GDPR & Data Processing

Last updated: August 2026

This document is provided for general information and does not constitute legal advice. Please consult a qualified professional for advice specific to your situation.

Our commitment

Notioff is committed to protecting personal data and supporting our customers' compliance with the European Union and United Kingdom General Data Protection Regulation (together, the "GDPR"). This page explains how we handle personal data in the context of the GDPR and complements our Privacy Policy. We build the Service with privacy in mind and aim to be transparent about our practices.

Roles: controller and processor

The GDPR distinguishes between a "controller," which decides why and how personal data is processed, and a "processor," which processes personal data on the controller's behalf. Our role depends on the context:

  • We act as a processor for the content our customers store in the Service. Our customers decide what personal data to put into their workspaces and how to use it, and we process that data on their instructions to provide the Service.
  • We act as a controller for the personal data we collect to run our business, such as account registration details, billing information, and website usage data.

Where we act as a controller, we process personal data only when we have a legal basis to do so. Depending on the situation, our legal bases include:

  • Contract. Where processing is necessary to provide the Service you have requested.
  • Legitimate interests. Where processing supports interests such as securing and improving the Service, provided these are not overridden by your rights.
  • Consent. Where you have given consent, such as for optional analytics cookies, which you can withdraw at any time.
  • Legal obligation. Where processing is necessary to comply with applicable law.

Data subject rights

Subject to the GDPR and applicable law, individuals in the EEA and UK have the following rights regarding their personal data:

  • Access. To obtain confirmation of whether we process your data and a copy of it.
  • Rectification. To have inaccurate or incomplete data corrected.
  • Erasure. To have your data deleted in certain circumstances.
  • Restriction. To limit how we process your data in certain circumstances.
  • Portability. To receive certain data in a portable, machine-readable format.
  • Objection. To object to processing based on legitimate interests.

You also have the right to lodge a complaint with your local supervisory authority. To exercise your rights, contact our privacy team using the details below. Where we act as a processor on behalf of a customer, we will refer your request to that customer and support them in responding. We may need to verify your identity before acting on a request, and we will respond within the time required by law.

International data transfers

Notioff is based in the United States, and personal data may be processed in the United States or other countries where we or our service providers operate. When we transfer personal data from the EEA or UK to a country that has not received an adequacy decision, we rely on appropriate safeguards, such as the European Commission's standard contractual clauses and the UK international data transfer mechanisms, together with additional measures where needed to protect the data.

Sub-processors

To provide the Service, we use a limited number of vetted third-party service providers ("sub-processors"), such as cloud hosting, payment processing, analytics, and customer support providers. We engage sub-processors under written contracts that require them to protect personal data and to process it only as needed to provide their services to us. We remain responsible for our sub-processors' handling of personal data as required by the GDPR, and we can provide a current list of sub-processors to business customers on request.

Data Processing Addendum

We make a Data Processing Addendum ("DPA") available to business customers who require one to support their GDPR compliance. Our DPA describes the roles of the parties, the subject matter and duration of processing, the categories of data and data subjects, and the technical and organizational measures we apply. To request our DPA, email info@notioff.org and we will provide it for review and signature.

Data retention and deletion

We retain personal data for as long as needed to provide the Service and for legitimate business or legal purposes. Where we act as a processor, customers control the content in their workspaces and can edit or delete it. When a customer deletes content or closes an account, we delete or de-identify the associated personal data within a reasonable period, subject to routine backup rotation and any retention required by law.

Security measures

We maintain technical and organizational measures designed to protect personal data, including encryption in transit and at rest, access controls, and regular backups. You can read more about our approach on our Security page. No system is completely secure, but we work continuously to reduce risk and protect the data entrusted to us.

Data breach notification

We maintain procedures to detect, investigate, and respond to security incidents. If we become aware of a personal data breach that affects personal data we process, we will notify affected customers without undue delay and provide the information needed to help them meet their own notification obligations under the GDPR. Where we act as a controller, we will notify the relevant supervisory authority and affected individuals as required by law.

Contact our privacy team

For any questions about this page, our data processing practices, or to exercise your rights, please contact our privacy team: