Legal

Privacy Policy

Last updated: May 1, 2025

Norixion, Inc. (“Norixion,” “we,” “our,” or “us”) is committed to protecting your privacy. This policy explains how we collect, use, share, and safeguard information when you use our platform and services. Please read it carefully.

1. Information We Collect

We collect information you provide directly to us, such as when you create an account, subscribe to our services, or contact us for support. This may include:

Account information: Name, email address, company name, job title, and password when you register for an account.

Usage data: Information about how you interact with our platform, including pages visited, features used, queries run, and time spent. We collect this via server logs and telemetry embedded in the Norixion agent.

Infrastructure metadata: When you connect your infrastructure to Norixion, we receive metadata about your services - such as service names, health metrics, trace spans, and logs - as described in our service agreement. We do not inspect the content of your application data.

Payment information: If you subscribe to a paid plan, payment details are processed by our third-party payment processor (Stripe). Norixion does not store raw card numbers.

Communications: If you contact us by email or support ticket, we retain those communications.

2. How We Use Your Information

We use the information we collect to:

- Provide, maintain, and improve our services
- Process transactions and send related information
- Send technical notices, updates, and security alerts
- Respond to comments, questions, and support requests
- Monitor and analyse usage patterns to improve the product
- Detect, prevent, and investigate fraud or abuse
- Comply with legal obligations

We do not sell your personal data to third parties. We do not use your infrastructure metadata to train models without your explicit consent.

3. Data Sharing and Disclosure

We may share your information in the following circumstances:

Service providers: We engage trusted third-party vendors (hosting, analytics, payment processing, customer support tooling) who process data on our behalf under data processing agreements consistent with this policy.

Business transfers: If Norixion is acquired or merges with another company, your information may be transferred as part of that transaction.

Legal requirements: We may disclose information if required by law, subpoena, or other legal process, or if we believe disclosure is necessary to protect our rights, property, or the safety of our users.

With your consent: We may share information for any other purpose with your explicit consent.

4. Data Retention

We retain your personal information for as long as your account is active or as needed to provide services. Infrastructure telemetry data (traces, metrics, logs) is retained according to the plan you subscribe to - ranging from 14 days on the free tier to 13 months on enterprise plans.

You may request deletion of your account and associated data at any time by contacting privacy@norixion.io. We will action deletion requests within 30 days, subject to any legal retention obligations.

5. Security

We take the security of your data seriously. We implement industry-standard technical and organisational measures including:

- TLS 1.3 encryption for all data in transit
- AES-256 encryption for data at rest
- Role-based access controls and audit logging for internal access
- Regular third-party penetration testing
- SOC 2 Type II compliance (in progress)

Despite these measures, no system is completely secure. We encourage you to use a strong, unique password and enable two-factor authentication on your account.

6. Your Rights

Depending on your jurisdiction, you may have the following rights with respect to your personal data:

- Access: Request a copy of the personal data we hold about you
- Correction: Request correction of inaccurate or incomplete data
- Deletion: Request erasure of your personal data
- Portability: Receive your data in a structured, machine-readable format
- Objection: Object to processing based on legitimate interests
- Restriction: Request we restrict processing of your data

To exercise these rights, contact privacy@norixion.io. We will respond within 30 days. If you are in the EU/EEA, you also have the right to lodge a complaint with your local data protection authority.

7. International Transfers

Norixion is headquartered in the United States. If you are accessing our services from outside the US, your data may be transferred to and processed in the US. Where required by applicable law (e.g., GDPR), we rely on Standard Contractual Clauses or other approved mechanisms to safeguard such transfers.

8. Cookies and Tracking

We use cookies and similar technologies to authenticate sessions, remember preferences, and analyse usage. We use:

- Essential cookies: Required for the platform to function (session tokens, CSRF protection)
- Analytics cookies: Aggregate, anonymised analytics to understand how users interact with our product
- Preference cookies: To remember your settings

You can control cookies through your browser settings. Disabling essential cookies will prevent you from using the platform. We do not use advertising or third-party tracking cookies.

9. Children's Privacy

Norixion's services are not directed to individuals under the age of 16. We do not knowingly collect personal information from children. If you believe we have inadvertently collected data from a minor, please contact us immediately and we will delete it.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or through a notice in the platform at least 30 days before the change takes effect. Your continued use of our services after the effective date constitutes acceptance of the updated policy.

11. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:

Norixion, Inc.
Privacy Team
privacy@norixion.io

We aim to respond to all inquiries within 5 business days.

Have questions about this policy? Reach out to privacy@norixion.io - we're happy to help.