Skip to content
GDPR and compliance1 min read

What compliance and security does NorReach have?

The answer

NorReach is built in Stockholm, Europe, and the product includes concrete controls. A campaign, flow or broadcast step won't send to a contact without a recorded lawful basis. You choose the basis; NorReach makes sure one is recorded. Unsubscribes, STOP replies, bounces and blocks go on one suppression list that covers every channel, and every campaign, flow and broadcast step checks it before it sends. Campaigns send inside a sending window (by default weekdays 09:00–17:00 in each contact's time zone, where it's known) and hold calls, texts and WhatsApp overnight. It's on by default for new campaigns; plan touches go out on the day and time shown on their card. Plan calls always open by naming your company and the person they call for. The rest of the opening is your AI caller's first line, which you set, and that is where it says it's an AI, as the EU AI Act (Art. 50) requires. Call coaching flags calls that miss a required disclosure.

Your workspace data is hosted in the EU. Some sub-processors (such as AI models, telephony and email delivery) may process data outside the EU under standard contractual clauses. A DPA is available on request. On formal certifications: rather than claim a badge here, we'll tell you exactly what's in place when you ask. We won't list a certification the product doesn't hold, and NorReach is a GDPR/EU-focused product, not a HIPAA one.

Any references to other tools reflect sourced public research as of 2026 and may be out of date — verify before relying on them. If anything here is inaccurate, tell us through the demo form and we'll fix it.

More answers

Every answer

See NorReach on your own outreach

Tell us your use case and we'll show you exactly how NorReach would run it — then set you up with a 14-day trial.

Pictured: Rundetaarn, Copenhagen, Denmark