Privacy Policy &
data protection.
Your trust is our foundation. Learn how Noruva Labs processes, protects, and isolates your data across all of our applications and enterprise services.
Noruva Labs never uses customer call audio, transcripts, uploaded legal documents, visa applications, or API payloads to train, fine-tune, or improve our or any third-party foundation models. Customer data is isolated, strictly confidential, and processed exclusively to deliver your requested service.
1. Information We Collect
We collect information you provide directly when you create an account, configure our software, or interact with our APIs:
- Account Identifiers: Name, business email, organization name, and authentication credentials.
- Billing Information: Payment processing is handled securely via Stripe. We do not store raw credit card numbers on our servers.
- Session Data: Telemetry metadata (e.g., call duration, timestamp, API endpoint invoked) used strictly for service monitoring and rate limiting.
2. Ephemeral Audio Processing in NoruvaAI
When using NoruvaAI Copilot, incoming meeting audio streams are buffered in volatile memory (RAM) in sub-second chunks to extract questions and generate real-time assistance. Raw audio packets are purged immediately after processing and are never stored on persistent storage drives.
3. Document Security in Torii & Law Assistant
Documents uploaded to Torii Immigration or Law Assistant are encrypted at rest with AES-256 and accessible only by your authorized team members via role-based access control (RBAC). You can permanently delete matter records, client profiles, and document packets at any time with immediate cascading deletion across our storage nodes.
4. GDPR & Japan APPI Compliance
We comply with the European General Data Protection Regulation (GDPR) and the Japanese Act on the Protection of Personal Information (APPI). If you are located in the European Economic Area (EEA), you retain all statutory rights regarding data portability, rectification, restriction of processing, and erasure.
5. Sub-processors
We work with trusted infrastructure providers meeting strict SOC 2 and ISO 27001 standards:
- Amazon Web Services (AWS) — Cloud hosting & isolated VPCs (Tokyo & US regions)
- Google Cloud Platform (GCP) — Compute clusters
- Stripe, Inc. — Payment processing
6. Contact Our Data Protection Officer
For privacy inquiries, Data Protection Officer (DPO) requests, or data erasure notices, contact:
Noruva Labs Data Privacy Team
Email: privacy@noruvalabs.com
Address: Minato-ku, Tokyo, Japan 105-8511