Norric
Log In

Privacy Policy

Last Updated: July 15, 2026

This Privacy Policy describes how Norric, Inc. ("Norric," "we," "us," or "our") collects, uses, and discloses personal data when you visit our marketing website at www.norric.ai, use our product applications, or otherwise interact with us (collectively, the "Services").

1. Who This Policy Covers

This Policy applies to:

  • Site visitors — anyone browsing our websites.
  • Prospective customers — individuals who request a demo or contact us.
  • Job applicants — individuals who apply to open roles or join our talent network.
  • Product users — individuals who hold an account for our product applications.

Content and data that our customers submit to Norric products in the course of using them ("Customer Data") is processed on behalf of our customers under our customer agreements, including any applicable data processing addendum. Except as described in Section 4 (AI and Model Training), this Policy does not apply to Customer Data. If you have questions about how Customer Data is handled, please refer to your organization's agreement with Norric.

2. Personal Data We Collect

Data you provide to us

  • Demo requests — name, email address, phone number, company, job title, country, and your message.
  • Contact inquiries — name, email address, and your message.
  • Job and talent-network applications — name, email address, the role you are interested in, and your resume or CV.
  • Product accounts — name, email address, and authentication and workspace information needed to operate your account.

Data collected automatically

  • Server and network logs — IP address, browser type and version, pages visited, and timestamps, collected by our hosting and content-delivery providers for security and reliability.
  • Product usage analytics — information about how you interact with the Services (such as features used and actions taken), collected through PostHog to help us improve the product.
  • Cookies and similar technologies — described in our Cookie Policy, which also explains how to manage your choices. Where consent is required by applicable law, optional cookies are loaded only after you consent.

3. How We Use Personal Data

We use personal data for the following purposes. Where the EU or UK GDPR applies, the legal basis for each purpose is noted.

  • Responding to demo requests and inquiries — to communicate with you about our products and services (steps taken at your request prior to entering into a contract, Art. 6(1)(b)).
  • Providing and operating the Services — to authenticate users, maintain accounts, and deliver product functionality (performance of a contract, Art. 6(1)(b)).
  • Evaluating job applications — to review candidates and manage our talent network (steps taken at your request prior to entering into a contract, and our legitimate interest in recruiting, Art. 6(1)(b) and (f)).
  • Improving the Services — to understand how the Services are used and make them better (our legitimate interest, Art. 6(1)(f); consent where required for cookies or similar technologies, Art. 6(1)(a)).
  • Security and abuse prevention — to protect the Services, our customers, and third parties (our legitimate interest, Art. 6(1)(f)).
  • Marketing communications — to send you information about our products, only where permitted, and you may opt out at any time (consent, Art. 6(1)(a)).
  • Legal compliance — to comply with applicable law and respond to lawful requests (legal obligation, Art. 6(1)(c)).

Where the Personal Information Protection Act of Korea (K-PIPA) applies, we collect and use personal data with your consent or on another basis permitted by K-PIPA, and only to the extent necessary for the purposes above.

4. AI and Model Training

Norric does not use Customer Data or personal data to train, fine-tune, or improve any foundation or proprietary AI models. Customer Data remains confidential and isolated to your environment, and is processed only to provide the Services in accordance with our customer agreements.

5. How We Share Personal Data

We do not sell personal data, and we do not share personal data for cross-context behavioral advertising. We share personal data only in the following circumstances:

  • Service providers acting on our behalf under written agreements: Google (business email and productivity — form submissions are delivered to and stored in our email system), Vercel (website hosting), and PostHog (usage analytics).
  • Legal requirements — where disclosure is required by law, regulation, or a valid legal process.
  • Business transfers — in connection with a merger, acquisition, or sale of assets, subject to notice where required by law.
  • With your consent — for any other purpose you approve.

6. International Data Transfers

We process personal data in the United States and in other countries where our service providers operate. Where we transfer personal data from the EU, EEA, or UK, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses, supplemented by the UK International Data Transfer Addendum where applicable.

For data subjects in Korea: the personal data described in this Policy is transferred to and processed by Norric and the service providers listed in Section 5 in the United States, for the purposes and retention periods described in this Policy. You may contact us at security@norric.ai with questions about these transfers.

7. Data Retention

We retain personal data only as long as necessary for the purposes described in this Policy, and then delete or anonymize it. As a general rule:

  • Demo requests and inquiries — up to 24 months after our last interaction with you.
  • Job and talent-network applications — up to 12 months after submission, unless you consent to a longer period or we hire you.
  • Server and network logs — up to 12 months.
  • Product account data — for the life of the account, plus any period required by law or our customer agreements.

We may retain data for longer where required by law or necessary to establish, exercise, or defend legal claims.

8. Your Rights

EU, EEA, and UK

You have the right to access, rectify, erase, restrict, or object to the processing of your personal data, the right to data portability, and the right to withdraw consent at any time. You also have the right to lodge a complaint with your supervisory authority.

California

Under the CCPA/CPRA, you have the right to know, correct, and delete personal information we hold about you, and the right not to be discriminated against for exercising these rights. We do not sell or share personal information as defined by California law, and we honor Global Privacy Control (GPC) signals. You can manage optional cookies at any time on the Cookie Preferences page.

Korea

Under K-PIPA, you have the right to access, correct, delete, and suspend the processing of your personal data. You may also contact the Personal Information Protection Commission (PIPC) or the Korea Internet & Security Agency (KISA) for dispute resolution.

To exercise any of these rights, contact us at security@norric.ai. We may need to verify your identity before acting on a request, and we will respond within the timeframe required by applicable law (one month under the GDPR; 45 days under the CCPA, extendable as permitted).

9. Children's Privacy

The Services are intended for business users and are not directed to children. We do not knowingly collect personal data from children under 16 (or the applicable minimum age in your jurisdiction). If you believe a child has provided us with personal data, please contact us and we will delete it.

10. Do Not Track and Global Privacy Control

We do not track visitors across third-party websites, and we do not permit third parties to use our Services to do so. Because there is no industry consensus on how to interpret "Do Not Track" browser signals, we do not respond to them. We do, however, honor Global Privacy Control (GPC) signals as described in our Cookie Policy.

11. Security

We apply technical and organizational measures appropriate to the sensitivity of the data we process, including encryption in transit, access controls operated under zero-trust principles, and isolation of customer environments. You can read more about our security practices on our Security page. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

12. Changes to This Policy

We may update this Policy from time to time. If we make material changes, we will notify you by email or by a notice on the Services before the changes take effect. The "Last Updated" date at the top of this Policy indicates when it was last revised.

13. Contact Us

For questions, concerns, or requests relating to this Policy or your personal data, contact us at:

Email: security@norric.ai