Data Processing Agreement

How Norian processes personal data on your behalf, as your processor.

Last updated: July 2026 (version 2026-07)

This Data Processing Agreement (“DPA”) forms part of the Terms of Servicebetween you (the “Customer”) and Norian and applies to the extent Norian processes personal data on your behalf under Article 28 of the EU General Data Protection Regulation (“GDPR”). Where this DPA conflicts with the Terms of Service on data-protection matters, this DPA prevails. A countersigned copy is available on request at privacy@norian.ai.


1. ROLES

For the core monitoring of your connected mailbox, you are the controllerof the personal data contained in your email (including your clients' and contacts' personal data), and Norian is your processor. Norian processes that data only on your documented instructions, which include your configuration choices in the app and your use of the service. For Norian's own purposes - product analytics, security, abuse prevention, and service improvement - Norian acts as an independent controller, as described in our Privacy Policy, and this DPA does not apply to that processing.

2. SUBJECT MATTER, DURATION, NATURE AND PURPOSE

Subject matter and duration: processing takes place for the duration of your subscription and until deletion of your data as described below. Nature and purpose: Norian connects to your mailbox in read-only mode and uses automated analysis (including AI, see clause 6) to detect commitments and requests and notify you of items at risk of being missed.

3. TYPES OF PERSONAL DATA AND CATEGORIES OF DATA SUBJECTS

  • Data subjects: you, and the people who correspond with you by email (your clients, colleagues, and contacts).
  • Types of data: names, email addresses, email subject lines, one-line summaries of message content, and email metadata (timestamps, response times, thread lengths). Raw email bodies are processed transiently and are never stored.

4. OUR OBLIGATIONS AS PROCESSOR

  • Process personal data only on your documented instructions.
  • Ensure persons authorised to process the data are bound by confidentiality.
  • Implement appropriate technical and organisational security measures (clause 5).
  • Respect the conditions for engaging sub-processors (clause 7).
  • Assist you, taking into account the nature of the processing, in responding to data-subject requests (clause 8) and in meeting your obligations on security, breach notification, and data protection impact assessments.
  • Delete or return the data at the end of the service, and make available the information needed to demonstrate compliance (clauses 9 and 10).

5. SECURITY

Norian implements appropriate measures under Article 32 GDPR, including: read-only mailbox access; encryption in transit and at rest; row-level security enforcing strict per-account isolation; no storage of raw email bodies; and least-privilege access to production systems. See our Security page.

6. AI PROCESSING

Norian uses OpenAI's GPT-4o-mini to extract commitments and requests. The relevant email content is sent to OpenAI transiently for analysis and is not stored by Norian. Norian has signed OpenAI's Data Processing Addendum, which prohibits use of your data to train models, and processing takes place under the transfer safeguards in clause 11. Norian makes no automated decisions with legal or similarly significant effects; items are surfaced for your review.

7. SUB-PROCESSORS

You authorise Norian to engage the sub-processors listed in our Privacy Policy (currently including UniPile, Scaleway, Microsoft (Graph), Slack (Slack Connect), OpenAI, Supabase, Resend, Stripe, PostHog, and Vercel), each under written terms imposing data-protection obligations equivalent to those in this DPA. We will give you reasonable notice of any intended addition or replacement of a sub-processor so you may object on reasonable data-protection grounds.

8. ASSISTANCE WITH DATA-SUBJECT REQUESTS

Taking into account the nature of the processing, Norian will assist you by appropriate technical and organisational measures, insofar as possible, to respond to requests from data subjects exercising their rights (access, rectification, erasure, restriction, portability, and objection). You can export or delete data directly in the app, and we will help with any request we cannot fulfil through self-service at privacy@norian.ai.

9. DELETION AND RETURN

On termination, or on your request, Norian deletes the personal data it holds for your account: data stored by Norian is deleted within 60 seconds of account deletion, and your inbox connection is revoked within 24 hours, except where retention is required by applicable law. You may export your data at any time before deletion.

10. AUDITS

Norian makes available the information necessary to demonstrate compliance with Article 28 GDPR and will allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate, subject to reasonable notice, confidentiality, and frequency limits.

11. INTERNATIONAL TRANSFERS

Norian's core infrastructure (email access, database, analytics) is hosted in the EU. Where a sub-processor processes data outside the EEA (currently OpenAI, and payment/email providers), transfers are protected by the EU Standard Contractual Clauses and/or the EU-US Data Privacy Framework where the provider is certified.

12. LIABILITY

Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service.


Questions about this DPA: contact privacy@norian.ai.

Norian
Ruyschstraat 31A, Amsterdam, Noord-Holland 1091 BS, Netherlands
privacy@norian.ai