Last Updated: September 1, 2026
This Privacy Policy describes how Norric, Inc. ("Norric," "we," "us," or "our") collects, uses, and discloses personal data when you visit our marketing website at www.norric.ai (the "Site"), use the Norric DDQ Agents platform and its related applications (the "Services"), or otherwise interact with us.
This Policy applies to:
Content and data that our customers submit to Norric products in the course of using them ("Customer Data") is processed on behalf of our customers under our customer agreements, including any applicable data processing addendum. Except as described in Sections 4 (AI and Model Training) and 5 (How We Share Personal Data), this Policy does not apply to Customer Data. If you have questions about how Customer Data is handled, please refer to your organization's agreement with Norric.
We use personal data for the following purposes. Where the EU or UK GDPR applies, the legal basis for each purpose is noted.
Where the Republic of Korea Personal Information Protection Act ("PIPA") applies, we collect and use personal data with your consent or on another basis permitted by PIPA, and only to the extent necessary for the purposes above.
Norric does not use Customer Data or personal data to train, fine-tune, or improve any foundation or proprietary AI model, and does not permit its AI providers to do so.
Delivering the Services requires sending content derived from Customer Data to third-party model providers for inference — document parsing, embedding generation, retrieval reranking, and answer suggestion. Those providers are engaged under written agreements with zero-data-retention terms or equivalent: they may not train on the content, and they retain nothing beyond the window needed to return a response. Retrieval is scoped to the customer's own workspace, so content is never surfaced across customers. The providers in use are identified in Section 5.
We do not sell personal data, and we do not share personal data for cross-context behavioral advertising. We share personal data only as described in this Section.
Providers for the data described in this Policy
Providers involved in delivering the Services
Where content derived from Customer Data is processed to deliver the Services, we engage the subprocessors authorized in the applicable data processing addendum. These currently include Amazon Web Services (hosting and storage), OpenAI, Anthropic, and Google (model and embedding inference), and Langfuse (model observability). Each is engaged under a written agreement and, for the model providers, under zero-data-retention terms as described in Section 4. The authoritative and current list, with processing locations and transfer mechanisms, is maintained in the data processing addendum; customers receive advance notice of additions as set out there.
Beyond the providers described above, we share personal data only:
Our production environment operates in the United States (AWS us-east-1) and our development environment in the Republic of Korea (AWS ap-northeast-2); the model providers identified in Section 5 process inference requests in the United States. Where we transfer personal data from the EU, EEA, or UK, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses, supplemented by the UK International Data Transfer Addendum where applicable.
For data subjects in Korea: the personal data described in this Policy is transferred to and processed by Norric and the service providers listed in Section 5 in the United States, for the purposes and retention periods described in this Policy. You may contact us at privacy@norric.ai with questions about these transfers.
We retain personal data only as long as necessary for the purposes described in this Policy, and then delete or anonymize it. As a general rule:
We may retain data for longer where required by law or necessary to establish, exercise, or defend legal claims.
You have the right to access, rectify, erase, restrict, or object to the processing of your personal data, the right to data portability, and the right to withdraw consent at any time. You also have the right to lodge a complaint with your supervisory authority.
Under the CCPA/CPRA, you have the right to know, correct, and delete personal information we hold about you, and the right not to be discriminated against for exercising these rights. We do not sell or share personal information as defined by California law, and we honor Global Privacy Control (GPC) signals. You can manage optional cookies at any time on the Cookie Preferences page.
Under PIPA, you have the right to access, correct, delete, and suspend the processing of your personal data. You may also contact the Personal Information Protection Commission (PIPC) or the Korea Internet & Security Agency (KISA) for dispute resolution.
To exercise any of these rights, contact our Data Protection Officer at privacy@norric.ai. We may need to verify your identity before acting on a request, and we will respond within the timeframe required by applicable law (one month under the GDPR; 45 days under the CCPA, extendable as permitted).
The Site and the Services are intended for business users and are not directed to children. We do not knowingly collect personal data from children under 16 (or the applicable minimum age in your jurisdiction). If you believe a child has provided us with personal data, please contact us and we will delete it.
We do not track visitors across third-party websites, and we do not permit third parties to use the Site or the Services to do so. Because there is no industry consensus on how to interpret "Do Not Track" browser signals, we do not respond to them. We do, however, honor Global Privacy Control (GPC) signals as described in our Cookie Policy.
We apply technical and organizational measures appropriate to the sensitivity of the data we process, including encryption in transit, access controls operated under zero-trust principles, and isolation of customer environments. You can read more about our security practices on our Security page. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
We may update this Policy from time to time. If we make material changes, we will notify you by email or by a notice on the Site or the Services before the changes take effect. The "Last Updated" date at the top of this Policy indicates when it was last revised.
For questions, concerns, or requests relating to this Policy or your personal data, contact our Data Protection Officer at privacy@norric.ai.
For security matters, including suspected unauthorized access or vulnerability reports, contact security@norric.ai.