Data Processing Agreement (DPA)
Last updated: September 26, 2026
This Agreement describes how Nora processes the personal data of a professional's clients when the professional uses the Service. It forms part of the Terms of Service and applies automatically from the moment you start using the Service.
1. Parties
- This Agreement is entered into between the professional who uses Nora to work with their clients (the "Controller") and the owner of the Nora Service, a natural person registered in Spain as self-employed (autónomo) (the "Processor").
- The Controller determines the purposes and means of processing their clients' personal data. The Processor processes that data on the Controller's behalf and only to provide the Service.
- This Agreement is entered into pursuant to Article 28 of Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 on data protection (LOPDGDD). Terms have the meaning given in the GDPR.
2. Subject matter and duration
- Subject matter: processing of the Controller's clients' personal data as needed to provide the Service — replies to clients, bookings, reminders, conversations and related features.
- This Agreement applies while the Controller uses the Service and afterwards until the data is deleted or returned under "End of processing".
3. Nature and purposes of processing
- Nature: collection, recording, storage, organisation, use, transmission over the channels the Controller has connected, and erasure of data, including automated processing of messages by the AI assistant.
- Purposes: communicating with clients on the Controller's behalf, including AI assistant replies; managing bookings and schedules; reminders and notifications; collecting prepayments through the Controller's Stripe account where connected; summaries and analytics for the Controller; operating and securing the Service.
4. Categories of data subjects and data
- Data subjects: the Controller's clients and people who message the Controller through connected channels; for salons, also salon staff.
- Categories of data: name; phone number; email; Telegram, WhatsApp and Instagram identifiers; message content (text and attachments); bookings, visit history and the Controller's notes; payment information (amount and status, without card details — those are processed by Stripe).
- The Service is not intended for special categories of data (Article 9 GDPR). If the Controller nevertheless enters such data, the Controller is responsible for having a legal basis for processing it.
5. Processor obligations
- Process personal data only on the Controller's documented instructions — the Terms of Service, the Service settings and the Controller's requests — including with regard to transfers to third countries, unless otherwise required by law. If the Processor considers that an instruction infringes data protection law, it will inform the Controller.
- Ensure that persons authorised to access the data are bound by confidentiality.
- Implement technical and organisational security measures under Article 32 GDPR appropriate to the risk, including encryption in transit (HTTPS/TLS), encrypted storage of channel access tokens, access control and error monitoring.
- Taking into account the nature of the processing, assist the Controller in responding to data subject requests: access, rectification, erasure, restriction, portability and objection.
- Assist the Controller with its obligations under Articles 32–36 GDPR (security of processing, breach notification, impact assessments, prior consultation), taking into account the nature of processing and the information available to the Processor.
- Notify the Controller of a personal data breach without undue delay after becoming aware of it and provide the information the Controller needs to notify the supervisory authority and data subjects.
- Make available to the Controller the information necessary to demonstrate compliance with Article 28 GDPR and allow for and contribute to audits and inspections by the Controller or an auditor it mandates, subject to reasonable prior notice and confidentiality.
6. Controller obligations
- Have a legal basis for processing your clients' data and inform them about the processing, including that an AI assistant may reply to them.
- Give lawful instructions and do not enter more data into the Service than is needed to work with your clients.
7. Sub-processors
- The Controller gives general authorisation for the use of sub-processors. The current list of sub-processors, with their purpose and location, is set out in the Privacy Policy.
- The Processor gives advance notice of any addition or replacement of a sub-processor by updating the list and notifying the Controller by email or in the Nora chat in Telegram. The Controller may object to the change; if the objection cannot be resolved, the Controller may stop using the Service.
- The Processor imposes on sub-processors contractual data protection obligations that are in substance no less protective than this Agreement and remains liable to the Controller for their performance.
8. International transfers
- Some sub-processors are located outside the European Economic Area (in particular in the United States) or access data from there. Such transfers rely on a European Commission adequacy decision (including the EU-U.S. Data Privacy Framework for companies certified under it) or on the European Commission's Standard Contractual Clauses (Article 46 GDPR).
9. End of processing
- When the Controller stops using the Service, the Processor will, at the Controller's choice, delete or return the personal data and delete existing copies unless retention is required by law.
- The Controller can delete the account in settings or request an export and deletion of data at privacy@hey-nora.online.
10. Other terms
- In case of conflict between this Agreement and the Terms of Service regarding personal data protection, this Agreement prevails.
- This Agreement is governed by Spanish law; disputes are resolved under the "Governing Law & Disputes" section of the Terms of Service.
- Data protection questions: privacy@hey-nora.online.