Legal
Data Processing Terms
Last updated 25 July 2026
These Data Processing Terms ("DPT") form part of the Terms of Service between you and Normis. They govern personal data that Normis processes on your behalf, and they are the written contract required by Article 28(3) of the GDPR. By accepting the Terms of Service you accept these terms, so no separate signature is needed. If your procurement process requires a countersigned copy, email hello@normis.app and we will provide one on the same terms.
Personal data that Normis handles as a controller in its own right, such as your account details and website visitors, is covered by our Privacy Policy instead.
1. Roles and scope
For personal data you put into your Normis account, your organisation is the controller and Normis is your processor. You decide why and how that data is used. We process it only to provide the service to you.
In these terms, "Normis" means [registered company name], registered under number [company registration number], registered office [registered address]. "Personal data", "processing", "controller", "processor" and "personal data breach" have the meanings given in the GDPR.
2. Details of the processing
Required by Article 28(3):
- Subject matter: providing the Normis service to you.
- Duration: for as long as your account is active, plus the deletion period in section 10.
- Nature and purpose: hosting, storing, organising and displaying the information you enter; sending service emails such as policy sign-off requests and reminders; generating evidence packs.
- Types of personal data:names, work email addresses, job roles and similar business contact details; sign-off records including the signer's name, timestamp, IP address and browser details; and any personal data you choose to enter into free-text fields.
- Categories of data subjects: your staff, contractors and other people whose details you record in Normis.
3. Your obligations as controller
- You confirm you have a lawful basis for the personal data you put into Normis, and that you have given the people concerned the information they are entitled to.
- Your instructions to us must comply with data protection law.
- Please do not enter special category data, or more personal data than you need, into free-text fields. Normis is not designed to hold it.
4. Our commitments as your processor
We will do each of the following, as required by Article 28(3)(a) to (h):
- Act only on your instructions. We process personal data only on your documented instructions, including on transfers, unless the law requires otherwise, in which case we will tell you before processing unless that law forbids it. If we think an instruction breaches data protection law, we will tell you.
- Keep it confidential. Everyone we authorise to process the data is bound by a duty of confidentiality.
- Secure it. We apply the technical and organisational measures set out in section 6, as required by Article 32.
- Control our sub-processors. We engage them only on the conditions in section 7, impose the same data protection obligations on them, and remain liable to you for their performance.
- Help with data subject requests. Taking into account the nature of the processing, we will help you respond to requests from people exercising their rights.
- Help with your wider duties. We will assist you with security, breach notification, data protection impact assessments and prior consultation, taking into account the information available to us.
- Return or delete at the end. On termination we return or delete personal data as you choose, per section 10.
- Demonstrate compliance and accept audits. We will make available the information necessary to show we meet these obligations, and allow and contribute to audits, on the terms in section 8.
5. Personal data breaches
We will notify you without undue delay after becoming aware of a personal data breach affecting personal data we process for you, with the information we reasonably have at the time, and will keep you updated as we learn more. We will not notify a supervisory authority or affected people on your behalf unless you ask us to, because as controller that decision is yours.
6. Security measures
The measures we apply include:
- hosting of the database, authentication and file storage in the European Union;
- encryption of data in transit and at rest;
- per-organisation isolation enforced at the database level through row-level security, so one customer cannot read another's data;
- an append-only audit log recording who changed what, and when, maintained by the database rather than the application so it cannot be bypassed;
- content hashing of published policies and evidence packs, so a document can be shown to be unaltered;
- passwordless authentication, role-based access control within each organisation, and least-privilege access for our own staff;
- managed platform backups, and monitoring for errors and outages.
We may change these measures as the service develops, provided the level of protection is not reduced.
7. Sub-processors
You give us general authorisation to engage the sub-processors below. Each is bound by written data protection terms no less protective than these.
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication and file storage | European Union |
| Resend | Sending sign-in and service emails | United States |
| Vercel | Application hosting and content delivery | United States, with EU edge delivery |
Changes.We will give you at least 30 days' notice before adding or replacing a sub-processor, by email to your account administrators. You may object within those 30 days on reasonable data protection grounds. If we cannot resolve your objection, you may terminate the affected part of the service without penalty and receive a refund of any fees paid for the unused period.
Website analytics providers are not listed here: they do not process personal data on your behalf, and are covered by our Privacy Policy and Cookie notice.
8. Audits and demonstrating compliance
On written request we will provide the information reasonably necessary to demonstrate compliance with these terms. If that is not enough for your obligations, you may audit us, or appoint an independent auditor who is not a competitor of ours, on these terms:
- at most once in any 12-month period, unless a regulator requires more or we have had a breach affecting your data;
- on at least 30 days' written notice, during business hours, and without unreasonable disruption to the service;
- subject to confidentiality, and not extending to other customers' data or our commercially sensitive information;
- at your cost, unless the audit finds material non-compliance, in which case we bear the reasonable cost.
We will contribute to the audit and respond to findings in good time.
9. International transfers
Our core systems, meaning the database, authentication and file storage, are hosted in the European Union. Where a sub-processor processes personal data outside the European Economic Area, we rely on appropriate safeguards under Chapter V of the GDPR, being the European Commission's Standard Contractual Clauses or, where applicable, the EU to US Data Privacy Framework. Where the Standard Contractual Clauses apply, they are incorporated into these terms, with the details in section 2 completing their annexes.
10. Return and deletion
You can export your data from the app at any time, including a full evidence pack. When your account ends you may ask us to return or delete personal data. We will delete it within 30 days of the request or of termination, whichever is later, except where the law requires us to keep it. Backups roll off automatically on the platform's retention cycle; we do not restore a backup in order to recover data you have asked us to delete.
11. Liability and precedence
The limitations of liability in the Terms of Service apply to these terms. If these terms conflict with the Terms of Service on the processing of personal data, these terms prevail. If they conflict with the Standard Contractual Clauses, the Clauses prevail.
12. Term
These terms apply for as long as we process personal data on your behalf, and the obligations that by their nature should survive, such as confidentiality and deletion, continue afterwards.
13. Contact
For data processing questions, to request a countersigned copy, to subscribe to sub-processor change notices, or to make a request under these terms, email hello@normis.app.