Legal

Privacy Policy.

Your team's context is the most valuable thing you trust us with. This policy explains what we collect, why, and the rights you have over your data.

Last updated: 22 July 2026

Security & compliance
GDPR compliant EU/UK data-protection requirements
SOC 2 Type II Independently audited security controls

Notio is built to meet GDPR data-protection requirements and maintains SOC 2 Type II certification. Customer data is encrypted in transit and at rest, access is least-privilege and logged, and our controls are independently audited each year.

1. Who we are

Notio Labs ("Notio", "we", "us") provides a shared intelligence platform for teams. This policy describes how we handle personal data across our platform, websites, and services (the "Service"). For personal data our customers submit to the Service, the customer is the data controller and Notio acts as a data processor; for our own websites and account records, Notio is the controller.

2. Information we collect

3. How we use information

We do not sell personal data, and we do not use your Customer Data to train foundation models for other customers.

4. Legal bases (GDPR)

Where the GDPR applies, we process personal data on one or more of these legal bases: performance of a contract with you; our legitimate interests in operating and securing the Service; your consent, where we ask for it; and compliance with a legal obligation. Where we rely on legitimate interests, we balance them against your rights and freedoms.

5. AI processing

To generate Output, Customer Data may be processed by large-language-model providers acting as our subprocessors under contractual confidentiality and data-protection terms. These providers are instructed not to use your Customer Data to train their models. Processing occurs within our controlled infrastructure and only as needed to deliver the feature you invoke.

6. Sharing and subprocessors

We share personal data only with service providers who help us run the Service — cloud hosting, database and vector storage, AI model providers, analytics, and payment processing — each bound by contracts that require appropriate safeguards. We may also disclose data where required by law. A current list of subprocessors is available on request at privacy@getnotio.com.

7. International transfers

We may process data in countries other than your own. Where personal data protected by the GDPR is transferred outside the EEA or UK, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum.

8. Data retention

We retain Customer Data for as long as your account is active and as needed to provide the Service. After termination, you may export your data for a reasonable period, after which we delete or de-identify it in line with our retention schedule, unless a longer period is required by law. Account and billing records are retained as required for legal and accounting purposes.

9. Your data rights

Subject to applicable law, and in particular under the GDPR, you have the right to:

Where Notio is a processor, we will forward your request to the relevant customer (controller) and assist them in responding. To exercise any right, contact privacy@getnotio.com. You also have the right to lodge a complaint with your local data-protection authority.

10. Data security

We maintain a SOC 2 Type II information security program. Data is encrypted in transit (TLS) and at rest, access is least-privilege and logged, secrets are managed centrally, and our controls are independently audited each year. We maintain a documented incident-response process and will notify affected customers of a personal data breach without undue delay as required by law.

11. Cookies and analytics

Our websites use cookies and similar technologies for essential functionality and to understand aggregate usage via analytics tools such as Google Analytics. You can control cookies through your browser settings. Essential cookies are required for the Service to function.

12. Children's privacy

The Service is intended for business use and is not directed to children under 16. We do not knowingly collect personal data from children.

13. Changes to this policy

We may update this policy from time to time. If we make material changes, we will notify you by email or in-app before they take effect. The "last updated" date above always reflects the current version.

14. Contact us

For any privacy question or request, contact our privacy team at privacy@getnotio.com, or write to Notio Labs, Lvl 1, 888 Brunswick Street, New Farm QLD 4005, Australia. See also our Terms of Service.