This Privacy Policy explains how Normal Technology LLC ("Normal," "we," "us") collects, uses, and protects information. It covers two situations:
- Visitors to this website (normaltechnologyllc.com).
- Customers who use our service, and the people whose information appears in our customers' business records.
We wrote this in plain language. If anything is unclear, email us at [email protected].
1. Who we are
Normal Technology LLC is a Delaware limited liability company based in the United States. We set up and manage AI assistants that work from a business's own records.
2. Information we collect from website visitors
We keep this site simple. We do not run analytics, advertising pixels, or tracking cookies.
Information you give us. If you book a call through the "Talk with us" button, the scheduling form is provided by Cal.com. It collects your name, email address, and any notes you type. Cal.com processes that information under its own privacy policy, and we receive it so we can hold the meeting. If you email us, we keep the email.
Information collected automatically. Our hosting provider records standard server logs (IP address, browser type, pages requested, timestamps) to keep the site running and secure. The Inter font on this site is loaded from rsms.me, which sees your IP address when the font is requested. We do not combine any of this with other information about you.
3. Information we handle for customers
When a business becomes a customer, we connect our service to the systems that business already uses: practice management, document storage, email, calendar, billing, phone, and similar. Those systems contain information about the customer's own clients, patients, residents, buyers, and staff.
We act on the customer's instructions. For that information, the customer is the controller (or "covered entity" or "business" under the laws that use those terms) and Normal is the processor (or "business associate" or "service provider"). We use it only to provide the service to that customer. We do not sell it, share it with advertisers, or use it to train any model that serves anyone other than that customer.
What the service does with it. The service reads the connected records so it can answer questions, prepare drafts, and flag items for a person at the customer's business to act on. It does not send messages, file documents, or contact anyone on its own. Every answer cites the record it came from.
Where it lives. The customer's records stay in the customer's own systems. Our service reads from them; it does not copy them into a database we own for any purpose other than the temporary processing needed to answer a request. For customers who choose an on-premises deployment, all processing runs on hardware inside the customer's facility.
Model providers. To generate answers, the service may send the relevant portion of a customer's records to a third-party AI model provider under an agreement that prohibits the provider from retaining or training on that data. Customers who do not want any data to leave their premises can choose the on-premises option, where the model runs locally.
Requests from individuals. If you are a client, patient, or resident of one of our customers and want to access, correct, or delete information about you, contact that business directly. We will help them respond.
4. How we use information
- To hold the meeting you booked and follow up on it.
- To provide, configure, support, and secure the service for customers.
- To respond to your questions.
- To meet legal obligations and enforce our agreements.
We do not use personal information for advertising. We do not sell it. We do not use it to train models that serve other customers.
5. When we share information
We share information only with:
- Service providers who help us run the business and the service, bound by contracts that limit what they can do with it. As of the date above, these are: Cal.com (scheduling), our website hosting provider, our email provider, and, for customers who choose it, an AI model provider under a no-retention, no-training agreement.
- The customer whose systems the information came from.
- Authorities when the law requires it, or to protect the rights and safety of Normal, our customers, or others.
- A successor if Normal is acquired or merges, in which case this policy continues to apply to the information already collected.
6. Security
Customer records are isolated per customer, encrypted in transit and at rest, and accessible only to the staff and systems that need them to provide the service. Access is logged. We review vendors before we use them. No system is perfectly secure, so if we learn of a breach affecting your information, we will notify affected customers without undue delay and as the law requires.
7. Retention
- Website inquiries and meeting bookings: kept while we are in contact and for a reasonable period afterward, then deleted.
- Customer service data: kept only as long as the customer's agreement is active. When a customer ends the service, any temporary copies we hold are deleted within 30 days. The customer's own systems are unaffected; the records were there the whole time.
- Server logs: kept for a limited period for security, then deleted.
8. Your choices and rights
Depending on where you live, you may have the right to access, correct, delete, or port your personal information, to object to or restrict certain processing, and to not be discriminated against for exercising those rights. To make a request, email [email protected]. We will verify your identity and respond within the time the law allows. If you are a resident of California or another U.S. state with a comprehensive privacy law, those rights apply to you, and you may use an authorized agent to make a request.
If your information reached us through one of our customers, we will direct your request to that customer, since they control it.
9. Health information
Some of our customers are medical or aesthetic practices whose records include protected health information under HIPAA. For those customers we act as a business associate and sign a Business Associate Agreement before connecting to any system that holds health information. We do not access health information for any purpose other than providing the service to that customer.
10. Children
Our website and service are for businesses. We do not knowingly collect information from anyone under 18 through this website.
11. International visitors
Normal is based in the United States and processes information here. If you visit from outside the U.S., your information will be transferred to and processed in the U.S.
12. Changes
If we change this policy, we will post the new version here with a new date at the top. If the change is significant, we will tell current customers directly.
13. Contact
Normal Technology LLC [email protected]