
Trust Center
How NorReach protects the contacts, messages and calls you trust us with: the infrastructure it runs on, the controls we apply, every company that processes your data, and the documents your security review needs.
Built on SOC 2 Type 2 infrastructure · EU-hosted · GDPR DPA included
Start your security review
Everything public is on this page. For a signed DPA or your security questionnaire, ask us.
Overview
NorReach plans and runs your outreach, so it holds your contacts, messages and calls. This Trust Center shows how that data is protected: the infrastructure it runs on, the controls we apply, every company that processes it, and the documents your security review needs.
We only list what is true today. Where we rely on a certified provider rather than our own audit, we say so.
Contacted by a business that uses NorReach? Manage your data in the Privacy Center.
Compliance
- GDPRIn place
Controller and processor terms (Art. 28 DPA) in our Privacy Policy; consent, suppression and deletion built into the product.
- EU hostingIn place
The primary database and application functions run in the European Union.
- EU AI ActIn place
A setting to disclose AI on voice calls, and human approval before AI-drafted messages go out.
- SOC 2 Type 2 infrastructureVia our providers
Your workspace runs on database and hosting providers that are SOC 2 Type 2 audited.
- PCI DSS (payments)Via our providers
Card payments are handled by a PCI DSS Level 1 payment processor. We never store card numbers.
- NorReach SOC 2 reportNot yet
We haven't completed our own SOC 2 or ISO 27001 audit yet, so we don't claim one.
Documents
Request sub-processor listSecurity controls
Open any line for the detail.


Data security

Application security

Access control

Data privacy

AI

Monitoring & incident response

Legal & compliance
Sub-processors
The kinds of companies that process personal data for NorReach, what they do and where. We give 14 days' notice before adding or replacing one. Full terms in the Privacy Policy.
Need the named list for your DPA or a security review? Ask us — customers receive it as part of their DPA, and we share it with prospects reviewing NorReach.
Request the full list| Category | What it does | Personal data | Location |
|---|---|---|---|
| Cloud hosting, database and storage | The database, user sign-in, file storage, background jobs, application hosting and content delivery the Service runs on | All Account Data and Customer Data stored in the Service; request and technical logs | EU data region; providers headquartered in the USA |
| Email sending and deliverability | Sending outreach and transactional email, delivery and bounce events, sending domains and mailboxes, mailbox warm-up and email address verification | Email content, sender and recipient addresses, delivery events, mailbox identities | EU / USA |
| Telephony and text messaging | Phone numbers, SMS, voice calls, call routing and call recording | Phone numbers, message content, call audio and recordings, call metadata | EU (Ireland) / USA |
| AI voice | AI voice agents for outbound and inbound calls, speech synthesis and transcription | Call audio, transcripts, and the contact name and context a call needs | EU / USA |
| AI language, image and video models | Writing drafts, understanding websites and documents, the Nora assistant (text and voice), and generating images and videos for ads and posts | Prompts and the content they include (brand details, contact and message context); Nora voice audio. No contact data is sent for image and video generation. Providers may not use it to train their models. | EU / USA |
| Web reading and creative research | Reading the public pages of a customer's own website and public social profile at setup, and searching a library of publicly running ads for creative references | Public website and profile content; search terms (no personal data) | USA / Canada |
| Business contact data | The source of business contact data for Nora's lead network, when a customer searches for leads | Search filters; returned names, job titles, company details and business contact details | USA |
| Social publishing | Publishing and scheduling posts to the social accounts a customer connects | Post content and media, connected account identifiers | USA |
| Meeting booking | Booking pages and calendar availability | Names, email addresses, meeting times and notes of people who book | EU / USA |
| Messaging and advertising platforms you connect | WhatsApp Business messaging, and Facebook and Instagram advertising and conversion events — only when a customer connects them | WhatsApp numbers and messages, ad audiences and conversion events, connected account data | EU (Ireland) / USA |
| Payments | Subscription billing and payment processing, by a PCI DSS Level 1 payment processor | Billing name and address, email; card details are handled by the processor and never stored by NorReach | EU (Ireland) / USA |
| Mobile push notifications | Delivering notifications to the NorReach mobile app | Device push tokens, notification content | USA |
Questions security teams ask
NorReach runs on SOC 2 Type 2–audited infrastructure — for the database, authentication, storage and hosting — and payments go through a PCI DSS Level 1 payment processor. NorReach itself hasn't completed its own SOC 2 or ISO 27001 audit yet, so we don't claim one. The controls we apply on top are listed on this page.
Trust Center updates
Trust Center, Privacy Policy and Terms published
ComplianceWe published this Trust Center, a full Privacy Policy with the GDPR Article 28 DPA and our sub-processor categories, a Privacy Center for opt-out, access and deletion requests, and updated Terms of Service.
Last reviewed 1 October 2026
See every control on your own outreach
Tell us your use case and we'll show you exactly how NorReach would run it — then set you up with a 14-day trial.
Pictured: Kronborg Castle, Helsingør, Denmark
