Skip to content

This Privacy Policy (the "Policy") describes how NorReach processes Personal Data that is submitted to NorReach, or that otherwise becomes available to NorReach, when Clients and other users use the Website, the Software and the Services. It explains how NorReach processes Personal Data (i) as a Controller, for its own purposes such as account administration, billing, security, customer support and its own marketing; and (ii) as a Processor, on behalf of Clients, when it provides the Services using Personal Data that Clients submit or instruct it to obtain.

This Policy forms part of the agreement between each Client and NorReach. Section 3 and Annexes I–III together make up the data processing agreement ("DPA") between the Client as Controller and NorReach as Processor for the purposes of Article 28 of the EU GDPR and the UK GDPR. Where NorReach processes Personal Data as Processor, it does so only on the Client's documented instructions, unless applicable law requires otherwise. A separately signed copy of the DPA is available on request.

Please read this Policy carefully. By using the Website, the Software or the Services, Clients confirm that they have had the opportunity to review it. We may update this Policy from time to time (see section 17).

1. Definitions

  1. Client — a legal person (or a sole trader acting in a business capacity) that registers for and uses the Service.
  2. Client Personal Data — Personal Data that NorReach processes on a Client's behalf as Processor, including the Client's contacts, leads, messages, calls and content.
  3. Controller and Processor — as defined in Article 4 of the EU GDPR and the UK GDPR.
  4. Data Subject — an identified or identifiable natural person whose Personal Data is processed, for example a Client's user, a contact the Client reaches, or a visitor to the Website.
  5. Data Protection Laws — the EU GDPR, the UK GDPR and the UK Data Protection Act 2018, the Swedish Data Protection Act (2018:218), national laws that implement or supplement them, the ePrivacy rules on electronic marketing as implemented in each country, and any other applicable data protection or privacy law.
  6. EU GDPR — Regulation (EU) 2016/679. UK GDPR — the EU GDPR as it forms part of the law of the United Kingdom.
  7. EU Standard Contractual Clauses ("SCCs") — the clauses adopted by the European Commission on 4 June 2021 (Implementing Decision (EU) 2021/914), or any successor clauses. UK Addendum — the international data transfer addendum to the SCCs issued under the UK GDPR. DPF — the EU–U.S. Data Privacy Framework, its UK extension and the Swiss–U.S. framework.
  8. Personal Data — any information relating to an identified or identifiable natural person. Processing — any operation performed on Personal Data, such as collection, storage, use, disclosure or erasure.
  9. Restricted Transfer — a transfer of Personal Data to a country that is not covered by an adequacy decision under the EU GDPR or adequacy regulations under the UK GDPR.
  10. Service(s) — the NorReach platform for planning and running multichannel outreach and marketing — email, SMS, WhatsApp, LinkedIn, AI voice calls, social posts and ads — including the Nora AI assistant, the lead network, the inbox, meeting booking and related features.
  11. Software — the NorReach web application, the NorReach mobile app, the NorReach browser extension for LinkedIn and any APIs NorReach provides.
  12. Sub-processor — a third party engaged by NorReach to process Client Personal Data (the categories are listed in Annex III).
  13. Website — www.norreach.app and any other website NorReach operates.

2. Who we are

NorReach is operated by Youpal Group AB, a company registered in Sweden with its office in Stockholm ("NorReach", "we", "us"). Because we are established in the European Union, the EU GDPR applies to all of our processing, and our lead supervisory authority is the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY).

For any question about this Policy or about Personal Data, contact us at privacy@norreach.ai.

3. Our two roles: controller and processor

3.1 NorReach as Processor (Client Personal Data)

When a Client uses the Service — imports contacts, searches the lead network, runs campaigns and plans, sends messages, places AI calls, books meetings or posts content — the Client is the Controller of that Personal Data and NorReach is its Processor. In that role NorReach:

  1. processes Client Personal Data only on the Client's documented instructions, given through the Client's configuration and use of the Service, its account settings, support requests, other written communications, the Terms and this DPA — unless applicable law requires otherwise, in which case we inform the Client first unless the law forbids it;
  2. tells the Client promptly if, in our opinion, an instruction infringes Data Protection Laws, and may decline to carry out an unlawful instruction;
  3. ensures that everyone authorised to process Client Personal Data is bound by confidentiality;
  4. applies the security measures in section 12 and Annex II;
  5. engages Sub-processors only as described in section 10 and Annex III, under written terms that protect Personal Data at least as well as this DPA, and remains responsible to the Client for their performance;
  6. helps the Client respond to Data Subjects' requests, meet its security, breach-notification, impact-assessment and prior-consultation obligations (Articles 32–36 GDPR), taking into account the nature of the processing and the information available to us;
  7. at the end of the Service, deletes or returns Client Personal Data as described in Annex I, unless law requires us to keep it; and
  8. makes available the information needed to demonstrate compliance with Article 28 and allows audits as described in section 9.

Subject matter and duration: the provision of the Service for as long as the Client's account exists, plus the deletion period in Annex I. Nature and purpose: hosting, organising, generating, sending, receiving, analysing and displaying communications and related data so the Client can run its outreach and marketing. Categories of Data Subjects: the Client's contacts, leads, prospects, customers, people who reply to or book meetings with the Client, and the Client's own users. Categories of Personal Data: those in section 4.3. Special categories: the Service is not designed for special category data (Article 9 GDPR) and Clients must not submit it unless they have a lawful basis and have told us in writing.

3.2 NorReach as Controller

NorReach is the Controller of Personal Data about the Client's users and representatives that it processes to run its own business: creating and securing accounts, billing, customer support, product communications and improvement, fraud prevention, legal compliance and the Website. Section 6.1 sets out our legal bases for this.

3.3 Independent controllers

Where a Client connects a third-party account (for example its own Google, LinkedIn, Meta, X or TikTok account, or a calendar), the data exchanged with that platform is also processed by the platform under its own terms and privacy policy. Business contact data supplied by our lead-network data provider is provided by that company as an independent controller of its own database; once a Client adds a record to its workspace, the Client is the Controller of it.

4. Personal data we process

4.1 Account and user data (Controller)

  • Name, work email address, phone number, password (stored only as a salted hash by our authentication provider) or Google sign-in identifier.
  • Workspace and company details, role, team membership, notification and contact preferences.
  • Billing details: plan, invoices and billing contact. Card details are collected and stored by our payment processor (PCI DSS Level 1); NorReach never stores full card numbers.
  • Support conversations and feedback.

4.2 Usage and device data (Controller)

  • Log data: IP address, browser and device type, timestamps, pages and features used, errors.
  • Mobile app: device type, app version and a push notification token, if notifications are allowed.
  • Browser extension: the pairing token that links the extension to a workspace, and the results of the LinkedIn actions it performs. The extension never collects the user's LinkedIn password.

4.3 Client Personal Data (Processor)

Its scope depends on how each Client uses the Service, and typically includes:

  • Contact and lead records: names, job titles, companies, business email addresses, phone numbers, LinkedIn and social profile links, locations, list membership, tags, notes, scores and the stage each person is at.
  • Communications: the content of emails, SMS, WhatsApp messages, LinkedIn messages and connection requests, and replies to them; delivery, open and click events; unsubscribe and suppression status.
  • Calls: call recordings, transcripts, call outcomes and summaries from AI voice calls and from the dialer.
  • Meetings: the names, email addresses and times of people who book meetings, and any notes they add.
  • Content: brand material, posts, ads, images and videos, documents and knowledge the Client uploads or generates — which may include images of people.
  • Advertising: audiences and conversion events the Client sends to an ad platform it connects.

4.4 Website visitors (Controller)

When someone visits the Website or requests a demo, we process the details they submit (name, work email, company, message) and technical log data needed to deliver and secure the Website.

4.5 Sources

We receive Personal Data from the Client and its users; from people who interact with a Client's outreach (replies, calls, bookings); from platforms the Client connects; from the lead-network data provider when a Client searches for leads; and from the public pages of a Client's own website and social accounts when the Client asks Nora to read them.

5. Why we process it

  • Providing the Service — running workspaces, plans and campaigns; sending and receiving messages; placing and recording calls; booking meetings; publishing posts and ads; finding and verifying leads.
  • AI features — drafting messages, plans, posts and ads; reading websites; the Nora assistant (text and voice); AI voice calls; generating images and video (see section 7).
  • Deliverability and compliance — verifying email addresses, warming up and monitoring mailboxes, honouring unsubscribes and suppression lists, respecting sending windows and caps.
  • Accounts, billing and support — creating and securing accounts, charging for the Service, answering questions.
  • Security and integrity — preventing abuse, fraud and spam, investigating incidents, keeping logs.
  • Improving the Service — understanding how features are used, fixing errors, developing new features, using aggregated or de-identified data where possible.
  • Communication — service notices, security alerts, digests a user asked for, and, where permitted, news about NorReach (with an unsubscribe link in every message).
  • Legal obligations — accounting, tax and responding to lawful requests from authorities.

6.1 Where NorReach is Controller

  • Contract (Art. 6(1)(b)) — to provide the Service to the Client and manage the account.
  • Legitimate interests (Art. 6(1)(f)) — security, fraud prevention, service improvement, support, and business-to-business communications about NorReach. You can object at any time.
  • Consent (Art. 6(1)(a)) — where the law requires it, for example optional marketing to individuals; consent can be withdrawn at any time.
  • Legal obligation (Art. 6(1)(c)) — bookkeeping, tax and lawful requests.

6.2 The Client's responsibilities as Controller

Where NorReach is Processor, the Client:

  1. is responsible for having a lawful basis for every processing activity it instructs, including outreach to people it has not been in contact with before, and for the accuracy and lawfulness of the data it submits;
  2. gives Data Subjects the information required by Articles 13 and 14 GDPR, including that it uses NorReach and AI tools to contact them;
  3. complies with the direct-marketing rules of each recipient's country — for email, SMS, WhatsApp and calls these differ, and many require prior consent for messages to individuals or a clear way to opt out in every message — and honours opt-outs promptly. NorReach provides unsubscribe handling, suppression lists, quiet hours and approval steps to help, but the Client decides how they are used;
  4. where it uses AI voice calls, makes sure people are told they are speaking with an AI system where the law requires it (for example under Article 50 of the EU AI Act), and obtains any consent required to record calls;
  5. does not use the Service to process special category data, data about children, or data it is not allowed to use; and
  6. tells NorReach without delay if the legal basis for any processing it has instructed ends.

NorReach only provides the technical means to generate, send and manage communications. The Client remains solely responsible for the content it sends and the people it contacts.

7. Artificial intelligence

AI is central to the Service. The AI features use large language, speech, image and video models from the AI providers in the categories listed in Annex III. When a feature runs, the content needed for that task — for example a contact's name and company, a message thread, a website's public text, or brand images — is sent to the relevant provider and the result is returned to the Service.

  • We do not share Client Personal Data with AI providers for the purpose of training their general models, and we use their business API services rather than consumer products.
  • AI output can be wrong. By default the Service asks a person to review and approve AI-drafted content before it is sent; Clients can change these approval settings and are responsible for what is sent.
  • The Service does not make decisions about Data Subjects based solely on automated processing that produce legal or similarly significant effects. Lead scores and suggested next steps only help Clients prioritise their own outreach.
  • AI voice calls are processed by our telephony and voice providers to place the call, generate speech, transcribe and summarise it. Recordings and transcripts are stored in the Client's workspace.
  • In the Nora voice mode (web and mobile), the user's voice is streamed to the voice model for the length of the session to understand and answer them; it is not used to identify the speaker. On mobile, speech-to-text may also use the operating system's own speech service (Apple or Google) under the user's device settings.

8. Data subjects' rights

Under Data Protection Laws, Data Subjects have the right to access their Personal Data, to have it corrected, erased or restricted, to data portability, to object (including, at any time, to direct marketing), to withdraw consent, and to complain to a supervisory authority.

  • Where NorReach is Controller (for example, if you are a user of the Service or a Website visitor), email privacy@norreach.ai. We answer within one month, which can be extended by two further months for complex requests; we will tell you if so.
  • Where NorReach is Processor (for example, if you received a message sent by one of our Clients), the Client is responsible for your request. Outreach emails sent through the Service can carry an unsubscribe link, and you can always reply asking to be removed. If you contact us, we will pass your request to the Client without undue delay and act on its instructions; where the Client cannot be identified or does not respond, we will help as far as we lawfully can.

9. Audits and assistance

NorReach will make available to the Client the information reasonably necessary to demonstrate compliance with Article 28 GDPR, and will allow for and contribute to audits, including inspections, by the Client or an independent auditor it mandates, at the Client's expense. Audits must be requested in writing with at least 30 days' notice, take place during normal business hours, avoid disrupting our operations, be subject to confidentiality, and normally not take place more than once a year unless a supervisory authority requires it or a Personal Data breach has occurred. We may first answer an audit request with written responses, documentation and the security reports our Sub-processors publish. Audit rights do not extend to Sub-processors' premises, which are covered by their own certifications and audit reports.

10. Sub-processors and other recipients

We do not sell Personal Data, and we do not share it for cross-context behavioural advertising.

  1. The Client gives NorReach general written authorisation to engage Sub-processors in the categories listed in Annex III. Some are only used when the Client turns on the related feature (for example WhatsApp, AI calls, social posting or ads). The current list of Sub-processors by name is available to Clients on request at privacy@norreach.ai, and forms part of this DPA.
  2. We will inform Clients of any intended addition or replacement of a Sub-processor by updating the named list (and Annex III where a new category is added) and, for Sub-processors of Client Personal Data, by notifying the account owner by email or in the app at least 14 days before the change takes effect (or as soon as possible where a change is urgent for security or continuity). A Client may object on reasonable data-protection grounds within that period; if we cannot reasonably resolve the objection, the Client may terminate the affected Service.
  3. Before engaging a Sub-processor we assess its security and data protection, and we bind it to written obligations no less protective than this DPA, including the SCCs or another transfer mechanism where needed.
  4. Other recipients: platforms the Client chooses to connect (section 3.3); professional advisers under confidentiality; a buyer or successor in a merger or acquisition, subject to this Policy; and authorities where the law requires it, to protect rights, safety or property, or to enforce our Terms. Where we receive a request from an authority for Client Personal Data, we will redirect it to the Client where possible and notify the Client unless the law forbids it.

11. Transfers outside the EEA and the UK

Our primary database and the application's server functions are hosted in the European Union. Some Sub-processors are established in, or access data from, countries outside the EEA and the UK — mainly the United States. For every Restricted Transfer we rely on one of the following:

  1. an adequacy decision, including the EU–U.S. Data Privacy Framework and its UK extension where the recipient is certified;
  2. the EU Standard Contractual Clauses (Module 2 or 3 as applicable) and, for UK data, the UK Addendum; or
  3. another safeguard or derogation permitted by Articles 46–49 GDPR (or the UK equivalents).

Where required we carry out transfer assessments and apply supplementary measures such as encryption in transit and at rest and strict access controls. The Client authorises the Restricted Transfers to the Sub-processors engaged under section 10. A copy of the relevant safeguards can be requested at privacy@norreach.ai.

12. Security

We implement technical and organisational measures appropriate to the risk, taking into account the state of the art, the cost of implementation and the nature, scope, context and purposes of the processing. Annex II describes them in detail. In short:

  • Built on SOC 2 Type 2 infrastructure. Your data lives on independently audited infrastructure: our database, authentication, storage and hosting providers are SOC 2 Type 2 audited, our other infrastructure providers hold ISO/IEC 27001 certification or SOC 2 reports, and our payment processor is certified PCI DSS Level 1.
  • Our own controls. On top of that infrastructure, NorReach applies the controls in Annex II. NorReach has not yet completed its own SOC 2 or ISO 27001 audit, and we do not claim certifications we do not hold — our providers' reports cover their platforms.
  • Encryption of all traffic in transit (TLS 1.2+) and of stored data at rest (AES-256 at our database and storage providers).
  • Tenant isolation enforced in the database itself (row-level security), so each workspace can only read its own records, and server-side checks on every API route.
  • Secrets and keys held server-side only, in encrypted environment configuration and the database vault; privileged keys never reach browsers or apps.
  • Verified webhooks — signatures from our telephony, email, payment, voice and social providers are checked before any event is accepted.
  • Least privilege — staff access to production systems is limited to the people who need it and removed when it is no longer needed.

13. Personal data breaches

If we become aware of a Personal Data breach affecting Client Personal Data, we will notify the Client without undue delay — and where feasible within 72 hours of becoming aware of it — with the information the Client needs to meet its own obligations to notify a supervisory authority or Data Subjects: the nature of the breach, the categories and approximate number of people and records concerned, the likely consequences, and the measures taken or proposed. We will cooperate with the Client and take reasonable steps to investigate, contain and remediate the breach. Where NorReach is Controller, we notify IMY and affected people as Data Protection Laws require.

14. Retention

We keep Personal Data only for as long as it is needed for the purposes in section 5, to comply with legal obligations, to resolve disputes and to enforce our agreements. Annex I sets out the periods. Clients control most retention of Client Personal Data themselves: they can delete contacts, conversations, recordings and content in the Service at any time.

15. Cookies and tracking

The Website and the web application use only cookies and similar storage that are strictly necessary — to keep users signed in, keep sessions secure and remember settings such as the theme or a sidebar state. We do not use third-party advertising or analytics cookies on the Website. If we ever add optional cookies, we will ask for consent first.

Outreach email sent through the Service can record when a message is delivered, opened or a link in it is clicked (links pass through a NorReach redirect). These events are Client Personal Data used to measure and schedule the Client's outreach; Clients are responsible for any notice or consent this requires in the recipient's country.

16. Children

The Service is a business tool and is not intended for anyone under 18. We do not knowingly collect Personal Data from children, and Clients must not use the Service to contact them.

17. Changes to this Policy

We may amend this Policy from time to time, for example when we add features or Sub-processors or when the law changes. The date at the top shows the latest version. We will tell account owners about material changes by email or in the app before they take effect. Changes to Sub-processors follow section 10.

18. Contact and complaints

Questions, requests, complaints and reports of suspected security vulnerabilities can be sent to us at any time. We will acknowledge and investigate them without undue delay.

Youpal Group AB (NorReach)

Stockholm, Sweden

Email: privacy@norreach.ai

You also have the right to lodge a complaint with a supervisory authority — in Sweden, Integritetsskyddsmyndigheten (IMY), www.imy.se; in the UK, the Information Commissioner's Office; or the authority where you live or work.

Annex I — Retention periods

  1. Client Personal Data: kept for as long as the Client keeps it in its workspace. Contacts, conversations, recordings and content that a Client deletes are removed from the live database straight away.
  2. Closed accounts: when a Client closes its account, its workspace data is deleted within 30 days, unless the Client asks us first to export it or the law requires us to keep part of it.
  3. Backups: our database provider keeps backups on a rolling basis; deleted data disappears from them as they are overwritten in the normal cycle and is never restored into the live Service except to recover from an incident.
  4. Suppression lists: the email address or phone number of a person who opted out is kept for as long as the Client's workspace exists, so that their opt-out keeps being honoured.
  5. Account and billing records (Controller): kept for the life of the account; invoices and accounting records for seven years after the end of the financial year, as Swedish bookkeeping law requires.
  6. Logs: application and security logs are kept by our hosting providers for a limited period for security and troubleshooting, then deleted.
  7. Support and Website enquiries: kept for up to 24 months after the last contact unless they become part of a customer relationship.
  8. Data sent to AI and other Sub-processors is retained by them only for as long as their service terms with us allow — typically briefly, for abuse monitoring — unless keeping it is part of the feature (for example a stored call recording).

Annex II — Technical and organisational measures

NorReach applies at least the following measures. They are reviewed and may be replaced with measures that are no less protective.

1. Hosting and infrastructure

  • Data is hosted with providers that maintain independently audited security programmes (SOC 2 Type 2, ISO/IEC 27001 and, for payments, PCI DSS Level 1). Their reports are available from each provider; which provider holds which report is shared with the named Sub-processor list on request.
  • The primary database and application functions run in the European Union.
  • Physical security of data centres is provided by these providers under their certifications.

2. Encryption and pseudonymisation

  • TLS 1.2 or higher for all traffic between users, the Service and Sub-processors; HTTPS enforced.
  • Encryption at rest (AES-256) for the database, file storage and backups.
  • Passwords are never stored in plain text — only as salted hashes by the authentication provider; Google sign-in is available.
  • Third-party access tokens and credentials are stored server-side and never exposed to client devices.

3. Access control and tenant isolation

  • Every workspace's data is separated in the database with row-level security policies; every API route checks the signed-in user and their workspace before reading or writing.
  • Privileged service credentials are used only by server-side code, never in browsers or apps.
  • Role-based access within workspaces; production access for NorReach staff is limited to named people who need it and removed when no longer needed.
  • The browser extension acts only inside the user's own LinkedIn session and authenticates with a revocable pairing token; it never sees or stores LinkedIn passwords.

4. Integrity of incoming data

  • Webhooks from our telephony, payment, email, voice and social publishing providers and from Meta are verified by signature or shared secret, compared in constant time, before they are processed.
  • Inputs are validated server-side before they are stored or acted on.

5. Availability and resilience

  • Managed database with automated backups and the ability to restore from them.
  • Background work runs through queues with retries, so a failing provider does not lose data.

6. Logging, monitoring and incident response

  • Application, authentication and security events are logged and monitored for errors and abuse.
  • An incident response process covers detection, containment, assessment, notification under section 13 and follow-up.

7. Secure development

  • Changes are made through version control with review, automated tests and type checks before release; separate staging and production environments.
  • Dependencies are kept up to date; secrets are kept out of source code and rotated when exposure is suspected.

8. Data minimisation and privacy by design

  • Only the data a feature needs is sent to each Sub-processor (for example, image generation receives brand assets, not contact data).
  • Built-in controls for compliant outreach: unsubscribe links and suppression lists, quiet hours and daily caps, approval before sending, and a setting to disclose AI on voice calls.

9. People and governance

  • Everyone with access to Personal Data is bound by confidentiality obligations that survive the end of their engagement, and is informed of their data protection duties.
  • Sub-processors are assessed before use and bound by written data protection terms.

Annex III — Sub-processor categories

The Client authorises NorReach to use Sub-processors in the following categories. Where a Sub-processor is part of a group, its affiliates may process data for the same purpose under the same safeguards. Transfers outside the EEA and the UK follow section 11.

CategoryPurposePersonal dataLocation
Cloud hosting, database and storageThe database, user sign-in, file storage, background jobs, application hosting and content delivery the Service runs onAll Account Data and Customer Data stored in the Service; request and technical logsEU data region; providers headquartered in the USA
Email sending and deliverabilitySending outreach and transactional email, delivery and bounce events, sending domains and mailboxes, mailbox warm-up and email address verificationEmail content, sender and recipient addresses, delivery events, mailbox identitiesEU / USA
Telephony and text messagingPhone numbers, SMS, voice calls, call routing and call recordingPhone numbers, message content, call audio and recordings, call metadataEU (Ireland) / USA
AI voiceAI voice agents for outbound and inbound calls, speech synthesis and transcriptionCall audio, transcripts, and the contact name and context a call needsEU / USA
AI language, image and video modelsWriting drafts, understanding websites and documents, the Nora assistant (text and voice), and generating images and videos for ads and postsPrompts and the content they include (brand details, contact and message context); Nora voice audio. No contact data is sent for image and video generation. Providers may not use it to train their models.EU / USA
Web reading and creative researchReading the public pages of a customer's own website and public social profile at setup, and searching a library of publicly running ads for creative referencesPublic website and profile content; search terms (no personal data)USA / Canada
Business contact dataThe source of business contact data for Nora's lead network, when a customer searches for leadsSearch filters; returned names, job titles, company details and business contact detailsUSA
Social publishingPublishing and scheduling posts to the social accounts a customer connectsPost content and media, connected account identifiersUSA
Meeting bookingBooking pages and calendar availabilityNames, email addresses, meeting times and notes of people who bookEU / USA
Messaging and advertising platforms you connectWhatsApp Business messaging, and Facebook and Instagram advertising and conversion events — only when a customer connects themWhatsApp numbers and messages, ad audiences and conversion events, connected account dataEU (Ireland) / USA
PaymentsSubscription billing and payment processing, by a PCI DSS Level 1 payment processorBilling name and address, email; card details are handled by the processor and never stored by NorReachEU (Ireland) / USA
Mobile push notificationsDelivering notifications to the NorReach mobile appDevice push tokens, notification contentUSA

The names of our Sub-processors are not published. Clients receive the current named list as part of this DPA, and we share it with prospective customers carrying out a security or procurement review. Request the list or email privacy@norreach.ai.

Platforms a Client connects to its workspace with its own account (for example Google Workspace or Gmail, LinkedIn, X, TikTok, or its own Meta business account) act under their own terms and are not Sub-processors of NorReach for that data.