Legal
Data Processing Agreement
Last updated · July 22, 2026
Version 1.0 · July 2026. This is the public reference copy of the Data Processing Agreement ("DPA") for Norma. It describes how Norma processes Customer Data on a customer firm's behalf. When a firm and Norma execute a DPA as part of onboarding, the executed copy governs; this page is maintained so any firm can read the terms before asking for them.
1. Parties and roles
This DPA is between the customer firm (the "Customer," acting as the data controller) and Norma, a registered trade name of Tal ADI LLC (the "Processor"). The Customer determines the purposes and means of processing its data; Norma processes that data only on the Customer's behalf and only as described here and in the Terms of Service.
2. Scope and purpose of processing
Processing is limited to operating the Service for the Customer: ingesting the firm data the Customer uploads or connects (financial records, timesheets, contracts, receivables, project and staffing data, and, where the Customer connects a payroll feed, employee records including compensation and benefits enrollment), computing analyses and documents from it, generating narrations and classifications through the AI providers described in the AI use statement, and producing the outputs the Customer requests. Norma does not use Customer Data to train AI models, does not sell it, and does not process it for any purpose of its own beyond operating and securing the Service.
3. Subprocessors
The Customer authorizes the subprocessors listed at norma-adi.com/subprocessors, which is incorporated into this DPA by reference. That page distinguishes subprocessors engaged by Norma from services the Customer connects on its own credentials, which are not subprocessors under this DPA. Norma will update the list before adding or replacing a subprocessor and will give the Customer at least fourteen days' notice of material changes by email, during which the Customer may object on reasonable data-protection grounds. Norma remains responsible for its subprocessors' performance under this DPA.
4. Confidentiality
Norma treats Customer Data as confidential. Access is limited to personnel who need it to operate, support, or secure the Service, and who are bound by confidentiality obligations. Norma does not disclose Customer Data to third parties except to the subprocessors above, as required by law, or as the Customer directs.
5. Security measures
Norma maintains the technical and organizational measures described on the Security page, which include: workspace isolation enforced in code and covered by a dedicated automated test suite; passwords hashed with bcrypt; rate-limited authentication with application-layer lockout; sessions on expiring JSON Web Tokens; encryption in transit over HTTPS/TLS; encryption at rest provided by the hosting environment; and encrypted storage of any integration credentials the Customer connects. The Security page also states, out loud, the controls that do not exist yet; Norma does not claim certifications it does not hold.
6. Breach notification
If Norma becomes aware of a personal-data breach affecting Customer Data, it will notify the Customer without undue delay, and in any event within seventy-two hours of becoming aware, at the administrative email on the account. The notice will describe what is known at the time: the nature of the breach, the data affected, the measures taken, and a contact for follow-up, with updates as the facts develop.
7. Assistance
Taking into account the nature of the processing, Norma will provide reasonable assistance so the Customer can respond to data-subject requests (access, correction, deletion, export) and meet its own obligations regarding security, breach notification, and data-protection assessments. Where a data subject contacts Norma directly about data controlled by the Customer, Norma will refer the request to the Customer.
8. Deletion and return on termination
When the Customer's subscription ends, the Customer may export its data through the end of the invoiced period. The workspace is then decommissioned: Customer Data is removed from active systems within thirty days, and backups containing it are purged within ninety days of decommissioning, consistent with the schedule in the Privacy Policy. A minimal account record (email address, account history) may be retained as described there for legal and financial record-keeping.
9. International transfers
The Service is operated from the United States, and Customer Data is processed there, consistent with the Privacy Policy. Where the Customer is subject to data-protection law that requires a transfer mechanism for processing in the United States, the parties will document the appropriate mechanism in the executed DPA.
10. Term and precedence
This DPA applies for as long as Norma processes Customer Data and survives termination of the subscription until deletion under section 8 completes. It supplements the Terms of Service; for the subject matter of data processing, if this DPA conflicts with the Terms, this DPA controls.
11. Contact
Questions about this DPA, or a request for an executable copy: hello@norma-adi.com.