Back to NormLedger

Privacy Policy

Last updated: 25 July 2026

1. Who we are

NormLedger is an EU Digital Compliance OS operated by [OPERATOR_NAME] (the data controller). This policy explains how we process personal data when you use normledger.com and related services.

2. What data we collect

  • Account data: name and email address (via Clerk authentication)
  • Organisation data: organisation name, country, sector, and website URLs you add to the platform
  • Compliance data: scan results, evidence log entries, remediation tasks, and accessibility statements you create
  • Prospect scan data: email and website URL if you submit a free audit
  • Usage data: page views and feature usage within the product (no third-party advertising analytics)
  • Technical data: IP address (server logs) and browser type

3. How we use it

  • Deliver the compliance platform service
  • Send notifications about scans, deadlines, and statement reviews
  • Respond to support requests
  • Improve the platform

We do not sell your data to third parties.

4. Legal bases (GDPR Art. 6)

  • Contractual performance - delivering the NormLedger service you signed up for
  • Legitimate interests - security, fraud prevention, and product improvement
  • Consent - marketing communications (you can opt out at any time)

5. Data storage and transfers

  • Application data is stored on EU infrastructure (Neon Postgres on AWS EU regions, Cloudflare Workers)
  • Transactional email may be delivered via Brevo (EU-based provider)
  • Authentication is provided by Clerk (may involve transfers outside the EEA, covered by appropriate safeguards such as SCCs / DPA)

6. Data retention

  • Account data: retained until account deletion + 30 days
  • Evidence log entries and compliance statements: retained for the duration of the subscription + 5 years (compliance records often have legal retention requirements)
  • Prospect scan data: 90 days if no account is created

7. Your rights (GDPR)

You have the right to access, rectify, erase (where legally permissible), restrict processing, data portability, and object to certain processing. You also have the right to lodge a complaint with your supervisory authority.

8. Contact

Privacy questions: [email protected]

9. Changes to this policy

We will notify registered users by email of material changes to this Privacy Policy.