1. Who is responsible for your data
The data controller for noryas is Yilmaz - Einzelunternehmen, Inh. Yilmaz, Yasin, Dachsbau 4, 21635 Jork OT Königreich, Germany. Contact for privacy questions: support@noryas.com.
2. What data we collect
- Account data: email address, password (stored as a salted hash, never in plain text, by Supabase Auth), first name (optional).
- Content you create: procedures, steps, notes, checkbox states, and any images/files you upload, plus a log of every execution (when it ran, what was checked off, notes entered).
- Billing data: if you upgrade to Pro, your plan status and billing identifiers are stored by us; your payment details (card, etc.) are handled entirely by Paddle and never touch our servers.
- Technical data: standard web server logs (IP address, timestamps, request metadata) generated by our hosting provider for security and abuse prevention.
- Cancellation requests: if you use our public cancellation page (no login required), we collect the email address and name you enter to identify the subscription, and use them only to send a one-time verification link and to process the cancellation once confirmed.
3. Why we process your data, and on what legal basis
- To provide the Service (your account, your procedures, your execution history) — performance of a contract with you (Art. 6(1)(b) GDPR).
- To process payments for the Pro plan — performance of a contract / compliance with legal (tax/invoicing) obligations (Art. 6(1)(b)/(c) GDPR).
- To send you transactional emails (email confirmation, password reset) — performance of a contract (Art. 6(1)(b) GDPR). We do not send marketing emails, and we do not use your email for anything beyond operating your account.
- Security, fraud, and abuse prevention — legitimate interest (Art. 6(1)(f) GDPR).
- To process a cancellation request submitted via our no-login cancellation page — compliance with a legal obligation to provide an easily accessible cancellation mechanism (Art. 6(1)(c) GDPR, § 312k BGB) and performance of the underlying subscription contract (Art. 6(1)(b) GDPR). The verification link expires after 48 hours and can only be used once.
4. Who we share data with
We use a small number of infrastructure providers ("processors") to run noryas. We don't sell your data, and we don't share it with anyone for advertising or marketing purposes. Where a processor is located outside the EU/EEA, transfers are made on the basis of Standard Contractual Clauses or another valid GDPR transfer mechanism.
- Supabase (database, authentication, file storage) — hosted within the European Union.
- Vercel Inc. (application hosting) — our application servers run in Frankfurt, Germany; Vercel is a US company and may process data in the US under Standard Contractual Clauses.
- Resend (transactional email delivery) — email sending infrastructure located in Ireland (eu-west-1).
- Zoho Corporation (support email hosting for support@noryas.com) — hosted within the European Union.
- Paddle.com Market Limited (payment processing, merchant of record for Pro plan billing) — processes your payment details directly; see their own privacy policy for how they handle payment data.
5. How long we keep your data
We keep your account and content for as long as your account exists. Deleting your account from Settings permanently removes your workspace, procedures, executions, and uploaded files from our systems — this cannot be undone.
On the Free plan, the execution history view only shows the last 30 days — this is a product feature limit, not a deletion policy. Underlying execution records are kept the same way on both Free and Pro plans until you delete your account.
Billing and invoice records related to Pro plan purchases are retained for up to 10 years after the end of the calendar year in which they were created, as required under German tax and commercial law (§ 147 AO, § 257 HGB), even after you delete your account.
6. Your rights
Under GDPR, you have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Erase your data (you can do this yourself at any time via Settings → Delete Account, or by contacting us)
- Restrict or object to certain processing
- Receive your data in a portable format
- Lodge a complaint with a supervisory authority — in Germany, Die Landesbeauftragte für den Datenschutz Niedersachsen (lfd.niedersachsen.de), or the supervisory authority in your own EU member state.
To exercise any of these rights, contact support@noryas.com.
7. Security
Access to your data is protected by Row-Level Security policies scoped to your workspace — other users cannot see your procedures, executions, or files. Passwords are hashed, never stored in plain text. Uploaded images and files live in private storage buckets accessed only via short-lived signed URLs. All traffic is encrypted in transit (HTTPS/TLS).
8. Cookies
noryas uses only strictly necessary cookies: one to keep you signed in, and one to track whether you've completed onboarding. Neither is used for tracking, advertising, or analytics, and under GDPR/ePrivacy rules, strictly necessary cookies don't require consent. If we ever add analytics or marketing cookies, we'll update this policy and ask for consent first.
9. Children
noryas is a professional tool intended for business and technical use and is not directed at, or intended for use by, children under 16.
10. Changes to this policy
We may update this Privacy Policy from time to time. We'll update the date at the top of this page when we do.
11. Contact
Questions about this Privacy Policy: support@noryas.com