Privacy Policy
1. Who We Are
Noryn System Ltd (“we”, “us”, “our”) operates the Noryn virtual employees platform. We are the data controller for the personal data described in this policy. We are registered in England and Wales (Companies House number: 17335896), registered office 44 Bellbrigg Lonning, Cockermouth, CA13 9DA, United Kingdom. ICO Registration: ZC199308.
Data protection contact: privacy@norynsystem.com
This Privacy Policy governs the data we collect and control directly — your account data, billing information, and platform usage. For data about your customers’ leads and contacts that flows through the platform, see our Data Processing Agreement (/legal/dpa).
2. What Data We Collect
2.1 Account data
- Name, email address, and password (hashed)
- Business name, registered address, and industry
- Account preferences and settings
2.2 Billing data
- Subscription tier and billing history
- Payment method details (tokenised by Stripe — we never see full card numbers)
- Invoice records
2.3 Usage data
- Login timestamps and IP addresses
- Pages visited and features used within the dashboard
- Error logs and performance data
2.4 Conversation and employee data
- AI employee configurations, system prompts, and voice samples you provide
- Conversation logs between your virtual employees and your customers’ contacts
- Integration connection metadata (which services you have connected)
2.5 Support communications
- Emails and messages you send to our support team
- Privacy rights request records
3. Why We Collect It and Our Lawful Basis
| Purpose | Data used | Lawful basis |
|---|---|---|
| Providing and operating the Service | Account, employee config, conversations | Contract (Art. 6(1)(b)) |
| Processing payments and issuing invoices | Billing data | Contract (Art. 6(1)(b)) |
| Account security and fraud prevention | Login data, IP addresses | Legitimate interests (Art. 6(1)(f)) |
| Customer support | Account data, support communications | Contract / Legitimate interests |
| Product improvement and analytics | Anonymised usage data | Legitimate interests (Art. 6(1)(f)) |
| Legal compliance (HMRC, ICO, courts) | Invoice records, audit logs | Legal obligation (Art. 6(1)(c)) |
| Marketing emails (opt-in only) | Email address, name | Consent (Art. 6(1)(a)) |
4. Who We Share Data With
We share data with sub-processors (third-party services that process data on our instructions). Our full, up-to-date sub-processor list is at /legal/sub-processors. Key sub-processors include:
- Anthropic — AI model inference (conversation content, system prompts)
- Supabase — database and authentication
- Stripe — payment processing
- Vercel — application hosting
- Resend — transactional email delivery
We do not sell your data. We do not share it for advertising purposes.
4.1 Google user data
If you connect a Google service to Noryn, we access only the Google data needed for the feature you connected, and only for the Google account you authorise. Each Google service is connected separately and asks for its own permission.
- Gmail — we check your inbox for unread messages that arrived after you connected Gmail, except messages in the Promotions or Social tabs and messages sent from your own address. For each one, we decide whether it needs a reply. If it does, we save the sender’s email address, their name if the email includes one, the subject line and up to the first 4,000 characters of the message text in Conversations, then send your virtual employee’s reply from your address in the same thread and mark the message as read. Messages that do not need a reply are marked as read and are not saved. We do not read attachments, we do not delete or archive messages, we add no labels of our own, and we do not change your Gmail settings; clearing the unread marker once a message has been handled is the only change we make to a message.
- Google Calendar — we check when your primary calendar is busy (free and busy times only) so we do not offer times you are unavailable, and we create, list, move and cancel the events your virtual employee books on your primary calendar. If a customer gives their email address, Google sends them an invitation. We do not create or delete calendars or change their sharing. We do not keep a copy of the busy times or events we read; we store only the ID of each event we create, so we can change it later.
- Google Sheets — we create a spreadsheet called “Noryn — Leads” in your Google Drive and add a row to it (time, name, email address and what the customer asked for) for each new lead. If Google Sheets is disconnected and connected again, a new spreadsheet is created. We cannot see or change any file we did not create.
- Google Drive — we create Google Docs your virtual employee is asked to write up and save. We cannot see or change any file we did not create.
Who receives it, and why. We share Google user data only to provide the features you connected:
- Anthropic, our AI provider. To decide whether an email needs a reply, we send the sender’s name and email address, the subject line and the first 2,000 characters of the message, including for messages we then decide not to answer. To write a reply, we send the subject line, up to 4,000 characters of the message and up to 20 earlier messages from the same conversation. When your virtual employee checks or changes a booking, it sends your calendar’s busy times and details of that customer’s appointments. If anyone in your organisation receives the weekly review email, short extracts of recent customer messages are sent to write it. Anthropic processes this under its commercial terms and data processing agreement, and states that it does not use data sent through its commercial API to train its models.
- Supabase, our database provider, stores the conversations described above and your encrypted connection tokens. Vercel, our hosting provider, runs the servers that process this data.
- Resend, our email provider, delivers the notification emails your owners and admins receive — for example when a conversation needs a person, with the customer’s name or email address and up to 300 characters of their latest message — and booking emails that include the customer’s name, email address and appointment details. Each person can switch these notifications off in their notification settings.
- Other tools you connect, such as a CRM, mailing list or payment provider: your virtual employee can pass a customer’s name, email address and details of their enquiry to them, to provide the feature you connected.
What we never do with it. We do not sell Google user data. We do not use or transfer it for advertising, including personalised advertising. We do not use it to determine creditworthiness or for lending. We do not use it to develop, improve or train any artificial intelligence or machine learning model, whether ours or anyone else’s. We do not transfer it to anyone other than the recipients listed above, except as necessary for security or where the law requires it.
Who can read it. Within your business, everyone you add to your Noryn organisation can see the conversations your virtual employee handles, whatever their role; only owners and admins can connect or disconnect Google services. Noryn’s administration console does not display what your emails say. For conversations it shows the customer’s name or email address, the conversation’s status and its date, so that we can monitor the service for faults and abuse. It can only be opened by Noryn platform administrators, who must use two-factor authentication. We read message content only where you ask us to for support with a specific message, where it is necessary for security purposes, or where the law requires it.
4.2 How we protect Google user data
- Encryption in transit. Every connection Noryn makes to Gmail, Google Calendar, Google Sheets and Google Drive is encrypted with HTTPS and goes to Google’s own service addresses. The data we send to Anthropic, Supabase and Resend also travels over encrypted HTTPS connections. The Noryn app is served over HTTPS: our hosting provider redirects unencrypted requests to a secure connection and accepts TLS 1.2 or newer, and the app tells browsers to connect to it only over HTTPS.
- Encryption of your connection tokens. The access and refresh tokens Google issues to us are encrypted on our servers with AES-256-GCM before they are saved to our database, and the encryption key is kept in our server environment, not in the database. They are decrypted only on our servers when Noryn needs to use them, are sent only to Google, are never shown in your dashboard, are not included in data exports, and are not written to our application logs.
- Encryption at rest. Conversations are stored with our database provider, Supabase, which encrypts the data it stores at rest as part of its service.
- Access control. When someone in your team opens a conversation in the Noryn dashboard, Noryn first checks that it belongs to the organisation they are signed in to. Noryn’s administration console is limited to platform administrators and requires two-factor authentication, and administrator actions such as pausing, resuming or editing your virtual employee, or flagging one of your conversations, are recorded in an audit log.
- Minimisation. We do not read Gmail messages that arrived before you connected, or any mailbox while your organisation has no active plan. Our application does not write the content of your emails to its logs. Our caching provider, Upstash, holds only short-lived markers such as Gmail message IDs while we check your inbox, not the text of your emails.
- Retention and deletion. A daily job deletes each conversation, with its messages, once 12 months have passed since its last message. When an owner or admin disconnects a Google service in Integrations, we immediately delete the stored tokens for that service from our live database; encrypted copies may remain in our database provider’s backups until those backups expire. Disconnecting does not withdraw the permission recorded in your Google Account, which you can do at any time at myaccount.google.com/connections; withdrawing it there does not delete the tokens we hold, so disconnect the service in Integrations as well. Anything already in your Google account — replies sent from your Gmail, calendar events, spreadsheet rows and documents — stays there, and details copied into a booking stay on that booking. If your organisation’s owner asks for the organisation to be deleted, it is deleted after a 7-day grace period, including its conversations, bookings and stored Google tokens. Sections 6 and 7 and /legal/data-deletion explain how to ask for data to be deleted sooner.
- Incidents. If a personal data breach affects data we process for you, including Google user data, we will record it in our incident register and notify you without undue delay and no later than 48 hours after becoming aware of it.
Noryn’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
5. International Transfers
Most of our sub-processors are based in the United States. We rely on Standard Contractual Clauses (SCCs) with the UK Addendum as the transfer mechanism for all US-based sub-processors, in line with UK GDPR requirements. A copy of the SCCs can be requested by emailing privacy@norynsystem.com.
6. How Long We Keep Your Data
| Data type | Retention period | Reason |
|---|---|---|
| Account info (organisation record, logins, virtual employee setup) | Kept until you ask us to delete it — erased after a 7-day grace period once you request deletion | Service delivery |
| Conversation logs | 12 months rolling, and removed with the row below after cancellation | Support and analytics |
| Your customers’ data after cancellation (conversations, waiting list, booking contact details, uploaded files) | 44 days after cancellation — a 30-day export window, then 14 days’ written notice | DPA clause 6.8 |
| Audit logs | 24 months, then anonymised | Security and compliance |
| Invoice records | 6 years | HMRC legal requirement |
| Marketing consents | Until withdrawn + 1 year | Regulatory accountability |
| Privacy requests | 6 years | ICO accountability |
| Support communications | 2 years | Legitimate interests |
Your account record itself is not deleted automatically when a subscription ends — that way a business which comes back finds its organisation, its team logins and its virtual employees exactly as they were. It is deleted when you ask us to: raise a deletion request at /dashboard/privacy/requests and the whole organisation is erased after a 7-day grace period, apart from the billing records HMRC requires us to keep for six years.
7. Your Rights Under UK GDPR
You have the following rights regarding your personal data:
- Access: Request a copy of the data we hold about you
- Rectification: Ask us to correct inaccurate data
- Erasure: Ask us to delete your data (subject to legal retention requirements)
- Restriction: Ask us to pause processing while a dispute is resolved
- Portability: Receive your data in a structured, machine-readable format
- Object: Object to processing based on legitimate interests or for marketing
- Withdraw consent: Withdraw marketing consent at any time
Exercise any of these rights at /dashboard/privacy/requests or by emailing privacy@norynsystem.com. We will respond within one calendar month, as UK GDPR requires.
8. Cookies
We use cookies and similar technologies. See our full Cookie Policy at /legal/cookies.
9. Children
Two different people meet this Service and the answer is different for each. Account holders — the businesses who contract with us — must be 18 or over. People who message a business’s virtual employee must be 13 or over: that is the threshold Terms §4, the AUP and the DPA all set, and the Customer is responsible for ensuring their virtual employees are not made available to children under it.
We do not knowingly collect personal data from anyone below those thresholds. If you believe a child’s data has reached us, contact privacy@norynsystem.com and we will delete it promptly.
10. Changes to This Policy
We will give 30 days’ notice of material changes by email and in-dashboard notification. The current version is always available at /legal/privacy.
11. Complaints
If you are unhappy with how we handle your data, please contact us first at privacy@norynsystem.com. If you remain dissatisfied, you have the right to complain to the Information Commissioner’s Office (ICO):
- Website: ico.org.uk
- Phone: 0303 123 1113
Noryn · Noryn System Ltd · Registered in England & Wales no. 17335896 · ICO Reg ZC199308
Registered office: 44 Bellbrigg Lonning, Cockermouth, CA13 9DA, United Kingdom · privacy@norynsystem.com