Privacy
Who controls the data, and who to ask
Noma holds some of the most sensitive information an organisation can hold. This page explains a distinction that matters more here than anywhere else: your organisation decides what happens to case data, and we only act on its instructions.
Last updated: 19 August 2026
01Two roles, and why the difference matters
When an organisation uses Noma to manage cases, the organisation is the controller. It decides which beneficiaries are registered, which fields are collected, who on its staff sees what, and how long records are kept. We are the processor: we run the software and act on its documented instructions.
This is not a formality. If you are a beneficiary and want to know what is held about you, to correct it, or to have it erased, address the organisation working with you, not us. We will support them technically, but the decision is theirs, and only they can verify who you are without putting you at risk.
For the accounts of staff who sign in, and for our own website, we are the controller.
02Who we are
Noma is built and operated by CreativMaro SRL, registration number 1009600037044, str. Calea Iesilor 16, no. 3, ap. 8V, MD-2069, Chisinau, Republic of Moldova.
Write to support@creatego.net with any question about this policy, or if you are an organisation that needs our help answering a request from a beneficiary.
We process personal data under Law no. 195/2024 on personal data protection of the Republic of Moldova, applicable from 23 August 2026, and, where organisations or beneficiaries are in the European Economic Area, under Regulation (EU) 2016/679.
03Special categories of data
Case records may include information about health, medical needs, disability, the nature of an incident, and children. Under art. 9 these are special categories, prohibited from processing unless a specific exception applies. The organisation, as controller, identifies that exception before it starts.
Because of this, we treat the case data differently from ordinary business records, and we hold it under the arrangements described in section 5.
04What each organisation decides for itself
Noma does not impose a fixed form. Each organisation configures which fields exist, which roles may read or write each field, and which service catalogue it uses. That means the exact data held varies between organisations, and only the organisation can give a complete list of what it collects.
We never use case data for our own purposes: not to train models, not for statistics across organisations, not for product analytics.
05How the data is protected
- Case data is held in a separate, restricted store rather than alongside general records, so that access can be controlled independently.
- Permissions apply per field, not only per page. A medical role, a case worker, an external agency and an analyst each see a different subset of the same record.
- Every read and change is written to an audit log, which stays available to the organisation.
- Erasing a case removes the record, the restricted store, the linked tasks and the uploaded files. What remains is a single entry in the audit log, which is the only evidence that the erasure took place.
- Data is encrypted in transit, and access requires authentication.
06Who else processes the data
We use a small number of providers, each acting as a sub-processor on our instructions:
- Google, for the database and authentication.
- Vercel, for hosting and access logs.
- Garage, running on Contabo servers located in France, for uploaded documents and attachments.
- OpenAI, used narrowly for assisted data entry, never for case narratives. Content is sent with instructions not to be retained or used for model training.
- MyMemory, a translation service used only for interface labels and value lists that an organisation configures, never for case content.
We tell organisations in advance if we intend to add or replace a sub-processor, so they can object, as required by art. 28(2).
07Where the data is stored
Uploaded documents and attachments are stored on servers in France. Being within the European Economic Area, these transfers require no additional formality under art. 44(2) of Law no. 195/2024.
Some providers process data in the United States. Those transfers rely on standard contractual clauses, a mechanism allowed without prior authorisation by art. 46(2)(c). Organisations may request a copy of these safeguards.
08How long data is kept
Retention for case data is set by the organisation, which knows its own legal and funding obligations. We keep the data for as long as the organisation instructs, and delete or return it when the service ends, as required by art. 28(3)(g).
For data we control ourselves: staff accounts last for the duration of the agreement plus 30 days; technical logs are kept for 90 days; backups are kept for at most 35 days, after which deleted data is not reintroduced.
09Rights, and how to use them
People have the right of access, rectification, erasure, restriction, portability, and objection, under art. 15 to 22. Where consent was the basis, it can be withdrawn as easily as it was given, under art. 7(3).
For case data these rights are exercised through the organisation, because it is the controller and because verifying identity safely is part of its work. Noma provides the organisation with the tools to answer: exporting a record, correcting fields, withdrawing a sharing consent, and erasing a case completely.
A complaint may be filed with the National Centre for Personal Data Protection, str. Serghei Lazo 48, Chisinau MD-2004, datepersonale.md, or with a court.
10Security incidents
If a personal data breach occurs, we notify the affected organisations without undue delay, as required by art. 33(2), so they can meet their own 72-hour notification duty under art. 33(1). We give them what they need for that notification: what happened, which records were involved, and what we did about it.
Where we are the controller, for staff accounts and this website, we notify the Centre directly within the same 72 hours.
11Cookies
This website uses only what is strictly necessary to work: your session, your language choice, and security. There are no analytics or advertising trackers, so there is nothing to consent to and nothing to refuse.
If you are an organisation evaluating Noma
You will need a written processing agreement with us before going live, and most funders will ask for it. We also provide the technical description you need for your own data protection impact assessment, which is your responsibility as controller under art. 35.
How we handle security