Data Processing Agreement.
This Data Processing Agreement (“DPA”) is incorporated into and forms part of the Terms of Service between Norma AI Ltd. (“Processor”) and you, the customer (“Controller”). It governs the processing of personal data by Norma on your behalf, as required by GDPR Article 28.
1. Definitions
Controller: The customer — the entity that determines the purposes and means of personal data processing.
Processor: Norma AI Ltd. — processes personal data on behalf of the Controller.
Personal data, processing, data subject: As defined in GDPR Article 4.
Sub-processor: Any third party appointed by Norma to process personal data under this DPA.
2. Scope and Nature of Processing
Categories of data subjects: The Controller’s employees, customers, or other individuals whose data appears in uploaded documents.
Categories of personal data: Names, email addresses, and any personal data contained within compliance policy documents uploaded by the Controller.
Purposes of processing: To provide AI-powered compliance gap analysis, policy generation, and related features of the Norma platform.
Duration: For the term of the Controller’s subscription, plus 90 days post-termination for data export.
3. Controller Instructions
Norma shall process personal data only on documented instructions from the Controller, including with regard to international transfers of personal data. The Terms of Service and this DPA constitute such instructions.
Norma shall inform the Controller immediately if it believes an instruction infringes GDPR or other applicable data protection law.
4. Confidentiality
Norma ensures that all personnel authorised to process personal data are bound by appropriate confidentiality obligations, whether by contract or statutory duty.
5. Security Measures
Norma implements appropriate technical and organisational security measures, including:
- Encryption of personal data at rest (AES-256) and in transit (TLS 1.2+)
- Role-based access controls and principle of least privilege
- Regular vulnerability assessments and penetration testing
- Incident response procedures
- EU-based infrastructure for primary data storage
Further details are available on our Security page.
6. Sub-processors
The Controller authorises Norma to engage the following sub-processors:
| Sub-processor | Purpose | Location |
|---|---|---|
| Anthropic | AI model inference for compliance analysis | USA (SCCs in place) |
| Supabase | Database and authentication infrastructure | EU |
| Stripe | Payment processing | USA (SCCs in place) |
| Clerk | User authentication | USA (SCCs in place) |
| Resend | Transactional email | USA (SCCs in place) |
| Vercel | Frontend hosting | USA (SCCs in place) |
Norma will notify the Controller of intended changes to sub-processors via email with 30 days’ notice, allowing the Controller to object. All sub-processors are bound by data processing agreements no less restrictive than this DPA.
7. Data Subject Rights
Norma shall assist the Controller in fulfilling its obligations to respond to data subject rights requests (access, rectification, erasure, portability, restriction, objection) by providing the technical means to retrieve or delete personal data on request.
8. Data Breach Notification
Norma shall notify the Controller without undue delay — and within 72 hours where feasible — upon becoming aware of a personal data breach affecting data processed under this DPA. Notification will include the nature of the breach, categories affected, and measures taken.
9. Data Protection Impact Assessments
Norma shall provide reasonable assistance to the Controller in conducting Data Protection Impact Assessments (DPIAs) where required under GDPR Article 35, including information about processing activities and security measures.
10. Deletion and Return of Data
On termination of the service or at the Controller’s request, Norma shall delete or return all personal data and certify such deletion within 30 days, unless EU law requires retention.
11. Audits
Norma shall make available all information necessary to demonstrate compliance with GDPR Article 28 and allow for, and contribute to, audits and inspections. Audits may be conducted by the Controller or a mandated auditor on reasonable written notice (minimum 30 days) and at the Controller’s cost.
12. International Transfers
Where personal data is transferred outside the EEA, Norma ensures appropriate safeguards are in place — specifically the Standard Contractual Clauses (EU Commission Decision 2021/914) with all relevant sub-processors.
13. Contact
DPA enquiries: [email protected]