Last Updated: July 15, 2026
This Privacy Policy describes how Norric, Inc. ("Norric," "we," "us," or "our") collects, uses, and discloses personal data when you visit our marketing website at www.norric.ai, use our product applications, or otherwise interact with us (collectively, the "Services").
This Policy applies to:
Content and data that our customers submit to Norric products in the course of using them ("Customer Data") is processed on behalf of our customers under our customer agreements, including any applicable data processing addendum. Except as described in Section 4 (AI and Model Training), this Policy does not apply to Customer Data. If you have questions about how Customer Data is handled, please refer to your organization's agreement with Norric.
Data you provide to us
Data collected automatically
We use personal data for the following purposes. Where the EU or UK GDPR applies, the legal basis for each purpose is noted.
Where the Personal Information Protection Act of Korea (K-PIPA) applies, we collect and use personal data with your consent or on another basis permitted by K-PIPA, and only to the extent necessary for the purposes above.
Norric does not use Customer Data or personal data to train, fine-tune, or improve any foundation or proprietary AI models. Customer Data remains confidential and isolated to your environment, and is processed only to provide the Services in accordance with our customer agreements.
We do not sell personal data, and we do not share personal data for cross-context behavioral advertising. We share personal data only in the following circumstances:
We process personal data in the United States and in other countries where our service providers operate. Where we transfer personal data from the EU, EEA, or UK, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses, supplemented by the UK International Data Transfer Addendum where applicable.
For data subjects in Korea: the personal data described in this Policy is transferred to and processed by Norric and the service providers listed in Section 5 in the United States, for the purposes and retention periods described in this Policy. You may contact us at security@norric.ai with questions about these transfers.
We retain personal data only as long as necessary for the purposes described in this Policy, and then delete or anonymize it. As a general rule:
We may retain data for longer where required by law or necessary to establish, exercise, or defend legal claims.
EU, EEA, and UK
You have the right to access, rectify, erase, restrict, or object to the processing of your personal data, the right to data portability, and the right to withdraw consent at any time. You also have the right to lodge a complaint with your supervisory authority.
California
Under the CCPA/CPRA, you have the right to know, correct, and delete personal information we hold about you, and the right not to be discriminated against for exercising these rights. We do not sell or share personal information as defined by California law, and we honor Global Privacy Control (GPC) signals. You can manage optional cookies at any time on the Cookie Preferences page.
Korea
Under K-PIPA, you have the right to access, correct, delete, and suspend the processing of your personal data. You may also contact the Personal Information Protection Commission (PIPC) or the Korea Internet & Security Agency (KISA) for dispute resolution.
To exercise any of these rights, contact us at security@norric.ai. We may need to verify your identity before acting on a request, and we will respond within the timeframe required by applicable law (one month under the GDPR; 45 days under the CCPA, extendable as permitted).
The Services are intended for business users and are not directed to children. We do not knowingly collect personal data from children under 16 (or the applicable minimum age in your jurisdiction). If you believe a child has provided us with personal data, please contact us and we will delete it.
We do not track visitors across third-party websites, and we do not permit third parties to use our Services to do so. Because there is no industry consensus on how to interpret "Do Not Track" browser signals, we do not respond to them. We do, however, honor Global Privacy Control (GPC) signals as described in our Cookie Policy.
We apply technical and organizational measures appropriate to the sensitivity of the data we process, including encryption in transit, access controls operated under zero-trust principles, and isolation of customer environments. You can read more about our security practices on our Security page. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
We may update this Policy from time to time. If we make material changes, we will notify you by email or by a notice on the Services before the changes take effect. The "Last Updated" date at the top of this Policy indicates when it was last revised.
For questions, concerns, or requests relating to this Policy or your personal data, contact us at:
Email: security@norric.ai