Privacy Policy.
Norma AI Ltd. (“Norma”, “we”, “us”) is committed to protecting your personal data and processing it in accordance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and applicable national data protection law.
1. Data Controller
Norma AI Ltd.
EU-registered company
Email: [email protected]
For questions about this policy or your data rights, contact our data protection team at the address above.
2. Data We Collect
Account data: Name, email address, company name, and plan tier when you register.
Usage data: Pages visited, features used, and session metadata for product improvement and security.
Document content: Policy documents, compliance materials, and other files you upload for gap analysis. These are processed to provide the service and are not used for training AI models.
Payment data: Billing information is collected and processed by Stripe. We do not store full card numbers.
Communication data: Emails and support messages you send to us.
3. Legal Basis for Processing
Contract performance (Art. 6(1)(b)): Processing your account and document data to deliver the service you signed up for.
Legitimate interests (Art. 6(1)(f)): Product analytics, fraud prevention, and security monitoring.
Consent (Art. 6(1)(a)): Marketing communications and optional analytics cookies — you can withdraw consent at any time.
Legal obligation (Art. 6(1)(c)): Retaining financial records as required by applicable law.
4. How We Use Your Data
- Provide, operate, and improve the Norma platform
- Generate AI-powered compliance gap analysis and policy documents
- Process payments and manage subscriptions
- Send service notifications and, where consented, product updates
- Detect and prevent fraud and abuse
- Comply with legal and regulatory obligations
We do not sell your personal data or use your uploaded documents to train AI models.
5. Data Processors and Third Parties
We use the following sub-processors to deliver the service:
- Anthropic: AI model inference for compliance analysis (documents processed under Anthropic’s data usage policy)
- Supabase: Database and authentication infrastructure, EU-hosted
- Stripe: Payment processing
- Clerk: User authentication
- Resend: Transactional email delivery
- Vercel: Frontend hosting
All sub-processors are bound by data processing agreements. Where transfers occur outside the EEA, appropriate safeguards (Standard Contractual Clauses) are in place.
6. Data Retention
Account data is retained for the duration of your subscription plus 90 days after account closure.
Uploaded documents are retained for 12 months from upload and deleted thereafter unless you choose to remove them earlier.
Financial records are retained for 7 years to comply with statutory accounting requirements.
You can request deletion of your data at any time (see Section 8).
7. Cookies
We use the following categories of cookies:
- Strictly necessary: Authentication session cookies — required for the service to function.
- Analytics (consent required): Aggregate usage statistics to improve the product. You can opt out via our cookie banner.
- Marketing (consent required): Not currently used.
You can manage or withdraw cookie consent at any time via your browser settings or our cookie preferences panel.
8. Your Rights Under GDPR
- Access (Art. 15): Request a copy of all personal data we hold about you.
- Rectification (Art. 16): Correct inaccurate or incomplete data.
- Erasure (Art. 17): Request deletion of your personal data (“right to be forgotten”).
- Restriction (Art. 18): Ask us to restrict processing in certain circumstances.
- Portability (Art. 20): Receive your data in a machine-readable format.
- Object (Art. 21): Object to processing based on legitimate interests.
- Withdraw consent: At any time, where processing is based on consent.
To exercise any of these rights, email [email protected]. We will respond within 30 days. You also have the right to lodge a complaint with your national supervisory authority.
9. Security
We implement technical and organisational measures to protect your personal data, including encryption at rest and in transit, access controls, and regular security assessments. See our Security page for details.
10. Changes to This Policy
We will notify you of material changes to this policy by email or in-app notification before the change takes effect. The “Last updated” date at the top of this page reflects the most recent revision.