Privacy Policy Terms of Service Twin Studio

Privacy Policy

Effective date: June 11, 2026

Last updated: June 11, 2026

1. Who we are

This Privacy Policy explains how Noord Studio ("Noord Studio," "we," "us," or "our") collects, uses, shares, and protects personal data when you visit noord.design, contact us about studio work or Twin Studio access, or use Twin Studio (collectively, the "Services").

  • Data controller: Noord Studio LTDA, CNPJ 64.592.227/0001-56
  • Registered address: 777 Paulista Avenue, 15th Floor, Suite 2242, São Paulo, SP 01311-914, Brazil
  • Contact for privacy matters: legal@noord.design

If you have questions about this Policy or how we handle your personal data, contact us at the address above.

2. Scope

This Policy applies to:

  • Visitors to noord.design and the Twin Studio marketing page (/twin)
  • People who email us a project inquiry or Twin Studio beta request
  • Users who create an account or otherwise access Twin Studio (when available)
  • Authorized users of OAuth-gated internal documentation at /docs/* (invite-only)

It does not cover third-party websites or services we link to, which have their own privacy policies.

3. What personal data we collect

3.1 Information you provide directly

Category Examples When collected
Contact details Name, email address, company name, role Email to studio@noord.design or beta@noord.design
Project information Description of your project, budget range, timeline, attachments you choose to share Project inquiry emails
Beta request details Email, team size, optional note Twin Studio beta request emails
Account information Name, email, password (hashed), workspace/organization details Twin Studio account creation
Product content Files, prompts, configurations, and other content you create or upload within Twin Studio Use of Twin Studio
Communications Messages you send us via email Any direct contact

3.2 Information collected automatically

Category Examples Source
Server and security logs IP address, browser type, request timestamps, pages requested Hosting provider (Vercel) when you load our site or APIs
Cookies and similar technologies Session cookies for login; sidebar and onboarding state cookies in Twin Studio Authentication and product functionality
Local storage preferences Theme choice (noord-theme) on marketing pages Your browser, only if you change appearance settings

We do not currently use third-party analytics or advertising trackers on noord.design or /twin.

3.3 Information from third parties

If you sign in with Google OAuth (internal docs or Twin Studio), we receive your name and email address from Google consistent with your Google account settings. If you interact with us via a third-party platform (e.g., LinkedIn or a scheduling tool), we may receive limited information from that platform consistent with your settings there.

4. How we use personal data

We use personal data to:

  1. Respond to project inquiries and Twin Studio beta requests
  2. Provide, maintain, secure, and improve noord.design and Twin Studio
  3. Create and manage Twin Studio user accounts and workspaces
  4. Send product or studio updates you have asked to receive (with the ability to opt out at any time)
  5. Detect, prevent, and address fraud, abuse, security incidents, and technical issues
  6. Comply with legal obligations, and establish, exercise, or defend legal claims

5. Legal bases for processing

Brazil (LGPD — Law No. 13,709/2018)

We rely on the following legal bases under Article 7 of the LGPD, as applicable:

  • Consent — where you opt in to optional communications
  • Legitimate interests — for responding to inquiries, securing our Services, and operating our website, balanced against your rights and freedoms
  • Contract performance — for providing Twin Studio to registered users
  • Legal obligation — where required by Brazilian law (e.g., tax or accounting records)

EU/UK visitors (GDPR / UK GDPR)

If you are located in the European Economic Area or United Kingdom, we process personal data on the following bases under Article 6 GDPR:

  • Consent (Art. 6(1)(a)) — optional marketing communications
  • Contract (Art. 6(1)(b)) — providing services you request, including Twin Studio accounts
  • Legitimate interests (Art. 6(1)(f)) — operating, securing, and improving our Services
  • Legal obligation (Art. 6(1)(c)) — where required by EU/UK law

California residents (CCPA/CPRA)

We do not sell or share personal data, as those terms are defined under the CCPA/CPRA, for cross-context behavioral advertising. Section 9 describes the rights available to California residents.

6. Cookies and similar technologies

noord.design and Twin Studio may use:

  • Strictly necessary cookies — required for authentication, session management, and security (e.g., Twin Studio login, internal docs OAuth, invite flows)
  • Functional storage — theme preference stored in your browser (localStorage) on marketing pages when you choose Light or Dark mode

We do not set analytics or advertising cookies on the public marketing site. Where we add non-essential cookies in the future, we will request consent where required by applicable law before setting them.

7. How we share personal data

We do not sell personal data. We may share personal data with:

  • Service providers / processors acting on our behalf (see Section 8)
  • Professional advisors (lawyers, accountants, auditors) where necessary
  • Authorities where required to comply with a legal obligation, court order, or to protect our rights, property, or safety, or that of others
  • A successor entity in connection with a merger, acquisition, financing, or sale of assets, subject to standard confidentiality protections

All third-party processors are required to handle personal data under contractual confidentiality and security obligations consistent with the LGPD, GDPR, and other applicable laws.

8. Subprocessors and international data transfers

Noord Studio is based in Brazil. Personal data may be processed in countries outside Brazil when our subprocessors operate there, including the United States and the European Union.

We currently use the following categories of subprocessors:

Provider Purpose Typical data Primary processing region
Vercel Website and API hosting, server logs IP address, request metadata, page URLs United States / global edge
Resend Transactional email delivery (when configured) Email address, message content for notifications United States
Google OAuth sign-in for internal docs and Twin Studio Name, email address United States / global
AI model providers (e.g., Google Gemini, Anthropic, OpenAI, via configured API) Twin Studio conversation generation Prompts and content you submit in Twin Studio United States / varies by provider

Where we transfer personal data internationally, we rely on appropriate safeguards required by applicable law, such as LGPD-recognized transfer mechanisms (Art. 33), including standard contractual clauses approved by the ANPD where applicable, and Standard Contractual Clauses (SCCs) under the GDPR, where relevant.

9. Your privacy rights

9.1 Brazil (LGPD)

Under the LGPD, you have the right to:

  • Confirm whether we process your personal data
  • Access your personal data
  • Correct incomplete, inaccurate, or outdated data
  • Request anonymization, blocking, or deletion of unnecessary or excessive data, or data processed in non-compliance with the LGPD
  • Request portability of your data to another provider
  • Obtain information about public and private entities with which we have shared data
  • Withdraw consent at any time, where processing is based on consent
  • Object to processing carried out on the basis of legitimate interest
  • Lodge a complaint with the Autoridade Nacional de Proteção de Dados (ANPD)

9.2 EU/UK residents (GDPR / UK GDPR)

You have the right to: access, rectify, erase, restrict, or object to processing of your personal data; data portability; and to lodge a complaint with your local supervisory authority (e.g., a national Data Protection Authority in the EU, or the ICO in the UK). Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.

9.3 California residents (CCPA/CPRA)

Subject to certain exceptions, California residents have the right to: know what personal information is collected, used, shared, or sold; request deletion; request correction; opt out of the sale or sharing of personal information (we do not currently sell or share personal information); limit use of sensitive personal information; and not be discriminated against for exercising these rights.

9.4 How to exercise your rights

To exercise any of these rights, contact us at legal@noord.design. We will respond within the timeframe required by applicable law (e.g., generally 15 days under the LGPD, extendable once by 15 days; one month under the GDPR, extendable by two further months for complex requests; 45 days under the CCPA, extendable once by 45 days). We may need to verify your identity before fulfilling certain requests.

10. Data retention

We retain personal data only for as long as necessary for the purposes described in this Policy, including to comply with legal, accounting, or reporting requirements. Specifically:

  • Project inquiry and beta request emails: retained for 45 days from last contact, or until you ask us to delete them
  • Twin Studio account data: retained for the duration of your account, plus 30 days after account closure for legal/operational purposes
  • Server logs: retained according to our hosting provider's default retention, typically up to 30 days unless needed for security investigation

11. Children's privacy

Our Services are intended for businesses and professionals and are not directed to individuals under the age of 18 (or the age of majority/digital consent in their jurisdiction). We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us so we can delete it.

12. Security

We implement technical and organizational measures designed to protect personal data against unauthorized access, alteration, disclosure, or destruction, consistent with the security obligations of the LGPD (Art. 46) and applicable international standards. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

13. Changes to this Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. We will post the revised version with an updated "Last updated" date and, where required by law, provide additional notice (e.g., for material changes affecting Twin Studio account holders).

14. Contact us

For any questions, requests, or complaints regarding this Privacy Policy or our data practices, contact:

Noord Studio Email: legal@noord.design

If you are located in Brazil and are not satisfied with our response, you may also contact the ANPD (Autoridade Nacional de Proteção de Dados) at gov.br/anpd.

© 2026 Noord Studio LTDA · CNPJ 64.592.227/0001-56 · legal@noord.design