Updated
Privacy & Security
How we collect, use, store, and safeguard personal data under the GDPR, and our security posture.
Foreword
At Norn Labs, we recognise the critical importance of data protection in today's digital landscape. Inspired by pioneering efforts in data privacy, we work to develop and review our practices for safeguarding personal information. As a technology company, we're committed to integrating cutting-edge protection measures into our services, fostering a culture of respect for data privacy.
Our Privacy Policy reflects our dedication to preserving your fundamental rights and freedoms, acknowledging that behind every piece of data lies a unique individual deserving of protection.
Personal data within Norn Labs
Why is Norn Labs involved?
All companies processing personal data and conducting their activities within the European Union must comply with European regulations and the legislation in force relating to the protection of personal data.
What is personal data?
Personal data refers to any information relating to an identified or identifiable natural person, either through an identifier or one or more elements specific to their identity. This may include, for example, your surname, first name, email address, location, identity card number, IP address, photos, or social or cultural profile.
What is the processing of personal data?
Processing of personal data refers to any operation or set of operations performed on such data, including collection, recording, organisation, storage, adaptation or modification, extraction, consultation, use, disclosure, erasure or destruction.
What is the purpose of the processing?
The purpose of the processing is the primary objective for which personal data is used. Personal data must be collected for a clearly defined and legitimate purpose and must not be further processed in a manner incompatible with this initial purpose. This principle of finality restricts how the data controller can use or reuse this personal data in the future.
Where is your data stored?
The corporate website is hosted by Hostinger on infrastructure in the EU (see the Legal Notices). Contact form submissions are stored separately in our Notion workspace.
Notion and its service providers may process data outside the European Economic Area. Notion storage depends on the workspace configuration; our website hosting location is not a guarantee of EU-only storage for enquiries. See Notion’s data residency information.
What this website collects
The corporate application is a static site without visitor accounts, analytics or advertising scripts. The contact page offers a Notion form that loads only when you request it.
- Server logs. The hosting provider records standard access logs (IP address, requested page, browser identification and time) to operate and secure the service.
- Theme preference. Your theme choice is kept in your browser’s local storage. See the Cookies notice.
- Contact form. When you submit the Notion form, your name, email address, selected enquiry details, message and privacy acknowledgement are saved in our workspace to handle your enquiry. Loading the form also connects your browser to Notion, which receives technical information such as your IP address and browser details.
- Email. If you use a direct email address, we receive the information you choose to send through your email provider.
Norn Labs OÜ is the controller for information you submit to us. We use it to assess and respond to enquiries and manage the resulting relationship. Depending on the enquiry, the legal basis is taking steps at your request before a contract, or our legitimate interests in responding to correspondence and managing business relationships. The privacy checkbox acknowledges this notice; it is not marketing consent.
Access is limited to people handling the enquiry and service providers supporting that processing, including Notion. Retention depends on the purpose and resulting relationship as described below. Please do not submit classified information, sensitive operational details, patient information or whistleblowing reports through this form.
Personal data we collect
Norn Labs, as part of its own activities, occasionally needs to collect personal data, without relying on large-scale processing. During such processing, the nature, retention period, and purpose of the personal data handled depend on the role of our interlocutors. In all cases, your personal data may be communicated internally to employees who have been strictly authorised to access it, to internal or external subcontractors, and, if necessary, to our partners and state bodies.
We require the utmost respect for your data from all parties involved and ensure they take every necessary precaution in processing your personal data by rigorously controlling their purposes in accordance with our instructions.
If you are a candidate, we may process personal data such as your email address, your curriculum vitae, and the information mentioned therein (surname, first name, address, date/place of birth, email, telephone number, family situation, extra-professional activities, schooling, training, diplomas, employers).
As the data controller, it is our responsibility to determine the purposes and means of processing. At Norn Labs, the collection of candidates' personal data is solely for the recruitment department to assess your suitability for the job offered by the company and to offer you the position that best matches your profile.
If you are unsuccessful in your application, we will delete any personal data you have shared with us no later than two (2) years after our last contact with you.
If you are one of our collaborators (or former collaborators), we are required to process the data included in your curriculum vitae, personnel information sheet (form completed by you upon hiring), or employment contract.
At Norn Labs, processing this data facilitates work organisation management, administrative personnel management, career development and training. Personal data is also used to highlight your skills in response to calls for tenders.
We will retain your personal data for the duration of your employment contract and then for a maximum of five (5) years after its termination.
If you are a third party (customer, prospect, supplier etc.), our obligations and responsibilities vary depending on whether our company acts as a data controller or subcontractor under GDPR regulations.
We act as a data controller when collecting all personal information specific to each project that is communicated by you. As a data controller, we process this data to send updates on progress; comply with contractual and regulatory obligations; maintain relationships necessary for business activities; ensure accessibility to information systems for various users; analyse existing client products for requested changes; or test products developed or under development using personal test data provided by you.
We retain your personal data for as long as our contractual and/or commercial relationship lasts. Unless otherwise stated in the contract, we then retain your personal data for five (5) years after the end of our contractual relationship.
Obligations regarding data processing
Beyond the general obligations naturally implemented, and fully aware of the challenges, we have gone further in protecting your personal data through effective internal tools. We place particular importance on complying with our legal obligations regarding the protection of personal data.
- Privacy requests and questions about personal-data processing can be sent to data@nornlabs.eu. That address is our privacy contact. It is not a statement that a formal Data Protection Officer has been appointed under the GDPR.
- We regularly document personal data in a register that specifies the objectives pursued, the categories of personal data used, the individuals with access to the data, and their retention periods.
- We ensure that the use of personal data is restricted to the purposes of the intended processing.
- We ensure that personal data is stored and retained only for the duration necessary to achieve the intended purposes.
- We are committed to cooperating with the supervisory authority when required.
- Appropriate security measures have been implemented to protect personal data according to its sensitivity.
Technical and organisational security measures
Norn Labs implements technical and organisational measures appropriate to each service and its maturity, built around our cloud-native architecture. Public references to security are not an independent certification or an unconditional guarantee.
Continuous compliance and access control
We design our services and internal practices with applicable EU data-protection and related digital rules in mind, including the GDPR and, where relevant to a given service, other instruments such as the DSA and the AI Act. This is a process commitment, not a claim of continuous, automated, or certified adherence across every framework. Access to personal data is strictly controlled and limited to internally authorised employees who require it to perform their duties. All subcontractors and partners are rigorously vetted and must comply with our data processing instructions, ensuring a secure and unified approach across our entire operational chain.
Confidentiality and incident response
Our employees are trained in implementing robust security measures and are bound by strict confidentiality regarding any personal data they handle. Furthermore, we have established incident-handling and response procedures appropriate to the service to enable a swift, appropriate response in the case of any unauthorised destruction, loss, or disclosure of personal data. These procedures are designed to effectively minimise the impact of any potential incident and uphold our commitment to data protection.
Your rights
The European regulation and the current laws relating to the protection of personal data have created new rights for the benefit of the persons whose data we collect. We offer everyone the opportunity to exercise them in the best conditions. We thus guarantee the effectiveness of:
- The right of access
- The right of information
- The right of modification
- The right of opposition
- The right to be forgotten
- The right to limit processing
- The right to personal data portability
To exercise your rights or ask about this notice, contact data@nornlabs.eu.
For more details on your rights, you may consult the European Data Protection Board: https://edpb.europa.eu. You also have the right to lodge a complaint with a competent EU data protection supervisory authority.
Updates to Norn's privacy & security policy
Norn Labs reserves the right to make minor changes to this Privacy Policy to ensure compliance with technological developments, industry practices, and regulatory requirements, or for other reasons. Any significant modification will be preceded by a visible publication on the homepage of this website before it becomes effective.
Contact
To exercise your rights or ask about this notice, contact data@nornlabs.eu.