Terms
The terms we work under
Sections 5 to 9 are the data processing agreement required by law. Accepting these terms puts it in place, so you do not need a separate signed document before going live, and you can show this page to a funder as it stands.
Last updated: 19 August 2026
01Who provides Noma
Noma is provided by CreativMaro SRL, registration number 1009600037044, str. Calea Iesilor 16, no. 3, ap. 8V, MD-2069, Chisinau, Republic of Moldova. Subscriptions are billed by Create Go LLC, 7901 4th St N, STE 300, St. Petersburg, FL 33702, United States.
In these terms, you means the organisation using Noma, and we means CreativMaro SRL. Creating an account means accepting these terms on behalf of your organisation.
02Your account and your people
You decide who in your organisation gets access and at what level. Noma gives you role and field level permissions precisely so that a case worker, a medical role, an external agency and an analyst see different parts of the same record. Configuring those roles correctly is your responsibility, and it is the single most important control you have.
You are responsible for what the people you authorise do inside your account. Tell us immediately if you suspect an account has been compromised; given the nature of the data, we treat these reports as urgent.
03Subscription and payment
The subscription is billed for the period shown at purchase and renews until you cancel. Prices are those published at the time of payment.
If your organisation depends on grant funding with a fixed end date, tell us in advance and we will align the billing period to it rather than renew automatically into a period you cannot fund.
04Availability and support
We make reasonable efforts to keep Noma available continuously, but we do not guarantee uninterrupted operation. We perform maintenance and our providers can have incidents.
Noma organises information and enforces the access rules you configure. The casework decisions themselves remain yours, and we are not liable for outcomes arising from them.
05Who controls the data
The case data you enter belongs to your organisation. Under Law no. 195/2024, you are the controller: you decide which beneficiaries are registered, which fields exist, who sees what, and how long records are kept.
We are the processor. We keep the software running and process the data only to provide the service to you. Sections 5 to 9 constitute the processing agreement required by art. 28(3), concluded in electronic form as permitted by art. 28(8).
The subject matter is the provision of Noma; the duration is the term of the contract; the nature and purpose are case management and referral; the categories of data subjects are the beneficiaries, family members, staff and external contacts you register; and the categories of personal data are those your own configuration defines, which may include special categories under art. 9 such as health, medical needs and disability, and data concerning children.
06What we commit to as processor
- We process personal data only on your documented instructions, which include your normal use and configuration of Noma, unless the law requires otherwise. If such an obligation arises, we inform you before processing, unless the law forbids that notice.
- Everyone on our side with access to personal data is bound by confidentiality, and access is limited to what is needed for support and operation.
- We apply the technical and organisational measures required by art. 32, including a separate restricted store for case data, permissions enforced per field, audit logging of reads and changes, and encryption in transit.
- We assist you in answering requests from beneficiaries exercising rights under art. 15 to 22, through export, correction, consent withdrawal and complete erasure functions in the product.
- We help you meet your obligations under art. 32 to 36, including your data protection impact assessment, by providing the technical description of how Noma processes and protects the data.
- We notify you without undue delay of any personal data breach affecting your data, as required by art. 33(2), with what we know about it, so that you can meet your own 72-hour deadline towards the Centre under art. 33(1).
- On termination we return or delete your data, at your choice, and remove existing copies, except what the law requires us to keep.
- We make available the information you need to demonstrate compliance, and allow reasonable audits and inspections, by you or by an auditor you appoint. Where a funder requires evidence, we will respond to reasonable requests directly.
07Sub-processors
By accepting these terms you give us general written authorisation, under art. 28(2), to engage the sub-processors listed in our Privacy Policy: Google, Vercel, Garage running on servers in France, OpenAI for assisted data entry, and MyMemory for interface labels only.
We inform you in advance of any intended addition or replacement, and you may object. We remain fully liable to you for the performance of each sub-processor's obligations.
Uploaded documents and attachments are stored in France, within the European Economic Area, which requires no transfer formality under art. 44(2). Transfers to providers in the United States rely on standard contractual clauses under art. 46(2)(c).
08Special categories, and what is on you
Because Noma is used for child protection and gender-based violence casework, the data usually falls under art. 9, where processing is prohibited unless a specific exception applies. Identifying that exception is yours to do, before you start, and it is normally found in the legal mandate or the service agreement under which your organisation works.
Two further responsibilities are yours and cannot be delegated to us:
- Carrying out a data protection impact assessment under art. 35 before processing at scale. We give you the technical input; the assessment and the decision are yours.
- Informing beneficiaries about the processing in a way appropriate to their situation. We have no contact with them and cannot do this on your behalf.
Please also configure only the fields you genuinely need. Every additional sensitive field is a risk you carry, not one the software removes.
09Security incidents
If we become aware of a personal data breach affecting your data, we notify you without undue delay and give you what you need for your own notification: what happened, which records were involved, the likely consequences, and the measures we took.
We keep documentation of every breach, as required by art. 33(5), and make it available to you and, on request, to the Centre.
10Ending the contract
You may leave at any time by cancelling. We may end the contract if you seriously breach these terms, after notice and a reasonable period to put it right, except in cases of obvious abuse.
After termination we keep your data for 30 days so you can export it, then remove it. If you need a longer window because of an ongoing handover to another organisation, ask us before the period ends; given what this data is, we would rather extend than let records be lost.
11Changes and applicable law
When we change something material we tell you by email or in the application at least 30 days beforehand. If you disagree, you can cancel before it takes effect. Where the Centre approves standard contractual clauses under art. 28(7), we will align these terms with them.
This contract is governed by the law of the Republic of Moldova. We try to settle disagreements directly first; failing that, the courts of the Republic of Moldova have jurisdiction.
Need this as a signed document?
Accepting these terms already puts the processing agreement in place. If your funder or your legal team needs a separately signed copy, or a version on your own template, write to support@creatego.net and we will prepare it.
