requires a signed DPA for procurement purposes, email [email protected] to request a countersigned copy.

1. Definitions

Controller: The customer — the entity that determines the purposes and means of personal data processing.

Processor: Norma AI Ltd. — processes personal data on behalf of the Controller.

Personal data, processing, data subject: As defined in GDPR Article 4.

Sub-processor: Any third party appointed by Norma to process personal data under this DPA.

2. Scope and Nature of Processing

Categories of data subjects: The Controller’s employees, customers, or other individuals whose data appears in uploaded documents.

Categories of personal data: Names, email addresses, and any personal data contained within compliance policy documents uploaded by the Controller.

Purposes of processing: To provide AI-powered compliance gap analysis, policy generation, and related features of the Norma platform.

Duration: For the term of the Controller’s subscription, plus 90 days post-termination for data export.

3. Controller Instructions

Norma shall process personal data only on documented instructions from the Controller, including with regard to international transfers of personal data. The Terms of Service and this DPA constitute such instructions.

Norma shall inform the Controller immediately if it believes an instruction infringes GDPR or other applicable data protection law.

4. Confidentiality

Norma ensures that all personnel authorised to process personal data are bound by appropriate confidentiality obligations, whether by contract or statutory duty.

5. Security Measures

Norma implements appropriate technical and organisational security measures, including:

  • Encryption of personal data at rest (AES-256) and in transit (TLS 1.2+)
  • Role-based access controls and principle of least privilege
  • Regular vulnerability assessments and penetration testing
  • Incident response procedures
  • EU-based infrastructure for primary data storage

Further details are available on our Security page.

6. Sub-processors

The Controller authorises Norma to engage the following sub-processors:

Sub-processorPurposeLocation
AnthropicAI model inference for compliance analysisUSA (SCCs in place)
SupabaseDatabase and authentication infrastructureEU
StripePayment processingUSA (SCCs in place)
ClerkUser authenticationUSA (SCCs in place)
ResendTransactional emailUSA (SCCs in place)
VercelFrontend hostingUSA (SCCs in place)

Norma will notify the Controller of intended changes to sub-processors via email with 30 days’ notice, allowing the Controller to object. All sub-processors are bound by data processing agreements no less restrictive than this DPA.

7. Data Subject Rights

Norma shall assist the Controller in fulfilling its obligations to respond to data subject rights requests (access, rectification, erasure, portability, restriction, objection) by providing the technical means to retrieve or delete personal data on request.

8. Data Breach Notification

Norma shall notify the Controller without undue delay — and within 72 hours where feasible — upon becoming aware of a personal data breach affecting data processed under this DPA. Notification will include the nature of the breach, categories affected, and measures taken.

9. Data Protection Impact Assessments

Norma shall provide reasonable assistance to the Controller in conducting Data Protection Impact Assessments (DPIAs) where required under GDPR Article 35, including information about processing activities and security measures.

10. Deletion and Return of Data

On termination of the service or at the Controller’s request, Norma shall delete or return all personal data and certify such deletion within 30 days, unless EU law requires retention.

11. Audits

Norma shall make available all information necessary to demonstrate compliance with GDPR Article 28 and allow for, and contribute to, audits and inspections. Audits may be conducted by the Controller or a mandated auditor on reasonable written notice (minimum 30 days) and at the Controller’s cost.

12. International Transfers

Where personal data is transferred outside the EEA, Norma ensures appropriate safeguards are in place — specifically the Standard Contractual Clauses (EU Commission Decision 2021/914) with all relevant sub-processors.

13. Contact

DPA enquiries: [email protected]