Privacy Policy

NORJI Ltd  ·  Last updated: April 2026  ·  Effective date: April 2026

1. Who We Are

This Privacy Policy describes how NORJI Ltd ("NORJI", "we", "us", "our") collects, uses, and protects your personal data when you use our website at norji.co.uk and our NORJI cloud service on Telegram (collectively, the "Service").

Data Controller

NORJI Ltd
Registered in England and Wales, company number 17180824
Registered office: York, England
Email: privacy@norji.co.uk

If you have any questions about how we handle your personal data, please contact us at samuel@norji.co.uk.

This policy applies to individuals aged 18 and over. Our Service is not intended for use by anyone under the age of 18, and we do not knowingly collect personal data from children.

2. Legal Basis for Processing

We process your personal data under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. The lawful bases we rely on are:

3. Personal Data We Collect

3.1 Account Data

When you create a NORJI account, we collect:

3.2 Technical Data

When you use our website or Service, we may automatically collect:

3.3 Command and Usage Data

When you use NORJI via Telegram, the text of commands you send is transmitted to our servers for processing. We retain command logs for a limited period for debugging and security purposes (see Section 7, Retention).

3.4 Payment Data

We do not store your payment card details. All payment processing is handled by Stripe (see Section 6, Third-Party Processors). We receive and store confirmation of payment status and subscription period from Stripe.

3.5 Files and Documents (Device-Local)

Important: Data processed by NORJI, including invoices, proposals, organised downloads, and other documents, are created and stored in your isolated account. Your data is isolated from other users and never shared with third parties other than our AI processing provider's servers.

3.6 Connected Inbox, Calendar and CRM Content

If you connect Gmail, Outlook, a calendar or a CRM, NORJI reads that content in order to draft replies, flag compliance items, and propose calendar and record updates. Nothing is sent or written back without your explicit approval. We store short summaries of past conversations, and their vector embeddings, so the assistant can reference them later. Every action taken on your behalf is written to an append-only audit log.

We do not claim end-to-end encryption, zero-knowledge architecture, or that NORJI "cannot see" your content. Those claims would be false for a service that drafts replies in your voice. Content is encrypted in transit and at rest and is decrypted only when the service needs it to function. It is never used to train AI models and never sold. OAuth tokens are encrypted at rest and deleted immediately when you disconnect an integration or close your account.

3.6.1 Exactly what you grant when you connect a mailbox

One consent screen covers the whole product surface, so you are asked once rather than repeatedly. That means the permissions you grant on day one are broader than what NORJI exercises on day one. This is the full list. Nothing is requested that is not in this table.

Permission requestedWhat it permitsWhen we use it
Google gmail.readonly
Microsoft Mail.Read
Read the messages in your mailboxFrom connection onwards, to classify threads and draft replies
Google gmail.send
Microsoft Mail.Send
Send mail as youOnly to send a draft you have explicitly approved. Not used at all during the day 1 to 14 observation window
Google gmail.modify
Microsoft Mail.ReadWrite
Alter mail: apply labels, mark read, move threads. This is more than readingTo label and mark triaged threads so your inbox reflects what has been handled
Google calendar, calendar.events
Microsoft Calendars.Read, Calendars.ReadWrite
Read your calendar and create or amend eventsTo find viewing slots, and to create an appointment you have approved
Google drive.fileRead and write only the files you explicitly open through the Google picker, plus files NORJI itself created. It cannot see the rest of your DriveWhen you attach or file a document against a thread
Microsoft Files.Read, Files.ReadWriteRead and write files in your OneDrive. This is broader than the Google equivalent: Microsoft does not offer a picker-scoped equivalent of drive.fileTo fetch documents attached to a thread and to file documents NORJI produces
Google / Microsoft openid, email, profile, User.Read, offline_accessYour name and email address, and a refresh token so the connection survives without you signing in dailyContinuously

The restraint on the send and modify permissions is application logic on our side, not a limit imposed by the grant itself. We think that is worth stating plainly rather than leaving you to infer it. If you would rather grant read-only access and authorise sending separately later, email privacy@norji.co.uk and we will arrange it.

We do not request access to your Google or Microsoft contacts. Where NORJI knows who you correspond with most, it has worked that out from your own sent mail, not from your address book.

Files and documents. Where you use the Drive or OneDrive permissions above, NORJI reads the file contents in order to draft or summarise, and the relevant extract is sent to our AI processing provider on the same basis as mail content. Files are retained under the same schedule as other connected-account content in Section 7.

3.7 Prospect Data (people we contact who are not customers yet)

NORJI operates a business-to-business outreach programme. If your data is in our prospect database, this is the basis:

4. How We Use Your Data

PurposeData UsedLawful Basis
Providing and managing your accountAccount dataContract
Processing subscription paymentsAccount data, payment statusContract
Processing your Telegram commandsCommand dataContract
Security, fraud prevention, debuggingTechnical data, command logsLegitimate interests
Responding to support enquiriesAccount data, communicationsContract / Legitimate interests
Compliance with legal obligations (e.g. tax records)Account data, payment dataLegal obligation
Service improvement and analyticsAggregated technical dataLegitimate interests
Sending transactional emails (receipts, alerts)Email addressContract
Sending marketing communications (if opted in)Email addressConsent

5. Cookies and Tracking

We use essential cookies only. We do not use advertising, tracking, or analytics cookies.

Essential cookies we set include:

We do not use Google Analytics, Facebook Pixel, or any third-party tracking scripts on our website. We do not sell your data to advertisers or data brokers.

6. Third-Party Processors

We share personal data with third-party service providers acting as processors on our behalf. Each is contractually required to process your data only as instructed and to maintain appropriate security measures.

There is one canonical list and it lives in the DPA sub-processor annex. It names every processor in the data path, what it does, where it sits, and the transfer safeguard that applies. We publish it in one place, and link to it from here and from the trust page, so the lists cannot drift apart. At the date of this policy it includes Anthropic, Deepgram, OpenAI, Railway, Stripe, Telegram, WATI, Meta Platforms Ireland, Microsoft, Google, Sentry, Resend and Vercel.

Two points worth calling out because they are easy to miss:

Apollo.io and Smartlead process prospect data for our own outbound marketing, where NORJI is the controller rather than a processor. See section 3.7. They are listed in the DPA annex too, so that no service we transmit data to is undisclosed.

Where you connect a CRM (for example Reapit or Salesforce), that provider also acts as a processor for the records NORJI reads and writes at your direction, under that provider's own terms. Neither connector is currently connectable.

We will not sell, rent, or trade your personal data to any third party.

7. Data Retention

We retain your personal data only for as long as necessary for the purposes set out in this policy, or as required by law.

Data TypeRetention Period
Account data (email, password hash, subscription status)Duration of your account + 6 years (legal obligation)
Payment records7 years (UK tax / financial reporting obligations)
Command logs (for debugging/security)30 days, then automatically deleted
Server access logs (IP, timestamps)90 days, then automatically deleted
Support communications3 years from last contact
User-uploaded contentUnder your control, deleted on request

When you close your account, we will delete or anonymise your personal data within 30 days, except where retention is required by legal obligation.

8. International Transfers

Some of our third-party processors operate outside the UK, including in the United States. Where personal data is transferred outside the UK, we ensure appropriate safeguards are in place, including:

Details of the safeguards for each processor are listed in Section 6.

9. Your Rights Under UK GDPR

Under the UK GDPR and Data Protection Act 2018, you have the following rights in relation to your personal data:

To exercise any of these rights, contact us at samuel@norji.co.uk. We will respond within one calendar month. We may need to verify your identity before fulfilling a request.

10. Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, disclosure, alteration, or destruction. These include:

No method of transmission or storage is 100% secure. If you believe your account has been compromised, contact us immediately at samuel@norji.co.uk.

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the ICO as required by law.

11. Age Restriction

NORJI is intended for use by individuals aged 18 and over only. We do not knowingly collect personal data from anyone under 18. If you believe we have inadvertently collected data from a minor, please contact us and we will delete it promptly.

12. Links to Other Websites

Our website may contain links to third-party websites. We are not responsible for the privacy practices of those sites and encourage you to review their privacy policies.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or by prominent notice on our website, giving at least 14 days' notice before changes take effect. The current version will always be available at norji.co.uk/privacy.

14. Complaints

If you have a concern about how we handle your personal data that we have not resolved to your satisfaction, you have the right to lodge a complaint with the UK's supervisory authority:

Information Commissioner's Office (ICO)
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Tel: 0303 123 1113
Website: ico.org.uk

We encourage you to contact us first at samuel@norji.co.uk and we will do our best to resolve any concern.

© 2026 NORJI Ltd · Companies House 17180824 · York, England.  |  Terms of Service  |  Home