Effective · 4 September 2026
1. General provisions
1.1. This Privacy Policy explains how NORMALIC OÜ (registry code 17483468, address Spektri tn 6, Tartu 50411, Estonia, email info@normalic.com; NORMALIC or we) processes personal data in connection with providing and using the NORMALIC software platform (the Platform).
1.2. The Privacy Policy primarily applies to the processing of personal data concerning representatives, contact persons and Platform users of our business customers (the Customer), as well as visitors to our website.
1.3. Where NORMALIC processes personal data on the Customer’s behalf and instructions as a processor—for example, operator data contained in the Customer’s Production Data—such processing is primarily governed by the data processing agreement entered into between the Parties (the DPA). In such cases, this Privacy Policy provides only a general overview.
1.4. Capitalised terms not defined in this Privacy Policy have the meanings given to them in the General Terms and Conditions available on the Normalic website (the Terms).
1.5. Unless stated otherwise in this Privacy Policy, NORMALIC is the controller.
1.6. For data protection enquiries, contact privacy@normalic.com.
2. Personal data we process
2.1. Information concerning Customer contacts and representatives:
- first and last name, position and employer;
- email address and telephone number; and
- the content of communications, such as correspondence, enquiries and meeting notes.
2.2. Platform account and usage information:
- username, email address, role and Platform permissions;
- login details, login times, IP address, device and browser information; and
- Platform usage logs, such as the views and functions used, including the content of conversations with the Normalic Assistant.
2.3. Production Data submitted by the Customer to provide the Service. Production Data generally consists of machine, process and production data, but may in some cases include information relating to individual natural persons, such as specific operators, including:
- an operator identifier or name associated with a particular workstation or shift; and
- performance, downtime and error data associated with a particular operator.
NORMALIC generally processes this part of the Production Data as a processor on the Customer’s behalf. The terms of such processing—including its purposes, duration and security measures—are further specified in the DPA between the Parties. The Customer is responsible for informing its employees and ensuring that a valid legal basis for the processing exists.
2.4. Billing and agreement administration data, including invoice recipient details, bank account information and payment history.
2.5. Website visitor data, including cookies and similar technologies described in more detail in our Cookie Policy.
2.6. For first-time language selection, the website may request a visitor's country code from ipapi.co using the visitor's IP address. Normalic receives only the country code and uses it to open the German-language site automatically for visitors in Germany. The selected language and a temporary check flag are stored in the visitor's browser. Visitors can override the automatic choice at any time using the language selector.
3. Purposes and legal bases for processing
- Entering into and performing the Agreement and providing the Service, including managing contacts, creating and administering user accounts, and providing customer support. Legal basis: performance of a contract under Article 6(1)(b) GDPR and our legitimate interest in managing the business relationship under Article 6(1)(f) GDPR.
- Providing Platform and Normalic Assistant functionality, including analysing usage logs to ensure service performance and security. Legal basis: performance of a contract and legitimate interests under Articles 6(1)(b) and 6(1)(f) GDPR.
- Billing and compliance with accounting obligations. Legal basis: compliance with a legal obligation under Article 6(1)(c) GDPR and performance of a contract under Article 6(1)(b) GDPR.
- Protecting the security of the Service and Platform and preventing fraud and misuse. Legal basis: legitimate interests under Article 6(1)(f) GDPR.
- Marketing and communication with existing and prospective business customers, such as newsletters and product updates. Legal basis: legitimate interests in relation to business contacts, or consent where required by law. Every marketing message includes an option to unsubscribe.
- Establishing, exercising and defending legal claims. Legal basis: legitimate interests under Article 6(1)(f) GDPR.
- Selecting the most relevant website language based on country and remembering the visitor's choice. Legal basis: Normalic's legitimate interest in presenting the website in an appropriate language under Article 6(1)(f) GDPR.
4. Sources of personal data
We collect personal data primarily from the data subject directly, such as information provided by a contact person when entering into the Agreement, and from the Customer, such as information required to create user accounts and Production Data. Certain technical data, including IP addresses and device information, is collected automatically when the Platform or website is used.
5. Recipients of personal data
We may engage processors to handle personal data, including:
- cloud service and hosting providers;
- artificial intelligence and LLM service providers used to operate the Normalic Assistant and analytics functions;
- customer relationship management, accounting and IT support providers; and
- IP-country lookup provider ipapi.co, used only for the initial website-language selection; and
- legal advisers, auditors and other professional advisers where necessary to protect our rights.
We enter into data processing agreements with our processors to ensure a level of protection that complies with the GDPR.
We do not sell personal data to third parties. We may also disclose personal data to a competent authority where required by law.
6. Transfers outside the European Economic Area
Where a processor, such as a cloud or artificial intelligence service provider, is located or processes data outside the European Economic Area (EEA), we implement appropriate safeguards for the transfer. These may include Standard Contractual Clauses approved by the European Commission or another transfer mechanism recognised under the GDPR.
7. Retention of personal data
We retain personal data only for as long as necessary to fulfil the purpose for which it was processed or to comply with a legal obligation:
- contact information—for the term of the Agreement and three years after its termination, corresponding to the limitation period for claims;
- usage logs and technical data—for up to 12 months, unless longer retention is necessary to investigate a security incident;
- accounting records—for seven years in accordance with the Estonian Accounting Act; and
- Production Data, including any personal data it contains—for the period agreed in the DPA, generally for the term of the Agreement, after which the data is deleted or anonymised in accordance with the DPA.
8. Rights of data subjects
Under the GDPR, every data subject has the right to:
- receive information about the personal data we process concerning them and request access to it;
- request the correction of inaccurate data;
- request deletion where a basis for deletion exists under the GDPR;
- request restriction of processing;
- object to processing based on legitimate interests;
- request data portability where processing is based on consent or a contract and is carried out by automated means;
- withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing carried out before withdrawal; and
- lodge a complaint with the Estonian Data Protection Inspectorate (info@aki.ee, www.aki.ee) or seek a judicial remedy.
To exercise these rights, contact us using the details in clause 1.6. Where we act as a processor of personal data contained in Production Data, we will normally refer the request to the Customer as controller or assist the Customer in responding in accordance with the DPA.
9. Security measures
We implement appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure and access. These measures include access-right management, encryption in transit and/or at rest, regular backups and employee training.
10. Automated decision-making
The Normalic Assistant and the Platform’s analytics functions provide recommendations and analyses intended to support decisions made by the Customer’s production managers and employees. The Platform does not make automated decisions about individuals that produce legal or similarly significant effects, such as employment decisions. Responsibility for such decisions always remains with a person.
11. Changes to this Privacy Policy
We may update this Privacy Policy from time to time, including in response to changes in law or development of the Service. We will notify Customers of material changes within a reasonable period. The current version is always available on our website and/or Platform.
12. Contact
For questions or requests, contact NORMALIC OÜ at info@normalic.com or Spektri tn 6, Tartu 50411, Estonia.
13. Website cookies and contact form
13.1. After a visitor makes a selection, the Normalic public website stores the first-party cookie normalic_cookie_consent for 180 days to remember separate preferences for the contact form and B2B website analytics. This cookie does not itself track browsing behaviour.
13.2. The embedded Pipedrive contact form and its security mechanisms are not loaded until the visitor gives consent. With consent, Pipedrive, Cloudflare and Google reCAPTCHA may process technical data, such as the IP address and browser information, and information relating to viewing or using the form. The names, purposes and retention periods of the cookies used are listed in our Cookie Policy.
13.3. The name, email address, telephone number and message voluntarily submitted through the contact form are processed to respond to the enquiry and prepare for a potential business relationship. Depending on the circumstances, the legal basis is taking steps at the data subject’s request before entering into a contract or Normalic’s legitimate interest in responding to business enquiries. Consent to contact-form cookies is separate from the legal basis for processing personal data submitted through the form.
13.4. Visitors may withdraw consent to optional cookies at any time through the “Cookie settings” link in the website footer. Withdrawal prevents the relevant optional services from loading in the future. Cookies and local-storage entries already stored can be deleted through browser settings.
13.5. Where the visitor separately consents to analytics, the website uses Leadfeeder Web Visitors technology provided by Leadfeeder Finland Oy, part of Leadfeeder Group GmbH, to identify companies visiting the website and analyse B2B browsing behaviour. This may involve processing the visitor’s IP address, a random visitor identifier, traffic source and campaign information, pages viewed, and the date, time and duration of the visit. Normalic is the controller for this processing and Leadfeeder acts as processor.
13.6. The Leadfeeder tracking script is fully blocked until analytics consent is given. The legal basis for analytics is the visitor’s consent under Article 6(1)(a) GDPR. Withdrawing consent prevents the tracking script from loading in the future. Previously stored first-party Leadfeeder cookies and local-storage entries can be removed through browser settings.