Data Processing Addendum

Last updated: 28 July 2026

This Data Processing Addendum (“DPA”) forms part of the Nora Terms and Conditions where a Nora customer uses the service to process personal data for which they are the controller.

1. Parties and roles

In this DPA, “Customer” means the therapist or organisation using Nora. CJHT DESIGN LTD, trading as Nora, of The Bungalow, The Green, Snitterfield, Stratford-Upon-Avon, England, CV37 0JG, is “Nora”. For Customer Personal Data, Customer is the controller and Nora is the processor, except where applicable law requires a different allocation of roles.

This DPA applies to processing governed by the UK GDPR and, where applicable, other data-protection law. If this DPA conflicts with the Terms in relation to Customer Personal Data, this DPA takes precedence to the extent of that conflict.

2. Documented instructions and purpose

Nora will process Customer Personal Data only on Customer's documented instructions, including the Terms, this DPA and Customer's use of the service, unless required to do otherwise by applicable law. If law requires otherwise, Nora will tell Customer before processing unless the law prohibits it.

Customer instructs Nora to process Customer Personal Data only to provide, secure, maintain, support and troubleshoot Nora; prevent abuse; comply with law; and meet Nora's contractual obligations. Nora will promptly tell Customer if an instruction, in Nora's reasonable opinion, infringes applicable data-protection law.

3. Details of processing

  • Subject matter: provision of the Nora therapist practice-management service.
  • Duration: for the term of the Customer's use of Nora and for the limited period needed for deletion, backups, legal obligations or claims after it ends.
  • Nature and purpose: hosting, storage, encryption, access, display, organisation, support, security and deletion of practice-management data.
  • Data subjects: Customer, Customer's clients and prospective clients, and individuals whose information Customer enters.
  • Data: identity/contact information, session and scheduling information, notes, documents, and any other content Customer chooses to enter. This may include special-category personal data, including health and therapy information, and risk information.

Customer is responsible for ensuring it has a lawful basis and, where required, a valid condition for special-category data; for providing appropriate notices to data subjects; and for determining whether Nora is suitable for its professional and legal obligations.

4. Confidentiality and security

Nora will ensure that people authorised to process Customer Personal Data are bound by confidentiality obligations. Nora will implement appropriate technical and organisational measures designed to protect Customer Personal Data, taking account of the nature, scope, context and purposes of processing and the risks to individuals.

Nora encrypts client records, notes, documents and file content in the browser before storage, and does not retain the keys needed to read that encrypted content at rest. This does not remove all risk: limited structural metadata, such as timestamps, statuses, record relationships and encrypted file size, remains necessary to operate the service.

5. Subprocessors

Customer gives Nora general written authorisation to use subprocessors. Nora will impose written data-protection obligations on subprocessors that are materially equivalent to those in this DPA and remains responsible for their processing to the extent required by law.

Current subprocessors may include:

  • Vercel — hosting, website analytics and performance monitoring
  • Supabase — database, authentication and private file storage
  • Upstash — rate limiting and abuse prevention
  • Resend — transactional email delivery
  • Anthropic — optional AI assistant, only when Customer enables and uses it
  • Stripe — payment processing, if and when paid plans are made available

Nora will provide notice of a material intended subprocessor change by updating this page or otherwise notifying Customer. Customer may object on reasonable data-protection grounds within 14 days; the parties will work in good faith on a reasonable solution. If none is possible, Customer may stop using the affected feature or terminate the affected service without penalty for the unused portion.

6. International transfers

Nora will not transfer Customer Personal Data outside the United Kingdom unless the transfer is permitted by applicable data-protection law and protected by an adequacy regulation, approved contractual safeguards or another valid transfer mechanism.

7. Assistance, incidents and audits

Taking account of the nature of processing, Nora will provide reasonable assistance to Customer to respond to data-subject requests and to meet obligations relating to security, personal-data breaches, data-protection impact assessments and prior consultation. Nora will notify Customer without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data.

On reasonable written request, and subject to confidentiality, security and proportionality, Nora will make available information reasonably necessary to demonstrate compliance with this DPA and permit an audit no more than once in any 12-month period, unless law or a material incident reasonably requires more frequent audit activity.

8. Return and deletion

At the end of the service, Customer may export or delete Customer Personal Data using available product features or request assistance from Nora. Nora will delete or return Customer Personal Data unless applicable law requires retention. Residual copies may remain in secure backups until overwritten in accordance with Nora's backup cycle, and will not be restored except where needed for disaster recovery or legal compliance.

9. Contact

For questions about this DPA or Customer Personal Data, contact Nora at support@meetnora.uk.