The terms on which we process your clients' personal data on your instructions. You are the controller; we are the processor.
For the personal data of the buyers, vendors, tenants, landlords and professionals who correspond with your agency, you are the controller and NORĴI Ltd is your processor. We process that data only to provide the service, and only on your instructions.
Message bodies are read in your own tenant at the moment a draft is prepared. We do not store them in our systems. What we store is set out on the security page.
We act on your documented instructions, which are these terms and the configuration you set in the product. If we think an instruction breaches data protection law, we will tell you and will not act on it until it is resolved. Our people are bound by confidentiality and have access only where their role requires it.
You authorise the sub-processors listed below. We will give you notice before adding or replacing one, and you may object.
Access is granted per user by that user and is revocable at any time. Tenant isolation is enforced at the database and tested by attempts to breach it. Data is encrypted in transit and at rest. One negotiator's mail is never used to serve another, and no customer's data is used to train any model.
Where personal data is transferred outside the UK, we rely on the UK's approved transfer mechanisms, including the International Data Transfer Addendum where applicable.
If we become aware of a personal data breach affecting your data, we will tell you without undue delay and give you what you need to meet your own notification obligations — what happened, which data was affected as far as we can tell, and what we have done about it.
If one of your clients exercises a data protection right with us, we will refer them to you and tell you. We will help you answer access, correction, erasure and portability requests, and the audit trail is designed to make that straightforward rather than an excavation.
On termination you may export your audit trail. After that we will delete or return the personal data we hold, except where we are required by law to keep it.
We will provide the information you reasonably need to demonstrate compliance, and will submit to audits at reasonable intervals on reasonable notice.