Skip to content
Included on every plan

Trust Center

How NorReach protects the contacts, messages and calls you trust us with: the infrastructure it runs on, the controls we apply, every company that processes your data, and the documents your security review needs.

Built on SOC 2 Type 2 infrastructure · EU-hosted · GDPR DPA included

Start your security review

Everything public is on this page. For a signed DPA or your security questionnaire, ask us.

Request documents

Overview

NorReach plans and runs your outreach, so it holds your contacts, messages and calls. This Trust Center shows how that data is protected: the infrastructure it runs on, the controls we apply, every company that processes it, and the documents your security review needs.

We only list what is true today. Where we rely on a certified provider rather than our own audit, we say so.

Contacted by a business that uses NorReach? Manage your data in the Privacy Center.

Compliance

  • GDPRIn place

    Controller and processor terms (Art. 28 DPA) in our Privacy Policy; consent, suppression and deletion built into the product.

  • EU hostingIn place

    The primary database and application functions run in the European Union.

  • EU AI ActIn place

    A setting to disclose AI on voice calls, and human approval before AI-drafted messages go out.

  • SOC 2 Type 2 infrastructureVia our providers

    Your workspace runs on database and hosting providers that are SOC 2 Type 2 audited.

  • PCI DSS (payments)Via our providers

    Card payments are handled by a PCI DSS Level 1 payment processor. We never store card numbers.

  • NorReach SOC 2 reportNot yet

    We haven't completed our own SOC 2 or ISO 27001 audit yet, so we don't claim one.

Security controls

Open any line for the detail.

Infrastructure

Data security

Application security

Access control

Data privacy

AI

Monitoring & incident response

Sub-processors

The kinds of companies that process personal data for NorReach, what they do and where. We give 14 days' notice before adding or replacing one. Full terms in the Privacy Policy.

Need the named list for your DPA or a security review? Ask us — customers receive it as part of their DPA, and we share it with prospects reviewing NorReach.

Request the full list
CategoryWhat it doesPersonal dataLocation
Cloud hosting, database and storageThe database, user sign-in, file storage, background jobs, application hosting and content delivery the Service runs onAll Account Data and Customer Data stored in the Service; request and technical logsEU data region; providers headquartered in the USA
Email sending and deliverabilitySending outreach and transactional email, delivery and bounce events, sending domains and mailboxes, mailbox warm-up and email address verificationEmail content, sender and recipient addresses, delivery events, mailbox identitiesEU / USA
Telephony and text messagingPhone numbers, SMS, voice calls, call routing and call recordingPhone numbers, message content, call audio and recordings, call metadataEU (Ireland) / USA
AI voiceAI voice agents for outbound and inbound calls, speech synthesis and transcriptionCall audio, transcripts, and the contact name and context a call needsEU / USA
AI language, image and video modelsWriting drafts, understanding websites and documents, the Nora assistant (text and voice), and generating images and videos for ads and postsPrompts and the content they include (brand details, contact and message context); Nora voice audio. No contact data is sent for image and video generation. Providers may not use it to train their models.EU / USA
Web reading and creative researchReading the public pages of a customer's own website and public social profile at setup, and searching a library of publicly running ads for creative referencesPublic website and profile content; search terms (no personal data)USA / Canada
Business contact dataThe source of business contact data for Nora's lead network, when a customer searches for leadsSearch filters; returned names, job titles, company details and business contact detailsUSA
Social publishingPublishing and scheduling posts to the social accounts a customer connectsPost content and media, connected account identifiersUSA
Meeting bookingBooking pages and calendar availabilityNames, email addresses, meeting times and notes of people who bookEU / USA
Messaging and advertising platforms you connectWhatsApp Business messaging, and Facebook and Instagram advertising and conversion events — only when a customer connects themWhatsApp numbers and messages, ad audiences and conversion events, connected account dataEU (Ireland) / USA
PaymentsSubscription billing and payment processing, by a PCI DSS Level 1 payment processorBilling name and address, email; card details are handled by the processor and never stored by NorReachEU (Ireland) / USA
Mobile push notificationsDelivering notifications to the NorReach mobile appDevice push tokens, notification contentUSA

Questions security teams ask

  • NorReach runs on SOC 2 Type 2–audited infrastructure — for the database, authentication, storage and hosting — and payments go through a PCI DSS Level 1 payment processor. NorReach itself hasn't completed its own SOC 2 or ISO 27001 audit yet, so we don't claim one. The controls we apply on top are listed on this page.

Trust Center updates

Trust Center, Privacy Policy and Terms published

Compliance
1 October 2026

We published this Trust Center, a full Privacy Policy with the GDPR Article 28 DPA and our sub-processor categories, a Privacy Center for opt-out, access and deletion requests, and updated Terms of Service.

Questions about security or this Trust Center?Contact us
Found a vulnerability? Please tell us.Report an issue

Last reviewed 1 October 2026

See every control on your own outreach

Tell us your use case and we'll show you exactly how NorReach would run it — then set you up with a 14-day trial.

Pictured: Kronborg Castle, Helsingør, Denmark