This Data Processing Agreement ("DPA") forms part of the Terms of Service or another agreement that expressly incorporates it (the "Agreement") between the customer identified in that Agreement ("Customer") and Vlad Gorokhov, Praça de Bocage 67, 2900-276 Setúbal, Portugal ("Norn"). It applies when Norn processes personal data on the Customer's behalf in providing Norn Cloud. It applies to the free service as well as any separately agreed arrangement.
Norn's data protection contact is privacy@norn.so. The Customer's contact is its authorised account or workspace administrator, or another contact it designates in writing. A Customer that needs a separately executed copy can request one at that email address. This DPA is not retroactive acceptance of terms on behalf of an existing customer.
1. Scope, roles, and precedence
"Customer Personal Data" means personal data submitted to, generated in, or otherwise processed through the service on the Customer's behalf. "Data Protection Law" means the GDPR and other data protection legislation applicable to that processing. "Controller", "processor", "personal data breach", and related terms have their meanings under that law.
The Customer is the controller and Norn is its processor. Where the Customer acts for another controller, the Customer is a processor and Norn is its subprocessor; the Customer must have authority to appoint Norn and issue the instructions in this DPA. Norn's duties apply to Customer Personal Data in either case.
This DPA does not govern information for which Norn determines its own purposes as a controller, such as administration of the direct account relationship and website visitor information. Those activities are described in the Privacy Policy. Operating a self-hosted Norn installation alone does not make Norn its processor. Any separate support access involving personal data must be covered by appropriate instructions and an applicable processing agreement.
This DPA takes priority over conflicting provisions of the Agreement concerning Customer Personal Data. Applicable mandatory transfer clauses take priority over conflicting terms of this DPA. Nothing in either agreement limits a data subject's statutory rights or a supervisory authority's powers.
2. Documented instructions
Norn will process Customer Personal Data only on the Customer's documented instructions, including instructions concerning disclosures and international transfers, unless applicable law requires otherwise. The Agreement, this DPA, authorised use of the service, and the Customer's configuration of access, integrations, notifications, runners, and deletion constitute those instructions. Further lawful instructions may be provided in writing to Norn's data protection contact.
Norn will tell the Customer if it considers an instruction to infringe Data Protection Law and may suspend the affected processing while the parties resolve it. If law requires processing outside the instructions, Norn will inform the Customer before processing unless that law prohibits notification on important grounds of public interest.
Norn will not sell Customer Personal Data, use it for advertising, train AI models on it, or use it for an independent commercial purpose. Processing necessary to provide and secure the contracted service remains subject to this DPA.
3. Customer responsibilities
The Customer determines the purpose and lawfulness of the processing, provides required information to data subjects, and obtains any necessary permissions. It is responsible for its instructions, the content it submits, and appropriate access and integration settings. It must limit submitted data to what is needed and must not instruct unlawful processing.
The service is not designed for special-category personal data under Article 9 GDPR or criminal-offence data under Article 10. The Customer must not intentionally submit such data without separately agreeing appropriate safeguards with Norn. Unexpected inclusion does not remove Norn's obligations under this DPA or applicable law.
4. Confidentiality and security
Norn will restrict access to authorised persons who need it for the instructed processing and ensure that those persons are subject to appropriate confidentiality obligations. Norn will implement and maintain technical and organisational measures appropriate to the risks, taking account of the nature of the data, the processing, the state of the art, and the cost of implementation, in accordance with Article 32 GDPR.
The security schedule below describes relevant measures and commitments. Norn may update measures as technology and risks change, without materially reducing the overall protection of Customer Personal Data. The schedule does not assert a certification, end-to-end encryption, or an independently audited control unless expressly stated in a separate written agreement.
5. Subprocessors
The Customer gives general written authorisation for Norn to use the subprocessors in the subprocessor schedule. Before engaging another subprocessor, Norn will ensure that a written agreement imposes data protection obligations providing at least the protection required by this DPA for the processing concerned. Norn remains responsible to the Customer for the subprocessor's performance of those obligations.
Norn will notify the Customer's designated contact in advance of adding or replacing a subprocessor, giving information about its function and processing location and sufficient time for the Customer to object on reasonable data protection grounds before it receives Customer Personal Data. Publication of an updated list alone does not replace that notice.
The parties will work in good faith to resolve an objection, including considering an alternative or avoiding the affected processing. If no solution is possible, the Customer may stop the affected service and request return or deletion of its data. Norn will not use the disputed subprocessor for that Customer's data before resolving the objection or ending the affected processing.
6. Customer-selected services and transfers
The Customer can instruct Norn to exchange data with its own AI provider, identity provider, source-control provider, MCP servers, webhook destinations, messaging services, and runners. Where the Customer contracts with and controls the recipient, that recipient is a Customer-selected service rather than a subprocessor engaged by Norn. The Customer is responsible for the recipient agreement and the lawfulness of its instruction. This distinction does not remove Norn's responsibility for its own processing and transfers.
Core Cloud infrastructure and storage are in Germany. Norn will not make a transfer of Customer Personal Data requiring safeguards under Data Protection Law without a valid transfer mechanism and any necessary supplementary measures. Norn will provide relevant information and assistance so the Customer can assess a proposed transfer. If safeguards can no longer be met, Norn will inform the Customer and suspend the affected transfer until it can lawfully resume, or arrange return or deletion as appropriate.
Where Standard Contractual Clauses or another contractual transfer instrument are needed, the parties will put the applicable instrument and completed annexes in place before the transfer. This DPA alone is not an assertion that a transfer instrument has been executed or that a customer's chosen non-EU provider has adequate safeguards. Norn will provide information about applicable safeguards on request.
7. Assistance with data protection obligations
Taking account of the nature of the processing, Norn will assist the Customer with appropriate technical and organisational measures to respond to data subject requests, including access, correction, erasure, restriction, objection, and portability. Norn will promptly pass on requests it receives concerning Customer Personal Data and will not decide the response on the Customer's behalf unless instructed or required by law.
Taking account of the processing and information available to it, Norn will assist the Customer with security obligations, breach notifications, data protection impact assessments, and prior consultation with supervisory authorities under Articles 32–36 GDPR. The Customer should supply the information and instructions reasonably needed for that assistance.
8. Personal data breaches
Norn will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. Norn will not wait for a complete investigation before giving an initial notification. Notification will be sent to the Customer's designated contact or authorised administrator.
As information becomes available, Norn will describe the nature of the breach, affected categories and approximate numbers of people and records where known, likely consequences, measures taken or proposed, and a contact for follow-up. Norn will provide updates, take reasonable steps to contain and remedy the breach, and assist the Customer with its own notification duties. The Customer determines its notices to authorities and individuals, unless the law requires Norn to act directly.
9. Return, deletion, and the end of processing
At the end of the relevant services, Norn will, at the Customer's choice, return or delete Customer Personal Data and delete remaining copies, unless applicable law requires retention. The Customer should give its choice and request any return before initiating permanent workspace deletion. Return will be in a reasonably usable electronic form; it does not depend on a particular self-service export feature being available.
A workspace deletion request ordinarily starts the recovery period displayed in the service, which defaults to 30 days, followed by background purge. The Customer may request different timing where required to meet a lawful erasure obligation. Deleting an individual member's account is not an instruction to erase all shared workspace content.
Residual backups will be isolated from ordinary use and removed through backup rotation. The current shared database backup policy preserves a 30-day recovery window and the backup chain needed to restore that window; individual backup copies can therefore be older than 30 days. Norn will continue to protect those copies under this DPA until they are removed, and reapply deletion instructions if a backup is restored. On request, Norn will explain the applicable deletion timetable and confirm completion, including any remaining legally required retention.
Where law requires retention, Norn will identify the requirement to the Customer unless prohibited, limit processing to the required purpose, and delete the data when the requirement ends. This DPA continues for as long as Norn holds Customer Personal Data.
10. Information, audits, and inspections
Norn will make available the information necessary to demonstrate compliance with this DPA and Article 28 GDPR and allow and contribute to audits and inspections by the Customer or an auditor it appoints. The parties may first use relevant documentation to address a request, but documentation does not replace a necessary inspection or statutory audit right.
The parties will arrange reasonable notice, scope, confidentiality, and safeguards for other customers' information and service security. These arrangements must not obstruct a necessary audit, an urgent investigation, or a supervisory authority's rights. Norn will inform the Customer if it considers an audit instruction to infringe Data Protection Law and work to resolve the issue.
Schedule 1. Processing details
- Subject matter: hosting and providing the Customer's Norn workspace and its requested collaboration, integration, notification, and agent coordination features.
- Duration: the service relationship and the period needed to complete return, deletion, backup rotation, or retention required by law as described above.
- Nature and purpose: receiving, organising, storing, retrieving, displaying, transmitting, updating, and deleting data; managing authorised access; routing instructed tool calls and notifications; coordinating customer runners; and maintaining, securing, and supporting these functions.
- Data subjects: the Customer's users, employees, contractors, customers, contacts, and other people whose information authorised users place in the service.
- Data categories: names, contact details, identifiers and membership information; project and issue content, comments, files, and imported records; integration configuration and credentials; agent instructions and conversations; execution logs, transcripts, code changes and artifacts; and associated activity, access, and diagnostic information, to the extent these contain personal data.
- Sensitive data: not intended, subject to section 3. The Customer controls the actual content and must minimise personal data submitted.
- Frequency: ongoing storage, with other operations when users, integrations, runners, or service maintenance initiate them.
- Customer rights and duties: determine and document lawful instructions, control authorised access, meet controller obligations, and exercise the assistance, audit, return, and deletion rights in this DPA.
Schedule 2. Security measures
- Access control: authenticated sessions, server-side workspace and resource permission checks, scoped agent and API-token access, revocation controls, and support for customer-configured single sign-on.
- Credentials: password hashing, hashed session tokens, and authenticated encryption of stored integration secrets using a separately configured server key. These protect credentials; they do not mean that all workspace content is encrypted with a key controlled solely by the Customer.
- Transport and files: HTTPS for public Cloud access, access-controlled file operations, time-limited signed object-storage links, and attachment delivery from an origin separate from the app's session-cookie origin.
- Abuse prevention and diagnostics: request and authentication limits, audit and diagnostic records, redaction of recognised secrets in structured logs, and restricted diagnostic collection. Session replay is not enabled in the Cloud deployment configuration.
- Continuity and deletion: scheduled database backups, a workspace recovery period before purge, and cleanup of workspace records and associated files. Norn will maintain recovery capability and assess the effectiveness of security measures as required by Article 32 GDPR. This is not an uptime or recovery-time guarantee.
- Organisational controls: access limited to authorised persons for the service purpose, confidentiality obligations, handling of data protection requests and incidents through Norn's designated contact, and subprocessor and transfer obligations under this DPA.
The Customer remains responsible for security of its endpoints and runners, the permissions it grants, the data it shares, and credentials held by its own systems. Norn's obligations continue to apply to data received and processed by Norn.
Schedule 3. Subprocessors and other services
Hetzner Online GmbH — Germany
Infrastructure hosting, database and file storage, and backup infrastructure for Norn's hosted systems in Germany. Depending on the hosted component, the data includes workspace content, attachments, credentials in their stored form, operational records, service email, and backup copies. Hetzner is the infrastructure subprocessor authorised under section 5. See Hetzner's data protection information.
Services operated by Norn's operator
Epostix handles outgoing service mail and enabled incoming email. Plausible at plausible.hexmere.com provides website analytics, and Sentry at events.hexmere.com provides error and performance reporting. These self-hosted services are operated by Vlad Gorokhov, the same operator as Norn, rather than separate subprocessors. Their underlying infrastructure provider is listed above. Whether their data is Customer Personal Data or controller data depends on the purpose of the particular processing.
Cloudflare — public websites and DNS
Cloudflare, Inc. provides public website and documentation delivery and DNS services on global infrastructure. Public visitor request data is covered by the Privacy Policy. Cloudflare is not configured as the proxy for the Cloud app's workspace traffic and is not listed here as a workspace-content subprocessor. If that role changes, Norn must follow the notice and authorisation provisions above.
Customer-selected recipients
AI providers use the Customer's own credentials; runners use the Customer's own machines. Connected source-control hosts, identity providers, MCP servers, webhook destinations, messaging services, and recipient mail providers depend on the Customer's choices. They are not universally engaged by Norn as subprocessors. Section 6 governs instructed exchanges with them. No model vendor is automatically included as a Norn-provided AI subprocessor merely because the software can connect to that vendor.