Contents
- Article 1 - Data Controller
- Article 2 - Definitions
- Article 3 - Guiding principles
- Article 4 - Categories of data processed
- Article 5 - Mandatory or optional nature of the data
- Article 6 - Sources of the data
- Article 7 - Purposes and legal bases
- Article 8 - Data liable to reveal sensitive information
- Article 9 - Banking aggregation
- Article 10 - Artificial intelligence
- Article 11 - Automated decision-making and profiling
- Article 12 - Communications and marketing
- Article 13 - Recipients and sub-processors
- Article 14 - Transfers outside the European Union
- Article 15 - Retention periods
- Article 16 - Security
- Article 17 - Data breaches
- Article 18 - Your rights
- Article 19 - Data protection officer and supervisory authority
- Article 20 - Cookies and trackers
- Article 21 - Minors
- Article 22 - Amendments
The protection of your personal data is at the heart of the design of the Noryo service. The purpose of this Privacy Policy (hereinafter the "Policy") is to inform you, in a clear, complete and transparent manner, of the processing of personal data carried out by Evorax Technologies (hereinafter the "Data Controller", "Noryo" or "we") in connection with the Noryo service (hereinafter the "Service"), as well as of the rights available to you.
This Policy is established pursuant to Regulation (EU) 2016/679 of 27 April 2016 (hereinafter the "GDPR") and French Act No. 78-17 of 6 January 1978 as amended. It applies to all interfaces of the Service and constitutes the reference document with regard to data protection.
Article 1 - Data Controller
1.1 Identity
The data controller is Evorax Technologies, operating under SIREN 102 146 594, whose full identification appears in the Legal Notice.
1.2 Point of contact
Any question relating to this Policy or to the exercise of your rights may be sent to legal@noryo.app. As of today, no data protection officer has been appointed; the aforementioned address constitutes the single point of contact in matters of data protection.
1.3 Scope
This Policy applies to all processing carried out in connection with the Service, whatever interface is used. It does not apply to processing carried out by third parties having their own policies, in particular your banking institutions.
Article 2 - Definitions
Definitions
- Personal data
- any information relating to an identified or identifiable natural person.
- Processing
- any operation performed on personal data, whatever the method used.
- Data Controller
- the person who determines the purposes and means of the processing.
- Processor
- the person who processes data on behalf of the Data Controller, on its instructions.
- User
- any natural person using the Service or holding an account.
- Consent
- any freely given, specific, informed and unambiguous indication of will by which the User accepts processing.
- Data breach
- any breach of security leading to the destruction, loss, alteration or unauthorised disclosure of data.
Article 3 - Guiding principles
The Data Controller applies the following principles: minimisation (only the data necessary is processed); purpose limitation (specified, explicit and legitimate purposes); storage limitation; accuracy; integrity and confidentiality; and transparency. These principles guide every decision relating to the processing carried out.
Article 4 - Categories of data processed
The data processed varies depending on the features you activate.
4.1 Identification and account data
Email address, first name, preferred language and currency, technical account identifiers and usage preferences.
4.2 Banking data
Account information (account identifiers, IBAN, type, currency), balances, transaction history and account-holding institutions, obtained through the aggregation provider, subject to your consent.
4.3 Document data
Documents, receipts and invoices that you import or receive in your space, as well as the text extracted from them for organisational purposes.
4.4 Usage data and technical data
Connection logs, IP address, device type and version, usage events, usage statistics and technical identifiers necessary for the security and proper functioning of the Service.
4.5 Billing data
Plan subscribed to, subscription status, billing history and payment identifiers, excluding any full bank card number, which is processed by the payment providers.
4.6 Household data
Household composition, members' roles and account sharing that you decide upon.
4.7 Data relating to the intelligent assistant
Questions sent to the assistant, context transmitted to produce the responses and, where applicable, memory items that you can view and delete.
4.8 Support and relationship data
Exchanges occurring in connection with assistance requests and service communications.
Article 5 - Mandatory or optional nature of the data
Certain data is necessary for the provision of the Service or for the performance of legal obligations; its absence may prevent the creation of the account, access to certain features or the handling of a request. Other data is optional and is only processed if you choose to activate the corresponding feature. The mandatory or optional nature is, where applicable, indicated at the time of collection.
Article 6 - Sources of the data
The data comes from: (i) the information you provide directly; (ii) the use of the Service; (iii) the aggregation provider, on the basis of your consent; and (iv) the payment providers, for the information necessary for billing only.
Article 7 - Purposes and legal bases
Each processing operation is based on a specific legal basis, in accordance with Article 6 of the GDPR.
| Purpose | Legal basis |
|---|---|
| Provision, operation and improvement of the Service | performance of the contract |
| Aggregation of bank accounts | consent |
| Categorisation, analyses and intelligent assistant | performance of the contract and legitimate interest |
| Billing and subscription management | performance of the contract and legal obligation |
| Security, prevention of fraud and abuse | legitimate interest |
| Compliance with accounting and tax obligations | legal obligation |
| Non-essential communications | consent |
Where a processing operation is based on legitimate interest, the Data Controller ensures a fair balance between that interest and your rights and freedoms, and you may object to it under the conditions of Article 18.
Article 8 - Data liable to reveal sensitive information
The Data Controller does not collect special categories of data within the meaning of Article 9 of the GDPR. However, the analysis of your banking transactions may indirectly reveal information relating, for example, to your health, your opinions or your beliefs. This information is not subject to any specific exploitation or any profiling for purposes other than the financial organisation that you request, and benefits from the same protection measures as all of your data.
Article 9 - Banking aggregation
9.1 Use of an authorised provider
Access to bank accounts is provided by an authorised account information service provider, within the framework of the second Payment Services Directive. The arrangements appear in the Account Access Conditions.
9.2 Consent and duration
Access is based on your explicit consent, in read-only mode, limited in time and renewable at most every ninety days, and revocable at any time.
9.3 Banking credentials
Your online banking credentials are never disclosed to the Data Controller nor retained by it.
Article 10 - Artificial intelligence
10.1 Local processing
The categorisation of transactions is first carried out on your device, with no network transmission.
10.2 Remote processing
Where remote assistance is necessary, only the information useful for the response is transmitted to the artificial intelligence provider established in the European Union. The details appear in the AI Transparency Policy.
10.3 Document recognition
Documents received electronically in your space may be subject to content recognition by that same provider.
Article 11 - Automated decision-making and profiling
The analyses and categorisations of the Service do not produce a legal effect concerning you nor do they significantly affect you within the meaning of Article 22 of the GDPR. They remain aids to organisation, under your control. You may at any time correct a categorisation and request human intervention by writing to legal@noryo.app.
Article 12 - Communications and marketing
Communications strictly necessary for the operation of the Service (service messages, security alerts, contractual information) are sent to you on the basis of the performance of the contract. Non-essential communications, in particular of a promotional nature, are sent to you only with your consent, where such consent is required. You may withdraw this consent at any time, free of charge, by means of the unsubscribe link or by writing to legal@noryo.app.
Article 13 - Recipients and sub-processors
The data is accessible to authorised persons within the Data Controller's organisation and to its sub-processors, acting on instructions and bound by confidentiality. The detailed list appears in the Sub-processors Register.
| Provider | Role | Location |
|---|---|---|
| Supabase | database, authentication, storage | European Union (Frankfurt) |
| Scaleway | document storage | France (Paris) |
| Vercel | hosting of the website and interfaces | United States |
| SendGrid | sending and receiving emails | United States |
| Mistral AI | intelligent assistant and document recognition | European Union |
| Stripe | card payment (website) | Ireland (EU) |
| Apple | in-app purchases and iOS notifications | United States |
| Atto | banking aggregation (PSD2) | United Kingdom |
The Data Controller does not sell or rent personal data and does not integrate any advertising network. The data may also be disclosed to authorised authorities where the law requires it.
Article 14 - Transfers outside the European Union
14.1 Transfers to the United States
Transfers to providers established in the United States are governed by the standard contractual clauses adopted by the European Commission, supplemented where appropriate by appropriate additional measures.
14.2 Transfers to the United Kingdom
Transfers to the United Kingdom benefit from the European Commission's adequacy decision.
14.3 Information
You may obtain a copy of the safeguards applicable to transfers by writing to legal@noryo.app.
Article 15 - Retention periods
The data is retained only for the period strictly necessary for the purposes pursued, and is then deleted or anonymised.
| Data | Period |
|---|---|
| Account and profile | duration of the account, then erasure within thirty days after request |
| Banking data and transactions | duration of the account; consent renewable at most every ninety days |
| Documents and files | duration of the account; items in the trash retained for seven days |
| Billing data | up to ten years (accounting obligations) |
| Support | ninety days after closure |
| Security and audit logs | up to twelve months |
| Audience measurement and statistics | thirteen months at most |
Article 16 - Security
The Data Controller implements appropriate technical and organisational measures in order to preserve the security, integrity and confidentiality of the data and to prevent any unauthorised access. These measures are described in the Security Policy.
Article 17 - Data breaches
In the event of a personal data breach liable to give rise to a risk to your rights and freedoms, the Data Controller carries out the notifications required by the regulations, in particular to the supervisory authority within the legal time limits and, where the law requires it, to the data subjects.
Article 18 - Your rights
18.1 List
You have the rights of access, rectification, erasure, restriction, objection and portability, the right to withdraw your consent at any time, as well as the right to give directives concerning the fate of your data after your death.
18.2 Exercise on your own
You may export your data and delete your account directly from the Service; deletion results in the erasure of the data within thirty days, subject to legal retention obligations.
18.3 Exercise by request
Other requests are sent to legal@noryo.app. The Data Controller may request additional information in order to verify your identity. A response is provided within one month, extendable by two months for complex requests, with information provided to you. The detailed procedure appears on the Exercise your rights page.
Article 19 - Data protection officer and supervisory authority
No data protection officer has been appointed as of today; the single point of contact is legal@noryo.app. You may at any time lodge a complaint with the CNIL (the French data protection authority), 3 place de Fontenoy, 75007 Paris, www.cnil.fr, without prejudice to any other administrative or judicial remedy.
Article 20 - Cookies and trackers
The Service uses only strictly necessary cookies and trackers. The details appear in the Cookie Management Policy.
Article 21 - Minors
The Service is intended for adults having the capacity to contract. A minor may only be present as a "junior" member of a household, under the responsibility of an adult member.
Article 22 - Amendments
This Policy may be amended in order to take account of legal, regulatory or technical developments. Substantial amendments are brought to your attention by an appropriate means. The applicable version is the one in force at the time of your use of the Service.