Contents
NORBr B.V. ("NORBr", "we", "us") is a Dutch company providing white-label payment infrastructure to businesses such as merchants, payment service providers, software platforms and payment facilitators. We are registered with the Dutch Chamber of Commerce under number 83441492 and have our registered office at WG Plein 167, 1054 SC Amsterdam, the Netherlands.
For the processing activities described in this notice, NORBr acts as data controller within the meaning of the General Data Protection Regulation (GDPR).
NORBr has designated a Data Protection Officer, who can be reached at dpo@norbr.com.
This notice explains how NORBr processes personal data for its own purposes, as a controller. It applies to:
What this notice does not cover. NORBr's core service consists of processing payment-related data on behalf of its customers and, where relevant, their own merchants. For that data, including end-customer identification, payment instrument and transaction data, NORBr acts as a processor (or sub-processor) under the agreement concluded with the relevant customer. The customer, or its merchant, determines the purposes of that processing and is responsible for informing the individuals concerned.
If you are a customer of a business that uses NORBr's infrastructure and you wish to exercise your rights in relation to a payment, please contact the business you purchased from: it is best placed to respond. If you contact us directly, we will forward your request to the relevant customer without undue delay.
When you browse norbr.com, technical data your browser transmits is processed on our behalf by our hosting provider: IP address, date and time of access, pages viewed, browser type and operating system, and the website you came from. This data is used to deliver the website and keep it secure and available. We do not use it to analyse your behaviour or to build a profile of you, and we do not access it other than where necessary to investigate a technical or security issue.
Legal basis: our legitimate interest in operating and securing our website.
Cookies. Our website uses cookies that are strictly necessary for it to function, and HubSpot analytics cookies which are placed only if you allow the analytics category through our cookie banner. We set no advertising cookies. For details, see our Cookie Policy at norbr.com/cookie-policy. You can change your choice at any time through the Cookie settings link in the footer of any page.
When you request a demo, contact us through the website, meet us at an event or otherwise exchange with our team, we process your name, professional contact details, company and role, and the content of our exchanges. We may also collect professional contact data from third-party sources, such as publicly available sources, professional networks and business partners.
Purposes: responding to your request, managing our commercial relationship, sending you communications about NORBr's services (you can object at any time) and inviting you to events.
Legal basis: our legitimate interest in developing our business-to-business activity, and your consent where required by applicable electronic marketing rules (you can withdraw it at any time), for example in jurisdictions that require prior consent for business contacts.
Where we obtain your data from third-party sources, we provide the information required by article 14 GDPR at the latest in our first communication with you.
In the context of concluding and performing agreements, we process the business contact details of the individuals involved: name, role, professional email address and phone number, correspondence and, for signatories, the data appearing in the agreement. For billing and financial administration we process the contracting entity's bank details and invoicing data. As part of our third-party risk process, we may also process identifying data about the directors and ultimate beneficial owners of the organizations we contract with, including their name, date of birth, nationality and the results of the checks described below.
Purposes: contract conclusion and performance, account management, billing and financial administration, verification of counterparties where required, and compliance with our legal obligations.
Counterparty screening. Where our third-party risk process requires it, we check the organizations we contract with, and their directors and ultimate beneficial owners, against sanctions and watchlists and other publicly available sources. These checks are carried out using OpenSanctions, a service operated from Germany. We do not take decisions about you based solely on automated processing; a positive match is always reviewed by a member of our team.
Legal basis: our legitimate interest in concluding and performing agreements with the organization you represent and in assessing the risk associated with our counterparties (the contract is concluded with that organization, not with you personally), and compliance with legal obligations, in particular applicable sanctions regimes (including the Dutch Sanctiewet 1977 and EU restrictive measures) and Dutch bookkeeping and tax retention duties.
Our customers authorize members of their teams to use the NORBr dashboard, back-office and developer tools. For these users, NORBr processes for its own purposes: account and registration data (name, professional email address, username), authentication data (login details, two-factor authentication data), device and connection data (IP address, browser type), logs of access and activity on the platform, and support requests and related correspondence.
Purposes: providing and securing access to the platform; preventing, detecting and investigating misuse, fraud and security incidents; verifying compliance with the agreement concluded with our customer; providing support; complying with legal obligations.
Legal basis: our legitimate interest in operating, securing and enforcing the proper use of our platform, and compliance with legal obligations.
This reflects the allocation of roles agreed with our customers: account, security and support processing is carried out by NORBr as controller, while the data you and your organization process through the platform is handled by NORBr as processor, on your organization's documented instructions.
AI connectors. If your organization enables optional AI integrations, such as the NORBr Brainpower MCP connector, a specific notice describing the associated data flows is provided in our developer documentation and at the point of connection.
We receive applications by email and through professional networks such as LinkedIn. When you apply, we process the data you provide: your CV, cover letter and correspondence, together with interview notes and, where you name them, references.
Legal basis: steps taken at your request prior to entering into an employment contract, and our legitimate interest in recruiting suitable candidates.
Retention: we delete application data 4 weeks after the end of the recruitment procedure, or keep it for up to 1 year with your consent, in line with Dutch practice. If you apply through LinkedIn, LinkedIn processes your data as a separate controller under its own privacy notice.
We share personal data with service providers acting on our instructions:
We may also share personal data with our professional advisers and insurers, with competent authorities where we are legally required to do so and, in the event of a corporate transaction, with the parties involved, subject to appropriate safeguards. We do not sell personal data and we do not share it with third parties for their own marketing.
Our platform and the personal data described in this notice are hosted in European regions of Google Cloud Platform and MongoDB Atlas. Depending on the region used, this can include the United Kingdom, which benefits from an adequacy decision of the European Commission.
Some of our providers, such as Zendesk and HubSpot, are US-based companies: they are certified under the EU-U.S. Data Privacy Framework (including its UK Extension) and additionally offer the European Commission's Standard Contractual Clauses in their data processing agreements. More generally, where personal data is transferred outside the EEA or the United Kingdom, we rely on an adequacy decision or on the Standard Contractual Clauses, supplemented where necessary. You can obtain further information about the safeguards used by contacting dpo@norbr.com.
| Category of personal data | Retention period |
|---|---|
| Prospect and business contact data | 3 years after our last meaningful contact |
| Invoices, ledger and bank records (contact details where applicable) | 7 years from the end of the financial year to which the record relates (article 52 AWR and article 2:10 BW) |
| Contracts (signatory and contact details) | 7 years from the end of the contract term (Dutch bookkeeping and tax retention duty, article 52 AWR and article 2:10 BW) |
| Platform user accounts | Term of the customer agreement, then deletion or anonymization within 6 months |
| Platform security and access logs | 24 months |
| Support tickets | Active for 3 months after closure, then archived; deleted after 3 years |
| Counterparty screening results | Term of the contract plus 2 years; 5 years from the decision where the screening led to a refused or terminated relationship |
| Job applications | 4 weeks after the end of the procedure; up to 1 year with consent |
Longer retention may apply where necessary to establish, exercise or defend legal claims, or where required by law.
We implement technical and organizational measures appropriate to the risk, including encryption in transit and at rest, access controls and least-privilege permissions, logging and monitoring, and contractual safeguards with our providers. Our infrastructure runs on Google Cloud Platform, which maintains recognized certifications (including ISO 27001), and our payment infrastructure is operated in line with PCI DSS requirements.
Under the GDPR you have the right to access your personal data, to have it rectified or erased, to restrict its processing, to receive it in a portable format where the processing is based on consent or a contract, and to object to processing based on our legitimate interests. You can object to direct marketing at any time, and this objection is absolute. Where processing is based on your consent, you can withdraw it at any time, without affecting the lawfulness of prior processing.
We do not take decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you.
To exercise your rights, contact dpo@norbr.com. We may ask you to verify your identity in a proportionate manner and will respond within one month, extendable where the request is complex.
You also have the right to lodge a complaint with the Dutch supervisory authority, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl), or with the supervisory authority of the EU/EEA country where you live or work. If you are in the United Kingdom, you may also lodge a complaint with the Information Commissioner's Office (ico.org.uk).
We may update this notice from time to time. Material changes will be signalled on our website. The date of the latest version appears at the top of this notice; previous versions are available on request at privacy@norbr.com.
Discretion isn’t a feature we sell. It’s how the product is built.