Privacy Policy
Effective date: June 11, 2026
Last updated: June 11, 2026
1. Who we are
This Privacy Policy explains how Noord Studio ("Noord Studio," "we," "us," or "our") collects, uses, shares, and protects personal data when you visit noord.design, contact us about studio work or Twin Studio access, or use Twin Studio (collectively, the "Services").
- Data controller: Noord Studio LTDA, CNPJ 64.592.227/0001-56
- Registered address: 777 Paulista Avenue, 15th Floor, Suite 2242, São Paulo, SP 01311-914, Brazil
- Contact for privacy matters: legal@noord.design
If you have questions about this Policy or how we handle your personal data, contact us at the address above.
2. Scope
This Policy applies to:
- Visitors to noord.design and the Twin Studio marketing page (/twin)
- People who email us a project inquiry or Twin Studio beta request
- Users who create an account or otherwise access Twin Studio (when available)
- Authorized users of OAuth-gated internal documentation at /docs/* (invite-only)
It does not cover third-party websites or services we link to, which have their own privacy policies.
3. What personal data we collect
3.1 Information you provide directly
| Category | Examples | When collected |
|---|---|---|
| Contact details | Name, email address, company name, role | Email to studio@noord.design or beta@noord.design |
| Project information | Description of your project, budget range, timeline, attachments you choose to share | Project inquiry emails |
| Beta request details | Email, team size, optional note | Twin Studio beta request emails |
| Account information | Name, email, password (hashed), workspace/organization details | Twin Studio account creation |
| Product content | Files, prompts, configurations, and other content you create or upload within Twin Studio | Use of Twin Studio |
| Communications | Messages you send us via email | Any direct contact |
3.2 Information collected automatically
| Category | Examples | Source |
|---|---|---|
| Server and security logs | IP address, browser type, request timestamps, pages requested | Hosting provider (Vercel) when you load our site or APIs |
| Cookies and similar technologies | Session cookies for login; sidebar and onboarding state cookies in Twin Studio | Authentication and product functionality |
| Local storage preferences | Theme choice (noord-theme) on marketing pages | Your browser, only if you change appearance settings |
We do not currently use third-party analytics or advertising trackers on noord.design or /twin.
3.3 Information from third parties
If you sign in with Google OAuth (internal docs or Twin Studio), we receive your name and email address from Google consistent with your Google account settings. If you interact with us via a third-party platform (e.g., LinkedIn or a scheduling tool), we may receive limited information from that platform consistent with your settings there.
4. How we use personal data
We use personal data to:
- Respond to project inquiries and Twin Studio beta requests
- Provide, maintain, secure, and improve noord.design and Twin Studio
- Create and manage Twin Studio user accounts and workspaces
- Send product or studio updates you have asked to receive (with the ability to opt out at any time)
- Detect, prevent, and address fraud, abuse, security incidents, and technical issues
- Comply with legal obligations, and establish, exercise, or defend legal claims
5. Legal bases for processing
Brazil (LGPD — Law No. 13,709/2018)
We rely on the following legal bases under Article 7 of the LGPD, as applicable:
- Consent — where you opt in to optional communications
- Legitimate interests — for responding to inquiries, securing our Services, and operating our website, balanced against your rights and freedoms
- Contract performance — for providing Twin Studio to registered users
- Legal obligation — where required by Brazilian law (e.g., tax or accounting records)
EU/UK visitors (GDPR / UK GDPR)
If you are located in the European Economic Area or United Kingdom, we process personal data on the following bases under Article 6 GDPR:
- Consent (Art. 6(1)(a)) — optional marketing communications
- Contract (Art. 6(1)(b)) — providing services you request, including Twin Studio accounts
- Legitimate interests (Art. 6(1)(f)) — operating, securing, and improving our Services
- Legal obligation (Art. 6(1)(c)) — where required by EU/UK law
California residents (CCPA/CPRA)
We do not sell or share personal data, as those terms are defined under the CCPA/CPRA, for cross-context behavioral advertising. Section 9 describes the rights available to California residents.
6. Cookies and similar technologies
noord.design and Twin Studio may use:
- Strictly necessary cookies — required for authentication, session management, and security (e.g., Twin Studio login, internal docs OAuth, invite flows)
- Functional storage — theme preference stored in your browser (localStorage) on marketing pages when you choose Light or Dark mode
We do not set analytics or advertising cookies on the public marketing site. Where we add non-essential cookies in the future, we will request consent where required by applicable law before setting them.
7. How we share personal data
We do not sell personal data. We may share personal data with:
- Service providers / processors acting on our behalf (see Section 8)
- Professional advisors (lawyers, accountants, auditors) where necessary
- Authorities where required to comply with a legal obligation, court order, or to protect our rights, property, or safety, or that of others
- A successor entity in connection with a merger, acquisition, financing, or sale of assets, subject to standard confidentiality protections
All third-party processors are required to handle personal data under contractual confidentiality and security obligations consistent with the LGPD, GDPR, and other applicable laws.
8. Subprocessors and international data transfers
Noord Studio is based in Brazil. Personal data may be processed in countries outside Brazil when our subprocessors operate there, including the United States and the European Union.
We currently use the following categories of subprocessors:
| Provider | Purpose | Typical data | Primary processing region |
|---|---|---|---|
| Vercel | Website and API hosting, server logs | IP address, request metadata, page URLs | United States / global edge |
| Resend | Transactional email delivery (when configured) | Email address, message content for notifications | United States |
| OAuth sign-in for internal docs and Twin Studio | Name, email address | United States / global | |
| AI model providers (e.g., Google Gemini, Anthropic, OpenAI, via configured API) | Twin Studio conversation generation | Prompts and content you submit in Twin Studio | United States / varies by provider |
Where we transfer personal data internationally, we rely on appropriate safeguards required by applicable law, such as LGPD-recognized transfer mechanisms (Art. 33), including standard contractual clauses approved by the ANPD where applicable, and Standard Contractual Clauses (SCCs) under the GDPR, where relevant.
9. Your privacy rights
9.1 Brazil (LGPD)
Under the LGPD, you have the right to:
- Confirm whether we process your personal data
- Access your personal data
- Correct incomplete, inaccurate, or outdated data
- Request anonymization, blocking, or deletion of unnecessary or excessive data, or data processed in non-compliance with the LGPD
- Request portability of your data to another provider
- Obtain information about public and private entities with which we have shared data
- Withdraw consent at any time, where processing is based on consent
- Object to processing carried out on the basis of legitimate interest
- Lodge a complaint with the Autoridade Nacional de Proteção de Dados (ANPD)
9.2 EU/UK residents (GDPR / UK GDPR)
You have the right to: access, rectify, erase, restrict, or object to processing of your personal data; data portability; and to lodge a complaint with your local supervisory authority (e.g., a national Data Protection Authority in the EU, or the ICO in the UK). Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
9.3 California residents (CCPA/CPRA)
Subject to certain exceptions, California residents have the right to: know what personal information is collected, used, shared, or sold; request deletion; request correction; opt out of the sale or sharing of personal information (we do not currently sell or share personal information); limit use of sensitive personal information; and not be discriminated against for exercising these rights.
9.4 How to exercise your rights
To exercise any of these rights, contact us at legal@noord.design. We will respond within the timeframe required by applicable law (e.g., generally 15 days under the LGPD, extendable once by 15 days; one month under the GDPR, extendable by two further months for complex requests; 45 days under the CCPA, extendable once by 45 days). We may need to verify your identity before fulfilling certain requests.
10. Data retention
We retain personal data only for as long as necessary for the purposes described in this Policy, including to comply with legal, accounting, or reporting requirements. Specifically:
- Project inquiry and beta request emails: retained for 45 days from last contact, or until you ask us to delete them
- Twin Studio account data: retained for the duration of your account, plus 30 days after account closure for legal/operational purposes
- Server logs: retained according to our hosting provider's default retention, typically up to 30 days unless needed for security investigation
11. Children's privacy
Our Services are intended for businesses and professionals and are not directed to individuals under the age of 18 (or the age of majority/digital consent in their jurisdiction). We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us so we can delete it.
12. Security
We implement technical and organizational measures designed to protect personal data against unauthorized access, alteration, disclosure, or destruction, consistent with the security obligations of the LGPD (Art. 46) and applicable international standards. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
13. Changes to this Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. We will post the revised version with an updated "Last updated" date and, where required by law, provide additional notice (e.g., for material changes affecting Twin Studio account holders).
14. Contact us
For any questions, requests, or complaints regarding this Privacy Policy or our data practices, contact:
Noord Studio Email: legal@noord.design
If you are located in Brazil and are not satisfied with our response, you may also contact the ANPD (Autoridade Nacional de Proteção de Dados) at gov.br/anpd.