Legal

Privacy Policy

Last updated: July 25, 2026

This Privacy Policy explains how Compliance Platform handles personal data for the public website, account access, support, compliance checks, reports, API use, and organization workspaces.

Controller and privacy contact

Compliance Platform is operated by the legal entity responsible for the service. The final company name and registered address must be published here before production launch.

During the current test-access phase, privacy requests can be sent through the Contact page or directly to privacy@norvext.com.

If a customer organization uses the platform for its own business data, that organization may act as an independent controller for the data it decides to enter into the platform. Compliance Platform may act as a processor for that customer data under the applicable customer agreement or data processing terms.

The standard Data Processing Terms are available on the DPA page and apply to every plan, including Free and trial plans, whenever the platform processes Customer Personal Data on behalf of an organization.

Data we process

We process account and profile data such as name, email address, authentication identifiers, organization membership, role, and workspace settings.

We process operational data entered into the platform, including TARIC/CN check inputs, countries, additional codes, entity screening subjects, saved case parameters, generated report metadata, support messages, invitations, API keys metadata, usage events, and audit-style logs needed to operate the service.

We also process technical data such as IP address, device/browser information, security events, request metadata, and error logs where needed for security, abuse prevention, troubleshooting, and service reliability.

Why we process data

We use personal data to provide the service, authenticate users, route users to the correct workspace, maintain organizations and access rights, generate reports, answer support requests, secure the platform, and meet legal or contractual obligations.

For B2B customers, some data may be processed on behalf of the customer organization. The customer remains responsible for deciding what business data is entered into the platform.

Legal bases under GDPR

We process account, authentication, workspace, support, and service-use data where processing is necessary to provide the service or take steps before entering into a service relationship (GDPR Article 6(1)(b)).

We process security logs, abuse-prevention data, error logs, product reliability data, and limited operational analytics where necessary for our legitimate interests in securing, maintaining, improving, and protecting the platform (GDPR Article 6(1)(f)).

We process billing, tax, accounting, legal, and compliance records where necessary to comply with legal obligations (GDPR Article 6(1)(c)).

If we later introduce optional non-essential cookies, marketing communications, or similar optional processing, we will rely on consent where required (GDPR Article 6(1)(a)) and provide a way to withdraw it.

Service providers

We use infrastructure and service providers to run the application, store data, authenticate users, deliver email, protect the network, provide the built-in AI assistant and process payments. The current providers are Supabase (managed database, authentication and file storage), Render (screening and compliance API), Vercel (web application), Cloudflare (DNS, content delivery and network protection), Resend (transactional email), Anthropic and OpenAI (model providers for the built-in AI assistant) and Stripe (subscription billing). The register published at /subprocessors is the authoritative list and names each provider's role, the data involved and its location.

The built-in AI assistant is optional, and there are three different situations. When it runs on the platform's own key, the content you submit in that conversation is sent to the model provider we have selected — today Anthropic, in the United States — to generate the reply; OpenAI is published in the subprocessor register as an approved alternative, and a switch to it would follow the 30 days' notice set out in the Data Processing Terms. When your organization configures its own provider and API key, that provider processes on your instructions under your own agreement with it, and it is not our subprocessor. When you drive the platform from your own AI client over the API or the MCP connector, we send nothing to any model provider at all. Under the commercial terms that apply to our own use of these services, submitted content is not used to train the provider's models, and screening, cases, reports and the API all work without the assistant.

We do not sell personal data. We do not intentionally use advertising profiles or marketing pixels on the public site at launch.

International transfers

The service itself runs in the European Union: the database, the screening API, the web application and email delivery are hosted in EU regions. Personal data leaves the European Economic Area for two providers — Anthropic in the United States for the optional AI assistant, and Stripe for billing — and passes through Cloudflare's global network, which carries traffic rather than storing records. Where this happens we rely on the safeguards required by GDPR Chapter V, such as European Commission Standard Contractual Clauses, an applicable adequacy mechanism, or equivalent contractual and technical safeguards offered by the provider.

Information about the European Commission Standard Contractual Clauses is available at https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/standard-contractual-clauses-scc_en.

Retention and security

We keep personal data only for as long as needed for the service, account administration, security, auditability, support, legal obligations, or the applicable customer agreement. The periods below apply from the platform side; a separately signed customer agreement may set different ones.

Screening records, cases and reports stay available in the workspace for the retention period of the organization's plan: 3 months on Free, 5 years on Starter and Team, 7 years on Professional and Business, and the period agreed in the contract on Enterprise. The paid-plan periods are set to meet the EU anti-money-laundering record-keeping minimum, so that the workspace can serve as evidence for an obliged entity. Deleting a case moves it to the workspace trash, from where it is permanently removed after 30 days. Technical runtime records of screening jobs are kept for 30 days. Account, invoicing and tax records are kept while the account exists and afterwards for the periods required by accounting and tax law.

We apply access controls, authentication, tenant separation, security checks, HTTPS, and operational logging to protect the platform. No system can be guaranteed perfectly secure, but we design the service with privacy and security as default operating assumptions.

Your rights

Depending on your location and relationship with the service, you may have rights to access, correct, delete, restrict, object to, or receive a copy of your personal data.

To exercise privacy rights, contact us through the Contact page and include the email address used for the platform. If your account belongs to an organization, we may coordinate the request with that organization where required.

If you are in Latvia or believe Latvian data protection law applies, you may lodge a complaint with Datu valsts inspekcija, the Latvian Data State Inspectorate. Website: https://www.dvi.gov.lv/en. Email listed by the authority: pasts@dvi.gov.lv.