Privacy statement

What we collect, why, and how long we keep it — in plain language.

Version 0.1 · 14 July 2026 · Items in [square brackets] are being finalised.

1. Who is responsible

This website and the Normly service are operated by [Matso legal entity name and form], KvK [KvK number], [address], the Netherlands. For anything privacy-related, use the contact page or write to [contact email].

2. Visiting the website

  • Analytics. We use GoatCounter, a cookieless analytics service, on our public pages. It counts page views in aggregate and does not build personal profiles. No advertising or tracking cookies are used.
  • Cookies. The site itself sets only essential cookies (session and CSRF protection). Your preferences (dark mode, cookie choice) are stored locally in your own browser and never sent to us.
  • Contact form. If you contact us, we store your email address and message so we can reply, and we receive them by email. Messages are kept for at most [12 months] after being handled, then deleted.

3. Trying the demo

The demo requires no account and stores no personal data about you. We record only the referring page (not your IP address) to count demo starts. The entire demo environment is automatically deleted after 48 hours.

4. Using Normly with an account

For account holders we process: name, business email address, hashed password (we cannot read it), company and role. We use this to operate the service — signing you in, applying your permissions, recording who entered and who approved data, which is the point of the product. Legal basis: performance of the agreement. Accounts are kept while active and deleted within 30 days of a deletion request.

5. Data your company stores in Normly

The tables your company maintains in Normly may contain personal data — that is your company's choice and responsibility. For that data your company is the controller and we are the processor: we process it only on your company's instructions, as laid down in the data processing agreement.

6. Where your data is stored

All application data is hosted on Microsoft Azure in the West Europe region, whose data centers are located in the Netherlands. We do not transfer your data outside the European Economic Area. Details are on the security page.

7. Who we share data with

We do not sell personal data and do not share it for advertising. We use a small number of service providers to run Normly — currently Microsoft (hosting and database, EU region) [and email provider, if configured]. We disclose data to authorities only where the law requires it.

8. How long we keep things

  • Demo environments: deleted automatically after 48 hours.
  • Contact-form messages: at most [12 months] after handling.
  • Account data: while your account is active; deleted within 30 days of a request.
  • Company table data: per the data processing agreement — 30-day export window after termination, then deletion, with backup copies expiring within the backup cycle.

9. Your rights

Under the GDPR you can ask us for access to, correction of, deletion of, restriction of, or a portable copy of your personal data, and you can object to processing. Email [contact email] and we will respond within one month. You also have the right to complain to the Dutch supervisory authority, the Autoriteit Persoonsgegevens.

10. Changes

We will update this statement as the service evolves and note the version and date at the top. Material changes are announced to account holders by email.