Privacy policy
Effective Date:
July 3, 2026
Table of contents:
Last Reviewed:
July 3, 2026
Table of contents:
- Introduction
- Data protection officer
- How we collect and use (process) your personal information
- Use of the North website
- Cookies and tracking technologies
- Use of North services
- When and how we share information with third parties
- Transferring personal data to the U.S. and other countries
- Data subject rights
- Security of your information
- Data storage and retention
- Children’s data
- Questions, concerns, or complaints
Section 1
Introduction
North Cloud Holdings, Inc. ("North," "we," "us," or "our") is a cloud technology company. We understand that you are aware of and care about your own personal privacy interests, and we take that seriously.
This Privacy Policy describes North's policies and practices regarding the collection, use, disclosure, and protection of personal information and explains the privacy rights that may be available to you. It applies when you visit North websites, communicate with us, request a demonstration, create or use an account, participate in an event or promotion, apply for a role, or use North products and services (collectively, the "Services").
We recognize that information privacy is an ongoing responsibility. We may update this Privacy Policy from time to time as we undertake new personal data practices, introduce or modify products and features, adopt new privacy policies, or respond to changes in law. We will update the "Last Updated" date above and, where required by law, provide additional notice of material changes.
When North determines the purposes and means of processing personal information, such as for website, prospect, account, marketing, support, security, service-usage, recruiting, and business-administration activities, North acts as a controller. When North processes personal information contained in customer data solely on behalf of a customer and under that customer's instructions, North generally acts as a processor or service provider. That processing is governed by the applicable customer agreement and data processing addendum ("DPA").
Section 2
Data protection officer
North is headquartered in New York, New York, United States. Questions about this Privacy Policy, requests to exercise privacy rights, and concerns about North's privacy practices may be directed to the contact below:
Yassine Açoine
North Inc.
dataprivacy@north.cloud
Section 3
How we collect and use (process) your personal information
The personal information North collects depends on how you interact with us and may include:
- Identity and business contact information, such as name, work email address, phone number, job title, employer, and company information.
- Account and authentication information, such as account identifiers, login information managed through North's authentication provider, roles, permissions, and account preferences.
- Customer and commercial information, such as subscription or contract information, billing contacts, purchase history, and communications about the customer relationship.
- Website and device information, such as IP address, approximate location, browser type, operating system, referring pages, pages viewed, cookie identifiers, and similar usage information.
- Service usage, diagnostic, and security information, such as feature usage, system events, audit records, support requests, and information used to detect, investigate, and prevent security incidents or misuse.
- Cloud cost and usage information processed through the Services, such as cloud account identifiers, resource identifiers, cost and usage records, tags, configuration metadata, and related operational data made available through connected cloud accounts.
- Event, promotion, and marketing information, such as registration details, eligibility information, preferences, communications, and shipping information where needed to administer an event or promotion.
- Applicant information if you apply for a role with North, such as resume, employment history, education, professional details, and communications regarding the application process. If you apply through our careers site, North may also collect voluntary demographic and equal employment opportunity information (such as race/ethnicity, gender, veteran status, and disability status) that you choose to provide during the application process.
- Information submitted to AI-enabled or conversational features, which may include prompts, instructions, connected service information, generated output, and related usage data.
North may collect personal information:
- Directly from you when you submit a form, request a demo, create an account, use the Services, contact support, participate in an event or promotion, or apply for a role.
- From the customer, employer, or organization with which you are associated, including when an administrator creates or manages your account.
- Automatically from websites, applications, devices, connected cloud accounts, cookies, and product telemetry.
- From service providers, business partners, event partners, and publicly available professional sources, such as company websites or professional networking platforms.
North may use personal information to:
- Provide, operate, maintain, secure, troubleshoot, and support the Services.
- Create and administer accounts, authenticate users, manage permissions, and communicate service-related information.
- Respond to inquiries, provide demonstrations, manage customer and prospect relationships, and deliver requested information.
- Analyze website and Service usage, improve functionality and reliability, develop new features, and understand customer needs.
- Detect, investigate, and prevent fraud, misuse, security incidents, and violations of applicable terms.
- Manage billing, contracts, audits, compliance obligations, corporate transactions, and other internal business operations.
- Administer events, promotions, recruiting, and marketing communications, subject to applicable law and your communication preferences. As part of recruiting, North may use AI tools to help review, analyze, or summarize job applications; final hiring decisions are made by North’s hiring team, not by AI, and applicants may opt out of AI-assisted review by notifying their recruiter in writing
- Comply with legal obligations, respond to lawful requests, establish or defend legal claims, and protect North, its users, and others.
Where GDPR, UK GDPR, or similar law applies, North relies on one or more lawful bases, which may include performance of a contract, steps requested before entering into a contract, compliance with legal obligations, consent, and North's legitimate interests in operating, securing, improving, and promoting its business and Services, provided those interests are not overridden by your rights and interests.
Use of the North website
As is true of most websites, North's website collects certain information automatically and stores it in log files. This information may include IP addresses, the region or general location from which a computer or device accesses the internet, browser type, operating system, referring pages, pages viewed, and other usage information. North uses this information to operate and secure the website, diagnose technical issues, analyze trends, understand visitor activity, improve website content and navigation, and better suit users' needs.
North may use IP address and similar information to help diagnose problems with its servers, administer the website, prevent abuse, gather broad statistical information, and understand how customers and potential customers use the website. This assists North in providing more relevant products and services and planning appropriate resources to meet customer needs.
If you submit a form, request a demo, register for an event, subscribe to communications, or otherwise contact North through the website, North will use the information you provide to respond, manage the relationship, and provide relevant information about North and its Services. You may unsubscribe from marketing emails through the unsubscribe link in the message. North may continue to send service or transactional communications where needed to administer an account or provide the Services.
The North website may contain links to or integrations with third-party websites and services. Their privacy practices are governed by their own privacy notices, and North is not responsible for those practices.
Cookies and tracking technologies
North and its service providers may use cookies, pixels, local storage, and similar technologies to operate the website, remember preferences, understand website use, measure performance, and support communications and marketing. These technologies may include:
- Strictly necessary technologies required for website functionality, security, and user-requested services.
- Functional technologies that remember choices and improve user experience.
- Analytics technologies that help North understand traffic, usage, and website performance.
- Advertising or social-media technologies, if used, that help measure campaigns or provide more relevant communications.
You can manage available choices through the Cookie Settings link on the North website and through your browser settings. Where required by law, North will request consent before using non-essential cookies or similar technologies. Disabling certain technologies may affect website functionality.
Use of North services
North provides cloud cost visibility, optimization, commitment-management, analytics, and related services. To provide these Services, North may process account information, cloud account identifiers, resource identifiers, cloud cost and usage records, tags, configuration metadata, system and security logs, support information, and Service usage information. The specific information processed depends on the Services selected, the connected cloud environment, customer configuration, and the permissions granted by the customer.
Customers are responsible for configuring their use of the Services, obtaining any required permissions or notices, and determining what data is made available to North. Customers and users must not submit special-category, highly sensitive, or regulated personal information through the Services unless North has expressly agreed to such processing in writing and appropriate contractual and security requirements are in place.
When North processes customer data under a customer's instructions, the customer remains responsible for its own privacy notice and for responding to requests from individuals. Individuals seeking to exercise rights regarding customer-controlled data should ordinarily contact the relevant customer. North will assist customers as required by the applicable DPA and law.
North may also provide AI-enabled or conversational features. Information submitted to those features may be processed to generate requested output, maintain security, troubleshoot, support users, and improve the reliability and performance of the feature, subject to the applicable customer agreement, DPA, and North's AI Policy.
When and how we share information with third parties
The personal information North collects may be stored in databases and systems hosted by North or by third-party service providers located in the United States and other countries. North requires service providers to process personal information only for authorized purposes and subject to appropriate contractual and security obligations.
North may disclose personal information to:
- Cloud hosting, infrastructure, authentication, security, monitoring, analytics, communications, customer-support, payment, marketing, recruiting, and other service providers that perform functions on North's behalf;
- Customers and authorized account administrators where needed to provide or administer the Services;
- Business partners, event partners, or promotion partners where needed to provide a requested activity and consistent with the notice provided at collection;
- Professional advisers, including auditors, accountants, attorneys, insurers, and consultants, where necessary for legitimate business, legal, security, and compliance purposes;
- Government authorities, courts, regulators, law enforcement, or other parties where North reasonably believes disclosure is required by law or necessary to protect rights, safety, property, or the integrity of the Services;
- Parties involved in a merger, financing, acquisition, reorganization, bankruptcy, sale of assets, or similar corporate transaction, subject to appropriate confidentiality protections; and
- Other parties with your consent or at your direction.
North may gather and disclose aggregated or de-identified information that cannot reasonably be used to identify an individual, subject to applicable law.
North maintains a list of subprocessors used to provide the Services. https://trust.north.cloud/subprocessors
North does not sell personal information. North will provide any additional disclosures or opt-out mechanisms required if its use of advertising or analytics technologies constitutes a “sale,” “sharing,” or targeted advertising under applicable U.S. state privacy laws.
Transferring personal data to the U.S. and other countries
North is headquartered in the United States. Information North collects may be processed in the United States and in other countries where North or its service providers operate. Those countries may have data protection laws that differ from the laws where you live.
Where required by applicable law, North uses appropriate safeguards for international transfers of personal information. These safeguards may include the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, and contractual, organizational, and technical measures designed to protect personal information. North may also rely on other transfer mechanisms permitted by applicable law.
North enters into data processing agreements and appropriate data-transfer terms with vendors and customers where required and appropriate. You may contact North for additional information about the transfer mechanism applicable to your personal information.
Data subject rights
The European Union's General Data Protection Regulation (GDPR), the UK GDPR, and other privacy laws provide certain rights for individuals. Depending on your location and the law that applies, those rights may include:
- The right to be informed about processing.
- The right to request access to personal information.
- The right to request correction of inaccurate personal information.
- The right to request deletion, subject to applicable exceptions.
- The right to request restriction of processing.
- The right to data portability.
- The right to object to certain processing, including direct marketing.
- The right to withdraw consent where processing is based on consent.
- Rights relating to certain automated decision-making or profiling.
- The right to lodge a complaint with an applicable data protection authority.
This Privacy Policy is intended to provide information about what personal information North collects and how it is used. You may request information about the purposes of processing, the categories of personal information involved, the recipients of the information, the source of information not obtained directly from you, and the period for which the information will be retained. You may also request correction, deletion, restriction, portability, or objection, subject to applicable legal exceptions.
Residents of certain U.S. states may also have rights to know, access, correct, delete, or obtain a portable copy of personal information; opt out of certain sales, sharing, targeted advertising, or profiling; limit certain uses of sensitive information; and appeal a decision regarding a privacy request. These rights apply only to the extent North is subject to the applicable law.
To submit a request regarding personal information for which North is the controller, contact North using the information below. North may need to verify your identity and authority before completing a request. North will not discriminate against you for exercising a privacy right. If your request concerns customer-controlled data processed by North on behalf of a customer, please contact that customer directly; North will assist the customer as required by contract and law.
If you are located in the European Economic Area or the United Kingdom, you may lodge a complaint with the data protection authority in your country of residence or work, or where you believe an infringement occurred.
Security of your information
North maintains administrative, technical, and organizational safeguards designed to protect personal information against unauthorized access, loss, misuse, alteration, or disclosure. Depending on the system and data involved, these measures may include access controls, multi-factor authentication, encryption in transit and at rest, logging and monitoring, vulnerability management, secure development practices, incident response procedures, personnel training, device security controls, and vendor risk management.
No system or method of transmission is completely secure, and North cannot guarantee absolute security. If you believe your interaction with North is no longer secure or that your account may have been compromised, please contact North promptly at support@north.cloud.
Data storage and retention
Personal information is stored by North on systems operated by North and by cloud-based service providers that North engages, primarily in the United States and, where applicable, other countries. North retains personal information only for as long as reasonably necessary for the purposes described in this Privacy Policy, including to provide and secure the Services, maintain business and compliance records, comply with legal and contractual obligations, resolve disputes, and enforce agreements.
Retention depends on the category and context of the information. In general:
- Customer account and relationship information is retained for the duration of the customer relationship and for an appropriate period afterward to meet contractual, legal, audit, and business-record requirements.
- Customer data processed through the Services is retained and deleted in accordance with the applicable customer agreement, DPA, customer instructions, and North's data retention and deletion procedures.
- Website, prospect, and marketing information is retained while it remains relevant to the relationship or business purpose, subject to opt-out rights and periodic review.
- Support, diagnostic, security, and audit records are retained based on security, operational, legal, and contractual needs.
- Event, promotion, recruiting, and shipping information is retained for the period needed to administer the activity and satisfy related legal or recordkeeping obligations.
When personal information is no longer needed, North will delete, de-identify, or securely dispose of it, subject to legal holds, backup cycles, fraud-prevention needs, and other lawful exceptions. Personal information that North controls may be deleted in response to a verified request where required by law and where no lawful exception applies.
Children’s data
North's websites and Services are intended for business users and are not directed to children. North does not knowingly attempt to solicit or collect personal information from children. If you believe a child has provided personal information to North, please contact North so that appropriate action can be taken.
Questions, concerns, or complaints
If you have questions, concerns, complaints, or would like to exercise a privacy right, please contact North at:
- North Cloud Holdings, Inc.
- 55 Washington Street, Suite 902, Brooklyn, NY 11201
- support@north.cloud
If you are located in the European Economic Area or United Kingdom, you may also have the right to lodge a complaint with the data protection authority in your country of residence or work, or where you believe an infringement occurred.