NORĴI Try demo

Data processing

The terms on which we process your clients' personal data on your instructions. You are the controller; we are the processor.

Roles

For the personal data of the buyers, vendors, tenants, landlords and professionals who correspond with your agency, you are the controller and NORĴI Ltd is your processor. We process that data only to provide the service, and only on your instructions.

Subject matter and scope

Subject matter
Preparing draft correspondence, tracking compliance dates, and maintaining an audit trail
Duration
For as long as your subscription runs, plus the retention period set out in your contract
Categories of data
Names, contact details, correspondence metadata, property and tenancy details, and the audit record of actions taken
Data subjects
Your clients and counterparties: buyers, vendors, applicants, tenants, landlords, solicitors, surveyors and contractors
Special category data
Not processed by design. Do not configure the product to handle it.

Message bodies are read in your own tenant at the moment a draft is prepared. We do not store them in our systems. What we store is set out on the security page.

Your instructions

We act on your documented instructions, which are these terms and the configuration you set in the product. If we think an instruction breaches data protection law, we will tell you and will not act on it until it is resolved. Our people are bound by confidentiality and have access only where their role requires it.

Sub-processors

You authorise the sub-processors listed below. We will give you notice before adding or replacing one, and you may object.

Sub-processorWhat it processes
Language model providerMessage content, at the moment a draft is written
Your own mail provider (Microsoft or Google)Your correspondence, in your own tenant
Hosting and database providerIdentifiers, timestamps, dates and the audit trail

Security measures

Access is granted per user by that user and is revocable at any time. Tenant isolation is enforced at the database and tested by attempts to breach it. Data is encrypted in transit and at rest. One negotiator's mail is never used to serve another, and no customer's data is used to train any model.

International transfers

Where personal data is transferred outside the UK, we rely on the UK's approved transfer mechanisms, including the International Data Transfer Addendum where applicable.

Breach notification

If we become aware of a personal data breach affecting your data, we will tell you without undue delay and give you what you need to meet your own notification obligations — what happened, which data was affected as far as we can tell, and what we have done about it.

Helping with requests

If one of your clients exercises a data protection right with us, we will refer them to you and tell you. We will help you answer access, correction, erasure and portability requests, and the audit trail is designed to make that straightforward rather than an excavation.

Return and deletion

On termination you may export your audit trail. After that we will delete or return the personal data we hold, except where we are required by law to keep it.

Audit

We will provide the information you reasonably need to demonstrate compliance, and will submit to audits at reasonable intervals on reasonable notice.

© 2026 NORĴI LtdRegistered in England and Wales, company no. 17180824 · Registered office: York, England ULI PropTech Innovation Challenge 2026 · UK & Ireland Finalist Built to UK GDPR