Legal
Data Processing Agreement
Last updated: October 6, 2026
1. Who this agreement is between
This Data Processing Agreement (“DPA”) is between Christian Pastor d/b/a Norvius (“Norvius,” “we,” “us”) and the business that holds a Norvius account (“you”). It forms part of our Terms of Service and applies whenever the data you connect to Norvius includes personal data about other people, such as the names and email addresses of your store's customers (“Customer Personal Data”). You accept it when you create an account. Where this DPA and the Terms of Service differ on the handling of Customer Personal Data, this DPA applies. It applies to every account from October 6, 2026.
2. Roles
For Customer Personal Data you are the controller (or business): you decide which tools to connect and why. Norvius is your processor (or service provider): we process Customer Personal Data only to provide the Service to you. Our Privacy Policy covers the data we hold about you yourself, as our own customer.
3. What we process, and why
- Purpose. To sync the data you choose from your connected tools, answer your questions about it, and run the reports and alerts you set up.
- People concerned. Your customers and contacts, as they appear in the tools you connect.
- Kinds of personal data.Whatever the tools you connect hold and you choose to sync. From a Shopify store, Norvius reads customers' names and email addresses with their orders, and the notes and tags on customers and orders, which hold whatever was typed into them. It does not read customers' phone numbers or postal addresses.
- Duration. For as long as the data source stays connected and your account is active, and then as described in section 8.
4. Your instructions
We process Customer Personal Data only on your instructions. Your use of the Service (the sources you connect, the questions you ask, the reports and alerts you create) is your instruction. We do not sell Customer Personal Data, use it for advertising, or use it to train artificial intelligence models, and we never contact or market to your customers. If the law requires us to process it in another way, we will tell you first unless the law forbids that.
5. Confidentiality and access
Access to the systems that hold Customer Personal Data is limited to Norvius's operator. Anyone given access in the future will be bound by a duty of confidentiality and given only the access their work needs.
6. Security
- Data is encrypted at rest (AES-256). Connections to Norvius use TLS. Norvius's connection to a database you connect uses TLS when that connection's settings ask for it.
- Every workspace's data is separated from every other's by row-level security in the database.
- Sign-in tokens and API keys for your connected tools are encrypted again by Norvius and are never sent to the AI service.
- Accounts that administer Norvius's systems use strong passwords and two-step sign-in.
- Test systems are separate from production.
- Daily database backups, and a written recovery and incident-response procedure.
7. Sub-processors
You authorise us to use the following sub-processors. Each processes Customer Personal Data for us under its own data-processing terms.
- Supabase — database, sign-in and file storage (United States)
- Railway — application hosting (United States)
- Anthropic — AI processing of your questions and the data needed to answer them (United States company)
- Resend — email delivery of your reports, alerts and notifications (United States)
- Cloudflare — network delivery and protection for norvius.com (global network)
- Sentry — error monitoring (United States)
We will update this list, and tell you by email or in the Service, at least 30 days before a new sub-processor begins processing Customer Personal Data. If you object, you can close your account before the change takes effect.
8. Deletion and return
- Export.You can export your data from Settings → Data Export, as described in the Privacy Policy.
- A disconnected data source stops syncing at once. Its stored data is kept for 30 days, during which you can restore it, and is permanently deleted within a week after that.
- A deleted account can be restored for 30days. After that, the account and its data, including Customer Personal Data, are permanently deleted, normally within one further day. Report files Norvius generated for you (PDF and Excel) are deleted on request. Copies in our database provider's backups are deleted when those backups expire.
- Shopify stores.When Shopify sends a customer-erasure request, we delete that customer's records from the store's synced data, including saved earlier copies. When Shopify sends a store-erasure request after an uninstall, we delete the store's synced data and its stored sign-in. Customer details that already appear in your chat answers or notifications are deleted on request and with your account; report files Norvius generated for you are deleted on request. When Shopify sends a customer data request, we notify you in the Service (and by email, if your email notifications are on) with how many of that customer's records your connected sources currently hold, so you can answer it.
9. Requests from your customers
If one of your customers asks to see, correct or delete their personal data, you can do most of this yourself in the tool the data comes from: Norvius's current copy follows at its next sync. Earlier saved copies are erased when Shopify sends its customer-erasure request, or when you ask us; so are copies in chat answers, reports and notifications. Where you need our help, we will help you answer within the time the law allows. If a customer contacts us directly, we will refer them to you.
10. Security incidents
If we confirm that Customer Personal Data has been accessed, disclosed or lost without authorisation, we will tell you without undue delay, and in any event within 72 hours of confirming it. We will tell you what happened, what data was affected, and what we have done, and will help you meet any duty you have to report it.
11. Where data is processed
Customer Personal Data is stored in the United States. The sub-processors in section 7 process it on our behalf, and traffic to norvius.com passes through Cloudflare's global network. Norvius does not currently accept accounts from the European Economic Area, the United Kingdom or Switzerland.
12. Information and audits
On request, we will give you the information reasonably needed to show that we meet this DPA, including answers to reasonable security questionnaires.
13. Liability, changes and contact
The limits of liability in the Terms of Service apply to this DPA. We may update it as described in the Terms of Service; a change that reduces the protection of Customer Personal Data takes effect no sooner than 30 days after we tell you. Questions: contact us at notifications@norvius.com or through our contact page.