PRIVACY NOTICE

Annex 2 to the CLAI Services Agreement

Updated: 12 August 2026

 This Privacy Notice explains how Dr. Nørby & Partners ApS collects and uses Personal Data when acting as a controller in connection with drnoerby.com, CLAI, customer and prospect relationships, account administration, support, payments, marketing and related activities. It also provides transparency about selected features of CLAI for business End Users.

 This Privacy Notice does not replace the Data Processing Agreement. Where CLAI processes Customer Personal Data on behalf of a business Customer, Customer is the controller and CLAI acts as processor under the DPA – Annex 1 to the CLAI Services Agreement.

 1. Controller and Contact

The controller for the processing described in this Privacy Notice is:

Dr. Nørby & Partners ApS

c/o People & Performance

Sommervej 31B

8210 Aarhus V

Denmark

CVR no. 44708949

Privacy contact: support@drnoerby.com

 2. Scope

This Privacy Notice applies to visitors to drnoerby.com, prospective and existing customer contacts, Customer Administrators, CLAI End Users, individual CLAI users, persons who contact support, and other persons whose Personal Data Dr. Nørby & Partners processes for its own business purposes.

 3. Personal Data We Process as Controller

Depending on how you interact with us, we may process:

  • Account and authentication data, such as name, email address, company, account settings, user identifiers and the authentication information necessary for the relevant login method. Individual users may use password credentials managed through drnoerby.com. Enterprise End Users may authenticate through Customer-managed single sign-on, in which case enterprise credentials are managed by Customer’s identity provider.
  • Customer, prospect and business-contact data, such as name, job title, employer, contact details and information relating to our business relationship.
  • Transaction and billing data, such as subscription, invoice, payment status and transaction information. Full payment-card details are handled by Stripe and are not stored by CLAI.
  • Support and communications data, including contact details and information you choose to provide when you contact us for support or other enquiries.
  • Technical and security data, such as IP address, browser and device information, login and session information, and security or operational logs necessary to operate and protect the Services.
  • Marketing-preference data and information relating to marketing communications where applicable.
  • Cookie and similar-technology data as described in Section 9.

 4. How We Use Personal Data and Legal Bases

We use Personal Data for the following controller purposes and legal bases, as applicable:

  • Account, customer administration and delivery of services: performance of a contract and/or our legitimate interests in administering customer and user relationships.
  • Support, security, fraud or abuse prevention, troubleshooting and service reliability: our legitimate interests in operating secure and reliable services.
  • Billing, payments and accounting: performance of a contract and compliance with legal obligations.
  • Usage analysis using aggregated or de-identified information and, where the information remains Personal Data: our legitimate interests in understanding and improving service operation and adoption.
  • Marketing communications: consent where required, or another lawful basis where applicable law permits.
  • Legal compliance, disputes and claims: compliance with legal obligations and/or our legitimate interests in establishing, exercising or defending legal rights.

 5. Business Customer Processing and CLAI Privacy Features

For business Customers, Customer Input and Customer Personal Data are processed on Customer’s behalf under the DPA. The following describes how selected CLAI features operate for transparency:

5.1. Company Knowledge Layer. Where enabled, Customer or its Administrator manages organizational knowledge made available in the Company Knowledge Layer. CLAI uses that knowledge to contextualise responses based on Customer-provided organizational knowledge.

5.2. Individual Knowledge Layer. Where enabled, an End User may store Customer Input in an Individual Knowledge Layer. That information is used to tailor and contextualise CLAI’s responses for that End User. Customer Administrators cannot access the content of an End User’s Individual Knowledge Layer through the Services.

5.3. Conversations. Customer Administrators cannot access End User conversation content through the Services. CLAI personnel do not routinely access or read End User conversations. Limited access by authorized CLAI personnel may occur only for the purposes described in the DPA.

5.4. Usage and adoption information. Customer Administrators can view named account and usage information such as account activation, last activity, number and frequency of interactions and feature usage. This information does not include conversation content, conversation topics, sentiment, leadership issues or content in the Individual Knowledge Layer. Authorized CLAI personnel may view the same account and usage metadata where necessary for onboarding, customer success, support, troubleshooting or security.

5.5. Deletion controls. End Users can delete individual conversations, their full conversation history and content in their Individual Knowledge Layer through the Services. Deletion is handled in accordance with the Services Agreement and DPA.

5.6. Connected services. Where Customer or an End User connects or uses a third-party service with CLAI, CLAI may receive and process information that the End User actively selects or sends to CLAI through that integration as necessary to provide the requested functionality. CLAI does not obtain general access to an End User’s mailbox, calendar or other third-party content merely because an integration is available.

 6. Service Providers and Recipients

We use service providers to operate our website, Services and business. Depending on the processing activity, they act as processors, subprocessors or independent service providers under applicable law. Current key providers include:

  • Microsoft Azure, for CLAI application hosting, technical infrastructure, data storage and AI model inference.
  • Kinsta, for website hosting.
  • WooCommerce, for webshop functionality.
  • Stripe Payment processing. Stripe handles full payment-card information; CLAI receives the transaction and billing information needed to administer the purchase.
  • Mailchimp for marketing communications, where used.

We may also use other service providers where necessary to operate our business or Services, subject to appropriate contractual and data-protection safeguards. Where a provider processes Customer Personal Data on behalf of a business Customer, the subprocessor rules in the DPA apply.

 7. International Transfers

CLAI’s primary application infrastructure, storage and AI model inference are configured for processing within the European Union. Some controller activities or service providers may involve processing outside the European Economic Area. Where Personal Data is transferred internationally, we use a transfer mechanism recognized under applicable Data Protection Law, such as an adequacy decision or the European Commission’s Standard Contractual Clauses, and supplementary safeguards where appropriate.

 8. Retention

We retain Personal Data for no longer than reasonably necessary for the purposes for which it was collected, taking into account legal, accounting, security and dispute-resolution requirements. Retention depends on the category and purpose of the data. In particular:

  • Account and customer-contact data is generally retained for the duration of the relationship and thereafter only as long as reasonably necessary for administration, legal obligations or claims.
  • Accounting and transaction records are retained for the period required under applicable Danish accounting law, generally five years from the end of the relevant financial year.
  • Support records and technical or security logs are retained for as long as reasonably necessary for support, security, troubleshooting and the establishment, exercise or defence of legal claims.
  • Marketing data is retained until you withdraw consent, object where applicable, unsubscribe, or we otherwise no longer have a lawful basis to retain it.
  • Customer Personal Data processed on behalf of a business Customer is retained and deleted in accordance with the DPA.

 9. Cookies and Similar Technologies

CLAI and drnoerby.com use cookies and similar technologies that are necessary to provide, secure and operate the website and Services, including authentication, session management and security. Necessary technologies cannot be disabled where they are required for the Services to function.

We may also use analytics or other non-essential cookies. Where required by applicable law, non-essential cookies are used only after you have provided consent through our cookie-preference tool. You may change or withdraw your consent at any time through the cookie settings available on drnoerby.com. The cookie settings provide current information about the cookies and similar technologies used.

 10. Your Rights

Where Dr. Nørby & Partners ApS acts as controller, you may, subject to applicable law, have rights to access, correct or delete Personal Data, restrict processing, receive portable data, object to certain processing, and withdraw consent where processing is based on consent. You also have the right to lodge a complaint with Datatilsynet in Denmark or another competent supervisory authority.

Requests concerning Personal Data for which Dr. Nørby & Partners ApS acts as controller may be sent to support@drnoerby.com.

Where CLAI processes Customer Personal Data on behalf of a business Customer, requests relating to that data should normally be directed to the Customer as controller. CLAI will assist Customer in accordance with the DPA.

 11. Security

We use technical and organizational measures appropriate to the nature and risk of the Personal Data we process. Detailed contractual security commitments for Customer Personal Data processed on behalf of business Customers are set out in the DPA.

 12. Marketing Communications

We may send service, transactional and relationship communications that are necessary to administer accounts, purchases or our relationship with you. Marketing communications are sent only where we have a lawful basis to do so. You can unsubscribe from marketing communications using the unsubscribe mechanism in the message or by contacting us. Unsubscribing from marketing does not prevent necessary service or transactional communications.

 13. Changes to this Privacy Notice

We may update this Privacy Notice from time to time. If changes are material, we will provide appropriate notice, such as by email or a notice on the Services, where required by law. The current version will state its updated date and will take effect when published unless a later date is stated.

 14. Contact

Questions or requests about this Privacy Notice may be sent to: support@drnoerby.com.

 End.