The documents that govern Nora and how a property's information is handled. Where a summary is shorter than the signed agreement, the agreement controls.
Effective 30 June 2026 · Last updated 21 August 2026
1Who we are
Nora is operated by Advant AI Pte. Ltd. (Singapore, UEN 202621829D), registered office 1 North Bridge Road, #18-06 High Street Centre, Singapore 179094 ("Advant", "we"). For privacy matters: privacy@advant.ai.
2Who this applies to
Visitors to dearnora.ai, people who join our waitlist or contact us, attendees of our sessions, and the named administrators and staff users of customer accounts. Personal data of a hotel's guests processed inside Nora is handled on the hotel's instructions as processor — see the DPA.
3What we collect
Contact & enquiry data (name, work email, role, property, message content); account & user data (names and contacts of staff users/administrators; authentication and access logs); usage data (how the site and product are used, via cookies); and communications with us. We do not seek special-category data and ask you not to send it unsolicited.
Shared presentations. When we send you a link to a presentation hosted on this site, we record each time that link is opened: the date and time, the approximate location and network derived from your IP address, the device, operating system and browser used, the referring page, and which parts of the presentation were viewed and for how long. We also record a replay of the session; all form input is masked. Where we sent you a personalised link, we associate that activity with the recipient we sent it to. We do not ask for, and do not collect, your name or email address in order to view a presentation.
4How we use it, and why
To respond to enquiries and deliver sessions; to provide, secure and improve the site and product and administer accounts; to send service and (where permitted) relevant updates with an easy opt-out; and to comply with law. Where the GDPR applies, we rely on your request, our legitimate interests, consent, contract and legal obligation as relevant.
Shared presentations. We use the access and engagement data described above to understand how material we have shared is received, and to time our follow-up. Our legal basis is our legitimate interest in managing our commercial relationships. This processing is not cookie-consent based. To object, or to request deletion, contact privacy@advant.ai.
5AI & automated processing
Nora is an AI product. To deliver it we share inputs with trusted third-party AI providers. We do not use personal data to train our own models, and do not subject website visitors to solely-automated decisions with legal or similarly significant effects. See our AI Transparency & Disclosures.
6Sharing & sub-processors
We share personal data only with service providers that help us run Nora and our business, each under appropriate obligations — see our Sub-processors list. We may also share where required by law or in a corporate transaction, with protections in place. We do not sell personal data.
7International transfers
We use providers in the EU and the United States, so personal data may be processed outside your country. Where personal data leaves the EU/EEA or UK, we rely on recognised safeguards such as the EU Standard Contractual Clauses, and make further information available on request.
8Retention
We keep personal data only as long as needed for the purposes described above, unless a longer period is required by law. Customer data processed within Nora is retained for the service term and applicable contractual period, and is scheduled for deletion within 90 days of a verified request or service termination as described in the DPA.
9Your rights
Depending on where you are, you may have rights to access, correct, delete, port, restrict or object, and to withdraw consent — write to privacy@advant.ai. If your data is processed within Nora on a hotel's instructions, contact that hotel as controller; we will assist. You may also complain to your local supervisory authority.
10Security
We use encryption in transit and at rest for customer data in the Cloudflare data plane, server-side authorization controls, administrative access restrictions, and security audit logging. Administrative MFA, final production access policies, and audit coverage continue to be expanded. No system is perfectly secure, but we work to protect data and respond promptly if something goes wrong.
11Cookies
Necessary cookies to run the site and, with consent where required, analytics cookies — see the Cookie Notice.
12EU & UK representatives
As a company outside the EEA, Advant has appointed an EU Representative under Article 27 GDPR: Sérgio Abreu, CIPP/E (EDPO), Senior Legal Manager — Sergio.abreu@edpo.com, +32 470 56 32 59. A UK Representative is appointed where required for UK data subjects.
13Children
Nora is a business tool, not directed to children, and we do not knowingly collect their personal data.
14Changes
We may update this policy; material changes show in the "Last updated" date, with notice where the law requires.
Nora · Legal
Terms of Use.
Effective 30 June 2026 · Last updated 21 August 2026
1Agreement to these terms
These Terms are between you (or the organisation you represent) and Advant AI Pte. Ltd. (Singapore, UEN 202621829D). By accessing dearnora.ai or using Nora, you agree to them. If accepting for an organisation, you confirm you're authorised to bind it.
2What Nora is
An AI commercial-intelligence assistant for hotels — a web Workbench and messaging — that surfaces signals and prepares briefs, drafts and recommendations for a property's team to review and release. We may improve, change or rename features, provided core functionality isn't materially degraded during a paid term.
3Eligibility & accounts
You must be able to form a binding contract and use Nora for business only. You are responsible for your account, credentials and all activity under them, and must promptly notify us of any suspected compromise.
4Acceptable use
See our Acceptable Use policy. In short: no reselling, reverse-engineering, uploading data you have no right to process, automated decisions with legal effect over individuals, unlawful use, or interference with security.
5AI outputs — read before you rely
Nora uses AI, including third-party language models. Outputs are probabilistic and may be incomplete or inaccurate; they support, and do not replace, your judgment. You are responsible for reviewing outputs before use and for any decision taken on them. Outputs are not professional advice.
Nora counsels; you decide.
6Your content & data
You retain your data and, subject to your agreement and fees, own outputs prepared specifically for you. You grant Advant only the rights needed to provide, secure, maintain, and support the Services. Advant may use fully anonymised, non-identifying aggregate statistics to improve the Services, but does not use Customer Data to train Advant-owned models. Personal data is handled under the Privacy Policy and DPA.
7Our intellectual property
Advant owns Nora and all related IP — models, prompts, code, templates and documentation — and improvements to them. No rights are granted by implication.
8Fees
Where you subscribe, fees and pricing are set out in your Order Form and MSA. Website access and the waitlist are free. Fees are exclusive of taxes.
9Warranties & disclaimers
EXCEPT AS EXPRESSLY STATED IN A SIGNED AGREEMENT, THE WEBSITE AND SERVICE ARE PROVIDED "AS IS" AND "AS AVAILABLE", AND WE DISCLAIM ALL IMPLIED WARRANTIES TO THE FULLEST EXTENT PERMITTED BY LAW, INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NON-INFRINGEMENT. WE DO NOT WARRANT THAT OUTPUTS ARE ACCURATE OR COMPLETE OR THAT THE SERVICE WILL BE UNINTERRUPTED.
10Limitation of liability
NEITHER PARTY EXCLUDES LIABILITY FOR FRAUD, OR DEATH OR PERSONAL INJURY CAUSED BY NEGLIGENCE, OR ANY LIABILITY THAT CANNOT BE EXCLUDED BY LAW. SUBJECT TO THAT, NEITHER PARTY IS LIABLE FOR INDIRECT OR CONSEQUENTIAL LOSS OR LOSS OF PROFIT, REVENUE, BUSINESS, GOODWILL OR DATA. FOR PAID CUSTOMERS, TOTAL LIABILITY IS CAPPED AS SET OUT IN THE MSA; FOR FREE USE OF THE WEBSITE, TO THE FULLEST EXTENT PERMITTED BY LAW.
11Suspension & termination
We may suspend or end access for breach, where required by law, or to protect the service. You may stop using Nora at any time. Provisions on content, IP, disclaimers, liability and governing law survive.
12Changes
We may update these terms; material changes take effect on posting or notice, and continued use means acceptance. Changes are not retroactive.
13Governing law
Singapore law. Disputes resolved by arbitration administered by the Singapore International Arbitration Centre (SIAC), seat Singapore, in English — save that we may seek injunctive relief in any competent court.
Nora · Legal
Data Processing Agreement.
Effective 30 June 2026 · Last updated 21 August 2026
Roles. The Customer is the Controller and Advant is the Processor of the Personal Data processed to provide the Services.
Customer responsibilities. The Customer is responsible for compliance as Controller, including establishing a lawful basis and providing notices to, and obtaining consents from, data subjects, and warrants that its instructions and provision of data comply. Mere receipt by Advant of data the Customer was not entitled to provide does not of itself render Advant liable.
Processing on instructions. Advant processes personal data only on the Customer's documented instructions (the agreement, Order Form and the Customer's configuration and use), save where law requires otherwise, with notice where permitted.
Subject-matter & data. Automated processing for the term to generate signals, briefs, drafts, recommendations, and AI-assisted workflows. Data subjects may include customer staff users, administrators, and other individuals whose personal data the Customer submits to the Services. Data may include names, contact details, message content, account metadata, and business content submitted by the Customer. The Services are not intended for payment-card data or special-category data unless expressly agreed.
AI service providers. The Services use third-party AI providers to generate outputs. AI Input and AI Output, including Customer Data, are shared with and processed by them to deliver the Services. Advant does not train its own models on Customer Data, and is not liable for a provider's independent acts beyond selecting reputable providers and imposing equivalent obligations.
Sub-processors. The Customer authorises Advant to engage sub-processors under equivalent obligations. Advant gives at least 30 days' notice of new sub-processors; the Customer may object on reasonable grounds within 14 days.
International transfers. Customer data in the Cloudflare production data plane is processed using the platform locations and jurisdictions configured for the Services. Sub-processors may process data in the regions listed in the Sub-processors page. Where personal data leaves the EU/EEA or UK, the parties rely on recognized safeguards such as the EU Standard Contractual Clauses, supported by a transfer assessment where required.
Security. The Services use transport encryption, encryption at rest for customer data in the Cloudflare data plane, administrative access restrictions, server-side authorization controls, and audit logging. Administrative MFA, final production access policies, and audit coverage continue to be expanded.
Breach notification. Advant notifies the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Data and within any period required by applicable law or the signed agreement.
Assistance, return & deletion. Advant reasonably assists with data-subject requests, security, breach notice, and impact assessments, and supports one audit per year via documentation. Following termination or a verified deletion request, Customer may request export where available, and customer-organization data is scheduled for deletion within 90 days unless law requires retention. Certain third-party records and provider recovery copies remain subject to documented provider retention periods.
Model training. Advant does not use Customer Data to train, retrain, or fine-tune Advant-owned models. Third-party AI providers process inputs and outputs only to provide the Services under their applicable contractual and data-protection terms. Current providers are listed on the Sub-processors page. Advant may use fully anonymised, non-identifying aggregate statistics to improve the Services.
EU Representative. As Advant is established outside the EEA, it has appointed an EU Representative under Article 27 GDPR: Sérgio Abreu, CIPP/E (EDPO), Senior Legal Manager — Sergio.abreu@edpo.com, +32 470 56 32 59.
Transparency
AI Transparency & Disclosures.
Effective 30 June 2026 · Last updated 21 August 2026
You're speaking with Nora — and Nora is AI
When you talk to Nora — in chat, on WhatsApp, anywhere she appears — you are speaking with an artificial-intelligence assistant, not a person. We say so plainly, at the start, as good practice and increasingly as law requires, including Article 50 of the EU AI Act (applicable from 2 August 2026). Outputs are identified as AI-assisted where the law expects it.
A draft, not a verdict
Nora uses AI, including third-party language models, to surface signals and prepare briefs, drafts and recommendations. Because that work is probabilistic, it can be incomplete, out of date, or simply wrong. It is prepared for a person to read, weigh and release.
Nora counsels. The property decides.
Her outputs are not legal, financial, tax or other professional advice, and should be checked before they are relied upon. You remain responsible for any decision taken on the strength of them.
The models behind her
To do her work, Nora passes information to trusted third-party AI providers, which generate the outputs she brings back. The inputs sent to them, and the outputs they return — including a property's data — are shared for one purpose only: to deliver the service. The providers that may process customer data for AI inference are listed in our Sub-processors page.
We don't train on your property
We do not use customer data, or any data that could identify a customer or individual, to train, retrain or fine-tune Advant-owned models. We may learn from fully anonymised, aggregated patterns that identify no one. AI providers process under their own terms; we choose them with care and hold them to obligations equivalent to ours.
Always a person in the loop
Nora is decision support, made to be used with human judgment. She is not to be used for automated decisions carrying legal or similarly significant weight over an individual, nor for any unlawful purpose.
Nora · Legal
Sub-processors.
Last updated 21 August 2026
We engage the following sub-processors to deliver Nora. Each is engaged under a written agreement with data-protection obligations at least equivalent to ours. We give at least 30 days' advance notice of any material change.
Vendor
Purpose
Region
Responsibility for the data you choose to upload to and process through Nora rests with you as the Customer, including ensuring you have the right to use it.
Nora · Legal
Cookie Notice.
Effective 30 June 2026 · Last updated 21 August 2026
We use cookies and similar technologies on dearnora.ai to run the site and understand how it is used.
Necessary cookies
Required for the site to function (security, load balancing, session). These are always on.
Analytics cookies
With your consent where required, we use Google Analytics to understand usage and improve the site. Analytics loads only after you accept via our cookie banner; declining loads nothing.
Cookies & storage we use
Name
Provider
Purpose
Type
User control
nora_cookie_consent
Dear Nora
Stores your cookie choice in your browser
Necessary (local storage)
"Change cookie settings" below
_ga, _ga_*
Google Analytics
Optional website analytics
Optional analytics
Set only after you accept
Consent record
Supabase
Records your accept/decline choice and the page it was made on
Consent record
Described in the Privacy Policy
Managing cookies
You can control cookies through your browser settings and our on-site controls. Declining non-essential cookies will not affect access to the site's core content.
Nora · Legal
Acceptable Use.
Effective 30 June 2026
When using Nora, you agree not to, and not to permit any third party to:
resell, sublicence or provide the Services to any third party except as agreed;
reverse-engineer, decompile or attempt to derive the source or models of Nora;
upload data you do not have the right to process;
use the Services to make automated decisions producing legal or similarly significant effects over individuals (including under Article 22 GDPR or equivalent laws);
use the Services for any unlawful, harmful or infringing purpose; or
interfere with the security or integrity of the Services.
Nora is provisioned to a designated named user and a single registered messaging number; access should not be shared or rotated across other numbers, devices or accounts. Nora is decision support and must be used with human oversight.
Nora · Security
Security & Trust FAQ.
Last updated 21 August 2026
Direct answers to the questions customer security reviews ask most. Where a signed agreement says more, the agreement controls.
Do you maintain security documentation and Trust Centre materials?
Yes. Dear Nora maintains this public Legal & Trust Centre. It includes privacy, terms, data processing, AI transparency, sub-processor, cookie, security, retention, and deletion information.
Which certifications do you hold, such as ISO 27001 or SOC 2?
Advant does not currently hold ISO 27001 or SOC 2 certification. Cloudflare, our primary infrastructure provider for the Cloudflare production fleet, maintains ISO 27001:2022 and SOC 2 Type II assurance covering Cloudflare's infrastructure controls.
What encryption standards do you use?
Our Cloudflare production standard requires TLS 1.2 or TLS 1.3 for external connections. Cloudflare-managed Durable Object and R2 storage is encrypted at rest using AES-256. Sensitive credentials use AES-256-GCM envelope encryption with separate per-Organization data-encryption keys. Capabilities, webhook signatures, audit records, and download links use HMAC-SHA-256.
Is all customer data encrypted in transit and at rest?
Customer data in the Cloudflare data plane is encrypted at rest, and application transport controls require TLS 1.2 or later.
How is customer data segregated between clients?
Customer data is logically segregated by organization using tenant-specific storage boundaries and server-side access controls. Access is authorized for the relevant customer before data is processed or returned.
What access controls protect dashboards, backend systems, and analytics?
Administrative access is restricted through identity-based authentication, server-side authorization, and separate permission levels. MFA and final production access policies are being completed.
How do you manage privileged access?
Privileged access is limited to authorized personnel, granted for an approved business need, logged, and periodically reviewed. Time-limited access is used where appropriate, with final account-level controls being completed.
What audit logging is available?
Security-relevant administrative, access, and data-handling events are logged with the actor, action, timestamp, and request context. Logs exclude customer content and secrets, are integrity-protected, and are retained for 365 days. Coverage continues to be expanded.
What are your data-retention policies?
Customer data is retained for the service term and applicable contractual period. Customer data is scheduled for deletion within 90 days of a verified request or service termination. Non-content security audit records are retained for 365 days.
What deletion capabilities are available?
Dear Nora supports customer-organization deletion for active data held within the platform. Deletion is controlled, auditable, and produces completion evidence. Automated data-subject deletion and third-party deletion coordination are being completed.
Can customer data be permanently deleted on request?
Yes, customer-organization data can be permanently deleted, including cryptographic key destruction where applicable. Certain third-party records and recovery copies remain subject to documented provider retention periods.