This Privacy Policy describes how NORJI Ltd ("NORJI", "we", "us", "our") collects, uses, and protects your personal data when you use our website at norji.co.uk and our NORJI cloud service on Telegram (collectively, the "Service").
Data Controller
NORJI Ltd
Registered in England and Wales, company number 17180824
Registered office: York, England
Email: privacy@norji.co.uk
If you have any questions about how we handle your personal data, please contact us at samuel@norji.co.uk.
This policy applies to individuals aged 18 and over. Our Service is not intended for use by anyone under the age of 18, and we do not knowingly collect personal data from children.
We process your personal data under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. The lawful bases we rely on are:
When you create a NORJI account, we collect:
When you use our website or Service, we may automatically collect:
When you use NORJI via Telegram, the text of commands you send is transmitted to our servers for processing. We retain command logs for a limited period for debugging and security purposes (see Section 7, Retention).
We do not store your payment card details. All payment processing is handled by Stripe (see Section 6, Third-Party Processors). We receive and store confirmation of payment status and subscription period from Stripe.
Important: Data processed by NORJI, including invoices, proposals, organised downloads, and other documents, are created and stored in your isolated account. Your data is isolated from other users and never shared with third parties other than our AI processing provider's servers.
If you connect Gmail, Outlook, a calendar or a CRM, NORJI reads that content in order to draft replies, flag compliance items, and propose calendar and record updates. Nothing is sent or written back without your explicit approval. We store short summaries of past conversations, and their vector embeddings, so the assistant can reference them later. Every action taken on your behalf is written to an append-only audit log.
We do not claim end-to-end encryption, zero-knowledge architecture, or that NORJI "cannot see" your content. Those claims would be false for a service that drafts replies in your voice. Content is encrypted in transit and at rest and is decrypted only when the service needs it to function. It is never used to train AI models and never sold. OAuth tokens are encrypted at rest and deleted immediately when you disconnect an integration or close your account.
One consent screen covers the whole product surface, so you are asked once rather than repeatedly. That means the permissions you grant on day one are broader than what NORJI exercises on day one. This is the full list. Nothing is requested that is not in this table.
| Permission requested | What it permits | When we use it |
|---|---|---|
Google gmail.readonlyMicrosoft Mail.Read | Read the messages in your mailbox | From connection onwards, to classify threads and draft replies |
Google gmail.sendMicrosoft Mail.Send | Send mail as you | Only to send a draft you have explicitly approved. Not used at all during the day 1 to 14 observation window |
Google gmail.modifyMicrosoft Mail.ReadWrite | Alter mail: apply labels, mark read, move threads. This is more than reading | To label and mark triaged threads so your inbox reflects what has been handled |
Google calendar, calendar.eventsMicrosoft Calendars.Read, Calendars.ReadWrite | Read your calendar and create or amend events | To find viewing slots, and to create an appointment you have approved |
Google drive.file | Read and write only the files you explicitly open through the Google picker, plus files NORJI itself created. It cannot see the rest of your Drive | When you attach or file a document against a thread |
Microsoft Files.Read, Files.ReadWrite | Read and write files in your OneDrive. This is broader than the Google equivalent: Microsoft does not offer a picker-scoped equivalent of drive.file | To fetch documents attached to a thread and to file documents NORJI produces |
Google / Microsoft openid, email, profile, User.Read, offline_access | Your name and email address, and a refresh token so the connection survives without you signing in daily | Continuously |
The restraint on the send and modify permissions is application logic on our side, not a limit imposed by the grant itself. We think that is worth stating plainly rather than leaving you to infer it. If you would rather grant read-only access and authorise sending separately later, email privacy@norji.co.uk and we will arrange it.
We do not request access to your Google or Microsoft contacts. Where NORJI knows who you correspond with most, it has worked that out from your own sent mail, not from your address book.
Files and documents. Where you use the Drive or OneDrive permissions above, NORJI reads the file contents in order to draft or summarise, and the relevant extract is sent to our AI processing provider on the same basis as mail content. Files are retained under the same schedule as other connected-account content in Section 7.
NORJI operates a business-to-business outreach programme. If your data is in our prospect database, this is the basis:
| Purpose | Data Used | Lawful Basis |
|---|---|---|
| Providing and managing your account | Account data | Contract |
| Processing subscription payments | Account data, payment status | Contract |
| Processing your Telegram commands | Command data | Contract |
| Security, fraud prevention, debugging | Technical data, command logs | Legitimate interests |
| Responding to support enquiries | Account data, communications | Contract / Legitimate interests |
| Compliance with legal obligations (e.g. tax records) | Account data, payment data | Legal obligation |
| Service improvement and analytics | Aggregated technical data | Legitimate interests |
| Sending transactional emails (receipts, alerts) | Email address | Contract |
| Sending marketing communications (if opted in) | Email address | Consent |
We use essential cookies only. We do not use advertising, tracking, or analytics cookies.
Essential cookies we set include:
localStorage, not as a cookie).We do not use Google Analytics, Facebook Pixel, or any third-party tracking scripts on our website. We do not sell your data to advertisers or data brokers.
We share personal data with third-party service providers acting as processors on our behalf. Each is contractually required to process your data only as instructed and to maintain appropriate security measures.
There is one canonical list and it lives in the DPA sub-processor annex. It names every processor in the data path, what it does, where it sits, and the transfer safeguard that applies. We publish it in one place, and link to it from here and from the trust page, so the lists cannot drift apart. At the date of this policy it includes Anthropic, Deepgram, OpenAI, Railway, Stripe, Telegram, WATI, Meta Platforms Ireland, Microsoft, Google, Sentry, Resend and Vercel.
Two points worth calling out because they are easy to miss:
Apollo.io and Smartlead process prospect data for our own outbound marketing, where NORJI is the controller rather than a processor. See section 3.7. They are listed in the DPA annex too, so that no service we transmit data to is undisclosed.
Where you connect a CRM (for example Reapit or Salesforce), that provider also acts as a processor for the records NORJI reads and writes at your direction, under that provider's own terms. Neither connector is currently connectable.
We will not sell, rent, or trade your personal data to any third party.
We retain your personal data only for as long as necessary for the purposes set out in this policy, or as required by law.
| Data Type | Retention Period |
|---|---|
| Account data (email, password hash, subscription status) | Duration of your account + 6 years (legal obligation) |
| Payment records | 7 years (UK tax / financial reporting obligations) |
| Command logs (for debugging/security) | 30 days, then automatically deleted |
| Server access logs (IP, timestamps) | 90 days, then automatically deleted |
| Support communications | 3 years from last contact |
| User-uploaded content | Under your control, deleted on request |
When you close your account, we will delete or anonymise your personal data within 30 days, except where retention is required by legal obligation.
Some of our third-party processors operate outside the UK, including in the United States. Where personal data is transferred outside the UK, we ensure appropriate safeguards are in place, including:
Details of the safeguards for each processor are listed in Section 6.
Under the UK GDPR and Data Protection Act 2018, you have the following rights in relation to your personal data:
To exercise any of these rights, contact us at samuel@norji.co.uk. We will respond within one calendar month. We may need to verify your identity before fulfilling a request.
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, disclosure, alteration, or destruction. These include:
No method of transmission or storage is 100% secure. If you believe your account has been compromised, contact us immediately at samuel@norji.co.uk.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the ICO as required by law.
NORJI is intended for use by individuals aged 18 and over only. We do not knowingly collect personal data from anyone under 18. If you believe we have inadvertently collected data from a minor, please contact us and we will delete it promptly.
Our website may contain links to third-party websites. We are not responsible for the privacy practices of those sites and encourage you to review their privacy policies.
We may update this Privacy Policy from time to time. We will notify you of material changes by email or by prominent notice on our website, giving at least 14 days' notice before changes take effect. The current version will always be available at norji.co.uk/privacy.
If you have a concern about how we handle your personal data that we have not resolved to your satisfaction, you have the right to lodge a complaint with the UK's supervisory authority:
Information Commissioner's Office (ICO)
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Tel: 0303 123 1113
Website: ico.org.uk
We encourage you to contact us first at samuel@norji.co.uk and we will do our best to resolve any concern.
© 2026 NORJI Ltd · Companies House 17180824 · York, England. | Terms of Service | Home