Privacy Policy
Effective Date: 1 August 2026
This Privacy Policy explains how Normal Software, Inc. ("Normal", "we", "us") collects, uses, shares, and protects information in connection with the Normal Portal and the Normal Framework software (together, the "Services").
It applies to everyone who uses the Services, including free trial users. If you are an enterprise customer with a negotiated agreement, that agreement and any Data Processing Agreement between us also apply and control in the event of a conflict.
1. Two kinds of data
Our Services handle two distinct categories of information, and we treat them differently.
Personal Data is information relating to an identified or identifiable person — for example the email address you use to sign in.
Building Data is operational technology data from your building automation systems: sensor readings, equipment metadata, BACnet point values, device configuration, and alarm and event logs. Building Data is generally not personal, but it can become personal where it indirectly identifies someone — occupancy sensor readings in a small space, for instance. Where that is the case we treat it as Personal Data.
For Personal Data that we process on your behalf as part of delivering the Services, you are the controller and we are the processor. For account and billing data that we process to run our own business, we are the controller.
2. What we collect
Personal Data
| Data | Why we collect it | How long we keep it |
|---|---|---|
| Email address | Authentication, notifications, billing | Duration of account + 30 days |
| Name | Display in the portal interface | Duration of account + 30 days |
| Organisation name | Tenant identification and access control | Duration of account + 30 days |
| IP address | Security logging, access control, abuse prevention | 365 days |
| Browser user agent | Security logging, acceptance records | 365 days |
| Billing information | Subscription management | Processed by Stripe under Stripe's retention policy. We store only a Stripe customer identifier — we never see or store your full card details |
| Legal acceptance records | Proving which terms you agreed to and when | Duration of account + 7 years |
Building Data
| Data | Why we collect it | How long we keep it |
|---|---|---|
| BACnet point values (temperatures, setpoints, statuses) | Storage, visualisation, analytics | Per your configured retention policy |
| Equipment metadata (names, locations, types) | Asset management and modelling | Duration of service |
| Device configuration | Backup, restore, device management | Duration of service |
| Alarm and event logs | Monitoring and notification | Per your configured retention policy |
Data we do not collect
We do not collect special categories of personal data (health, biometric, racial or ethnic origin, political opinions, religious beliefs, trade union membership, sexual orientation). Please do not enter such information into the Services.
3. How we use data
We use Personal Data to authenticate you, provide and support the Services, send service-related notifications, meet legal and contractual obligations, secure the Services and investigate abuse, and administer billing.
We process Building Data only to provide the Services to you — storing it, displaying it, running the analytics and automations you configure, backing it up, and restoring it.
We do not sell your data. We do not share it with advertisers, and we do not use your Building Data to train machine learning models for other customers or for our own product development without your separate, explicit consent.
4. Who we share data with
We share data with subprocessors who help us deliver the Services. Each is bound by data protection obligations no less protective than those we owe you. Our current subprocessors and the purpose each serves are listed in our Subprocessor List, available on request. At the effective date of this policy they include our cloud infrastructure provider, our authentication provider, our payment processor, and our network security and content delivery provider.
We will give at least 30 days' notice before adding a new subprocessor. If you object and we cannot resolve the objection, you may terminate the affected Services.
We may also disclose data where required by law, court order, or other legal process; to establish or defend legal claims; or to protect the rights, safety, or property of Normal, our customers, or the public. Where we are legally permitted to notify you of such a request, we will.
If Normal is involved in a merger, acquisition, or sale of assets, data may transfer as part of that transaction. We will give notice before your data becomes subject to a different privacy policy.
5. Where we process data
We process data in the United States, in the Azure East US 2 region. Our subprocessors are located in the United States.
If you are in the European Economic Area, the United Kingdom, or Switzerland, transfers of Personal Data to us rely on the European Commission's Standard Contractual Clauses (Module 2: Controller to Processor), which are incorporated into our Data Processing Agreement.
6. How we protect data
We maintain technical and organisational measures appropriate to the risk, including:
| Category | Measures |
|---|---|
| Access control | Role-based access with OAuth/JWT; scoped API keys; administrative access over VPN only; multi-factor authentication available |
| Encryption in transit | TLS 1.2 or higher for all external traffic; SSL required for database connections |
| Encryption at rest | Server-side encryption for databases and storage; managed key vault for secrets |
| Network security | Web application firewall and DDoS protection; network security groups; host firewall; no public-facing administrative ports |
| Infrastructure | Infrastructure-as-code; automated security patching; intrusion prevention; hardened SSH; host audit logging |
| Backup | Daily automated backups to geo-redundant storage; 14-day point-in-time restore |
| Incident response | Documented incident response plan with severity classification, containment, and notification procedures |
No system is perfectly secure, and we cannot guarantee absolute security. If a breach affects your Personal Data, we will notify you without undue delay and in any event within 72 hours of becoming aware, describing what happened, who is affected, the likely consequences, and what we are doing about it.
7. Your rights
Depending on where you live, you may have the right to access the personal data we hold about you; correct inaccurate data; delete your data; export it in a portable format; restrict or object to processing; and withdraw consent where processing is based on consent.
To exercise any of these, email privacy@normal.dev. We will respond within 30 days. We will not discriminate against you for exercising these rights.
If you are an end user whose data we process on behalf of an enterprise customer, please direct your request to that customer; we will assist them in responding.
If you are in the EEA or UK and believe we have not handled your data properly, you may lodge a complaint with your local supervisory authority.
8. Deletion and export
You can export your Building Data from the portal at any time while your account is active.
When your account or trial ends, you may choose to have your Personal Data and Building Data returned in a standard format (JSON or CSV) or deleted. Absent a choice, we delete it within 30 days of account closure. Backup copies are purged within 90 days. We may retain data where required by law, and will tell you if we do.
9. Trials
Free trial accounts are covered by this policy in full. Two things specific to trials:
- Trial Building Data is deleted within 30 days of the trial ending unless you convert to a paid plan or ask us to return it first. Export your data before the trial expires if you want to keep it.
- We use aggregate, non-identifying statistics about trial usage (for example, how many trials reach the point of connecting a device) to improve our product. This never includes your Building Data or anything identifying you or your buildings.
10. Children
The Services are intended for business use and are not directed to children. We do not knowingly collect personal data from anyone under 18. If we learn that we have, we will delete it.
11. Cookies and similar technologies
We use cookies that are strictly necessary to operate the portal — keeping you signed in, maintaining your session, and protecting against cross-site request forgery. We do not use advertising cookies or third-party tracking cookies.
12. Changes to this policy
We may update this policy. Material changes will be notified through the portal or by email at least 30 days before they take effect. Every version remains available at its own permanent link, and the version history is shown at the bottom of this page, so you can always see what changed and when.
13. Contact
Questions about this policy, or about how we handle your data:
Normal Software, Inc. PO Box 261 Leetsdale, PA 15056 privacy@normal.dev