Legal
Privacy Policy
This policy explains what personal data NormScan collects, why, how we protect it, and the choices you have.
1. Who we are
NormScan (“NormScan”, “we”, “us”) provides a managed service that finds and removes unauthorized copies of technical standards on behalf of the organizations that publish them. The data controller for this website and our general communications is [legal entity name], [registered address]. You can reach us at hello@normscan.com.
2. Scope
This policy covers personal data we handle as a controller, chiefly the contact details of prospective and current clients, website visitors, and people who correspond with us. Where we process data on behalf of a client to deliver the service, the client is the controller and we act as processor under our Data Processing Agreement.
3. Information we collect
- Contact and business details you provide when you email us or request access: name, organization, role and email address.
- Service and case datarelating to the standards we protect for a client. This is generally not personal data; where it incidentally contains personal data, we handle it as a processor under the client's instructions.
- Evidence data we collect in the course of enforcement: source URLs, page captures, timestamps and related records.
- Website usage data such as pages viewed and approximate location, collected through limited analytics. See our Cookie Policy.
4. How we use information
- To respond to enquiries and provide and administer our service.
- To detect, document and remove unauthorized copies of a client's standards.
- To communicate with you about your engagement and, where permitted, relevant updates.
- To maintain the security and integrity of our systems and evidence.
- To comply with legal obligations and to establish or defend legal claims.
5. Legal bases (GDPR)
Where the GDPR applies, we rely on:
- Contract: to take steps at your request and to provide the service.
- Legitimate interests: to operate, secure and improve our business, balanced against your rights.
- Consent: for optional analytics and any marketing you opt into, which you may withdraw at any time.
- Legal obligation: where we are required by law to process or retain data.
6. Sharing and subprocessors
We do not sell personal data. We share it only with vetted service providers acting on our instructions (for example, cloud hosting and email), and, where needed to enforce a takedown on a client's behalf, with the platforms, hosts and registrars to whom notices are addressed. Our security practices and subprocessor handling are described on our Trust & security page.
7. International transfers
We host within the European Union. Where any transfer outside the EEA is necessary, we rely on an adequacy decision or appropriate safeguards such as the European Commission's Standard Contractual Clauses.
8. Retention
We keep personal data only as long as needed for the purposes above: for the life of a client relationship and a reasonable period afterward, and longer where evidence records or legal obligations require it. Specific retention windows are set per engagement.
9. Your rights
Subject to applicable law, you may request access to, correction or deletion of your personal data; restrict or object to processing; request portability; and withdraw consent. To exercise any of these, email hello@normscan.com. You also have the right to complain to your local data-protection supervisory authority.
10. Security
We protect personal data with encryption in transit and at rest, least-privilege access, and a defined incident-response process. Read more on our Trust & security page.
11. Changes
We may update this policy as our service evolves. We'll revise the date above and, for material changes, take reasonable steps to let affected clients know.
12. Contact
Questions about this policy or your data? Write to hello@normscan.com.