Version
1.0
Effective
2026-08-01
SHA-256
3309d9c7bf434b0b

Privacy Policy

Effective Date: 1 August 2026

This Privacy Policy explains how Normal Software, Inc. ("Normal", "we", "us") collects, uses, shares, and protects information in connection with the Normal Portal and the Normal Framework software (together, the "Services").

It applies to everyone who uses the Services, including free trial users. If you are an enterprise customer with a negotiated agreement, that agreement and any Data Processing Agreement between us also apply and control in the event of a conflict.

1. Two kinds of data

Our Services handle two distinct categories of information, and we treat them differently.

Personal Data is information relating to an identified or identifiable person — for example the email address you use to sign in.

Building Data is operational technology data from your building automation systems: sensor readings, equipment metadata, BACnet point values, device configuration, and alarm and event logs. Building Data is generally not personal, but it can become personal where it indirectly identifies someone — occupancy sensor readings in a small space, for instance. Where that is the case we treat it as Personal Data.

For Personal Data that we process on your behalf as part of delivering the Services, you are the controller and we are the processor. For account and billing data that we process to run our own business, we are the controller.

2. What we collect

Personal Data

DataWhy we collect itHow long we keep it
Email addressAuthentication, notifications, billingDuration of account + 30 days
NameDisplay in the portal interfaceDuration of account + 30 days
Organisation nameTenant identification and access controlDuration of account + 30 days
IP addressSecurity logging, access control, abuse prevention365 days
Browser user agentSecurity logging, acceptance records365 days
Billing informationSubscription managementProcessed by Stripe under Stripe's retention policy. We store only a Stripe customer identifier — we never see or store your full card details
Legal acceptance recordsProving which terms you agreed to and whenDuration of account + 7 years

Building Data

DataWhy we collect itHow long we keep it
BACnet point values (temperatures, setpoints, statuses)Storage, visualisation, analyticsPer your configured retention policy
Equipment metadata (names, locations, types)Asset management and modellingDuration of service
Device configurationBackup, restore, device managementDuration of service
Alarm and event logsMonitoring and notificationPer your configured retention policy

Data we do not collect

We do not collect special categories of personal data (health, biometric, racial or ethnic origin, political opinions, religious beliefs, trade union membership, sexual orientation). Please do not enter such information into the Services.

3. How we use data

We use Personal Data to authenticate you, provide and support the Services, send service-related notifications, meet legal and contractual obligations, secure the Services and investigate abuse, and administer billing.

We process Building Data only to provide the Services to you — storing it, displaying it, running the analytics and automations you configure, backing it up, and restoring it.

We do not sell your data. We do not share it with advertisers, and we do not use your Building Data to train machine learning models for other customers or for our own product development without your separate, explicit consent.

4. Who we share data with

We share data with subprocessors who help us deliver the Services. Each is bound by data protection obligations no less protective than those we owe you. Our current subprocessors and the purpose each serves are listed in our Subprocessor List, available on request. At the effective date of this policy they include our cloud infrastructure provider, our authentication provider, our payment processor, and our network security and content delivery provider.

We will give at least 30 days' notice before adding a new subprocessor. If you object and we cannot resolve the objection, you may terminate the affected Services.

We may also disclose data where required by law, court order, or other legal process; to establish or defend legal claims; or to protect the rights, safety, or property of Normal, our customers, or the public. Where we are legally permitted to notify you of such a request, we will.

If Normal is involved in a merger, acquisition, or sale of assets, data may transfer as part of that transaction. We will give notice before your data becomes subject to a different privacy policy.

5. Where we process data

We process data in the United States, in the Azure East US 2 region. Our subprocessors are located in the United States.

If you are in the European Economic Area, the United Kingdom, or Switzerland, transfers of Personal Data to us rely on the European Commission's Standard Contractual Clauses (Module 2: Controller to Processor), which are incorporated into our Data Processing Agreement.

6. How we protect data

We maintain technical and organisational measures appropriate to the risk, including:

CategoryMeasures
Access controlRole-based access with OAuth/JWT; scoped API keys; administrative access over VPN only; multi-factor authentication available
Encryption in transitTLS 1.2 or higher for all external traffic; SSL required for database connections
Encryption at restServer-side encryption for databases and storage; managed key vault for secrets
Network securityWeb application firewall and DDoS protection; network security groups; host firewall; no public-facing administrative ports
InfrastructureInfrastructure-as-code; automated security patching; intrusion prevention; hardened SSH; host audit logging
BackupDaily automated backups to geo-redundant storage; 14-day point-in-time restore
Incident responseDocumented incident response plan with severity classification, containment, and notification procedures

No system is perfectly secure, and we cannot guarantee absolute security. If a breach affects your Personal Data, we will notify you without undue delay and in any event within 72 hours of becoming aware, describing what happened, who is affected, the likely consequences, and what we are doing about it.

7. Your rights

Depending on where you live, you may have the right to access the personal data we hold about you; correct inaccurate data; delete your data; export it in a portable format; restrict or object to processing; and withdraw consent where processing is based on consent.

To exercise any of these, email privacy@normal.dev. We will respond within 30 days. We will not discriminate against you for exercising these rights.

If you are an end user whose data we process on behalf of an enterprise customer, please direct your request to that customer; we will assist them in responding.

If you are in the EEA or UK and believe we have not handled your data properly, you may lodge a complaint with your local supervisory authority.

8. Deletion and export

You can export your Building Data from the portal at any time while your account is active.

When your account or trial ends, you may choose to have your Personal Data and Building Data returned in a standard format (JSON or CSV) or deleted. Absent a choice, we delete it within 30 days of account closure. Backup copies are purged within 90 days. We may retain data where required by law, and will tell you if we do.

9. Trials

Free trial accounts are covered by this policy in full. Two things specific to trials:

10. Children

The Services are intended for business use and are not directed to children. We do not knowingly collect personal data from anyone under 18. If we learn that we have, we will delete it.

11. Cookies and similar technologies

We use cookies that are strictly necessary to operate the portal — keeping you signed in, maintaining your session, and protecting against cross-site request forgery. We do not use advertising cookies or third-party tracking cookies.

12. Changes to this policy

We may update this policy. Material changes will be notified through the portal or by email at least 30 days before they take effect. Every version remains available at its own permanent link, and the version history is shown at the bottom of this page, so you can always see what changed and when.

13. Contact

Questions about this policy, or about how we handle your data:

Normal Software, Inc. PO Box 261 Leetsdale, PA 15056 privacy@normal.dev